Skip to main content
Mayara AbreuMA
Open to opportunities

Mayara Abreu

@mayaraabreu

I’m an IT/IS GRC Analyst bridging law and technology to deliver compliant, auditable risk management.

Brazil
Message

What I'm looking for

I’m looking for a role where I can bridge legal and engineering to build measurable IT GRC programs—mapping controls, managing third‑party risk, and supporting HIPAA/SOC 2 readiness with clear communication and stakeholder alignment.

I’m an IT/IS GRC Analyst recognized for collaboration, clear communication, and building trust across Legal, Technology, and business teams. With a dual background in Law and Technology, I translate complex regulatory requirements into structured controls, policies, and technical evidence that stand up in internal and external audits.

In a regulated healthcare technology environment, I led the structuring and evolution of the GRC program to support international expansion and audit readiness. I secured IEC 62304 Class C regulatory approval by mapping technological and regulatory risks to internal controls, and facilitated HIPAA compliance and SOC 2 Type II audit readiness with zero critical findings, strengthening the security posture for U.S. healthcare partnerships.

I also focus on pragmatic risk prioritization—adopting CIS Control 1 to mitigate critical operational risks, conducting targeted LGPD gap analysis with executive-ready action points, and developing IT governance policies and procedures aligned to SOC 2, HIPAA, and IEC 62304. I’m at my best analyzing data, mapping controls, evaluating third-party risk, and supporting audit readiness, while contributing to risk committee discussions and security awareness initiatives that build shared accountability.

Experience

Work history, roles, and key accomplishments

Medome logoME

IT GRC Analyst

Aug 2025 - May 2026 (9 months)

Leading the structuring and evolution of the Governance, Risk, and Compliance (GRC) program in a regulated healthcare technology environment, bridging Legal, Engineering, and Leadership teams to enable international expansion and regulatory readiness.

- Secured IEC 62304 Class C regulatory approval for medical software by mapping technological and regulatory risks to internal controls, ensuring s

Medome logoME

Product Owner

Feb 2024 - May 2026 (2 years 3 months)

Operating at the intersection of product, information security, and regulatory compliance within a regulated medical software environment, with a focus on traceability, risk mitigation, and adherence to HIPAA, IEC 62304, and OWASP standards.

- Contributed to a 6% improvement in satisfaction scores (6.4 → 6.8) and a 400% expansion of the active feedback base, reinforcing an evidence-driven continu

Mercado Eletrônico logoME

Product Management

May 2023 - Oct 2023 (5 months)

Product-oriented role in IT operations focused on cost rationalization, process standardization, and data-driven decision-making, developing practical experience directly transferable to IT Governance, Risk, and Compliance, with emphasis on IT asset management, operational controls, and performance oversight.

- Rationalized software license usage and reduced operational costs by leading the migra

Mercado Eletrônico logoME

Software Development

Jun 2022 - May 2023 (11 months)

Contributed to the sustainment and evolution of core business systems within a 5-person agile squad, operating in a complex corporate environment with a strong focus on operational reliability and service continuity.

- Maintained critical legacy .NET and ASP services, leveraging modern communication architectures such as REST and gRPC to ensure system stability and the integrity of integrations s

Education

Degrees, certifications, and relevant coursework

UP

USP - Universidade de São Paulo

Master of Business Administration - MBA, Governança

2025 - 2027

Executive education focused on corporate governance, management, internal controls, and compliance. Topics include internal and external auditing, ESG, data protection (LGPD/GDPR), SOX, COSO, internal investigations, crisis management, cybersecurity, blockchain, artificial intelligence, and international regulations such as the FCPA and UK Bribery Act.

IT

ITXPRO

High-performance professional mentoring, IT/IS Governance

UB

UNDB - Unidade de Ensino Superior Dom Bosco

Computer Software Engineering

2022 - 2025

Focused on software development, algorithms, and data structures. Gained proficiency in programming, database management, and system design, with exposure to AI, cybersecurity, and problem-solving techniques

UB

UNDB - Unidade de Ensino Superior Dom Bosco

Bachelor of Laws - LLB, Direito

2012 - 2017

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan