Cbsm - IT Security Governance Engineer

hace 1 semana


Saltillo, México Chubb INA Holdings Inc. A tiempo completo

Job Requirements

Core IT Security GRC Domains.

Governance & Oversight
- Oversee current programs (I.e., SOX, Risk assessments, risk profiles, iso, global and or regional strategic projects/tasks, etc.).
- Provide oversight and coordination of control executions to ensure IT policies and procedures are being followed.
- Coordinate periodic metrics follow up and reporting to key stakeholders to ensure accountability and ownership of projects/tasks.
- Managing of regional cyber security catalog.

Control Framework
- Evaluate the adequacy and effectiveness of internal controls as they relate to the design and operation of computer-based information systems.
- Develop and implement procedures and processes supporting Chubb IT Security and compliance policies, control objectives.
- Produce, document and maintain IT policies and internal controls at various level of the organization in relation to the IT landscape.
- Provide support and guidance over the development and implementation of controls and remediation actions based on practical solutions and sound risk management.

Risk Management
- Proactively identify and assess of on-going and emerging IT risks, challenges and process gaps through periodic internal management risk assessments
- Analyze and prioritize areas of focus for mitigation, remediation or process improvement opportunities using a risk-based approach to maximize the efficiency and effectiveness.

IT Control Monitoring and Testing
- Proactively identify control gaps.
- Remediation monitoring and tracking to ensure issues and risks are mitigated timely.
- Collaborate with IT to validate and verify audit findings and/or deficiencies.
- Facilitate audit and assessments scoping, planning, pre-audit risk assessment and process walkthroughs during the audit process.
- On-going monitoring and testing of controls to ensure adherence to risk requirements.
- Support the oversight and governance over subservice IT hosting provider(s)

Communication
- Serve as the central communication point between the regional security organization and key stakeholders.
- Provide timely status reporting on current audit statuses, issues, control deficiencies, remediation tracking, ongoing assessments, pen-tests and overall health of the IT environment.

Training & Education
- Help on coordinate IT security related training for the IT community and key stake holders on current and new security best practices.
- Contribute to IT Security Training Course development.

Special projects and initiatives
- Collaborate with Global Information Security on new global initiatives.
- Coordinate COG and Global projects and activities at the region.
- Perform quality control analysis over the outcomes of IT security projects and initiatives executed at the region.

Work Experience

Requirements for the role
- Reports to the regional GRC Head.
- In-depth understanding of information security standards, best practices and governance, risk and compliance.
- Collaborative with the ability to influence without authority and have impact.
- Superior verbal and written communication and presentation skills, strong interpersonal skills and the ability to work independently.
- Demonstrates sense of prioritization, urgency and a high degree of initiative and professional judgment.
- Being adaptative in highly changing and ambiguous environments.

Desired Qualifications
- Desirable CISA, CISSP, CISM or CRISC - either currently possess the certification or working towards completing the certification.
- Project management experience. PMP certification a plus.
- BS in a computer science, management information systems or related field.
- IT Security Audit experience a plus.
- Desirable Information Security risk management framework experience.


  • IT Engineer

    hace 2 semanas


    Saltillo, México HX Investment A tiempo completo

    HX Investment is an upcoming company from China which provides steel parts for construction machinery, mining machinery, agricultural machinery and other structural components and accessories. We are located in Marín, Nuevo León.- Designing and implementing technology solutions that meet the needs of the organization.- Evaluating and recommending hardware...

  • IT Engineer

    hace 2 semanas


    Saltillo, México HX Investment A tiempo completo

    HX Investment is an upcoming company from China which provides steel parts for construction machinery, mining machinery, agricultural machinery and other structural components and accessories. We are located in Marín, Nuevo León. - Designing and implementing technology solutions that meet the needs of the organization. - Evaluating and recommending...


  • Saltillo, México Hyundai Glovis Mexico A tiempo completo

    Descripción del trabajo About us Hyundai Glovis Mexico is a logistic company headquartered in Seoul, South Korea and part of the Hyundai Motor Group.Provides ocean, air, inland transportation, logistic consulting, storage, packaging services as well as supply chain management services.We are part of Kia Motors industrial complex. Requisitos Conversational...


  • Saltillo, México Hyundai Glovis Mexico A tiempo completo

    Descripción del trabajo About usHyundai Glovis Mexico is a logistic company headquartered in Seoul, South Korea and part of the Hyundai Motor Group.Provides ocean, air, inland transportation, logistic consulting, storage, packaging services as well as supply chain management services.We are part of Kia Motors industrial complex. Requisitos Conversational...


  • Saltillo, México Hyundai Glovis Mexico A tiempo completo

    Descripción del trabajo About usHyundai Glovis Mexico is a logistic company headquartered in Seoul, South Korea and part of the Hyundai Motor Group.Provides ocean, air, inland transportation, logistic consulting, storage, packaging services as well as supply chain management services.We are part of Kia Motors industrial complex. Requisitos Conversational...

  • IT Analyst

    hace 3 semanas


    Saltillo, México International Automotive Components A tiempo completo

    **Job description**- The Specialist IT Senior is a professional who acts as the liaison between business and IT; he/she interacts directly with other managers, users, and Central IT. Focused on customer service, he/she will align IT services to plant(s) operations in order to create IT value and achieve company goals.- Ensure all Central IT and Global IT...


  • Saltillo, México Chubb INA Holdings Inc. A tiempo completo

    Job Requirements **Dynamics CRM - Engineer**: **Must have**: - Minimum 8 years of overall Dynamics CRM technical experience. - Strong business analysis and problem-solving skills and proven ability to identify and recommend solutions to issues, concerns, and challenges Work Experience **Required Skills**: - Very strong, in-depth and demonstrable...

  • Data Engineer

    hace 3 semanas


    Saltillo, México Johnson Controls International A tiempo completo

    **JOB SUMMARY**The JCI Global Products **Data Engineer** is a crucial member of a larger Commercial Operations & Analytics team that supports 10+ distinct business units, all centralized business functions and a much larger combined sales team. This role is critical to executing and driving the improved processes and management of the Snowflake environment...


  • Saltillo, México Pepsico A tiempo completo

    Overview At PepsiCo, we’re redefining what it means to be a consumer products company with a digital-first mindset, and our Global IT team is leading that charge. Our technology teams unlock digital capabilities, enhance cybersecurity safeguards, deliver data-driven insights, and create unmatched consumer and customer experiences. Our culture is guided by...


  • Saltillo, México PepsiCo A tiempo completo

    Overview:At PepsiCo, we’re redefining what it means to be a consumer products company with a digital-first mindset, and our Global IT team is leading that charge. Our technology teams unlock digital capabilities, enhance cybersecurity safeguards, deliver data-driven insights, and create unmatched consumer and customer experiences.Our culture is guided by...