Login Enter

Empresa Confidencial

5 days ago

Deputy Director of Information Security

Sign up free Log in

Sign up to save this job, get alerts, and apply with an optimized CV.

Company information

Company
Empresa Confidencial
Location
México, Ciudad de México Mexico
Posted
5 days ago
View all jobs at Empresa Confidencial

Job description

Important Financial Institution is looking for:

Deputy Director of Information Security

Requirements

  • Completed Bachelor's Degree, Master's Degree Desired (Systems Engineering, Computer Science, Cybersecurity, Risk Management, or related discipline, Desired: Master's in Information Security, Risk Management, Information Technology).

Knowledge:

  • Proficiency in CNBV regulations (technological risk and continuity), LFPDPPP (data privacy), and audit processes before regulatory authorities (CONDUSEF, INAI, UIF).
  • Specialization in ISO 27001, NIST, CIS Controls, and technological risk methodologies to design policies, define tolerance thresholds (KRIs), evaluate third parties (TPRM), and supervise controls under the Three Lines of Defense model.
  • Security by Design principles in projects, critical incident management with institutional impact, and definition of technical security requirements for disaster recovery plans (DRP, RPO/RTO).


Experience:

  • Governance and Regulatory Compliance: Define and maintain an updated Information Security Governance Framework aligned with international standards (ISO 27001, NIST) and local regulations (CNBV, LFPDPPP).
  • Technological Risk Management: Establish the risk framework (KRIs, tolerances) and direct the assessment, mitigation, and monitoring of threats in projects, architectures, and third parties.
  • Supervision of Controls and Authority: Evaluate the effectiveness of controls in operational areas, issuing binding observations and blocking projects or acquisitions that put institutional security at risk.
  • Incident Response and Continuity: Manage significant incidents by coordinating with the first line of defense, ensure communication with regulatory authorities (CNBV, INAI), and define minimum requirements for recovery plans (DRP/BCP).
  • Executive Reporting and Awareness: Present the status of risk and compliance to the Audit and Risk Committee (CAR), as well as design the institutional cybersecurity awareness strategy.

We offer:

- Statutory and superior benefits

If you are interested, apply through this medium and we will be in touch with you.


Required skills

Interested in this position?

Create your free account and tailor your CV to match this job.