GRC Specialist

Empresa Confidencial

Naucalpan de Juárez

Presencial

MXN 600.000 - 900.000

Jornada completa

Hace 11 días
Generador de candidaturas

Transforma esta oferta en una entrevista: un currículum y una carta de presentación creados pensando en lo que quiere el empleador.

Supera los filtros ATS

Descripción de la vacante

Empresa Confidencial is seeking a Security Governance & Risk Specialist to support the standardization and continuous improvement of the CSO governance framework. You will develop and standardize security policies, coordinate risk management sessions with senior leadership, and oversee third-party security assessments.

Collaborate with Procurement, Legal, Business Units, and external providers to identify and mitigate security risks while ensuring regulatory compliance and protection of assets.

Formación

  • Minimum 2 years in cybersecurity, governance, risk, compliance, or related field.
  • Preferred 4+ years of relevant professional experience.
  • English language proficiency at an intermediate level (reading, writing, speaking).
  • Familiarity with PCI DSS, ISO 27001, and security governance practices.

Responsabilidades

  • Review and validate security risk requirements with senior leaders and AVPs.
  • Communicate risks clearly and define strategies to mitigate identified risks.
  • Coordinate quarterly risk management sessions with AVPs and VPs.
  • Standardize and maintain CSO policies, procedures, and governance practices.

Conocimientos

Security governance
Risk management
PCI DSS
ISO 27001
Third-party assessments
Stakeholder communication
Policy development

Educación

Bachelor's in CS / IS / Networking / Telecom
Master's in Cybersecurity / IT / MBA (preferred)

Descripción del empleo

Security Governance & Risk Specialist
About the Role

We are looking for a Security Governance & Risk Specialist to support the standardization and continuous improvement of the CSO governance framework. This role is responsible for developing and standardizing security policies and procedures, coordinating risk management sessions with senior leadership, overseeing third-party security assessments, and promoting security awareness across the organization.

The position works closely with key stakeholders, including AVPs, Vice Presidents, Procurement, Legal, Business Units, and external providers, to identify, communicate, and mitigate security risks while ensuring compliance with internal policies, standards, and regulatory requirements.

Key Responsibilities
  • Review and validate security risk requirements in collaboration with key stakeholders, including senior leaders, AVPs, and Vice Presidents.
  • Communicate security risks and findings clearly and effectively, working with stakeholders to define strategies and action plans to mitigate identified risks.
  • Coordinate and lead quarterly security risk management sessions with AVPs and Vice Presidents.
  • Standardize and maintain CSO policies, procedures, processes, and governance practices in alignment with established security standards.
  • Manage, monitor, and coordinate third-party security assessment processes (SISR), ensuring compliance with established requirements and security guidelines.
  • Collaborate with Procurement, Legal, Business Units, and vendors to ensure the proper execution and follow-up of third-party security assessments.
  • Recommend and monitor remediation plans when security requirements or standards are not met.
  • Review and validate the ongoing update of CSO policies, procedures, and processes in accordance with area
  • Ensure that security governance practices meet minimum security requirements and contribute to the protection, integrity, and confidentiality of assets, data, and services.
  • Maintain and continuously update the security awareness plan in collaboration with CSO International and the different CSO teams in Mexico.
  • Design, coordinate, and publish security awareness communications and initiatives for employees.
  • Lead and coordinate cross-functional teams to ensure effective CSO governance across Mexico, including compliance with security standards, requirements, and data protection controls.
  • Support security governance activities related to the protection of customers’ payment card data, ensuring compliance with applicable requirements and maintaining PCI certification.
  • Prepare reports, monitor compliance, and promote continuous improvement through training, preventive measures, policies, and procedures.
Education
  • Bachelor’s degree in Computer Science, Information Systems, Networking, Telecommunications, Electronics, or a related field.
  • Preferred: Master’s degree in Cybersecurity, Information Technology, Business Administration (MBA), or a related field.
Experience
  • Min. 2 years of experience in cybersecurity, security governance, risk management, compliance, or a related field.
  • Preferred: 4+ years of relevant professional experience.
Language
  • English: Intermediate level — speaking, writing, and reading.
Technical Knowledge
  • PCI DSS / PCI compliance
  • Scrum / Agile methodologies
  • ISO/IEC 27001
  • Security governance and risk management
  • Third-party security assessments
  • Security policies, standards, and procedures
  • Security awareness programs
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Security Governance & Risk Strategist
Security Governance & Risk Strategist

Empresa Confidencial • Naucalpan de Juárez

Presencial
MXN 600.000 - 900.000
GRC Analyst - Security & Compliance (Mexico City)
GRC Analyst - Security & Compliance (Mexico City)

Concord • Ciudad de México

Presencial
MXN 360.000 - 540.000
Grocery Vouchers
Internet Bonus
Medical Insurance
+3
GRC Analyst, InfoSec - Compliance & Automation
GRC Analyst, InfoSec - Compliance & Automation

Concord • Ciudad de México

Presencial
MXN 360.000 - 540.000
Grocery Vouchers
Internet Bonus
Medical Insurance
+3
GRC Analyst — InfoSec & Compliance (Mexico City)
GRC Analyst — InfoSec & Compliance (Mexico City)

Powerofconcord • Ciudad de México

Presencial
MXN 300.000 - 400.000
Grocery Vouchers
Internet Bonus
Medical Insurance
+3
Business Information Security Officer
Business Information Security Officer

RGP • Ciudad de México

Híbrido
Medical insurance
Dental insurance
Vision insurance
+7
Technology Compliance Engineer
Technology Compliance Engineer

Turtle Trax S.A. • Estado de México

Híbrido
MXN 70.000 - 90.000
Information Security Analyst
Information Security Analyst

Tata Consultancy Services • Región Centro

Presencial
MXN 90.000 - 120.000
GRC Analyst — InfoSec & Compliance (Mexico City)
GRC Analyst — InfoSec & Compliance (Mexico City)

Concord Servicing • Ciudad de México

Presencial
Grocery Vouchers
Internet Bonus
Medical Insurance
+3
Senior GRC Analyst: PCI/ISO, Security & AWS
Senior GRC Analyst: PCI/ISO, Security & AWS

Pomelo • Estado de México

Híbrido
MXN 900.000 - 1.200.000
Information Risk & Compliance Sr Manager
Information Risk & Compliance Sr Manager

Trinity Structural Towers • Monclova

Presencial
MXN 1.100.000 - 1.600.000