Chief Information Security Officer (CISO), Mexico - Global Payment (Ciudad de México)

Chief Information Security Officer (CISO), Mexico - Global Payment (Ciudad de México)

06 ago
|
Tiktok
|
Ciudad de México

06 ago

Tiktok

Ciudad de México

Responsibilities

About the Team Security / Technology sits within Global Payment Tech. We build a world-class technology risk and information security team, systems, and controls to proactively mitigate cyber and technology risks and enable business growth through sound control implementation and license acquisitions. We are technology risk managers who implement an effective, end-to-end security framework.

We are also smart business enablers, supporting growth with resilient platforms and a sound security strategy. We are looking for an experienced and pragmatic technology risk and information security leader to serve as Chief Information Security Officer (CISO) for our Mexican entity in the process of licensing as Institución de Fondos de Pago Electrónico (IFPE). Responsibilities

Regulatory & Governance Responsibilities

- Serve as the designated CISO / Oficial de Seguridad de la Información for the IFPE, appointed by the Board, holding personal accountability for cybersecurity and technology risk oversight.
- Coordinate the IFPE's Information Security / Technology Risk Committee (or equivalent governance body), responsible for approving security policies, reviewing risk events, and endorsing reports to the authorities.
- Serve as the primary point of contact for the CNBV and Banxico (joint supervisors of IFPEs) and external auditors on information security and technology risk matters.
- Lead and coordinate responses to CNBV and Banxico inspection visits (visitas de inspección), supervisory reviews, mandatory independent security audits, internal audits, and assurance activities, ensuring timely and effective remediation of findings.
- Provide regular and ad-hoc technology risk and cybersecurity reporting to the Board, the Committee, and Senior Management, including escalation of material issues.

Technology Risk & Cybersecurity Framework Implementation

- Develop, implement, and continuously enhance the IFPE's technology risk management strategy, policies, and control framework, aligned with industry best practices (NIST CSF/800-53, ISO 27001/27002, COBIT) and CNBV/Banxico regulatory requirements.
- Conduct and maintain the IFPE's enterprise-wide cyber and technology risk assessment, covering infrastructure, applications, data, and third-party/vendor risk, with specific focus on electronic-funds flows and platform-enabled activity.
- Oversee the design, engineering, and operationalization of preventive and detective controls across key domains: IAM/PAM, data security (classification, encryption/key management, secrets management, DLP), vulnerability/patch management, security logging and monitoring, configuration hardening, and incident-to-controls feedback loops.
- Identify and escalate emerging and upstream technology risk through the firm's risk management framework tools (risk event management, reporting, action-plan tracking), providing expert counsel to stakeholders on their security obligations.
- Lead root-cause analysis, corrective-action design, validation,



and sustainable closure for audit and regulatory findings, ensuring recurrence prevention.
- Define and run KRIs/KPIs (control coverage, compliance health, exceptions, exposure windows, remediation performance), delivering clear, decision-oriented insight to senior leadership.

Advisory & Stakeholder Engagement

- Work with Security, Tech, Platform-Data Compliance, and Compliance teams during the launch of new products and services to build "Security by Design," ensuring CNBV/Banxico expectations are embedded from the outset.
- Provide authoritative technology risk and cybersecurity advice to Senior Management, product, operations, compliance, and legal teams on IFPE regulatory requirements.
- Establish and maintain strong relationships with internal and external stakeholders — cross-functional team leads, regulators, and auditors — to ensure compliance with legal, regulatory, and industry standards.
- Build strong working relationships across the business to promote security ownership, awareness, and timely issue escalation.
- Maintain a strong understanding of Mexican technology-risk legislative and regulatory developments — LRITF secondary provisions, CNBV/Banxico circulars, and payments-specific requirements- — and ensure timely implementation. Qualifications

Minimum Qualification(s) - Extensive, senior-level experience in technology risk management, information security, or a related field, with strong preference for experience in regulated payments entity, e-money/IFPE, or financial institution.

- Proven experience serving as a designated CISO or equivalent senior security function within a CNBV-supervised institution, with direct accountability to Mexican regulators.
- Demonstrated experience engaging with the CNBV, Banxico, and/or external auditors, including managing inspection visits, examinations, and audits.
- Strong understanding of the electronic payments ecosystem and the operating model of an IFPE — including electronic-funds products, transaction flows, and associated technology/cyber risks — with the ability to translate a product flow into concrete security obligations: regulatory reporting, audit-ready evidence, operational SLAs, third-party/vendor controls, and end-user risk exposure.
- Experience conducting enterprise-wide technology/cyber risk assessments and developing or enhancing security manuals, policies, procedures, and control frameworks under Mexican law.
- Proven ability to lead cross-functional teams, manage large programs, influence executive-level decision-making, and translate technical risk into business impact for senior executives.

Preferred

Qualification(s)





- University degree (Bachelor's or equivalent) in Computer Science, Information Security, Systems/Software Engineering, Telecommunications, or a related field; Master's preferred.
- Direct experience within an authorized IFPE, bank, or prior experience within a Mexican regulatory authority.
- Familiarity with the Ley Fintech authorization process, Banxico secondary provisions, and CNBV technology/cybersecurity disposiciones.
- Proven ability to engineer and operationalize scalable controls, including automation (policy-as-code/control-as-code), standardized evidence capture, and measurable control-effectiveness improvements.

Certifications preferred (one or more): CISSP, CISM, CRISC, CISA, ISO 27001 LI/LA, cloud security certifications (AWS/Azure/GCP), ITIL, PMP/PRINCE2.

- Strong leadership, decision-making, and stakeholder-management skills, with the ability to operate independently and exercise sound judgment in a complex environment.

About

TikTok

TikTok is the leading destination for short-form mobile video. At TikTok, our mission is to inspire creativity and bring joy. TikTok's integral headquarters are in Los Angeles and Singapore, and we also have offices in New York City, London, Dublin, Paris, Berlin, Dubai, Jakarta, Seoul, and Tokyo.​ Why Join Us

Inspiring creativity is at the core of TikTok's mission. Our innovative product is built to help people authentically express themselves, discover and connect – and our global, diverse teams make that possible. Together, we create value for our communities, inspire creativity and bring joy - a mission we work towards every day.​

We strive to do great things with great people. We lead with curiosity, humility, and a desire to make impact in a rapidly growing tech company. Every challenge is an opportunity to learn and innovate as one team. We're resilient and embrace challenges as they come. By constantly iterating and fostering an "Always Day 1" mindset, we achieve meaningful breakthroughs for ourselves, our company, and our users. When we create and grow together, the possibilities are limitless. Join us.​



Diversity & Inclusion​

TikTok is committed to creating an inclusive space where employees are valued for their skills, experiences, and unique perspectives. Our platform connects people from across the globe and so does our workplace. At TikTok, our mission is to inspire creativity and bring joy. To achieve that goal, we are committed to celebrating our diverse voices and to creating an environment that reflects the many communities we reach. We are passionate about this and hope you are too.​ TikTok Accommodation

TikTok is committed to providing reasonable accommodations in our recruitment processes for candidates with disabilities, pregnancy, sincerely held religious beliefs or other reasons protected by applicable laws. If you need assistance or a reasonable accommodation, please reach out to us at https://tinyurl.com/RA-request​

📌 Chief Information Security Officer (CISO), Mexico - Global Payment (Ciudad de México)
🏢 Tiktok
📍 Ciudad de México

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: chief information security officer (ciso), mexico - global payment (ciudad de méxico) / ciudad de méxico

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: chief information security officer (ciso), mexico - global payment (ciudad de méxico) / ciudad de méxico