Chief Information Security Officer (CISO), Mexico - Global Payment

TikTok

Mexico

On-site

MXN 2,400,000 - 5,200,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Accommodation support

Job summary

TikTok seeks an experienced technology risk and information security leader to serve as Chief Information Security Officer for its Mexican entity during the IFPE licensing phase. You will operate as the senior security executive, report to the Board, and own the regulatory and risk program for the local entity.

You will drive the security strategy across governance, risk, and compliance, partnering with Legal, Compliance, and product teams to ensure secure, compliant growth of the payments

Qualifications

  • Senior-level experience in technology risk management and information security within regulated payments entities.
  • Experience as designated CISO with accountability to Mexican regulators.
  • Experience engaging with CNBV, Banxico, and external auditors.
  • Knowledge of electronic payments ecosystem and IFPE operations.
  • Ability to translate risk into business impact for senior leadership.

Responsibilities

  • Lead technology risk and cybersecurity reporting to the Board and Senior Management.
  • Oversee design, engineering, and deployment of a risk-based control framework aligned with NIST CSF/800-53, ISO 27001/27002, COBIT, and CNBV requirements.
  • Coordinate CNBV/Banxico inspections and audits and remediate findings.
  • Develop KRIs/KPIs and provide decision-oriented risk insights to executives.
  • Advise product and business teams on Security by Design for new launches.

Skills

Technology risk
Information security
Regulated payments
CISO leadership
Stakeholder management

Education

Bachelor's degree
Master's degree (preferred)

Job description

Responsibilities

About the Team

Security / Technology sits within Global Payment Tech. We build a world-class technology risk and information security team, systems, and controls to proactively mitigate cyber and technology risks and enable business growth through sound control implementation and license acquisitions. We are technology risk managers who implement an effective, end-to-end security framework. We are also smart business enablers, supporting growth with resilient platforms and a sound security strategy.

We are looking for an experienced and pragmatic technology risk and information security leader to serve as Chief Information Security Officer (CISO) for our Mexican entity in the process of licensing as Institución de Fondos de Pago Electrónico (IFPE).

Regulatory & Governance Responsibilities
  • Serve as the designated CISO / Oficial de Seguridad de la Información for the IFPE, appointed by the Board, holding personal accountability for cybersecurity and technology risk oversight.
  • Coordinate the IFPE's Information Security / Technology Risk Committee (or equivalent governance body), responsible for approving security policies, reviewing risk events, and endorsing reports to the authorities.
  • Serve as the primary point of contact for the CNBV and Banxico (joint supervisors of IFPEs) and external auditors on information security and technology risk matters.
  • Lead and coordinate responses to CNBV and Banxico inspection visits (visitas de inspección), supervisory reviews, mandatory independent security audits, internal audits, and assurance activities, ensuring timely and effective remediation of findings.
  • Provide regular and ad-hoc technology risk and cybersecurity reporting to the Board, the Committee, and Senior Management, including escalation of material issues.
Technology Risk & Cybersecurity Framework Implementation
  • Develop, implement, and continuously enhance the IFPE's technology risk management strategy, policies, and control framework, aligned with industry best practices (NIST CSF/800-53, ISO 27001/27002, COBIT) and CNBV/Banxico regulatory requirements.
  • Conduct and maintain the IFPE's enterprise-wide cyber and technology risk assessment, covering infrastructure, applications, data, and third-party/vendor risk, with specific focus on electronic-funds flows and platform-enabled activity.
  • Oversee the design, engineering, and operationalization of preventive and detective controls across key domains: IAM/PAM, data security (classification, encryption/key management, secrets management, DLP), vulnerability/patch management, security logging and monitoring, configuration hardening, and incident-to-controls feedback loops.
  • Identify and elevate emerging and upstream technology risk through the firm's risk management framework tools (risk event management, reporting, action-plan tracking), providing expert counsel to stakeholders on their security obligations.
  • Lead root-cause analysis, corrective-action design, validation, and sustainable closure for audit and regulatory findings, ensuring recurrence prevention.
  • Define and run KRIs/KPIs (control coverage, compliance health, exceptions, exposure windows, remediation performance), delivering clear, decision-oriented insight to senior leadership.
Advisory & Stakeholder Engagement
  • Work with Security, Tech, Platform-Data Compliance, and Compliance teams during the launch of new products and services to build "Security by Design," ensuring CNBV/Banxico expectations are embedded from the outset.
  • Provide authoritative technology risk and cybersecurity advice to Senior Management, product, operations, compliance, and legal teams on IFPE regulatory requirements.
  • Establish and maintain strong relationships with internal and external stakeholders — cross-functional team leads, regulators, and auditors — to ensure compliance with legal, regulatory, and industry standards.
  • Build strong working relationships across the business to promote security ownership, awareness, and timely issue escalation.
  • Maintain a strong understanding of Mexican technology-risk legislative and regulatory developments — LRITF secondary provisions, CNBV/Banxico circulars, and payments-specific requirements- — and ensure timely implementation.
Qualifications
Minimum Qualification(s)
  • Extensive, senior-level experience in technology risk management, information security, or a related field, with strong preference for experience in regulated payments entity, e-money/IFPE, or financial institution.
  • Proven experience serving as a designated CISO or equivalent senior security function within a CNBV-supervised institution, with direct accountability to Mexican regulators.
  • Demonstrated experience engaging with the CNBV, Banxico, and/or external auditors, including managing inspection visits, examinations, and audits.
  • Strong understanding of the electronic payments ecosystem and the operating model of an IFPE — including electronic-funds products, transaction flows, and associated technology/cyber risks — with the ability to translate a product flow into concrete security obligations: regulatory reporting, audit-ready evidence, operational SLAs, third-party/vendor controls, and end-user risk exposure.
  • Experience conducting enterprise-wide technology/cyber risk assessments and developing or enhancing security manuals, policies, procedures, and control frameworks under Mexican law.
  • Proven ability to lead cross-functional teams, manage large programs, influence executive-level decision-making, and translate technical risk into business impact for senior executives.
Preferred Qualification(s)
  • University degree (Bachelor's or equivalent) in Computer Science, Information Security, Systems/Software Engineering, Telecommunications, or a related field; Master's preferred.
  • Direct experience within an authorized IFPE, bank, or prior experience within a Mexican regulatory authority.
  • Familiarity with the Ley Fintech authorization process, Banxico secondary provisions, and CNBV technology/cybersecurity disposiciones.
  • Proven ability to engineer and operationalize scalable controls, including automation (policy-as-code/control-as-code), standardized evidence capture, and measurable control-effectiveness improvements.
  • Certifications preferred (one or more): CISSP, CISM, CRISC, CISA, ISO 27001 LI/LA, cloud security certifications (AWS/Azure/GCP), ITIL, PMP/PRINCE2.
  • Strong leadership, decision-making, and stakeholder-management skills, with the ability to operate independently and exercise sound judgment in a complex environment.
About TikTok

