Senior Associate – Security Risk Management

EX Squared LATAM

Región Centro

Híbrido

MXN 700.000 - 1.000.000

Jornada completa

hace 7 horas
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Consigue una respuesta de este empleador — un currículum y una carta de presentación adaptados exactamente a lo que busca para contratar.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Remote-work allowance
Vacation premium
Statutory benefits

Descripción de la vacante

EX Squared LATAM's client in Mexico seeks a Senior Associate – Security Risk Management to perform security reviews and IT risk assessments across projects, vendors, and technology environments. This individual contributor role emphasizes understanding security reports from Penetration Testing, SOC, and Vulnerability Management teams.

The ideal candidate has 3–5 years of experience in security reviews, IT risk assessments, IT audits, or risk audits, and advanced English for cross-border

Formación

  • 3–5 years of experience performing Security Reviews, IT Risk Assessments, IT Audits, or related activities.
  • Experience reviewing SOC, Penetration Testing, and Vulnerability Management reports.
  • Broad information security domain knowledge: application security, security architecture, access control, data protection, cryptography, monitoring, and secure development practices.
  • Familiarity with standards and regulatory frameworks (NIST 800-series, ISO 27000, PCI-DSS, HIPAA).

Responsabilidades

  • Conduct Security Reviews, IT Risk Assessments, IT Audits, and related security evaluations for projects, vendors, and environments.
  • Evaluate security posture against standards, policies, methodologies, and control objectives.
  • Interpret technical reports from Penetration Testing, SOC, and Vulnerability Management teams.
  • Identify security/control gaps and assess impact within risk frameworks.
  • Assess security considerations across application security, architecture, access control, data protection, monitoring, and vulnerability management.
  • Review projects/vendors against information security and regulatory requirements.
  • Document findings clearly and communicate security requirements to stakeholders.

Conocimientos

Security reviews
IT risk assessments
SOC reports
Vulnerability management
Advanced English
Security governance
Regulatory awareness
Risk communication

Herramientas

Qualys
Carbon Black
Okta
Active Directory
IDS/IPS

Descripción del empleo

At EX Squared LATAM, we partner with leading organizations across global and regional markets to connect exceptional professionals with high-impact career opportunities.

Our client is a leading global organization in the professional services and consulting industry, supporting businesses with complex technology, cybersecurity, risk, compliance, and transformation initiatives.

For this position, EX Squared LATAM is supporting our client with the recruitment and selection process. The selected professional will be hired directly by the client under their local payroll in Mexico, becoming part of their internal team.

Role Overview

We’re currently looking for a Senior Associate – Security Risk Management to perform security reviews and IT risk assessments across projects, vendors, applications, and technology environments.

This is an Individual Contributor role focused on assessing security posture, reviewing technical evidence, identifying control gaps, and determining whether projects and third parties align with established security standards, policies, methodologies, and control requirements.

The ideal candidate will bring approximately 3-5 years of experience in Security Reviews, IT Risk Assessments, IT Audits, Risk Audits, or similar activities, along with enough technical cybersecurity knowledge to interpret findings and reports produced by specialized teams such as Penetration Testing, SOC, and Vulnerability Management.

This position does not perform Penetration Testing or Ethical Hacking directly. Instead, the professional must be able to understand technical security reports and use that information as part of broader risk and control assessments.

Location

Mexico. Candidates located in Mexico City or Guadalajara are highly preferred.

  • For professionals based in Mexico City or Guadalajara, the position follows a hybrid model with onsite attendance approximately 2-3 days per week.
  • Candidates based in other cities in Mexico may be considered for a remote arrangement; however, Mexico City and Guadalajara profiles will receive priority.
Contract Duration

Permanent, direct employment with the client.

This is a 100% payroll position in Mexico.

Working Hours

Monday through Friday, 8:00 a.m. to 5:00 p.m.

Language Requirement

Advanced English.

Candidates must be comfortable conducting business and technical conversations with both technical and administrative stakeholders, including U.S.-based teams.

