Job Description
Company Overview
If you see technology as a way to smooth your path in life, our team does too: Your Path, Our Journey.
We believe in technology that connects talented people who embrace diversity to create and share paths we don't even know about (yet!). We work to generate value not only for our users but, above all, for the communities we serve and for society as a whole, making every day better for everyone with mobility and delivery services (99) or digital payments (99Pay).
To make life easier for millions of people every day, since 2018, we have been part of DiDi DiDi Global Inc., the world’s leading mobility technology platform. We are pioneers in creating innovative solutions that start in Brazil and scale up to make a positive impact in more than 12 countries where DiDi operates. This innovation encompasses sustainability, safety, artificial intelligence, financial markets, and much more.
Whether building projects from scratch or improving our solutions, we enjoy challenges that give us butterflies, which is why we work at a fast pace with respect, collaboration, and good humor. Along this journey, we also draw strength from diverse experiences and opinions to grow together, fail quickly, learn, and adjust the course to create solutions that deliver even better results.
#LI-Hybrid
Team Overview
We are seeking a detail-oriented and motivated Information Security Expert to join our Fintech Information Risk & Security Tech team in Brazil. This role focuses on ensuring data security compliance and risk remedation within our BPO (Business Process Outsourcing) operations management. You will be responsible for implementing BPO security governance, workplace(site) security check, personnel access control and indentity management and ensuring that our BPO partners adhere to our security standards. And Vendor risk assessement, Vulnerability management, Regulatory analysis and audit response.
Role Responsibilities
- Ecosystem Onboarding Technical Assessment: Conduct security assessments for overseas ecosystem partners (merchants, channels, service providers, etc.) during the onboarding process. Deeply evaluate their enterprise security architecture, API interface security, data encryption schemes, and compliance qualifications. Output technical assessment conclusions and drive the closure of remediation actions.
- Vulnerability Management & Risk Operations: Implement and execute the domestic HQ's security operations SOPs. Analyze security risks in overseas business based on vulnerability scans, penetration testing, or daily monitoring results. Guide and drive partners to complete vulnerability remediation and verification to ensure timely risk mitigation.
- Regulatory Review & Audit Response: Act as the overseas security liaison to cooperate with local regulatory authorities (e.g., central banks, data protection bureaus) and external auditors during inspections and inquiries. Prepare technical evidence regarding system architecture and security policies, and draft compliance reports.
- Security Standard Localization & Enablement: Assist the Team Lead in promoting and adapting HQ's security control standards and AI-driven automated assessment strategies for overseas business lines. Translate complex compliance requirements (e.g., PCI-DSS) into actionable technical baselines, collect frontline feedback from overseas teams, and contribute to the continuous improvement of security capabilities.
Role Qualifications
- Education & Experience: Bachelor’s degree or above in Computer Science, Information Security, or related fields.
- Experience in information security, security architecture, or security operations. Prior experience in overseas finance, cross-border payments, or global internet companies is highly preferred.
- Technical & Architecture Capabilities: Solid technical foundation in security, with a strong understanding of enterprise security architecture design, common Web/API vulnerability principles, and remediation strategies. Familiarity with data lifecycle encryption and security baseline configurations for mainstream cloud platforms (AWS/GCP/Azure).
- Compliance & InfoSec Knowledge: Familiarity with major overseas data privacy regulations (e.g., GDPR, CCPA) and financial security standards (e.g., PCI-DSS, ISO27001). Ability to translate compliance requirements into actionable technical metrics.
- English Proficiency: Fluent in English as a working language. Excellent cross-cultural communication skills, with the ability to independently draft technical compliance reports in English, respond to regulatory inquiries, and handle email communications.[
- Operations & Resilience: Strong execution and closed-loop thinking skills. Ability to independently drive cross-functional collaboration with limited resources, and handle unexpected security incidents or regulatory inquiries calmly.
- Bonus Points: Certifications such as CISSP, CCSP, CISP-PTE, or CISA are highly preferred. Prior experience in Information Security/Compliance Auditing (technical focus) at Big 4 firms or renowned consulting companies is a plus.
EEO Statement
- We create customer value – We strive to always create valuable experiences for our users in everything we do. Our focus is to always innovate new experiences that are safe, pleasant, and efficient.
- We are data-driven – We are strong believers in making informed decisions, that’s why we are data-driven. We can better navigate the business landscape strategically by analyzing valuable metrics.
- We believe in Win-win Collaboration – Success is a team sport. When we work to help our partners and colleagues win, we win, too. While keeping everyone's best interest at heart, we communicate with candor and execute with excellence in all we do.
- We believe in integrity – Integrity is at the very core of our business. We are people who always want to do the right thing. Our intentions are sincere, we speak our minds and listen to each other.
- We always strive to do better. That means venturing beyond our comfort zones, learning from our mistakes, and helping each other grow.
- We believe in Diversity and Inclusion – Diversity is one of our biggest strengths. Our differences are what makes us distinct. We respect each other and believe in equal opportunities for all.
Diversity & Inclusion
Diversity is not a future vision or a wish for something we want someday; it is a non-negotiable value of who we are today.
We embrace inclusion, plurality, and respect, and to achieve this, we rely on the governance of the Diversity Committee, which works alongside HR, our leadership, and identity groups—99Adapta, 99Afro, 99Colors, 99Womem, and 99Familys.
This is our ongoing journey, with much more still to come.
We reinforce that this position is open to everyone, including pregnant people and people with disabilities (PwD). I acknowledge that prior to submitting this application, I have read and accepted the Privacy Notice for Candidates which is available on https://careers.didiglobal.com/terms