CyberSecurity Manager

Lean Solutions Group

Colombia

Presencial

COP 120.000.000 - 200.000.000

Jornada completa

Hace 13 días
Generador de candidaturas

Una candidatura completa en un minuto: currículum y carta de presentación adaptados, listos para enviar.

Supera los filtros ATS

Descripción de la vacante

Global Technology Services in Medellín, Colombia is seeking a Senior CyberSecurity Manager to be the first dedicated security hire, own the security posture, define the program, and drive SOC 2 Type II readiness and certification. You will write Terraform, tune AWS controls, build policies, and participate in customer security discussions, reporting directly to leadership.

This role is hands‑on, with no immediate team management; you will coordinate with engineering, IT, HR, and operations to

Formación

  • 5–7 years in security with meaningful hands‑on ownership.
  • Deep AWS security experience in production environments.
  • Experience with SOC 2, HIPAA or similar audits is a plus.
  • Ability to write policies and executive updates clearly.

Responsabilidades

  • Define scope and trust services criteria; run readiness and gaps.
  • Close control gaps across engineering and cloud environments.
  • Own the audit relationship and timeline with the firm.
  • Drive SOC 2 Type I/II and maintain ongoing compliance.

Conocimientos

AWS security
SOC 2 knowledge
Terraform
Policy writing
Security governance
Incident response
Communication skills

Educación

Bachelor's degree in Computer Science

Herramientas

Terraform
AWS Cloud
IAM
KMS

Descripción del empleo

Company Overview:

Global Technology Services is a rapidly expanding organization situated in Medellín, Colombia. We pride ourselves on possessing one of the most influential networks within software development and IT services for the entertainment, financial, and logistics sectors. Our corporate projections offer a multitude of opportunities for professionals to elevate their careers and experience substantial growth. Joining our team means engaging with expansive engineering teams across Latin America, Philippines and the United States, contributing to cutting-edge developments in multiple industries.

Position Title: CyberSecurity Manager
Category: Cybersecurity & Risk Management
Seniority: Senior
Location: LATAM (Colombia Preferred)
What you will be doing:

You will be the first dedicated security hire and the single owner of our security posture. Nobody else is going to do this for you, and nobody else is going to do it for you, you set the program, you run it, you maintain compliance, you’re accountable for it.

Your first-year headline objective: get the company to a clean SOC 2 Type II certification report. Everything else supports that or protects the company while you do it. Once certification is achieved, you will be fully responsible for always maintaining it.

This is a hands-on role. You will write Terraform, tune AWS security controls, build policies, run tabletops, enforce personnel compliance, chase evidence, and sit on customer security calls — often in the same week. If you want a role where you manage a team and review dashboards, this isn’t it yet. If you want to build a real security program from scratch and own the outcome, it is.