What you'll do
  • Perform Security Reviews, IT Risk Assessments, IT Audits, and related security evaluation activities for projects, vendors, applications, and technology environments.
  • Evaluate security posture against established standards, policies, methodologies, control objectives, and security best practices.
  • Review and interpret technical documentation and reports generated by teams such as Penetration Testing, Security Operations Centers (SOC), and Vulnerability Management.
  • Identify potential security and control gaps and evaluate their impact within the broader risk assessment.
  • Assess security considerations across areas such as application security, architecture, access control, cryptography, data protection, monitoring, vulnerabilities, and secure development practices.
  • Review projects and vendors against relevant information security and regulatory requirements.
  • Work with technical and business stakeholders to clarify findings, collect supporting evidence, and communicate security requirements.
  • Document assessments, findings, risks, and recommendations clearly and accurately.
  • Escalate issues when appropriate and maintain documentation that can withstand internal or external audit review.
  • Manage multiple concurrent assessments and priorities in a customer-focused and collaborative environment.
  • Stay current with evolving information security requirements, threats, technologies, controls, and practices.
What you'll bring
  • Approximately 3-5 years of experience performing Security Reviews, IT Risk Assessments, IT Audits, Risk Audits, or similar activities.
  • Experience reviewing and interpreting SOC, Penetration Testing, and Vulnerability Management reports.
  • Broad understanding of multiple information security domains, including:
  • Application security
  • Security architecture
  • Secure coding concepts
  • Access control
  • Data protection
  • Cryptography
  • Monitoring
  • Vulnerability management
  • Understanding of security principles, IT security controls, and related technologies and products.
  • Knowledge of the OWASP Top 10 web application security risks.
  • Familiarity with standards and regulatory frameworks such as NIST 800 series, ISO 27000, PCI-DSS, and HIPAA.
  • Familiarity with security technologies such as Active Directory, LDAP, Okta or other access management solutions, IDS, firewalls, load balancers, proxies, DLP, Qualys, Carbon Black, Symantec CCS, or comparable technologies.
  • Strong analytical, troubleshooting, organizational, and documentation skills.
  • Ability to prioritize and manage multiple projects or assessments simultaneously.
  • Strong written and verbal communication skills and the ability to collaborate effectively with stakeholders at different organizational levels.
What will make you stand out
  • Experience with GRC platforms such as Archer.
  • Certifications such as CISSP, CCSP, CISA, CCSK, or similar credentials.
  • Strong experience reviewing third-party or vendor security risks.
  • Exposure to several cybersecurity domains rather than expertise limited to only one technical area.
  • Experience working with U.S.-based or multicultural teams.
  • Ability to take highly technical security findings and translate them into understandable risk, control, and business implications.
  • Experience operating in environments where assessments and documentation may be subject to internal or external audit.
Why this opportunity?

This is an opportunity to join a large, globally recognized organization in the professional services and consulting industry, working with multidisciplinary and international teams on cybersecurity and technology risk initiatives.

The role provides exposure to a broad range of security domains, enterprise technologies, projects, and vendors while allowing the professional to develop deeper expertise in Security Risk Management, security assessments, IT controls, and cybersecurity governance.

It is particularly well suited for someone that enjoys understanding technical security issues but wants to apply that knowledge from a risk assessment and advisory perspective rather than an offensive security role.

What the Client Offers
  • Annual performance review with potential salary adjustments and internal growth.
  • Savings fund.
  • Vacation premium and statutory benefits.
  • Remote-work allowance, when applicable.
Selection Process

The selection process is expected to include:

  • Initial interview with the local/direct leader.
  • Technical interviews with the U.S.-based team, typically involving two interviewers per session.
  • Final interview with the U.S. Area Director.
  • Background check.
Eligibility Note

This opportunity is available to candidates currently residing in Mexico.

Candidates located in Mexico City and Guadalajara are strongly preferred due to the hybrid working model. Candidates located elsewhere in Mexico may also be considered for remote work depending on profile and business requirements.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Information Security & IT Risk Manager (GRC)
Information Security & IT Risk Manager (GRC)

Exceptional Dental • Texcoco de Mora

Híbrido
MXN 900.000 - 1.200.000
Meal/grocery vouchers
Savings fund
Remote-work allowance
Manager - Cyber Assessment (Penetration Testing)
Manager - Cyber Assessment (Penetration Testing)

EX Squared LATAM • Región Centro

Híbrido
MXN 1.200.000 - 1.700.000
Savings fund
Remote-work allowance
Hybrid Security Risk Management Specialist
Hybrid Security Risk Management Specialist

EX Squared LATAM • Región Centro

Híbrido
MXN 700.000 - 1.000.000
Remote-work allowance
Vacation premium
Statutory benefits
Senior Risk Advisory Consultant - Remote (Mexico) Posted on Sep 09 / 2026
Senior Risk Advisory Consultant - Remote (Mexico) Posted on Sep 09 / 2026

Echelon Cyber • México

Híbrido
MXN 1.200.000 - 1.600.000
Private medical insurance
Life insurance
30-day Christmas bonus
+7
Senior Risk Advisory Consultant - Remote (Mexico)
Senior Risk Advisory Consultant - Remote (Mexico)

Echelon Risk + Cyber • México

A distancia
MXN 900.000 - 1.200.000
Private medical insurance
Life insurance
30-day Christmas bonus and stipend
+5
Cyber Security Engineer - Mexico City
Cyber Security Engineer - Mexico City

Yeah! Global • Ciudad de México

Presencial
MXN 1.059.000 - 1.413.000
Information Security Analyst
Information Security Analyst

Tata Consultancy Services • Región Centro

Presencial
MXN 90.000 - 120.000
Head of Security Engineering
Head of Security Engineering

Base Labs • Ciudad de México

Presencial
MXN 1.200.000 - 1.800.000
Medical insurance
Senior Risk Advisory Consultant - Remote Mexico
Senior Risk Advisory Consultant - Remote Mexico

Echelon Risk + Cyber • México

A distancia
MXN 900.000 - 1.200.000
Private medical insurance
Life insurance
30-day Christmas bonus and stipend
+5
Business Information Security Officer
Business Information Security Officer

RGP • Ciudad de México

Híbrido
Medical insurance
Dental insurance
Vision insurance
+7