$ cat ricardo-resume.md
Ricardo Lewin Lewinsohn
Senior GRC Analyst
- Location
- Brazil — remote or relocation
- Languages
- Portuguese (native), English (full professional)
01 / profile
Professional summary
I design and operate security and compliance programs for high-growth technology companies, translating risk and control requirements into practical, scalable operating processes.
Focused on connecting governance, business priorities, and technical execution through practical, collaborative, and evidence-driven programs.
02 / expertise
Core expertise
Compliance & Assurance
Control design, evidence quality, audit readiness, and continuous compliance across complex security frameworks.
PCI DSS · SOC 2 · ISO 27001 · Audit ReadinessRisk & Resilience
Enterprise risk assessment, accountable treatment plans, business continuity, and disaster recovery practices.
Risk Management · BCP · DR · ISO 22301GRC Engineering
Platform ownership, workflow automation, service design, and practical integrations that make governance scale.
Automation · AuditBoard · Intake · Evidence03 / experience
Professional experience
Senior GRC Analyst
TRACTIAN
Leading risk management, business continuity, disaster recovery, and broader GRC initiatives at an industrial technology company that combines software, hardware, IoT, and AI for maintenance and reliability operations.
- Established an official GRC intake process and launched an internal help center.
- Automated security questionnaire workflows to improve consistency and response efficiency.
- Conducted risk assessments across business functions and created the enterprise risk management program.
- Improved governance documentation and implemented workflow automations.
- Developed business continuity and disaster recovery practices alongside the broader compliance program.
Information Security Analyst III
Azion
Progressed from IT Operations Intern to Information Security Analyst III, moving from scalable IT operations and endpoint governance into ownership of GRC programs, risk management, and audit readiness.
- Information Security Analyst III
- Information Security Analyst II
- Information Security Analyst I
- IT Operations Analyst II
- IT Operations Intern
- Delivered full PCI DSS 4.0.1 compliance, implementing newly applicable requirements ahead of schedule.
- Led and matured GRC programs across PCI DSS, SOC 2, and ISO frameworks.
- Optimized AuditBoard workflows and control structures, reducing audit preparation time by 20%.
- Built Python and workflow automations for compliance operations, evidence collection, and control execution.
- Reduced tooling expenses by BRL 150,000 per year without impacting compliance operations.
- Implemented endpoint and identity controls across 250+ macOS devices and established the first centralized IT asset inventory.
04 / selected work
Selected GRC work
PCI DSS 4.0.1 early adoption
Azion
GRC platform implementation & automation
Azion
GRC intake & questionnaire automation
TRACTIAN
05 / credentials
Credentials & frameworks
Certifications
- ISO/IEC 27001:2022 Lead AuditorMastermind
- ISO/IEC 42001:2023 Lead AuditorMastermind
- Verified Vanta AdminVanta
- JumpCloud Advanced Certification 2025JumpCloud
- ITIL 4 Foundation Certificate in IT Service Management
- AuditBoard Certified Core AdministratorAuditBoard
- Voxy Proficiency Achievement CertificateVoxy
Framework context
SOC 2 · ISO 27001 · ISO 22301 · ISO 42001 · FedRAMP · PCI DSS · LGPD · GDPR
Tools & platforms
Vanta · AuditBoard · OneTrust · AWS · Google Workspace · JumpCloud · Apple Business Manager · Jira & Confluence · Jira Service Management & Assets · Python · n8n · KnowBe4
06 / education
Education
Pontifícia Universidade Católica do Rio Grande do Sul
Bachelor of Business Administration — Information Technology Administration and Management
Columbia International College
Second Language Learning