14 ago
|
Ria Money Transfer (Dandelion)
|
Santiago de Querétaro
14 ago
Ria Money Transfer (Dandelion)
Santiago de Querétaro
**Description**
Ria Money Transfer, a business segment of Euronet Worldwide, Inc. (NASDAQ: EEFT), delivers innovative financial services including fast, secure, and affordable global money transfers to millions of customers along with currency exchange, mobile top-up, bill payment and check cashing services, offering a reliable omnichannel experience. With over 600,000 locations in nearly 200 countries and territories, our purpose remains to open ways for a better everyday life.
We believe we can create a world in which people are empowered to build the life they dream of, no matter who they are or where they are. One customer, one family, one community at a time.
**ABOUT THIS ROLE**
Responsible for coordinating and overseeing the information security program, ensuring that policies, controls, and processes meet internal performance indicators and the regulatory requirements applicable to SPEI. Acts as the liaison between the security compliance and technical teams, reporting to the Global Security GRC team.
**ROLES & RESPONSIBILITIES**
**Responsibilities**:
- ** Development and Maintenance of Security Governance Framework**:
- Develops, implements, and maintains robust Information Security policies, standards, and procedures that align with regulatory requirements and industry best practices.
- Manage and update the suite of security policies, procedures, and standards based on ISO 27001, and NIST, incorporating Banco de México’s SPEI-specific requirements.
- ** KPI Monitoring**:
- Define and maintain KPIs related to response times, issue remediation, and patch compliance; review periodic reports and recommend adjustments to technical teams.
- Produce regular briefings for senior management and Banxico, highlighting trends and critical deviations.
- ** Collaboration Across Departments**:
- Works closely with IT,
Compliance, Privacy, Legal, Risk Management, and Internal Audit teams to ensure security programs support business objectives and comply with applicable laws, regulations, and contractual obligations.
- Acts as a liaison between technical teams and non-technical stakeholders to translate complex security requirements into actionable processes.
- ** Compliance and Audit**:
- Ensure compliance with SPEI regulations (Banxico circulars, Fintech Law, etc.).
- Supports internal and external audits, control reviews, and risk assessments to ensure continuous compliance and readiness for regulatory inspections.
- Manages audit findings and ensures timely implementation of remediation plans to address identified gaps.
- Develops and monitors IT security compliance metrics, generating regular reports for internal stakeholders and regulators.
- ** Third-Party Risk Management (TPRM)**:
- Evaluate and monitor the security posture of partners, vendors, and providers, ensuring compliance with both company security standards and SPEI regulatory requirements.
- ** Risk Management and Reporting**:
- Manages the identification, assessment, and mitigation of security risks across IT and Security operations, with a focus on SPEI systems and infrastructure.
- Maintains a centralized risk register, tracks risk mitigation activities, and reports on the status of key security risks to Integral Security GRC Director.
- ** Continuous Improvement and Training**:
- Keeps abreast of technological advances, evolving threats, and emerging standards in cybersecurity, financial services, and regulatory compliance.
- Provides training and awareness programs for staff, ensuring all employees understand their roles in maintaining compliance and security.
- Promotes a culture of continuous improvement by identifying and implementing process enhancements to strengthen the security posture.
- ** Project Support**:
- Acts as an advisor to project teams, ensuring that new systems and services comply with security requirements from design to deployment.
- Advise development and SPEI system teams to ensure security requirements are addressed from design through production.- Bachelor’s degree in Engineering (Information Security, Systems, or related).
- Postgraduate studies in Information Security preferred.
- CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Auditor.
- Minimum 5 years in Information Security within the financial services or payments sector preferred.
- Proven track record with SPEI or interbank transfer systems.- Excellent verbal and written communication for presenting findings to committees and executives.
- Strong negotiation and coordination skills without direct authority.
- Critical thinking, keen attention to detail, and ability to manage multiple projects simultaneously.
- Professional proficiency in English (reading and writing) and native-level Spanish.- ** Regulatory Commitment**: Rigorous focus on regulatory compliance and ethical standards.
- ** Strategic Vision**: Ability to align the security program with business objectives and regulatory mandates.
- ** Global Collaboration**:Skill in harmonizing local SPEI requi
📌 Manager Information Security (Santiago de Querétaro)
🏢 Ria Money Transfer (Dandelion)
📍 Santiago de Querétaro