TikTok is the leading destination for short-form mobile video. At TikTok, our mission is to inspire creativity and bring joy. TikTok's global headquarters are in Los Angeles and Singapore, and we also have offices in New York City, London, Dublin, Paris, Berlin, Dubai, Jakarta, Seoul, and Tokyo.

Why Join Us

Inspiring creativity is at the core of TikTok's mission. Our innovative product is built to help people authentically express themselves, discover and connect – and our global, diverse teams make that possible. Together, we create value for our communities, inspire creativity and bring joy - a mission we work towards every day.

We strive to do great things with great people. We lead with curiosity, humility, and a desire to make impact in a rapidly growing tech company. Every challenge is an opportunity to learn and innovate as one team. We're resilient and embrace challenges as they come. By constantly iterating and fostering an "Always Day 1" mindset, we achieve meaningful breakthroughs for ourselves, our company, and our users. When we create and grow together, the possibilities are limitless. Join us.

Diversity & Inclusion

TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At TikTok, our mission is to inspire creativity and bring joy. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.

TikTok Accommodation

TikTok is committed to providing reasonable accommodations in our recruitment processes for candidates with disabilities, pregnancy, sincerely held religious beliefs or other reasons protected by applicable laws. If you need assistance or a reasonable accommodation, please reach out to us at https://tinyurl.com/RA-request

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

CISO, Mexican Regulated Payments & Tech Risk
CISO, Mexican Regulated Payments & Tech Risk

TikTok • Mexico

On-site
MXN 2,400,000 - 5,200,000
Accommodation support
Accounting Manager - Mexico
Accounting Manager - Mexico

TikTok • Mexico

On-site
MXN 1,200,000 - 2,100,000
TikTok Shop - Services Solutions Program Manager
TikTok Shop - Services Solutions Program Manager

TikTok • Mexico

On-site
MXN 700,000 - 900,000
Independent Director (BSP-regulated entity) - Philippines - Global Payment
Independent Director (BSP-regulated entity) - Philippines - Global Payment

Hammerjack Pty Ltd • Taguig

On-site
PHP 2,000,000 - 5,000,000
Independent Director (BSP-regulated entity) - Philippines - Global Payment
Independent Director (BSP-regulated entity) - Philippines - Global Payment

ByteDance • Taguig

On-site
PHP 4,000,000 - 7,000,000
Independent Director (SEC Financing Regulated Entity) - Philippines - Global Payment Corporate Functions Taguig Regular
Independent Director (SEC Financing Regulated Entity) - Philippines - Global Payment Corporate Functions Taguig Regular

Bytedance • Taguig

On-site
PHP 900,000 - 1,500,000
Business Enablement Manager
Business Enablement Manager

PayJoy • Mexico

On-site
MXN 900,000 - 1,300,000
Health & dental plan
Life insurance
Grocery coupons
+7
SME Compliance Lawyer
SME Compliance Lawyer

Plata Card • Mexico

On-site
MXN 900,000 - 1,200,000
Risk Monitoring Analyst
Risk Monitoring Analyst

Checkout.com • Mexico

Hybrid
PHP 1,557,000 - 2,001,000
Independent Director (SEC Financing Regulated Entity) - Philippines - Global Payment
Independent Director (SEC Financing Regulated Entity) - Philippines - Global Payment

ByteDance • Taguig

On-site
PHP 2,000,000 - 4,000,000