Cybersecurity Manager

CIMMYT - International Maize and Wheat Improvement Center

Mexico

On-site

PHP 4,426,000 - 7,377,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Year-end bonus
Vacation premium
Life and medical insurance
Supermarket coupons
Savings fund
Mexican benefits (IMSS/SAR)

Job summary

CIMMYT is seeking an experienced Cybersecurity Manager to lead the protection of its information assets underpinning its global research operations. The postholder heads CIMMYT's information security function and its ISMS aligned to ISO/IEC 27001:2022, with ownership of security platforms and the team that runs them.

Requirements include a Bachelor’s degree, CISSP/CISM or ISO/IEC 27001 Lead Implementer/Auditor, and +8 years in information security including 3 years in leadership.

Qualifications

  • Bachelor’s degree in computer science, IT, or related field.
  • Security certification required: CISSP, CISM, ISO/IEC 27001 Lead Implementer or Lead Auditor, or equivalent.
  • +8 years of professional experience in information security, including 3 years managing/supervising a tech team.
  • Experience implementing ISO/IEC 27001 and producing audit evidence.
  • Experience in multi-country or distributed organizations is a plus; non-profit/ international research background is an advantage.
  • Foreign nationals must have legal work documents for Mexico.

Responsibilities

  • Lead CIMMYT's information security function and coach the cybersecurity team.
  • Operate and improve the ISO/IEC 27001:2022 ISMS with documented controls.
  • Prepare risk and control items and drive actions.
  • Oversee configuration, integration, tuning and troubleshooting across security platforms including SIEM.
  • Own vulnerability and patch management, and incident response end-to-end.
  • Validate control effectiveness and maintain technical evidence.
  • Coordinate security standards with regional IT and conduct security awareness.
  • Report monthly on security posture, risk and control performance.

Skills

Cybersecurity leadership
Risk assessment
Incident response
Security architecture
Mentoring & coaching

Education

Bachelor’s degree in Computer Science / Information Technology or related field
Master’s degree (advantage)

Tools

ISO/IEC 27001
NIST CSF
SIEM platforms
Identity & Access Management
Vulnerability management

Job description

CIMMYT is a cutting-edge, non-profit, international organization dedicated to solving tomorrow’s problems today. It is entrusted with fostering improved quantity, quality, and dependability of production systems and basic cereals such as maize, wheat, triticale, sorghum, millets, and associated crops through applied agricultural science, particularly in the Global South, through building strong partnerships. This combination enhances the livelihood trajectories and resilience of millions of resource-poor farmers, while working towards a more productive, inclusive, and resilient agrifood system within planetary boundaries. CIMMYT is a core CGIAR Research Center, a global research partnership for a food-secure future, dedicated to reducing poverty, enhancing food and nutrition security, and improving natural resources. For more information, visit https://www.cimmyt.org/

We are seeking an experienced, hands-on Cybersecurity Manager to lead the protection of the information assets underpinning its global research operations.

The postholder leads CIMMYT's information security function and its Information Security Management System, aligned to ISO/IEC 27001:2022, with operational ownership of the Center's security platforms and of the team that runs them.

Key Responsibilities
  • Lead CIMMYT's information security function, and manage, coach and develop the cybersecurity team, including objective setting, evidence-based performance assessment, technical mentoring and cross-cover.
  • Operate and continuously improve the Information Security Management System aligned to ISO/IEC 27001:2022 and NIST CSF v2.0, maintaining the supporting standards, procedures and the evidence that demonstrates the controls operate as documented.
  • Prepare and present risk and control items, and follow through on decisions and actions arising.
  • Perform and oversee hands-on configuration, integration, tuning and troubleshooting across the security platform estate, endpoint detection and response, identity and privileged access management, vulnerability management, encryption, SIEM and log management, and network security.
  • Own vulnerability and patch management: scan coverage, remediation targets by severity, exception handling and verified closure.
  • Own security incident response end to end , detection and triage, containment decisions, documented timelines, root cause analysis, post-incident review and corrective actions.
  • Validate control effectiveness before controls are declared in place, including testing for bypass routes, and maintain the technical evidence that supports that conclusion.
  • Own identity and access governance.
  • Support internal audit, external audit and donor due diligence.
  • Manage security suppliers and licences and renewals.
  • Coordinate security standards and support with regional IT specialists across country offices, and run the organization-wide security awareness programme.
  • Report monthly on security posture, risk and control performance through agreed metrics.
  • Bachelor’s degree in computer science, Information Technology, Information Security or a related field. A master's degree is an advantage.
  • A security certification is required: CISSP, CISM, ISO/IEC 27001 Lead Implementer or Lead Auditor, or equivalent. Technical platform certifications are an advantage
  • +8 years of professional experience in information security, of which at least three years managing or supervising a technical team.
  • Practical experience implementing and operating an ISO/IEC 27001 management system, including Annex A control mapping, Statement of Applicability, and the production of audit evidence.
  • Experience managing security vendors, contracts, licences and budgets.
  • Experience in a multi-country or distributed organization is an advantage; experience in international research, development or non-profit organizations is a further advantage.

