Information Security Risk Assessor

hace 2 semanas


Monterrey, México Nearshore Cyber A tiempo completo

**Location: Monterrey or Matamoros, Mexico**:
**Applications from persons not living in Mexico will NOT be accepted.**

Information Security Risk Assessors report continuously on the state of risk, providing visibility and helping business leaders and risk managers understand where risk resides and where improvements must be made to protect the business. Such reporting includes adherence to regulations and industry guidelines, as well as corporate risk acceptance. The cybersecurity risk assessor focuses on third-party risk, as well as risks within internal and business-controlled areas of security, technology, and business processes. Information Security Risk Assessors partner with audit, compliance, and legal as needed.

**Essential Job Duties**
- Serve on a distributed risk team responsible for reviewing and documenting where security and technology controls are adequate, as well as areas requiring improvement and where risk is to high.
- Recommend risk reduction steps to be implemented and maintained through policies, procedures, frameworks, and technical controls.
- Work closely with risk management and security leadership, teammates, and stakeholders to evaluate and recommend models aligning with organizational risk posture.
- Identify strengths and weaknesses in the program as they relate to privacy, security, business resiliency, and compliance frameworks.
- Document, formulate and enforce security improvements that balance risk with business operations, and do not diminish efficiencies or innovation.
- Attend change and project management meetings to understand and proactively strengthen controls to avoid unnecessary risk across lines of business.
- Support company risk posture through development of controls and processes used in test, quality assurance and production environments from conception to completion.
- Analyze workflows, design documents and procedures to identify gaps in risk posture and risk acceptability based on controls.
- Create and present risk posture discovery and recommendation reports to leadership.
- Review technical reports from vulnerability and penetration testing assessments, and results from tabletop exercises.
- Monitor plans of action and milestones for risk remediation requirements from internal and external security assessments, vulnerability reports, audit findings and security gaps.
- Remain educated on regulatory requirements, internal policies, and industry best practices.
- Liaise with technical and business teams on business continuity and disaster recovery requirements.
- Provide strong oversight of third parties, vendors, and business partners to safeguard against undue risk presented by external entities.
- Frequently interact with business units to understand their plans, risk posture and tolerance, and how to support their vision and business obligations with security and risk in mind.
- Openly support the organization, the management team, and executive leadership team, even during times of adversity.
- Perform other duties as assigned.

**Skills and Experience**
- Preferably 3-5+ years experience in security systems administration, with 2+ years risk management experience.
- Ideally familiar with one or more regulatory requirements and laws such as, but not limited to, SOX, HIPAA, GDPR, and GLBA. Additionally, experience in one or more: ISO 17799, ITIL and NIST.
- General understanding of the Factor Analysis of Information Risk (FAIR) methodology.
- Track record of taking pride in work, seeking to excel, and being curious and flexible. Strong written and oral communication skills across varying levels of the organization.
- Understanding of service design, delivery concepts and control frameworks.
- Organized, with the ability to prioritize and complete tasks within defined SLAs.
- Excellent judgment and ability to make quick decisions when working with complex situations.
- High degree of integrity, trustworthiness, and confidence; represents the company and its management team with the highest level of professionalism.
- Education Requirements
- Bachelors degree or equivalent industry experience in information assurance, computer science, engineering, or related field.

**Certification Requirements**
- CRISC, CISSP, CISA, CGEIT, GCCC, GSEC, GISP, or other relevant certifications preferable but not required.



  • Monterrey, México Nemak A tiempo completo

    Objective As part of the Information Security organization, develop a strategic program to ensure compliance of regulatory requirements to support the organization's resilience. Through a process of Risk Management and the systematic evaluation of potential threats, the organization will be able to meet the law, regulations and contractual requirements and...


  • Monterrey, México Chubb INA Holdings Inc. A tiempo completo

    Job Requirements **Role Purpose**: The Information Security Intern (ISI) assists in the development, implementation, and maintenance of the global information security program, focusing on regional vulnerability management. As a member of the regional information security team, the ISI position is tasked with providing support and follow up for regional...

  • Ot Risk

    hace 4 semanas


    Monterrey, México Neoris A tiempo completo

    **OT Risk & Compliance**: **Date**:Nov 2, 2023 **Location**: MONTERREY, MX **Company**:NEORIS We are **NEORIS**! **As a digital accelerator we help companies step into the future! Currently we are looking for a OT Risk & Compliance. **RESPONSIBILITIES**: - Define OT Cybersecurity policies. - Develop metrics framework that effectively measures...


  • Monterrey, México Celestica A tiempo completo

    Performs tasks such as, but not limited to, the following: - Be able to administratively configure and manage key security solutions - Manage an enterprise-sized solution base of more than 15,000 endpoints - Provide 3rd level security solution support ensuring specified service levels are met - Able to provide input to and work with the larger security team...

  • Consultant Security

    hace 4 semanas


    Monterrey, México Axen A tiempo completo

    Description At AXEN IT Consulting we are growing exponentially with clients with great growth projections, We have more than 25 years of experience in the information technology services market, Focused on our growth and at the same time offering improvement plans to our talent, We are currently looking for " Consultant Security " with the...


