Back to portfolio

$ cat ricardo-resume.md

Ricardo Lewin Lewinsohn

Senior GRC Analyst

Location
Brazil — remote or relocation
Languages
Portuguese (native), English (full professional)

Professional summary

I design and operate security and compliance programs for high-growth technology companies, translating risk and control requirements into practical, scalable operating processes.

Focused on connecting governance, business priorities, and technical execution through practical, collaborative, and evidence-driven programs.

Core expertise

Compliance & Assurance

Control design, evidence quality, audit readiness, and continuous compliance across complex security frameworks.

PCI DSS · SOC 2 · ISO 27001 · Audit Readiness

Risk & Resilience

Enterprise risk assessment, accountable treatment plans, business continuity, and disaster recovery practices.

Risk Management · BCP · DR · ISO 22301

GRC Engineering

Platform ownership, workflow automation, service design, and practical integrations that make governance scale.

Automation · AuditBoard · Intake · Evidence

Professional experience

Senior GRC Analyst

TRACTIAN

Leading risk management, business continuity, disaster recovery, and broader GRC initiatives at an industrial technology company that combines software, hardware, IoT, and AI for maintenance and reliability operations.

  • Established an official GRC intake process and launched an internal help center.
  • Automated security questionnaire workflows to improve consistency and response efficiency.
  • Conducted risk assessments across business functions and created the enterprise risk management program.
  • Improved governance documentation and implemented workflow automations.
  • Developed business continuity and disaster recovery practices alongside the broader compliance program.

Information Security Analyst III

Azion

Progressed from IT Operations Intern to Information Security Analyst III, moving from scalable IT operations and endpoint governance into ownership of GRC programs, risk management, and audit readiness.

  • Information Security Analyst III
  • Information Security Analyst II
  • Information Security Analyst I
  • IT Operations Analyst II
  • IT Operations Intern
  • Delivered full PCI DSS 4.0.1 compliance, implementing newly applicable requirements ahead of schedule.
  • Led and matured GRC programs across PCI DSS, SOC 2, and ISO frameworks.
  • Optimized AuditBoard workflows and control structures, reducing audit preparation time by 20%.
  • Built Python and workflow automations for compliance operations, evidence collection, and control execution.
  • Reduced tooling expenses by BRL 150,000 per year without impacting compliance operations.
  • Implemented endpoint and identity controls across 250+ macOS devices and established the first centralized IT asset inventory.

Selected GRC work

PCI DSS 4.0.1 early adoption

Azion

Newly applicable requirements delivered ahead of scheduleView public case study

GRC intake & questionnaire automation

TRACTIAN

A scalable entry point for GRC requests and guidanceView public case study

Credentials & frameworks

Certifications

  • ISO/IEC 27001:2022 Lead AuditorMastermind
  • ISO/IEC 42001:2023 Lead AuditorMastermind
  • Verified Vanta AdminVanta
  • JumpCloud Advanced Certification 2025JumpCloud
  • ITIL 4 Foundation Certificate in IT Service Management
  • AuditBoard Certified Core AdministratorAuditBoard
  • Voxy Proficiency Achievement CertificateVoxy

Framework context

SOC 2 · ISO 27001 · ISO 22301 · ISO 42001 · FedRAMP · PCI DSS · LGPD · GDPR

Tools & platforms

Vanta · AuditBoard · OneTrust · AWS · Google Workspace · JumpCloud · Apple Business Manager · Jira & Confluence · Jira Service Management & Assets · Python · n8n · KnowBe4

Education

  • Pontifícia Universidade Católica do Rio Grande do Sul

    Bachelor of Business Administration — Information Technology Administration and Management

  • Columbia International College

    Second Language Learning