Key Responsibilities
SOC 2 certification (the priority)
  • Define scope and trust services criteria; run the readiness/gap assessment
  • Close control gaps across engineering, AWS Cloud, IT, HR, and operations
  • Select and manage the audit firm; own the relationship and timeline
  • Drive Type I, then manage the observation window through to Type II
  • Build the program so year-two renewal is routine, not a fire drill
Drata
  • Full ownership as administrator: control mapping, monitoring coverage, and evidence automation
  • Policy lifecycle — author, version, publish, and enforce annual attestation
  • Personnel onboarding/offboarding controls, enforcing personnel compliance, access reviews, and background check tracking
  • Vendor and risk registers kept genuinely current, not backfilled the week before an audit
AWS cloud security
  • IAM least privilege, role hygiene, and elimination of long-lived credentials
  • AWS Organizations, SCPs, and account separation between environments
  • GuardDuty, Security Hub, Config, CloudTrail, and centralized log retention
  • Encryption at rest and in transit; KMS key management and rotation
  • VPC design, network segmentation, security group review, WAF
  • Secrets management, S3 and RDS access controls, and public-exposure prevention
  • Backup, restore testing, and disaster recovery with defined RTO/RPO
  • Patch and vulnerability management with remediation SLAs that are actually met
Application security (with Engineering)
  • Owning Aikido for repository scanning and vulnerability resolution with engineering
  • Bi-annual pentesting with Aikido
  • Embed SAST, DAST, dependency, and IaC scanning into CI/CD
  • Secure SDLC standards, security review of designs, and developer guardrails
  • Coordinate annual penetration testing and drive remediation to closure
  • Audit logging and monitoring of PHI access inside our products
HIPAA and healthcare-specific compliance
  • Serve as our designated HIPAA Security Official
  • Maintain the HIPAA Security Rule risk analysis and risk management plan
  • BAA governance in both directions — customers and subprocessors
  • 42 CFR Part 2 controls for substance use disorder records
  • Breach assessment and notification procedures, with defined timelines
  • Track applicable state privacy laws affecting our customer base
Identity, endpoints, and internal IT security
  • SSO and enforced MFA across all business systems
  • MDM, disk encryption, and endpoint protection on every company device
  • Quarterly access reviews and least-privilege enforcement on internal tools
Physical security
  • Office access control, visitor procedures, and badge/key management
  • Camera coverage, clean desk standards, and secure device and document disposal
  • Remote and home-office security standards for our distributed staff
  • Document inherited AWS data center controls for audit purposes
Incident response
  • Write and maintain the IR plan; define severity levels and escalation paths
  • Run tabletop exercises at least semiannually, including a ransomware and a PHI-exposure scenario
  • Lead investigations and post-incident reviews
Security awareness and customer trust
  • Annual training plus ongoing phishing simulations, with completion enforcement
  • Own security questionnaires, RFP responses, and customer security calls — fast turnaround here directly wins deals
  • Maintain our public trust page and customer-facing security documentation
Required Skills & Experience
  • 5 – 7 years in security, with meaningful hands-on ownership rather than pure oversight
  • Degree in computer science or related field.
  • Deep, practical AWS security experience in a production environment
  • You have taken at least one compliance audit (SOC 2, ISO 27001, HITRUST, or similar) from gap assessment through to issued report
  • Working knowledge of HIPAA and handling PHI in a SaaS environment
  • Comfort in infrastructure as code (Terraform preferred) and scripting to automate controls
  • Ability to write clearly — policies, customer responses, and executive updates all land on your desk
  • Judgment about risk. You can tell a real threat from an audit artifact and prioritize accordingly
Nice to Have Skills
  • CISSP, CCSP, AWS Certified Security – Specialty, CISA, or equivalent
  • Healthcare or behavioral health SaaS background
  • Familiarity with 42 CFR Part 2 or HITRUST
  • Prior experience as a first security hire at a growing company
Soft Skills
  • Strong problem-solving and debugging skills
  • Ability to work independently and take ownership of projects
  • Strong communication skills with the ability to articulate, diagram and document complex engineering concepts.
Why you will love GTS:
  • Join a powerful tech workforce and help us change the world through technology
  • Professional development opportunities with international customers
  • Collaborative work environment
  • Career path and mentorship programs that will lead to new levels.

Join GTS and contribute to shaping the data landscape within a dynamic and growing organization. Your skills will be honed, and your contributions will play a vital role in our continued success. GTS is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Senior DevOps Engineer
Senior DevOps Engineer

Lean Solutions Group • Medellín

Presencial
COP 90.000.000 - 150.000.000
Senior Integration Developer
Senior Integration Developer

Lean Solutions Group • Medellín

Presencial
COP 203.602.000 - 281.911.000
Principal Software Engineer
Principal Software Engineer

Lean Solutions Group • Colombia

Presencial
COP 42.000.000 - 64.000.000
Senior Backend Engineer
Senior Backend Engineer

Lean Solutions Group • Colombia

Presencial
COP 40.000.000 - 70.000.000
Junior Support Specialist
Junior Support Specialist

Lean Solutions Group • Medellín

Híbrido
COP 33.480.000 - 55.800.000
Professional development opportunities
Collaborative work environment
Mentorship programs
First Security Hire — SOC 2 Lead & Cloud Security
First Security Hire — SOC 2 Lead & Cloud Security

Lean Solutions Group • Colombia

Presencial
COP 120.000.000 - 200.000.000
Senior DevOps Engineer - AWS, Terraform & Kubernetes (Advanced English)
Senior DevOps Engineer - AWS, Terraform & Kubernetes (Advanced English)

Sutherland • Bogotá ciudad

Híbrido
COP 120.000.000 - 180.000.000
Hybrid work arrangement
Senior DevOps Engineer - AWS, Terraform & Kubernetes (Advanced English)
Senior DevOps Engineer - AWS, Terraform & Kubernetes (Advanced English)

Sutherland Global • Bogotá

Híbrido
COP 120.000.000 - 240.000.000
Remote Cybersecurity Manager - Build SOC 2 & Cloud Security
Remote Cybersecurity Manager - Build SOC 2 & Cloud Security

Lean Tech, a Lean Solutions Group Division • Colombia

Presencial
COP 120.000.000 - 260.000.000
Global Field Ops Technician, GFO AMER
Global Field Ops Technician, GFO AMER

Amazon Web Services (AWS) • Bogotá

Presencial
COP 90.000.000 - 140.000.000