22 дня назад
Head of Information Security (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Head of Information Security (Fintech): Leading Mexican information security regulatory compliance, reporting, examinations, audits, and remediation with an accent on CNBV, Banco de México, SPEI, and evidence-based governance. Focus on translating regulatory requirements into actionable controls, coordinating cross-functional stakeholders, and maintaining continuous readiness for regulatory reviews.
Location: Mexico; office work
Company
is a financial technology company operating in Mexico and subject to local financial and information security regulation.
What you will do
- Monitor Mexican information security, cybersecurity, technology risk, business continuity, and related regulatory obligations.
- Own regulatory reports, formal responses, evidence packages, information requests, and audit trails for Mexican regulators.
- Coordinate regulatory examinations and responses with the Global CISO, Legal, Compliance, Risk, Internal Audit, Technology, and Operations.
- Lead preparation for internal audits, regulatory reviews, SPEI assessments, PCI DSS activities, and other assurance exercises.
- Maintain remediation plans, evidence repositories, regulatory commitments, owners, deadlines, and acceptance criteria.
- Manage the local information security regulatory function and represent Information Security before local management and control functions.
Requirements
- At least 5 years of experience in information security, cybersecurity governance, technology risk, regulatory compliance, or IT audit.
- At least 3 years of experience within a regulated financial institution in Mexico.
- Direct experience with CNBV requirements and regulatory examinations, plus practical experience with Banco de México and SPEI-related activities.
- Experience owning regulatory submissions, formal responses, evidence collection, remediation tracking, and translating requirements into operational and technical controls.
- Experience coordinating senior stakeholders and managing employees or specialist regulatory and security teams.
- Fluent Spanish and professional working proficiency in English are required.
Nice to have
- Experience with PCI DSS, ISO 27001, regulatory incident reporting, business continuity, and disaster recovery.
- Certifications such as CISSP, CISM, CRISC, CISA, or ISO 27001 Lead Auditor.
Culture & Benefits
- Continuous readiness for regulatory and audit reviews throughout the year.
- Clear ownership, measurable objectives, transparent reporting, and proactive escalation of risks and blockers.
- Cross-functional collaboration with local and global Information Security, Technology, Legal, Compliance, Risk, Audit, and Operations teams.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →