04 sep
|
Empresa Confidencial
|
Nezahualcóyotl
04 sep
Empresa Confidencial
Nezahualcóyotl
Security Governance & Risk Specialist
About the Role
We are looking for a Security Governance & Risk Specialist to support the standardization and continuous improvement of the CSO governance framework. This role is responsible for developing and standardizing security policies and procedures, coordinating risk management sessions with senior leadership, overseeing third-party security assessments, and promoting security awareness across the organization.
The position works closely with key stakeholders, including AVPs, Vice Presidents, Procurement, Legal, Business Units, and external providers, to identify, communicate, and mitigate security risks while ensuring compliance with internal policies, standards, and regulatory requirements.
Key Responsibilities
Review and validate security risk requirements in collaboration with key stakeholders, including senior leaders, AVPs, and Vice Presidents.
Communicate security risks and findings clearly and effectively, working with stakeholders to define strategies and action plans to mitigate identified risks.
Coordinate and lead quarterly security risk management sessions with AVPs and Vice Presidents.
Standardize and maintain CSO policies, procedures, processes, and governance practices in alignment with established security standards.
Manage, monitor, and coordinate third-party security assessment processes (SISR), ensuring compliance with established requirements and security guidelines.
Collaborate with Procurement, Legal, Business Units, and vendors to ensure the proper execution and follow-up of third-party security assessments.
Recommend and monitor remediation plans when security requirements or standards are not met.
Review and validate the ongoing update of CSO policies, procedures,
and processes in accordance with area
Ensure that security governance practices meet minimum security requirements and contribute to the protection, integrity, and confidentiality of assets, data, and services.
Maintain and continuously update the security awareness plan in collaboration with CSO International and the different CSO teams in Mexico.
Design, coordinate, and publish security awareness communications and initiatives for employees.
Lead and coordinate cross-functional teams to ensure effective CSO governance across Mexico, including compliance with security standards, requirements, and data protection controls.
Support security governance activities related to the protection of customers’ payment card data, ensuring compliance with applicable requirements and maintaining PCI certification.
Prepare reports, monitor compliance, and promote continuous improvement through training, preventive measures, policies, and procedures.
Education
Bachelor’s degree in Computer Science, Information Systems, Networking, Telecommunications, Electronics, or a related field.
Preferred: Master’s degree in Cybersecurity, Information Technology, Business Administration (MBA), or a related field.
Experience
Min. 2 years of experience in cybersecurity, security governance, risk management, compliance, or a related field.
Preferred: 4+ years of relevant professional experience.
Language
English: Intermediate level — speaking, writing, and reading.
Technical Knowledge
PCI DSS / PCI compliance
Scrum / Agile methodologies
ISO/IEC 27001
Security governance and risk management
Third-party security assessments
Security policies, standards, and procedures
Security awareness programs
📌 GRC Specialist (Nezahualcóyotl)
🏢 Empresa Confidencial
📍 Nezahualcóyotl