Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

IT & Compliance Specialist

Latamcent
CompanyLatamcent
CategoryOperations & Admin
LocationBrazil
RemoteHybrid
EmploymentNot stated
LevelNot stated
SalaryUSD 48k–66k
Posted23 Jun 2026
Last verified9 Aug 2026
SourceEmployer ATS (ashby)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
ABOUT THE ROLE We're looking for an experienced IT & Compliance Specialist to own and scale our security compliance program while managing internal IT operations. You'll work closely with Engineering, Operations, and Leadership, supported by the CTO and a part-time consultant with deep SOC 2 and MDM expertise, but day-to-day ownership is yours. KEY RESPONSIBILITIES SOC 2 COMPLIANCE (PRIMARY PRIORITY) - Own and maintain the SOC 2 compliance program: continuous monitoring, audit readiness, evidence collection, and control tracking - Administer Vanta as the primary compliance automation platform, it needs work, and cleaning it up is part of the job - Conduct regular access reviews and ensure documentation is complete and accurate - Facilitate tabletop exercises covering scenarios like AWS outages, cyber incidents, and availability failures - Manage vendor relationships: Vanta contract, pentester engagements, and third-party security assessments - Develop, maintain, and improve information security policies, procedures, and documentation Device Fleet & MDM - Own corporate device management across a mixed fleet of macOS, Linux, and Windows machines - Implement centralized MDM controls: encryption, anti-malware, endpoint detection, and remote management - Establish and enforce a BYOD policy for employees and contractors using personal hardware - Build repeatable onboarding and offboarding processes so device and access controls are never an afterthought Cloud & AWS Compliance - Maintain AWS security hygiene: IAM roles, Identity Center, GuardDuty, AWS Config, and access reviews - Identify and remediate overly permissive roles, stale credentials, and misconfigured controls - Collaborate with the technical team in Caxias do Sul to resolve vulnerabilities and apply patches - Support cloud-related evidence collection for SOC 2 controls IT Operations & Access Management - Own IT onboarding and offboarding: provisioning, deprovisioning, and access controls - Manage access across Google Workspace, Slack, GitHub, Rippling, AWS Identity Center, and other core tools - Serve as the primary internal IT resource and respond to urgent issues as they arise REQUIREMENTS - 3+ years in IT, Security, Compliance, or related roles within a SaaS or high-growth tech environment - Proven hands-on experience managing SOC 2 Type I and/or Type II programs - Direct experience with Vanta, including interpreting findings and driving remediation - Experience managing devices across macOS, Linux, and Windows using MDM tools such as JumpCloud, Jamf, Kandji, or similar - Working knowledge of AWS security: IAM, Identity Center, GuardDuty, AWS Config, and access best practices - Strong understanding of identity and access management, MFA, encryption, endpoint security, and audit controls - C1+ English for daily collaboration with the US-based CTO and leadership - Execution-focused: the CTO and consultant will support you, but the day-to-day needs someone who follows through without being managed step by ste PREFERRED QUALIFICATIONS - Scripting experience (Python preferred) for automating compliance checks or IT workflows - Experience with AI tools such as Claude or ChatGPT applied to compliance or IT operations - Familiarity with our stack: Google Workspace, Slack, GitHub, Rippling, Linear, AWS Identity Center - Experience owning vendor contracts or working with pentesters and external assessors - Prior experience working with or at a US-headquartered company with a Brazilian engineering team - Certifications such as CompTIA Security+, AWS Security, or SOC 2-related credentials are a plus SUCCESS IN THE FIRST 3–6 MONTHS First 60 Days - Every open finding in Vanta has a clear owner and remediation timeline - The device fleet is fully inventoried: what's enrolled, what's not, what needs to happen - Working relationships built with the technical team in Caxias do Sul - Top AWS hy