  • Monterrey, México SWBC A tiempo completo

    SWBC is seeking a talented individual to assist the Offices of Corporate Information Security and Corporate Physical Security in the management and exaction of information and physical security controls to protect company owned and controlled assets, information, personnel, and property. Manage the first line of defense that is our Physical Security presence...


  • Monterrey Centro, México SWBC A tiempo completo

    Additional Job Description SWBC is seeking a talented individual to assist the Offices of Corporate Information Security and Corporate Physical Security in the management and exaction of information and physical security controls to protect company owned and controlled assets, information, personnel, and property. Manage the first line of defense that is...


  • Monterrey, México Neoris A tiempo completo

    En NEORIS es un acelerador Digital que ayuda a las compañías a entrar en el futuro, teniendo 20 años de experiência como Socios Digitales de algunas de las mayores compañías del mundo. Somos más de 4,000 profesionales en 11 países, con nuestra cultura multicultural de startup en donde cultivamos innovación, aprendizaje continuo para crear soluciones...


  • Monterrey, México Pinkerton A tiempo completo

    Job Summary: The Security Coordinator assigned to a specific client, will be responsible for developing all security programs, personnel, contractors, and consultants. The coordinator will be responsible for the strategic identification of security risks, threats, and vulnerabilities as well as the prevention and protection of the client's employees,...


  • Monterrey, México CHUBB A tiempo completo

    The Chubb Information Security team is responsible for protecting information and information systems against unauthorized access, detecting and responding to attempts to gain access and enabling access through our identity processes. Chubb operates a global information security team supporting local business units across five regions (Asia Pacific, North...


  • Monterrey, México CHUBB A tiempo completo

    The Chubb Information Security team is responsible for protecting information and information systems against unauthorized access, detecting and responding to attempts to gain access and enabling access through our identity processes. Chubb operates a global information security team supporting local business units across five regions (Asia Pacific, North...


  • Monterrey, México Danfoss A tiempo completo

    Job Responsibilities Responsibilities of this position include, but are not limited to, the following: Being a reliable consulting partner, understanding the limits of what is sensible and feasible Producing substantiated materials as basis for management decision Quickly adapting to emerging technologies, projects, and various other challenges ...


  • Monterrey, México Danfoss A tiempo completo

    Job Responsibilities Responsibilities for this position include, but are not limited to, the following. Day2day collaborate with infrastructure and applications teams to response to cyber security incidents, take a lead role to facilitate the security incident investigation, assessment, containment, and mitigations. Conduct vulnerability discovery,...

  • Seguridad Digital

    hace 4 semanas


    Monterrey, México HB Soluciones A tiempo completo

    Empresa Americana de manufactura y refrigeración busca: IT Cybersecurity Analyst - Monitor and analyze intrusion detection to identify security issues - Monitor and manage next-generation anti-virus, EDR and DLP - Monitor and respond to threat alert from SIEM - Recognize potential, successful, and unsuccessful intrusion attempts and compromises through...


  • Monterrey, México Danfoss A tiempo completo

    Requisition ID: 37398- Job Location(s): Monterrey, MXAre you a dedicated Security Consultant and want be part of the team that provides latest technology for securing Danfoss digitalization journey? Then join us in, one of Danfoss IT teams that enables Danfoss in secure, proactive and automation journey. Consultant work as a part of security operations...

  • Ot Cybersecurity Lead

    hace 4 semanas


    Monterrey, México Neoris A tiempo completo

    **OT Cybersecurity Lead**: **Date**:Nov 27, 2023 **Location**: MONTERREY, MX **Company**:NEORIS **Main responsibilities**: Resource Description - Align to IT Services for OT - Facilitate cyber security governance through the implementation of governance program - Develop and monitor a strategic, comprehensive enterprise Cyber Security and Risk Management...

  • Cyber Security Analyst

    hace 4 semanas


    Monterrey, México Charger Logistics Inc A tiempo completo

    Job Title: - Cyber Security Analyst- Location: - Monterrey, Mexico- Category: - Information Technology- Experience: - Mid Senior**Job Description**: Description **_We’re proud to say we’ve been named one of "Super Empresas Expansión 2023 Top_** Charger Logistics is a world class asset-based carrier. We specialize in delivering your assets, on time and...


  • Monterrey, México ZF Group A tiempo completo

    Responsibilities Support ISMS (Information Security Management System) Statement of Applicability and measure the effectiveness of the security processes Perform site security assessments according to the Corporate Security Standards and ensures proper security measures, procedures, and processes for the protection of our employees and the...


  • Monterrey, México Praxis A tiempo completo

    **PRAXIS **is a leading company that seeks to strengthen companies through the use of specialized methodologies and tools and with a focus on consulting, integration, outsourcing, and systems development. We're looking for a **Project Manager for Market Risk & Credit Risk** **(Remote 100%)** **Responsibilities**: - Advises executive management of...

  • Security Engineer

    hace 4 semanas


    Monterrey, México Atos A tiempo completo

    **Publication Date**: Jun 13, 2023 **Ref. No**: 483200 **Location**: Monterrey, Nuevo Len, MX, 66490 The future is our choice At Atos, as the global leader in secure and decarbonized digital, our purpose is to help design the future of the information space. Together we bring the diversity of our people’s skills and backgrounds to make the right...