Information Security Risk Assessor

hace 5 meses


Monterrey, México Nearshore Cyber A tiempo completo

**Location: Monterrey or Matamoros, Mexico**:
**Applications from persons not living in Mexico will NOT be accepted.**

Information Security Risk Assessors report continuously on the state of risk, providing visibility and helping business leaders and risk managers understand where risk resides and where improvements must be made to protect the business. Such reporting includes adherence to regulations and industry guidelines, as well as corporate risk acceptance. The cybersecurity risk assessor focuses on third-party risk, as well as risks within internal and business-controlled areas of security, technology, and business processes. Information Security Risk Assessors partner with audit, compliance, and legal as needed.

**Essential Job Duties**
- Serve on a distributed risk team responsible for reviewing and documenting where security and technology controls are adequate, as well as areas requiring improvement and where risk is to high.
- Recommend risk reduction steps to be implemented and maintained through policies, procedures, frameworks, and technical controls.
- Work closely with risk management and security leadership, teammates, and stakeholders to evaluate and recommend models aligning with organizational risk posture.
- Identify strengths and weaknesses in the program as they relate to privacy, security, business resiliency, and compliance frameworks.
- Document, formulate and enforce security improvements that balance risk with business operations, and do not diminish efficiencies or innovation.
- Attend change and project management meetings to understand and proactively strengthen controls to avoid unnecessary risk across lines of business.
- Support company risk posture through development of controls and processes used in test, quality assurance and production environments from conception to completion.
- Analyze workflows, design documents and procedures to identify gaps in risk posture and risk acceptability based on controls.
- Create and present risk posture discovery and recommendation reports to leadership.
- Review technical reports from vulnerability and penetration testing assessments, and results from tabletop exercises.
- Monitor plans of action and milestones for risk remediation requirements from internal and external security assessments, vulnerability reports, audit findings and security gaps.
- Remain educated on regulatory requirements, internal policies, and industry best practices.
- Liaise with technical and business teams on business continuity and disaster recovery requirements.
- Provide strong oversight of third parties, vendors, and business partners to safeguard against undue risk presented by external entities.
- Frequently interact with business units to understand their plans, risk posture and tolerance, and how to support their vision and business obligations with security and risk in mind.
- Openly support the organization, the management team, and executive leadership team, even during times of adversity.
- Perform other duties as assigned.

**Skills and Experience**
- Preferably 3-5+ years experience in security systems administration, with 2+ years risk management experience.
- Ideally familiar with one or more regulatory requirements and laws such as, but not limited to, SOX, HIPAA, GDPR, and GLBA. Additionally, experience in one or more: ISO 17799, ITIL and NIST.
- General understanding of the Factor Analysis of Information Risk (FAIR) methodology.
- Track record of taking pride in work, seeking to excel, and being curious and flexible. Strong written and oral communication skills across varying levels of the organization.
- Understanding of service design, delivery concepts and control frameworks.
- Organized, with the ability to prioritize and complete tasks within defined SLAs.
- Excellent judgment and ability to make quick decisions when working with complex situations.
- High degree of integrity, trustworthiness, and confidence; represents the company and its management team with the highest level of professionalism.
- Education Requirements
- Bachelors degree or equivalent industry experience in information assurance, computer science, engineering, or related field.

**Certification Requirements**
- CRISC, CISSP, CISA, CGEIT, GCCC, GSEC, GISP, or other relevant certifications preferable but not required.



  • Monterrey, Nuevo León, México Danfoss A tiempo completo

    Job Responsibilities:The ideal candidate will drive the continuous development of the risk management process, communicate effectively with various stakeholders across the organization, and support the Security Governance of the ISMS. Responsibilities include:Ensuring application of security standards, principles, and practicesContributing to design,...


  • Monterrey, México Nemak A tiempo completo

    Objective As part of the Information Security organization, develop a strategic program to ensure compliance of regulatory requirements to support the organization's resilience. Through a process of Risk Management and the systematic evaluation of potential threats, the organization will be able to meet the law, regulations and contractual requirements and...


  • Monterrey, Nuevo León, México Nemak A tiempo completo

    About NemakNemak is a leading provider of automotive components, committed to delivering high-quality products and services to its customers.Job Title: Global Information Security Risk and Compliance StrategistWe are seeking an experienced Global Information Security Risk and Compliance Strategist to join our team. This role will be responsible for...


  • Monterrey, Nuevo León, México Ikraft Solutions A tiempo completo

    Job SummaryThe Sr Information Security Analyst will be a key member of the Information Security team at Ikraft Solutions. This person will work closely with cross-functional teams to ensure appropriate physical, administrative, and technical controls are operating effectively to ensure the confidentiality, integrity, and availability of information...


  • Monterrey, Nuevo León, México Nemak A tiempo completo

    OverviewIn this critical role, you will develop and implement a strategic program to ensure compliance with regulatory requirements, supporting Nemak’s resilience.You will identify and assess potential Information Security risks, developing risk mitigation plans and monitoring their effectiveness.Main ResponsibilitiesCompliance Strategy: Create and...


