Head of Data Security and Compliance

hace 4 semanas


Ciudad de México, Ciudad de México Addington Place of Shoal Creek A tiempo completo
Job: Head of Data Security and Compliance

At Addington Place of Shoal Creek, we're seeking a highly skilled Head of Data Security and Compliance to join our fast-growing SaaS company. This leadership role is responsible for ensuring the company's data security, regulatory compliance, and overall protection of sensitive information. The ideal candidate will possess a deep understanding of data security best practices, compliance frameworks, and risk management strategies. Moreover, the Head of Data Compliance and Security should demonstrate a customer-centric approach, ensuring that security measures do not impede product functionality, ease of use, or hinder the sales process. This role requires a unique blend of technical expertise, strategic thinking, and business acumen.

Responsibilities
  • Ensure compliance with ISO, SOC 2, GDPR, Mexico, Ecuador, California and other relevant data privacy laws in the USA and Latam, developing and implementing policies, procedures, and controls to meet the requirements.
  • Collaborate with internal teams to establish data minimization practices, consent management processes, and procedures to address data subjects' rights, including the right to be forgotten.
  • Work with product team to ensure that all our client's product is best-in-class from a Data Security perspective
  • Lead and oversee audits, including SOC 1, SOC 2, and SOC 3 audits and ISO 27001 certification, ensuring compliance with control objectives and requirements.
  • Stay updated on emerging data privacy laws and regulations, such as GDPR, CCPA and PIPEDA, and assess their impact on our client's data protection practices.
  • Lead incident response efforts, including managing data breach incidents, coordinating investigations, and executing data breach notification procedures in accordance with GDPR and other applicable regulations.
  • Conduct regular risk assessments and vulnerability assessments to identify potential weaknesses and implement appropriate controls.
  • Stay informed about emerging threats, trends, and industry developments, and proactively update security strategies to address new risks.
  • Develop and maintain documentation, such as Data Protection Impact Assessments (DPIAs), privacy policies, and procedures, to demonstrate compliance with data protection regulations.
  • Understand cloud technologies and architectures, such as Google Cloud Platform and AWS, and apply associated security and compliance considerations in data protection strategies.
  • Apply data security principles, including encryption, anonymization, and pseudonymization techniques, to safeguard sensitive data.
  • Collaborate with cross-functional teams to embed security considerations throughout the product development lifecycle without compromising functionality or user experience.
  • Conduct thorough security assessments of new features, products, and systems to identify potential risks and recommend appropriate security controls.
  • Champion a culture of secure coding practices, security testing, and ongoing vulnerability management to ensure the product is robust and resilient.
  • Address security issues related to database technologies, ensuring secure database configurations and access controls.
  • Balance security requirements with customer expectations and usability, ensuring security measures do not create unnecessary obstacles or impede the overall user experience.
  • Engage with customers, understand their security concerns, and provide guidance on secure product usage, privacy, and data protection practices.
  • Collaborate with customer support and sales teams to address security-related inquiries, concerns, and provide expertise during the sales process.
Requirements
  • In-depth knowledge of data privacy and protection laws, regulations, and frameworks in the LatAm region, including specific knowledge of Mexico's data protection landscape, as well as expertise in GDPR requirements, such as data minimization, right to be forgotten, consent management, etc.
  • Has experience as DPO in a fintech, highly regulated start-up or equivalent.
  • Experience with SOC 1, SOC 2, SOC 3 audits, and ISO 27001, understanding the control objectives and requirements associated with these standards.
  • Familiarity with other data privacy laws and regulations, such as GDPR, CCPA (California Consumer Privacy Act), PIPEDA (Personal Information Protection and Electronic Documents Act), and other relevant global privacy frameworks.
  • Proficiency in risk assessment methodologies and experience conducting security risk assessments to identify and mitigate potential risks to data security and compliance.
  • Ability to develop and maintain documentation, including Data Protection Impact Assessments (DPIAs), privacy policies, procedures, and other necessary documentation to ensure compliance with data protection regulations.
  • Experience in incident response and data breach notification procedures as per GDPR and other applicable regulations, including coordination with relevant stakeholders, regulatory bodies, and legal teams.
  • Proficiency in Python programming language for data analysis, automation, and security-related tasks.
  • Understanding of cloud technologies and architectures (Google Cloud Platform, MongoDB, AWS) and the associated security and compliance considerations.
  • Knowledge of data security principles, including encryption, anonymization, and pseudonymization techniques.
  • Familiarity with database technologies and associated security issues.
  • In-depth knowledge of data security frameworks, such as ISO 27001, NIST Cybersecurity Framework, or CIS Controls.
  • Strong understanding of regulatory compliance requirements, such as GDPR, CCPA, or HIPAA.
  • Demonstrated experience in developing and implementing comprehensive information security strategies.
  • Proven track record of successfully integrating security into product development lifecycles while maintaining usability and customer satisfaction.
  • Familiarity with secure coding practices, vulnerability management, and security testing methodologies.
  • Excellent communication and interpersonal skills to collaborate effectively across departments and communicate complex security concepts to non-technical stakeholders.
  • Strong analytical and problem-solving skills to identify and mitigate potential risks effectively.
  • Relevant certifications such as CISSP, CISM, or CRISC are highly desirable.


  • Ciudad de México, Ciudad de México Addington Place of Shoal Creek A tiempo completo

    About the Role:At Addington Place of Shoal Creek, we are seeking a highly skilled Head of Data Security and Compliance to join our team. This leadership role is responsible for ensuring the company's data security, regulatory compliance, and overall protection of sensitive information. The ideal candidate will possess a deep understanding of data security...


  • Ciudad de México, Ciudad de México Citi A tiempo completo

    About the RoleCiti seeks a seasoned executive to lead its enterprise information security program. As Head of Enterprise Information Security, you will be responsible for developing and implementing a comprehensive information security strategy that protects the organization's digital assets.This strategic role requires a deep understanding of regulatory...


  • Ciudad de México, Ciudad de México Rackspace A tiempo completo

    Job DescriptionRackspace Technology is seeking a highly skilled Security Risk and Compliance Management Specialist IV to join our team. As a key member of our Information Security team, you will be responsible for developing and implementing information security, compliance, and risk management programs globally.Key Responsibilities:Act as an advocate in the...

  • SAP Security Analyst

    hace 4 semanas


    Ciudad de México, Ciudad de México NTT DATA A tiempo completo

    About the RoleWe are seeking a highly skilled SAP Security Analyst to join our team in Guadalajara, Jalisco (MX-JAL), Mexico (MX). As a key member of our SAP Platform Services team, you will be responsible for providing operational and technical security support for the business.Key ResponsibilitiesDesign, implement, and support SAP security...


  • Ciudad de México, Ciudad de México NTT DATA, Inc. A tiempo completo

    About the RoleNTT DATA is seeking an experienced Information Security Manager to join our team in Mexico City. As a key member of our security team, you will be responsible for ensuring the delivery of information security services to our clients is in compliance with contractual and regulatory requirements.Key ResponsibilitiesCollaborate with clients to...


  • Ciudad de México, Ciudad de México NTT DATA Services A tiempo completo

    About the RoleWe are seeking a highly skilled Information Security Manager to join our team in Mexico City, Mexico. As a key member of our organization, you will be responsible for ensuring the delivery of information security services to our customers is in compliance with contractual and regulatory requirements.Key ResponsibilitiesCollaborate with...


  • Ciudad de México, Ciudad de México NTT DATA Services A tiempo completo

    About the Role:We are seeking a highly skilled Information Security Governance Lead to join our team at NTT DATA Services. In this role, you will be responsible for ensuring the delivery of information security services to our clients is in compliance with contracts and applicable standards and regulatory requirements.Key Responsibilities:Collaborate with...


  • Ciudad de México, Ciudad de México Nuvit Service A tiempo completo

    Job Title: Security Compliance AnalystDescription:The Security Compliance Analyst will work with the team to help homologate the tool and process to measure hardening compliance across Nuvit Service entities. The Security Compliance Analyst will support the team to understand hardening compliance gaps by setting up the initial configurations of the...

  • Data Entry Specialist

    hace 3 semanas


    Ciudad de México, Ciudad de México Doit Security A tiempo completo

    **Job Overview**We are seeking a highly skilled Data Entry Executive to join our team at Doit Security. This individual will be responsible for accurately inputting data into our database systems, ensuring the integrity of information used for analysis and reporting.**Key Responsibilities**Input, update, and maintain accurate data across various database...


  • Ciudad de México, Ciudad de México Diageo A tiempo completo

    Job Title: Head of Business Intelligence and Data StrategyJob Summary:Diageo, the world's leading premium drinks company, is seeking a highly skilled and experienced professional to lead its Business Intelligence and Data Strategy function. The successful candidate will be responsible for overseeing data management, data capability, insights generation,...


  • Ciudad de México, Ciudad de México Sequoia Connect A tiempo completo

    Sequoia Connect: Data Platforms Practice LeaderSequoia Connect, a leading consulting and technology company, is seeking a seasoned professional to lead our Data Platforms Practice. As a key member of our team, you will be responsible for developing and executing a long-term strategy for our Data Platform Practice, expanding capabilities and service...

  • Cybersecurity Strategist

    hace 2 semanas


    Ciudad de México, Ciudad de México NTT DATA A tiempo completo

    Job SummaryWe are seeking a highly skilled Cybersecurity Strategist to join our team in Mexico City. The successful candidate will play a key role in ensuring the confidentiality, integrity, and availability of our clients' environments and data.Key ResponsibilitiesInformation Security ServicesEnsure delivery of information security services in compliance...


  • Ciudad de México, Ciudad de México Nuvit Service A tiempo completo

    Job SummaryWe are seeking a highly skilled Senior SIEM Engineer to join our team at Nuvit Service. As a key member of our security team, you will play a critical role in onboarding log sources to Splunk Enterprise Security, ensuring the secure collection, storage, and correlation of event data across the enterprise.Key ResponsibilitiesCoordinate the...


  • Ciudad de México, Ciudad de México AIG A tiempo completo

    Head of Claims Operations LAC LeaderAIG is seeking a Head of Claims Operations LAC Leader to drive claims transformation and excellence in Latin America and the Caribbean. The successful candidate will lead a team of professionals to deliver strategic initiatives, improve claims processes, and enhance governance and compliance.The ideal candidate will have a...

  • Data Architect Lead

    hace 4 semanas


    Ciudad de México, Ciudad de México Data Privacy A tiempo completo

    At Data Privacy, we're seeking a highly skilled Data Architect to lead the technical implementation of projects and propose transitional architectures for incremental value delivery. The role involves directing the technical implementation of projects, overseeing workload distribution, resolving conflicts, and managing a team focused on solution...


  • Ciudad de México, Ciudad de México Hyatt Corporate Office, Chicago A tiempo completo

    **About the Role**Hyatt Corporate Office, Chicago, is seeking a seasoned Director of Security and Safety to lead all Safety & Security efforts across all brands and operations for Hyatt in Mexico.This critical role requires a Subject Matter Expert in safety & security concerns, events, and incidents. The successful candidate will provide proactive and...


  • Ciudad de México, Ciudad de México Rackspace A tiempo completo

    Job SummaryWe are seeking a highly skilled Security Risk and Compliance Management Specialist III to lead our security policy management function within GRC. This role requires a strong understanding of Archer GRC Tool and excellent communication skills to navigate across departments and network with various employees.Key ResponsibilitiesLead the security...


  • Ciudad de México, Ciudad de México Nearshorecoders A tiempo completo

    Job Description: In this role, you will work closely with the Head of Cyber Security, supporting all areas of the business. You will be taking the lead across several security projects as well as providing advice, training, and support to the rest of the business.The role requires a deep understanding of decentralized finance and its unique security...


  • Ciudad de México, Ciudad de México Takeda A tiempo completo

    About the RoleWe are seeking a highly skilled Information Security and Data Privacy Analyst to join our team at Takeda's Innovation Capability Center in Mexico City. As a key member of our risk management team, you will play a critical role in ensuring the security and integrity of our third-party relationships.Key ResponsibilitiesConduct thorough risk...

  • Senior Data Architect

    hace 2 semanas


    Ciudad de México, Ciudad de México Data Privacy A tiempo completo

    Job Title: Data Architect SRJob Summary:We are seeking a highly skilled Data Architect to lead the technical implementation of projects and ensure that technology solutions for data are aligned with business needs and comply with established guidelines and security regulations.About the Role:As a Data Architect, you will be responsible for directing the...