Head of Information Security

platacard

Mexico

On-site

PHP 4,425,000 - 6,637,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

platacard seeks a Head of Information Security to own regulatory compliance in Mexico, translating regulatory requirements into actionable tasks and coordinating delivery across Information Security, Technology, and operations. You will validate evidence and manage regulatory reporting to CNBV, Banco de México, and SPEI while ensuring readiness for examinations.

The role requires disciplined execution, escalation of risks, and continuous readiness throughout the year, with close collaboration

Responsibilities

  • Translate regulatory requirements into clear actions for Information Security, Technology, Internal IT, Operations, Fraud Prevention, Business Continuity, and other teams.
  • Own preparation and coordination of Information Security reports, indicators, evidence packages, and regulator information requests (CNBV, Banco de México, SPEI).
  • Serve as the primary Information Security contact for regulatory examinations in Mexico and coordinate responses with stakeholders.
  • Lead preparation for internal audits, regulatory reviews, SPEI assessments, PCI DSS activities, and related assurance exercises.
  • Maintain an evidence repository, review submissions for accuracy, and convert findings into remediation plans with owners and deadlines.
  • Represent Information Security to local management and ensure alignment of local regulatory requirements with global programs.

Job description

The primary responsibility is to ensure that the company understands its obligations, submits accurate information on time, and remains continuously prepared for regulatory reviews. This is not primarily a security engineering role. Global Information Security and Technology teams implement technical controls. The Head of Information Security must translate Mexican regulatory requirements into clear actions, coordinate delivery across those teams, validate evidence, and remain accountable for the final regulatory outcome. The successful candidate must combine senior regulatory judgment with disciplined execution. The role requires someone who personally verifies facts, follows issues through to completion, and does not rely on last-minute intervention from other functions.

Challenges that await you:

Regulatory Compliance
  • Monitor Mexican Information Security, cybersecurity, technology risk, business continuity, and related regulatory requirements applicable to The Company.
  • Maintain a complete register of regulatory obligations, reporting deadlines, responsible owners, required evidence, dependencies, and current status.
  • Interpret regulatory requirements and translate them into clear, actionable tasks for Information Security, Technology, Internal IT, Operations, Fraud Prevention, Business Continuity, and other responsible teams.
  • Assess the impact of regulatory changes and coordinate required updates to controls, processes, policies, procedures, and reporting.
  • Escalate regulatory risks, missing evidence, and potential delays before obligations become overdue.
Regulatory Reporting
  • Own the preparation and coordination of Information Security reports, formal responses, indicators, evidence packages, and information requests submitted to Mexican regulators.
  • Coordinate reporting related to CNBV, Banco de México, SPEI, and other applicable local supervisory activities within the scope of Information Security.
  • Verify all submitted information against source systems and supporting evidence.
  • Ensure that reports accurately identify the work performed, responsible owners, control status, findings, incidents, and remediation progress.
  • Maintain a clear audit trail of data sources, reviews, approvals, submissions, and regulator correspondence.
  • Prevent incomplete, unsupported, inconsistent, or misleading information from being submitted to management, auditors, or regulators.
Regulatory Engagement and Examinations
  • Act as the primary Information Security contact in Mexico for regulatory examinations, formal information requests, interviews, and follow-up activities.
  • Coordinate responses with the Global CISO, Legal, Compliance, Risk, Internal Audit, Technology, and other relevant stakeholders.
  • Prepare Company representatives for regulatory meetings and ensure that answers are consistent, accurate, and supported by evidence.
  • Track all commitments made to regulators until formally completed.
  • Maintain readiness throughout the year rather than preparing only after an examination or request begins.
Audit and Assurance
  • Lead Information Security preparation for internal audits, regulatory reviews, SPEI assessments, PCI DSS activities, and other assurance exercises applicable to Mexico.
  • Maintain an evidence repository that is complete, current, and easy to validate.
  • Review evidence before submission and challenge unsupported statements or incomplete control descriptions.
  • Convert findings into remediation plans with clear owners, actions, deadlines, dependencies, and acceptance criteria.
  • Monitor remediation and elevate overdue or blocked actions.
  • Ensure that Information Security audit and regulatory activities remain owned by the Local CISO and do not require another function to take over coordination.
Information Security Governance
  • Represent Information Security before local management and control functions.
  • Provide clear reporting on regulatory exposure, control gaps, audit findings, incidents, remediation, and material risks.
  • Coordinate local implementation of the global Information Security Program.
  • Ensure that local regulatory requirements are reflected in The Company's Information Security documentation.
  • Review local-language policies, procedures, standards, and regulatory responses to ensure that they preserve the original requirements and control meaning.
  • Support regulatory aspects of information security incidents, including assessment of reporting obligations, evidence collection, and coordination of formal notifications.
Team and Stakeholder Management
  • Manage the local Information Security regulatory function with clear responsibilities, measurable objectives, and regular performance reviews.
  • Build effective working relationships with Compliance, Legal, Internal Audit, Risk, Technology, Operations, Fraud Prevention, Business Continuity, and global Information Security teams.
  • Assign work based on actual responsibilities and demonstrated workload.
  • Address underperformance promptly and
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Head of Information Security & Regulatory Excellence
Head of Information Security & Regulatory Excellence

platacard • Mexico

On-site
PHP 4,425,000 - 6,637,000
Head of IT Security and Technology Governance
Head of IT Security and Technology Governance

FWD Insurance • Taguig

On-site
PHP 1,800,000 - 3,000,000
Specialist - Governance Risk and Compliance
Specialist - Governance Risk and Compliance

Concentrix • Morong

On-site
PHP 600,000 - 1,000,000
Director Information Security
Director Information Security

Optum Philippines • Philippines

On-site
PHP 1,800,000 - 2,400,000
Security Risk Management
Security Risk Management

LaPieza • Mexico

On-site
PHP 4,991,000 - 6,862,000
Cyber Security Specialist
Cyber Security Specialist

Sterling Global Call Center, Inc. • Pasig

On-site
PHP 900,000 - 1,300,000
Information Security Analyst
Information Security Analyst

Satellite Office • Metro Manila

On-site
PHP 1,200,000 - 1,600,000
Associate Specialist, Governance, Risk and Compliance
Associate Specialist, Governance, Risk and Compliance

Concentrix • Angeles

On-site
PHP 600,000 - 900,000
Information Security Analyst, GRC & ISMS
Information Security Analyst, GRC & ISMS

GMV • España

Hybrid
PHP 600,000 - 800,000
Hybrid working model
Flexible working hours
Competitive compensation
+1
Cybersecurity Analyst
Cybersecurity Analyst

ContactPoint360 • Cebu City

On-site
PHP 900,000 - 1,300,000