  • Monterrey, Nuevo León, México Danfoss A tiempo completo

    Job SummarySenior Information Security Expert: A Key Role at DanfossAt Danfoss, we are seeking a highly skilled Senior Information Security Expert to join our team. This role is critical in ensuring the security and integrity of our information systems and assets. The ideal candidate will have a strong background in information security, with a focus on risk...


  • Monterrey, México iKraft Solutions A tiempo completo

    The **Sr Information Security Analyst **will be a key member Information Security team. This person will work closely with cross functional teams to ensure appropriate physical, administrative and technical controls are operating effectively to ensure the confidentiality, integrity and available information resources. Strategize on the development and...


  • Monterrey, Nuevo León, México Nearshore Cyber A tiempo completo

    Job SummaryWe are seeking an experienced Enterprise Information Security Manager to join our team at Nearshore Cyber. This is a unique opportunity to drive information security initiatives and make a significant impact on our organization.About the RoleThe Enterprise Information Security Manager will be responsible for leading our third-party risk management...


  • Monterrey, México Nearshore Cyber A tiempo completo

    **Location: Monterrey or Matamoros, Mexico**:** Applications from persons not living in Mexico will NOT be accepted.** The role also requires an understanding of business goals/strategy and operational requirements in a fast-paced environment. Throughout the roles key responsibilities, the Information Security Engineer must always consider opportunities to...


  • Monterrey, Nuevo León, México Danfoss A tiempo completo

    At Danfoss, we are seeking a highly skilled Information Security Consultant to join our team.Job Summary:We offer a competitive salary of $120,000 per year, based on your qualifications and experience. This is a full-time position with excellent benefits.About the JobThis role will drive the continuous development of the risk management process. As an...


  • Monterrey, Nuevo León, México Nemak A tiempo completo

    Nemak is committed to fostering a culture that values diversity, equity and inclusion.We are seeking an Information Security Analyst to join our team in this critical role.This position will play a pivotal part in maintaining the integrity and security of our systems.Key ResponsibilitiesDesign and implement security access management architecture models for...


  • Monterrey, Nuevo León, México Axen A tiempo completo

    Cybersecurity Expertise for Industrial ProcessesAt Axen IT Consulting, we are committed to delivering exceptional cybersecurity services to our clients. As a cybersecurity expert, you will play a vital role in protecting our clients' industrial processes from cyber threats.Key ResponsibilitiesManage all aspects of Information Technology cybersecurity...


  • Monterrey, Nuevo León, México Nemak A tiempo completo

    Job SummaryWe are seeking a highly skilled Information Security Governance Analyst to join our team at Nemak. As a key member of our IT security team, you will be responsible for designing and implementing security access management architecture models for SAP and other critical platforms, ensuring compliance with industry best practices.Main...


  • Monterrey, Nuevo León, México NEORIS A tiempo completo

    About NEORISNEORIS is a pioneering digital accelerator that empowers companies to navigate the future. With 20 years of experience as a trusted digital partner to global leaders, we boast a multicultural startup culture that fosters innovation and continuous learning, yielding high-value solutions for our clients.We're Hiring: Chief Information Security...


  • Monterrey, México Nearshore Cyber A tiempo completo

    **Location: Monterrey or Matamoros, Mexico**:** Applications from persons not living in Mexico will NOT be accepted.** The Information Security Analyst is responsible for activities relating to monitoring and responding to security events. The analyst receives, researches, triages, and documents all security events and alerts as they are received,...

  • Information Security Lead

    hace 4 semanas


    Monterrey, Nuevo León, México Danfoss A tiempo completo

    Job ResponsibilitiesThis role involves driving the continuous development of the risk management process.The ideal candidate will communicate effectively with various stakeholders across the organization and support the Security Governance of the ISMS.Responsibilities include supporting the Information Security Governance tactics and approaches, ensuring the...


  • Monterrey, Nuevo León, México Scranton, PA A tiempo completo

    Job Title: Information Security SpecialistThis role is responsible for ensuring the security and integrity of University systems and networks. The ideal candidate will have a strong background in information security technologies, including auditing tools, antivirus software, and firewalls.Key Responsibilities:Research and implement information security...


  • Monterrey, Nuevo León, México Epicor A tiempo completo

    About the Role:">The Governance, Risk Management & Compliance Specialist is responsible for collaborating with cross-functional teams to analyze and implement robust Security & Risk Management frameworks, policies, standards, and best practices.- Supports the review of evidence for compliance requirements (PCI-DSS, SOX, SSAE18, etc.) and industry-recognized...


  • Monterrey, Nuevo León, México Danfoss A tiempo completo

    About DanfossAt Danfoss, we are dedicated to engineering solutions that allow the world to use resources in smarter ways. Our mission is to drive the sustainable transformation of tomorrow by developing innovative technologies that enable efficient energy use and reduce emissions.We believe that innovation and great results are driven by a diverse team of...


  • Monterrey, México Envia.com A tiempo completo

    **What do we expect from you in the area?** As an **Information Security Analyst**, you will be responsible for protecting the company's systems, networks, and data against cyber threats. You will detect and respond to security incidents, mitigate vulnerabilities, educate staff on security, ensure compliance with applicable security regulations and...