Plata Card·Mexico·2 дн назад
Head of Information Security
🏢 ОфисDirectorПолная занятость
Вилки нет, про деньги придётся договариваться с нуля.
Наша компания
The primary responsibility is to ensure that the company understands its obligations, submits accurate information on time, and remains continuously prepared for regulatory reviews. This is not primarily a security engineering role. Global Information Security and Technology teams implement technical controls. The Head of Information Security must translate Mexican regulatory requirements into clear actions, coordinate delivery across those teams, validate evidence, and remain accountable for the final regulatory outcome.
О роли
The successful candidate must combine senior regulatory judgment with disciplined execution. The role requires someone who personally verifies facts, follows issues through to completion, and does not rely on last-minute intervention from other functions.
Чем предстоит заниматься
Own the preparation and coordination of Information Security reports, formal responses, indicators, evidence packages, and information requests submitted to Mexican regulators
Coordinate reporting related to CNBV, Banco de México, SPEI, and other applicable local supervisory activities within the scope of Information Security
Verify all submitted information against source systems and supporting evidence
Ensure that reports accurately identify the work performed, responsible owners, control status, findings, incidents, and remediation progress
Maintain a clear audit trail of data sources, reviews, approvals, submissions, and regulator correspondence
Prevent incomplete, unsupported, inconsistent, or misleading information from being submitted to management, auditors, or regulators
Lead Information Security preparation for internal audits, regulatory reviews, SPEI assessments, PCI DSS activities, and other assurance exercises applicable to Mexico
Maintain an evidence repository that is complete, current, and easy to validate
Review evidence before submission and challenge unsupported statements or incomplete control descriptions
Convert findings into remediation plans with clear owners, actions, deadlines, dependencies, and acceptance criteria
Monitor remediation and escalate overdue or blocked actions
Ensure that Information Security audit and regulatory activities remain owned by the Local CISO and do not require another function to take over coordination
Manage the local Information Security regulatory function with clear responsibilities, measurable objectives, and regular performance reviews
Build effective working relationships with Compliance, Legal, Internal Audit, Risk, Technology, Operations, Fraud Prevention, Business Continuity, and global Information Security teams
Assign work based on actual responsibilities and demonstrated workload
Address underperformance promptly and document management actions
Request additional resources only when supported by a clear scope, workload, capability gap, and expected outcome
Наши требования
Experience with PCI DSS, ISO 27001, regulatory incident reporting, business continuity, and disaster recovery
Professional certifications such as CISSP, CISM, CRISC, CISA, or ISO 27001 Lead Auditor
At least 5 years of experience in Information Security, cybersecurity governance, technology risk, regulatory compliance, or IT audit
At least 3 years of experience within a regulated financial institution in Mexico
Direct experience working with CNBV requirements and regulatory examinations
Practical experience with Banco de México and SPEI-related security, audit, reporting, or compliance activities
Proven ownership of regulatory submissions, formal responses, evidence collection, and remediation tracking
Experience translating regulatory requirements into operational and technical controls
Experience coordinating senior stakeholders across Information Security, Technology, Legal, Compliance, Risk, Internal Audit, and Operations
Experience managing employees or specialist regulatory and security teams
Strong understanding of Information Security governance, risk management, incident response, access management, business continuity, third-party risk, logging, vulnerability management, and data protection
Fluent Spanish and professional working proficiency in English
Excellent written communication skills in both languages
Дополнительно
Monitor Mexican Information Security, cybersecurity, technology risk, business continuity, and related regulatory requirements applicable to The Company
Maintain a complete register of regulatory obligations, reporting deadlines, responsible owners, required evidence, dependencies, and current status
Interpret regulatory requirements and translate them into clear, actionable tasks for Information Security, Technology, Internal IT, Operations, Fraud Prevention, Business Continuity, and other responsible teams
Assess the impact of regulatory changes and coordinate required updates to controls, processes, policies, procedures, and reporting
Escalate regulatory risks, missing evidence, and potential delays before obligations become overdue
Act as the primary Information Security contact in Mexico for regulatory examinations, formal information requests, interviews, and follow-up activities
Coordinate responses with the Global CISO, Legal, Compliance, Risk, Internal Audit, Technology, and other relevant stakeholders
Prepare Company representatives for regulatory meetings and ensure that answers are consistent, accurate, and supported by evidence
Track all commitments made to regulators until formally completed
Maintain readiness throughout the year rather than preparing only after an examination or request begins
Represent Information Security before local management and control functions
Provide clear reporting on regulatory exposure, control gaps, audit findings, incidents, remediation, and material risks
Coordinate local implementation of the global Information Security Program
Ensure that local regulatory requirements are reflected in The Company’s Information Security documentation
Review local-language policies, procedures, standards, and regulatory responses to ensure that they preserve the original requirements and control meaning
Support regulatory aspects of information security incidents, including assessment of reporting obligations, evidence collection, and coordination of formal notifications
Regulatory reports are complete, accurate, approved, and supported by source-system evidence
All regulatory obligations and findings have documented owners, actions, deadlines, status, and evidence
Risks and blockers are escalated before they affect delivery
The Company remains ready for regulatory and audit reviews without emergency preparation
Engineering and operational teams receive clear, actionable requirements rather than copied regulatory text
Remediation activities progress without repeated intervention from the Global CISO
Local Information Security responsibilities are managed independently and transparently