Global Information Security Risk and Compliance

hace 2 meses


Monterrey, México Nemak A tiempo completo

Objective

As part of the Information Security organization, develop a strategic program to ensure compliance of regulatory requirements to support the organization's resilience. Through a process of Risk Management and the systematic evaluation of potential threats, the organization will be able to meet the law, regulations and contractual requirements and ensure the organization's objectives are fulfilled.

Furthermore, this role strategically aligns risk management and compliance efforts with the broader organizational strategy, fostering a culture of continuous improvement, supporting the organization's growth and that Information Security efforts are sustainable across Nemak.

Main Responsibilities
- Compliance Strategy: Create and implement compliance strategies and policies to ensure the organization fulfills Information Security requirements of laws, regulations, contracts and IT standards.
- Risk Management and Mitigation: Identify and assess potential Information Security risks to the organization's operations, financial stability, and reputation. Develop risk mitigation plans and monitor their effectiveness. Foster a culture of continuous improvement within the organization, ensuring that risk management and compliance strategies evolve to address emerging risks and regulatory changes.
- Regulatory Compliance: Stay current with relevant laws and regulations affecting the organization's industry and geographic locations. Ensure that policies and controls fulfill these Information Security requirements and work with executive and functional areas to ensure the gaps are closed.
- Policy Development and Management: Develop and manage Information Security compliance policies, codes of conduct, and internal control frameworks. Communicate policies effectively throughout the organization and develop programs to ensure their effectiveness across the organization.
- Training and Education: Provide Information Security compliance training and awareness programs to employees, management, and relevant stakeholders to ensure a culture of compliance and risk management.
- Compliance Monitoring and Reporting: Establish systems and processes to monitor compliance with Information Security policies, regulations, and standards. Regularly provide updates to executive management on the key performance indicators and risk levels. Provide information requirements to certification entities required for Information Security and Sustainability process to ensure growth strategic goals are achieved.
- Third-Party Due Diligence: Assess and manage Information Security risks associated with third-party relationships, such as vendors, suppliers, and partners. Implement due diligence processes and ongoing monitoring to comply with Information Security Requirements for Suppliers policy.
- Data Protection and Privacy: Oversee and coordinate data protection and privacy compliance with GDPR and other privacy relevant regulations. Ensure data handling practices are in line with legal requirements.
- Audit Management: Prepare and support Information Security regular audits, whether internal or external. Ensure that the organization is always prepared to comply with audit requirements, minimizing disruptions and potential penalties. Monitor the correct implementation of Information Security controls across Nemak. Ensure remediation programs are in place.
- Access Management: Develop strategies to ensure that the access management practice operates with industry best practices for key critical systems like SAP, Success Factors and key platforms. Define security frameworks to improve security models in SAP and supported platforms. Manage the Security Architecture in SAP and SAP GRC ensuring controls are in place and evidences are produced.

Position Requirements
- Career: Computer Systems Engineering, Law, Business Administration
- Experience: 5- 8 years’ experience in Audit and Compliance, Risk Management, Internal Control Management, Data Privacy and Security, IT Systems Management, Multicultural experience.
- Certifications: Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC).
- Strong knowledge of industry standards, regulations, and frameworks (e.g., ISO 27001, NIST, GDPR).
- Behavioral Skills: Analysis and problem solving, Drive, Multitasking, Manage and energize teams, Common sense and urgency, Leadership, Work under pressure, Desire for new challenges, Embrace change, Excellent communication skills, Challenge the status quo, Proactive, Analytic, Self-learner, Desire for innovation, Positive.
- Strong project management skills with the ability to prioritize and manage multiple initiatives simultaneously.
- Strong communication and leadership skills, with the ability to collaborate effectively with cross-functional teams and senior management.
- Advanced English and Spanish.
- At Nemak, Diversity, Equity and Inclusion



  • Monterrey, México Nearshore Cyber A tiempo completo

    **Location: Monterrey or Matamoros, Mexico**: **Applications from persons not living in Mexico will NOT be accepted.** Information Security Risk Assessors report continuously on the state of risk, providing visibility and helping business leaders and risk managers understand where risk resides and where improvements must be made to protect the business....

  • IT Security Risk

    hace 1 mes


    Monterrey, México Neoris A tiempo completo

    **IT Security Risk & Compliance Analyst**: **Date**:Mar 6, 2023 **Location**: MONTERREY, MX **Company**:NEORIS En **NEORIS**, acelerador digital que ayuda a las compañías a entrar en el futuro, estamos en búsqueda de IT Security Risk & Compliance Analyst , **Principales Responsabilidades**: - Definición de planes de trabajo - Diseño de soluciones...

  • Ot Risk

    hace 1 mes


    Monterrey, México Axen A tiempo completo

    Description At AXEN IT Consulting we are growing exponentially with clients with great growth projections, We have more than 25 years of experience in the information technology services market, Focused on our growth and at the same time offering improvement plans to our talent, We are currently looking for " OT Risk & Compliance " with the profile: ...


  • Monterrey, México Nemak A tiempo completo

    IT Risk and Compliance Specialist Objective Ensure continuity of SAP Security projects and to ensure SAP Security roles are properly maintained. This function plays an important role for compliance with external audits. Main Responsibilities Ensure the security and compliance of SAP and IT critical systems within the organization by...


  • Monterrey, México Nearshore Cyber A tiempo completo

    **Location: Monterrey or Matamoros, Mexico**:** Applications from persons not living in Mexico will NOT be accepted.** The role also requires an understanding of business goals/strategy and operational requirements in a fast-paced environment. Throughout the roles key responsibilities, the Information Security Engineer must always consider opportunities to...


