Назад
Company hidden
1 день назад

Information Security Specialist Lead (Cybersecurity)

Формат работы
remote (только Costa_rica)/hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
CR
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Information Security Specialist Lead (Cybersecurity): Leading the design, implementation, and evaluation of enterprise security risk and controls frameworks with an accent on GRC, control assurance, and regulatory alignment. Focus on mapping controls to risks in Archer, identifying remediation gaps, automating governance processes, and presenting security requirements to business stakeholders.

Location: Heredia, Costa Rica; hybrid role also described as remote

Company

hirify.global is a global data and technology company serving markets including financial services, healthcare, automotive, agribusiness, and insurance.

What you will do

  • Lead the modularisation of the security risk and controls framework and maintain the enterprise controls library.
  • Review business-unit control activities, identify gaps, and recommend remediation.
  • Map information security controls to risks and risk register entries in the Archer GRC platform.
  • Prepare management reports, analysis, presentations, and controls implementation workshops.
  • Monitor internal and external risk indicators and contribute them to control assurance activities.
  • Standardize and automate risk and controls processes while supporting strategic information security governance projects.

Requirements

  • Bachelor’s degree in computer science, management information systems, or a relevant field, or equivalent experience.
  • 5+ years of hands-on experience designing, implementing, and evaluating security controls.
  • Experience with GRC tools such as Archer and strong knowledge of governance, risk, and controls principles.
  • Understanding of NIST, ISO, COBIT, CMMI, OWASP, and ITIL best practices.
  • Knowledge of IT security, cloud security, cybersecurity operations, risk management, architecture, threats, and vulnerabilities.
  • Ability to translate technical requirements for non-technical audiences; CCSP, CRISC, CISSP, CISM, or equivalent experience is relevant.

Nice to have

  • Working knowledge of the AWS cloud environment.
  • Knowledge of financial services regulations.
  • Experience using AI to automate processes.

Culture & Benefits

  • People-first, inclusive, and purpose-driven culture across 32 countries.
  • Medical, life, and dental insurance.
  • Flex work and work-from-home options with paid time off.
  • Annual performance bonus and International Share Save Plan.
  • Education reimbursement, family bonding and bereavement leave, referral program, and Asociacion Solidarista.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →