Logo for Visa

GRC Consultant

Role overview

Qualifications

  • 5 years relevant work experience with a Bachelor's degree or 2 years relevant work experience with an Advanced degree or 0 years relevant work experience with a PhD; OR 8 years relevant work experience
  • Minimum 5 years of experience in Governance, Risk Compliance, Information Security, Risk Management, Internal Audit, or related consulting roles
  • Strong understanding of risk management methodologies and information security governance principles
  • Professional certifications such as CISSP, CISM, CISA, RISC, ISO 27001 Lead Auditor or Lead Implementer, CGRC

Responsibilities

  • Lead the development, maintenance, and continuous improvement of governance frameworks, policies, standards, and procedures
  • Conduct compliance assessments, gap analyses, and maturity reviews, identifying opportunities for control enhancement and process improvement
  • Facilitate enterprise, operational, technology, and cybersecurity risk assessments
  • Support security due diligence activities, client assessments, and assurance requests from financial institutions, partners, regulators, and payment networks

Key facts

  • Remote from: Brazil
  • Freelance
  • Senior (5-10 years)
  • Consultant
  • English

Hard skills

Other skills

  • Governance
  • Analytical Thinking
  • Communication
  • Presentations
  • Report Writing

About the company

Visa logo

Visa

Fintech: Finance + Technology

Visa (NYSE: V) is a world leader in digital payments, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories. Our purpose is to uplift everyone, everywhere by being the best way to pay and be paid. Learn more at Visa.com.

Company details

Company typeXLarge
IndustryFintech: Finance + Technology
Company size10001

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

About Us
Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories, dedicated to uplifting everyone, everywhere by being the best way to pay and be paid.

At Visa, you'll have the opportunity to create impact at scale — tackling meaningful challenges, growing your skills and seeing your contributions impact lives around the world.

Join Visa and do work that matters – to you, to your community, and to the world. Progress starts with you.

Job Description

Job Summary

The Governance, Risk & Compliance (GRC) Consultant is responsible for leading strategic governance, compliance, risk management, audit, and resilience initiatives across Pismo's global operations. This role partners with security, engineering, legal, privacy, product, infrastructure, and business teams to strengthen the company's security and compliance posture while supporting client, regulatory, and Visa requirements.

The successful candidate will provide subject matter expertise across information security governance, regulatory compliance, risk management, audit readiness, third-party risk management, business continuity, and operational resilience. The role requires strong stakeholder management skills and the ability to present complex risk and compliance matters to both technical and executive audiences.


Key Responsibilities:

Governance & Compliance:

  • Lead the development, maintenance, and continuous improvement of governance frameworks, policies, standards, and procedures.
  • Support compliance with industry standards and regulatory requirements, including ISO 27001, SOC 1, SOC 2, PCI DSS, PCI PIN Security, data localisation requirements, and other applicable frameworks.
  • Conduct compliance assessments, gap analyses, and maturity reviews, identifying opportunities for control enhancement and process improvement.
  • Coordinate internal and external audits and support remediation of identified findings.

Risk Management:

  • Facilitate enterprise, operational, technology, and cybersecurity risk assessments.
  • Maintain risk registers and support risk treatment, monitoring, and reporting activities.
  • Collaborate with stakeholders to implement effective mitigation strategies and monitor risk exposure.
  • Prepare executive-level risk reporting and dashboards to support leadership decision-making.

Client & Regulatory Assurance:

  • Support security due diligence activities, client assessments, and assurance requests from financial institutions, partners, regulators, and payment networks.
  • Coordinate responses to regulatory inquiries and examinations.
  • Engage directly with clients and external stakeholders to communicate Pismo's security, compliance, and resilience capabilities.
  • Prepare reports, executive summaries, and evidence packages for customer and regulatory reviews

Strategic Initiatives:

  • Drive continuous improvement initiatives through automation, AI-enabled processes, and operational efficiency programmes.
  • Support the implementation of new compliance and security initiatives resulting from regulatory or business changes.
  • Contribute to organisational security awareness and compliance maturity programmes.
  • Mentor junior GRC professionals and contribute to knowledge sharing across the organisation

This is a remote position. A remote position does not require job duties be performed within proximity of a Visa office location. Remote positions may be required to be present at a Visa office with scheduled notice.

Qualifications

Basic Qualifications:

  • 5 years relevant work experience with a Bachelor's degree or 2 years relevant work experience with an Advanced degree (e.g. Masters, MBA, JD, MD) or 0 years relevant work experience with a PhD; OR 8 years relevant work experience

Preferred Qualifications:

  • Bachelor's degree in Information Security, Cybersecurity, Risk Management, Information Technology, Law, Business Administration, or a related field.
  • Minimum 5 years of experience in Governance, Risk & Compliance, Information Security, Risk Management, Internal Audit, or related consulting roles.
  • Demonstrated experience supporting audits, regulatory reviews, or certification programmes.
  • Strong understanding of risk management methodologies and information security governance principles.
  • Experience interacting with senior stakeholders and executive leadership.
  • Strong analytical, communication, presentation, and report-writing skills.
  • Professional certifications such as:
    • CISSP
    • CISM
    • CISA
    • CRISC
    • ISO 27001 Lead Auditor or Lead Implementer
    • CGRC
  • Experience in banking, payments, fintech, or other highly regulated industries.
  • Familiarity with cloud-native environments and modern software development practices.
  • Knowledge of privacy and data protection regulations.

Visa is an EEO Employer

Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with EEOC guidelines and applicable local law.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Consultant Related jobs

Other jobs at Visa

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.