Dlocal

Senior Cyber Assurance Partner - Third-Party Risk

Sao Paulo (Hybrid) / Buenos Aires / Montevideo (Hybrid) / Madrid / Barcelona / Romania Full Time
Why should you join dLocal?

dLocal enables the biggest companies in the world to collect payments in 40 countries in emerging markets. Global brands rely on us to increase conversion rates and simplify payment expansion effortlessly. As both a payments processor and a merchant of record where we operate, we make it possible for our merchants to make inroads into the world’s fastest-growing, emerging markets. 

By joining us you will be a part of an amazing global team that makes it all happen. Being a part of dLocal means working with 1000+ teammates from 30+ different nationalities and developing an international career that impacts millions of people’s daily lives. We are builders, we never run from a challenge, we are customer-centric, and if this sounds like you, we know you will thrive in our team.




About Us & The Role

We do not do "check-box" compliance, and we don’t do corporate fluff.

Within the Security Department, under the guidance of the CISO and security leadership, our GRC and Assurance team operates with a street-smart, pragmatic approach. We are looking for a versatile, self-driven Senior Cyber Assurance Partner to completely disrupt how we handle Third-Party Risk Management (TPRM).

Traditionally, TPRM is a bureaucratic bottleneck—sending 200-question spreadsheets and blocking procurement for months. We don't want that. Our business relies on hundreds of third-party providers globally—including payment processors, financial institutions, infrastructure providers, and technology vendors—often in emerging markets where there is a gap between standard compliance checklists and actual operational security reality.

We need a visionary builder who hates the traditional TPRM status quo. You will operate at the intersection of vendor governance, security assurance, and enterprise risk management to help us implement and scale our global Payment Processor Assessment Framework. You will build a pragmatic, tiered system that skips deep reviews for low-risk vendors so the business can move fast, while focusing intense scrutiny on critical partners. You will define technical flows for AI agents to chase vendors, extract data, and shift accountability back to the business owners.

You don't need to be a software developer, but you must be highly technical, AI-fluent, and capable of working with our security engineers to build automated workflows. Most importantly, you must have the grit to roll up your sleeves and do the manual work with your own hands until those automated systems are fully built. You will have the CISO and security leadership as your executive sponsors to make pragmatic trade-offs and drive results.