CIMMYT offers an attractive remuneration package and support for continuous professional development. In addition to the provisions of the Mexican Labor Law our package of benefits includes year-end bonus (40 days), vacation premium (56%), life and medical insurance, supermarket coupons, savings fund, social Mexican benefits (IMSS, SAR / Infonavit).

Please note only short-listed candidates will be contacted.

Foreign national candidates must have legal documents to work in Mexico.

This position will remain open until filled.

CIMMYT is an equal opportunity employer. It fosters a multicultural work environment that values gender equality, teamwork, and respect for diversity.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Global Cybersecurity Manager | ISO 27001 & NIST Lead
Global Cybersecurity Manager | ISO 27001 & NIST Lead

CIMMYT - International Maize and Wheat Improvement Center • Mexico

On-site
PHP 4,426,000 - 7,377,000
Year-end bonus
Vacation premium
Life and medical insurance
+3
Global Cybersecurity Manager - ISO 27001 & Risk Lead
Global Cybersecurity Manager - ISO 27001 & Risk Lead

CIMMYT • Mexico

On-site
MXN 900,000 - 1,300,000
Year-end bonus (40 days)
Vacation premium (56%)
Life and medical insurance
+3
M26338 Assistant Research Associate
M26338 Assistant Research Associate

CIMMYT • Mexico

On-site
MXN 280,000 - 420,000
Life and medical insurance
Year-end bonus (40 days)
Vacation premium (56%)
+3
Program Manager - Genetics Resources Program
Program Manager - Genetics Resources Program

CIMMYT - International Maize and Wheat Improvement Center • Mexico

On-site
PHP 3,320,000 - 5,533,000
Year-end bonus
Vacation premium
Life and medical insurance
+3
Program Finance Business Partner
Program Finance Business Partner

CIMMYT - International Maize and Wheat Improvement Center • Mexico

On-site
PHP 3,321,000 - 5,535,000
GRC Specialist (Governance, Risk and Compliance)
GRC Specialist (Governance, Risk and Compliance)

CIMMYT - International Maize and Wheat Improvement Center • Mexico

On-site
PHP 2,214,000 - 3,690,000
Year-end bonus (40 days)
Vacation premium (56%)
Life and medical insurance
+3
M26273 Financial Planning Analysis Manager (Locally Recruited)
M26273 Financial Planning Analysis Manager (Locally Recruited)

CIMMYT • Mexico

On-site
MXN 900,000 - 1,200,000
Year-end bonus (40 days)
Vacation premium (56%)
Life and medical insurance
+3
M26336 Program Finance Business Partner (Locally Recruited)
M26336 Program Finance Business Partner (Locally Recruited)

CIMMYT • Mexico

On-site
MXN 700,000 - 900,000
Year-end bonus (40 days)
Vacation premium (56%)
Life and medical insurance
+3
CLM Specialist (Contract Lifecycle Management) - Locally Recruited
CLM Specialist (Contract Lifecycle Management) - Locally Recruited

CIMMYT • Hinoba-an

On-site
PHP 796,000 - 1,326,000
Health insurance
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Description Ciklum • Mexico

On-site
PHP 5,576,000 - 8,055,000
Medical insurance
Udemy license
Language courses
+2