Назад
Company hidden
4 часа назад

Senior Manager, GRC People and Policy (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Mexico
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Manager, GRC People and Policy (Cybersecurity): Leading global cybersecurity governance, risk, and compliance programs covering people risk, vulnerability assurance, security awareness training, and corporate information security policies with an accent on behavioral risk reduction, audit readiness, and cross-functional leadership. Focus on adaptive phishing education, translating regulatory changes into actionable policies, and aligning security programs with SOC 2 and ISO 27001 requirements.

Location: Guadalajara, Mexico; hybrid work under hirify.global's Freedom to Flex model

Company

hirify.global develops cybersecurity and application delivery solutions that help organizations create, secure, and run applications.

What you will do

  • Lead and coach a cross-functional team covering policy governance, vulnerability assurance, security training development, and training compliance.
  • Oversee risk profiling and threat modeling for high-risk internal groups.
  • Mature phishing simulations with adaptive learning paths based on real-time vulnerability data.
  • Set the strategic direction for global security awareness training, onboarding requirements, and annual compliance programs.
  • Govern the lifecycle of global cybersecurity policies, standards, and procedures.
  • Partner with legal, HR, engineering, and executives to translate regulatory and technical changes into approved business policies.

Requirements

  • 8+ years of experience in cybersecurity GRC, information security policy, or security awareness management.
  • 3+ years of direct people management experience leading technical and non-technical teams in a corporate environment.
  • Experience building and scaling people risk or vulnerability assurance programs in technology or security industries.
  • Bachelor's degree in Cybersecurity, Computer Science, Technical Communications, or a related field, or equivalent professional experience.
  • Strategic communication skills for presenting risk insights and program performance to the VP of GRC.
  • Ability to manage distributed teams within a hybrid work framework.

Nice to have

  • CISSP, CISM, CRISC, or SANS Security Awareness Professional certification.

Culture & Benefits

  • Hybrid work combining remote flexibility with purposeful in-office collaboration.
  • Human-first culture focused on inclusion and employee development.
  • Opportunity to lead global programs supporting SOC 2, ISO 27001, and regulatory audits.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →