Pietro Castilho Tranquilini

Pietro Castilho Tranquilini

Head of IT Controls & Access Management (IT Department) @ Braskem

About

Professional with over 15 years of experience in Governance, Risk & Compliance (GRC), mostly focused on IT Risks, Controls, Audit and Access Management. For the last decade, I´ve been working at Braskem, starting as Internal Controls Analyst back in 2014 and building my way up to IT Controls & IAM Leader, facing many challenges, always available to take new opportunities to grow and learn with several areas, positions, regions and activities worked during these years: Compliance, IT, Legal, Internal Audit, Accouting, Data Protection, among others. Before that, in 2011, I had also a great experience at a Big Four company, EY, where I have built a strong foundation in risk management, information security, as well as critical and analytical auditing mindset. Throughout my career, I have contributed, led and developed many projects and skills from scratch, from Excel, Power BI to SAP GRC AC/PC/RM, Data Protection and Privacy Program, without fear of stepping out my comfort zone and thinking outside the box to achieve personal, professional and enterprise goals.

Country

Brazil

City

São Paulo

Industry

Plastics

Skill

Avaliação de riscos, Tecnologia da informação, Cibersegurança, Gestão de riscos corporativos, Microsoft Office, Controle interno, Gestão de identidades e acessos, Controle de acesso, COBIT, ITIL, Sarbanes-Oxley Act, IT Audit, Internal Audit, SOX Compliancy, Consulting, ISO 27001, Information Security, IT Management, CMMI, ERP

Experience

Braskem

Head of IT Controls & Access Management (IT Department)

Braskem

LinkedIn
2023-3 - Present · 3 yrs 7 mos

São Paulo, São Paulo, Brasil

Global Head of IT Internal Controls, leading a team of 8 direct reports, focusing on the following 3 areas: 1. IT Controls: Management of IT general controls with a focus on SOx, from planning, defining systems in scope, maintaining the risk and control matrix, test of design (ToD), gathering evidence for internal and external audits, as well as executing access controls and SoD, monitoring of automatic controls in the GRC PC and participation in IT Project Committees with an ITGC perspective. 2. SAP Security, GRC AC and Access Management: Governance and global management of access at Braskem with a focus on defining rules, policies, guidelines, norms, procedures, processes, access controls, annual access review certification campaign, risks of segregation of functions (SoD) and participation in IT Committees with the view of SAP profiles and accesses. Act as a Gatekeeper between governance, IT security, and business process owners to comply with policy and governance rules regarding audit and security standards relevant to SAP roles/profiles management and security authorizations on ECC, HCM, BW, Solman, Fiori, BTP, ATC, GRC AC, PC, RM, and BRM. Focal point for transformational SAP projects, including profile and SOD redesign, rise S/4 HANA and cloud/SaaS integrations, with close interface with Basis, Security, ABAP and functional teams. 3. IAM: Identity and Access Management Governance, including the definition of guidelines, rules and policies, as well as the operation and support (evaluations of integrations, structure, updates, standardization of profiles and approving groups), in order to ensure the correct execution of access controls in IT environments via IDM.

Braskem

Privacy and Data Protection Officer (Compliance Department)

Braskem

LinkedIn
2019-1 - 2023-4 · 4 yrs 4 mos

São Paulo, Brasil

Global Data Protection Officer (DPO), supervising 3 direct reports, responsible for the implementation and continuous management of the Privacy and Data Protection Program, including compliance with GDPR in Europe and LGPD in Brazil. Among my main responsibilities are: - Establish and maintain the governance and privacy structure with adequate assessment and risk management controls for the Protection of Personal Data, including participation in the Global Privacy Committee. - Act on identification (data mapping and discovery), Record of Processing Activities (ROPAs), classification of personal data, risk/gap analysis, Data Protection Impact Assessments (DPIAs) and definition of Action Plans to be applied in the Company's processes and areas with a focus on adapting to the Data Protection Laws (LGPD) and maintaining the privacy of our customers, suppliers and employees in all regions. - Create, publish and disseminate the Global Privacy and Data Protection Policy, as well as the Personal Data Incident Response Plan/Procedure (for data breaches and/or data leaks), standard contractual privacy clauses, standard Privacy Disclaimer, Data Processing Agreements (DPAs) with third parties and International Data Transfer Agreements. - Prevent, monitor and implement technical and organizational security measures in order to ensure privacy and protection of personal data, such as the implementation of global anonymization/encryption/masking tools, retention periods, access restrictions, access review in Microsoft Office 365 and Checklist of new and ongoing projects involving personal data in order to comply with the law (privacy by default and by design). - Define and execute an awareness campaign for Privacy and Data Protection Program in the Company, including communications, request channel for data subjects access rights (DSARs), internal and external privacy notices/statements, as well as training plan with standard e-Learning, lectures and specific training.

Braskem

Senior Risk Management Analyst (Compliance Department)

Braskem

2018-1 - 2019-1 · 1 yr 1 mo

São Paulo e Região, Brasil

Focusing on the mapping, evaluation and monitoring of corporate risks (strategic, financial, operational and regulatory), as well as threats of Cyber Security / Information Security and Personal Data Protection / Privacy (GDPR and LGPD) laws. Responsible for leading the corporate implementation of the SAP GRC RM Risk Management tool, as well as its configuration and administration. Developed several dashboards, executive reports and indicators (KPIs and KRIs) using Office 365 Power BI tool.

Braskem

Internal Controls Analyst (Compliance Department)

Braskem

LinkedIn
2014-10 - 2018-1 · 3 yrs 4 mos

São Paulo Area, Brazil

Responsible for detecting, mitigating and remediating business risks through mapping and evaluation of the internal controls structure at the process level, in order to maintain the SOx Certification, with a focus on Braskem America (USA) and ITGC (General IT Controls) based on the CobIT framework. Also responsible for managing and updating the SAP GRC Process Control (PC) and Access Control (AC) tool to manage SOx audit work, continuous monitoring, SoD and other areas involved, as well as automation of tests and controls in order to achieve a greater maturity and reliability in audited processes.

EY

Senior IT Consultant

EY

LinkedIn
2014-8 - 2014-10 · 3 mos

São Paulo e Região, Brasil

Advisory Services - IT Risk and Assurance Senior Consultant as an IT Risk Advisor with experience and several projects performed regarding IT internal audit compliance, IT risk management, risk and control analysis. Responsible for field execution regarding internal audit, SOX and maturity level processes based on CobIT, ITIL, CMMi, ISO 27.001 and ISO 27.002. Key clients include: Ambev, CIP (Câmara Interbancária de Pagamentos), Bunge Alimentos e Fertilizantes S.A., Grupo AES – Eletropaulo, Grupo Bandeirantes de Comunicação, Groupon Serviços Digitais Ltda., Honda South America Ltda., Sociedade Hospital Samaritano, SESC SP, TOTVS S.A., Unilever Brasil Ltda. and Votorantim Metais Ltda.

EY

IT Risk Management Consultant

EY

LinkedIn
2012-10 - 2014-7 · 1 yr 10 mos

São Paulo, Brazil

Advisory Services - IT Risk and Assurance Consultant as an IT Risk Advisor with experience and several projects performed regarding IT internal audit compliance, IT risk management, risk and control analysis. Responsible for field execution regarding internal audit, SOX and maturity level processes based on CobIT, ITIL, CMMi, ISO 27.001 and ISO 27.002. Key clients include: Ambev, CIP (Câmara Interbancária de Pagamentos), Bunge Alimentos e Fertilizantes S.A., Grupo AES – Eletropaulo, Grupo Bandeirantes de Comunicação, Groupon Serviços Digitais Ltda., Honda South America Ltda., Sociedade Hospital Samaritano, SESC SP, TOTVS S.A., Unilever Brasil Ltda. and Votorantim Metais Ltda.

EY

Trainee

EY

LinkedIn
2011-11 - 2012-9 · 11 mos

São Paulo, Brazil

Advisory Services - IT Risk Management Trainee as an IT Risk Advisor with experience and several projects performed regarding IT internal audit compliance, IT risk management, risk and control analysis. Responsible for field execution regarding internal audit, SOX and maturity level processes based on CobIT, ITIL, CMMi, ISO 27.001 and ISO 27.002. Key clients include: Ambev, CIP (Câmara Interbancária de Pagamentos), Bunge Alimentos e Fertilizantes S.A., Grupo AES – Eletropaulo, Grupo Bandeirantes de Comunicação, Groupon Serviços Digitais Ltda., Honda South America Ltda., Sociedade Hospital Samaritano, SESC SP, TOTVS S.A., Unilever Brasil Ltda. and Votorantim Metais Ltda.

AMD South America Ltda

Intern as Global Customer Care Latin America Analyst

AMD South America Ltda

2010-2 - 2011-11 · 1 yr 10 mos

São Paulo, Brazil

Main activities: to offer internal and external tech support through phone contacts, web-mail and SAP in Portuguese and English; to provide assistance and several information to customers; to update and insert data into Dashboard of all Global Customer Care; to generate comparative graphs using Microsoft Excel.

Santo Almoço

Cashier

Santo Almoço

2008-8 - 2010-2 · 1 yr 7 mos

São Paulo, Brazil

Restaurant's cashier, experience with customer care, cash closure and restocking.

Education

Universidade Paulista

Universidade Paulista

LinkedIn

Computer Science

2008 - 2012 · 4 yrs

Pietro Castilho Tranquilini's Contact Information

Email

******@***.com

Phone

(**) *** ****

Find the Right Leads
Find Verified Contact Data

Try with: Jensen Huang @ nvidia.com Click to autofill
LeadContact awards, five-star ratings, and GDPR compliance badges

What LeadContact does well

Find verified emails, phone numbers, and decision-makers with 98% accuracy.

Find Leads

Find Leads

Find the right people by company, role, industry, location, and more.

925M+ professional profiles

Find Leads
Find Emails

Find Emails

Access verified email addresses for your target contacts.

657M+ emails

Find Emails
Find Phone Numbers

Find Phone Numbers

Get cross-validated phone data from multiple top sources.

239M+ phone numbers

Find Phone Numbers

More Accurate. Lower Cost.

Find contact data in 1 tool with 98% accuracy

LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.

LeadContact Logo
Competitor Tools

All these = $289 per month

Great conversations start with the right contact.

It’s time to find yours.