Empresa Confidencial
5 days ago
Deputy Director of Information Security
Sign up to save this job, get alerts, and apply with an optimized CV.
Company information
- Company
- Empresa Confidencial
- Location
- México, Ciudad de México Mexico
- Posted
- 5 days ago
Job description
Important Financial Institution is looking for:
Deputy Director of Information Security
Requirements
- Completed Bachelor's Degree, Master's Degree Desired (Systems Engineering, Computer Science, Cybersecurity, Risk Management, or related discipline, Desired: Master's in Information Security, Risk Management, Information Technology).
Knowledge:
- Proficiency in CNBV regulations (technological risk and continuity), LFPDPPP (data privacy), and audit processes before regulatory authorities (CONDUSEF, INAI, UIF).
- Specialization in ISO 27001, NIST, CIS Controls, and technological risk methodologies to design policies, define tolerance thresholds (KRIs), evaluate third parties (TPRM), and supervise controls under the Three Lines of Defense model.
- Security by Design principles in projects, critical incident management with institutional impact, and definition of technical security requirements for disaster recovery plans (DRP, RPO/RTO).
Experience:
- Governance and Regulatory Compliance: Define and maintain an updated Information Security Governance Framework aligned with international standards (ISO 27001, NIST) and local regulations (CNBV, LFPDPPP).
- Technological Risk Management: Establish the risk framework (KRIs, tolerances) and direct the assessment, mitigation, and monitoring of threats in projects, architectures, and third parties.
- Supervision of Controls and Authority: Evaluate the effectiveness of controls in operational areas, issuing binding observations and blocking projects or acquisitions that put institutional security at risk.
- Incident Response and Continuity: Manage significant incidents by coordinating with the first line of defense, ensure communication with regulatory authorities (CNBV, INAI), and define minimum requirements for recovery plans (DRP/BCP).
- Executive Reporting and Awareness: Present the status of risk and compliance to the Audit and Risk Committee (CAR), as well as design the institutional cybersecurity awareness strategy.
We offer:
- Statutory and superior benefits
If you are interested, apply through this medium and we will be in touch with you.
Required skills
- compliance
- governance
- information technology
- risk management
- computer science
- cybersecurity
- systems engineering
- incident management
- financial institution
- information security
- iso 27001
- audit committee
- nist
- bcp
- security by design
- rto
- tprm
- uif
- cis controls
- rpo
- deputy director
- cybersecurity awareness
- risk committee
- kris
- cnbv
- drp
- condusef
- three lines of defense
- disaster recovery plan
- lfpdppp
- inai
Interested in this position?
Create your free account and tailor your CV to match this job.