  • Monterrey, México Neoris A tiempo completo

    **Mexico Cyber and OT Security Specialist**: **Date**:Nov 9, 2023 **Location**: MONTERREY, MX **Company**:NEORIS We are **NEORIS**! **As a digital accelerator we help companies step into the future! Currently we are looking for a Mexico Cyber and OT Security Specialist. **REQUIREMENTS**: - Bilingual (Spanish and English)- 20% availability to travel into...


  • Monterrey, México Praxis A tiempo completo

    **PRAXIS **is a leading company that seeks to strengthen companies through the use of specialized methodologies and tools and with a focus on consulting, integration, outsourcing, and systems development. We're looking for a **Information security - Privileged Access Management**(Remote 100%)** **Responsibilities**: - Review Identity and Access Management...


  • Monterrey, México Chubb INA Holdings Inc. A tiempo completo

    Job Requirements **Key Responsibilities**: Management and completion of Chubb inherent risk ranking of ALL suppliers in compliance with the Global Third-Party Cyber Risk policy. This includes liaising with and working alongside the Global Third-Party team as well as Business relationship Owners. Risk assessments of Cloud providers Identification, tracking...


  • Monterrey, Nuevo León, México Danfoss A tiempo completo

    Job DescriptionAre you looking to join a company that is passionate about the environment and is actively contributing to the green movement? Do you want to be a part of safeguarding the future of this remarkable organization? Are you someone who thrives in a progressive and dynamic work environment that prioritizes Information Security? Do you aspire to...

  • Consultant Security

    hace 4 semanas


    Monterrey, México HLS Group A tiempo completo

    **Vacante para la empresa HLS Group en Centro Col. Poniente -Monterrey, Nuevo León**: HLS Group: 100% Mexican company, experts in providing comprehensive technology solutions, we are looking for talent such as: **Consultant Security** **Requirements**: TSU, Engineering or degree in computer science or similar. Experience of 5 years or...


  • Monterrey, México grow.com A tiempo completo

    **General information**: - Office (s)- Monterrey, MEX- Date Published- Wednesday, August 23, 2023- Country- Mexico- Job ID- 22814- Function- Information Technology**Description & Requirements**: **About the role**: - The Governance, Risk Management & Compliance Analyst is responsible for working with the GRC leadership team, Information Technology, Epicor...


  • Monterrey, México Nearshore Cyber A tiempo completo

    **Location: Monterrey or Matamoros, Mexico**:** Applications from persons not living in Mexico will NOT be accepted.** The Information Security Analyst is responsible for activities relating to monitoring and responding to security events. The analyst receives, researches, triages, and documents all security events and alerts as they are received,...


  • Monterrey, México Danfoss A tiempo completo

    Job Description Do you want to work in an exciting company that cares about the climate and that contributes to the green transition? Do you want to help protect this great company? Do you thrive in a developing and dynamic company that invests in Information Security? Do you want to play a key part in the management of information security risks? If you can...


  • Monterrey, México Envia.com A tiempo completo

    **What do we expect from you in the area?** As an **Information Security Analyst**, you will be responsible for protecting the company's systems, networks, and data against cyber threats. You will detect and respond to security incidents, mitigate vulnerabilities, educate staff on security, ensure compliance with applicable security regulations and...


  • Monterrey, México ContactPoint 360 A tiempo completo

    **Responsibilities**: - Oversee and manage all aspects of the delivery center’s physical security, including access controls, surveillance systems, alarm systems, and security personnel. - Conduct regular assessments and audits to identify potential vulnerabilities and areas for improvement within the delivery center’s security infrastructure. - Stay...

  • Third Party Risk Advisor

    hace 4 semanas


    Monterrey, México Nearshore Cyber A tiempo completo

    **Location: Monterrey or Matamoros, Mexico**:** Applications from persons not living in Mexico will NOT be accepted.** The Third Party Risk Advisor is responsible for third-party information risk management related to suppliers and other third parties. The individual creates and leads an effective program to improve suppliers' information security maturity...


  • Monterrey, N.L., México Danfoss GmbH A tiempo completo

    Press Tab to Move to Skip to Content Link Select how often (in days) to receive an alert: Create Alert Select how often (in days) to receive an alert: Do you want to work in an exciting company that cares about the climate and that contributes to the green transition? Do you want to help protect this great company? Do you thrive in a developing and...


  • Monterrey, México Axented A tiempo completo

    A Security Specialist focused on app development and IT infrastructure plays a crucial role in ensuring the security and integrity of digital assets. They are responsible for identifying vulnerabilities, implementing security measures, and responding to security breaches. Below are the tools commonly used by Security Specialists to perform their duties...

  • IT Compliance Analyst

    hace 4 semanas


    Monterrey, México Nearshore Cyber A tiempo completo

    **Location: Monterrey or Matamoros, Mexico**:** Applications from persons not living in Mexico will NOT be accepted.** **Position Summary** **Essential Job Duties** - Serve on a distributed compliance team responsible for reviewing and documenting where security and technology controls are adequate or need improvement. Work closely with compliance and...


  • Monterrey, México British American Tobacco A tiempo completo

    **BAT MEXICO** **IS LOOKING FOR A SECURITY INTERN** **SENIORITY LEVEL**:Intern **FUNCTION**: Legal & External Affairs **LOCATION**:Monterrey, Mexico **ROLE POSITIONING AND OBJECTIVES** This role is part of legal & External Affairs The role is responsible for Assist on the delivery of Security strategies. **Reports to**:LM **WHAT YOU WILL BE...