Global Information Security Risk and Compliance

hace 4 días


Monterrey, México Nemak A tiempo completo

Objective

As part of the Information Security organization, develop a strategic program to ensure compliance of regulatory requirements to support the organization's resilience. Through a process of Risk Management and the systematic evaluation of potential threats, the organization will be able to meet the law, regulations and contractual requirements and ensure the organization's objectives are fulfilled.

Furthermore, this role strategically aligns risk management and compliance efforts with the broader organizational strategy, fostering a culture of continuous improvement, supporting the organization's growth and that Information Security efforts are sustainable across Nemak.

Main Responsibilities
- Compliance Strategy: Create and implement compliance strategies and policies to ensure the organization fulfills Information Security requirements of laws, regulations, contracts and IT standards.
- Risk Management and Mitigation: Identify and assess potential Information Security risks to the organization's operations, financial stability, and reputation. Develop risk mitigation plans and monitor their effectiveness. Foster a culture of continuous improvement within the organization, ensuring that risk management and compliance strategies evolve to address emerging risks and regulatory changes.
- Regulatory Compliance: Stay current with relevant laws and regulations affecting the organization's industry and geographic locations. Ensure that policies and controls fulfill these Information Security requirements and work with executive and functional areas to ensure the gaps are closed.
- Policy Development and Management: Develop and manage Information Security compliance policies, codes of conduct, and internal control frameworks. Communicate policies effectively throughout the organization and develop programs to ensure their effectiveness across the organization.
- Training and Education: Provide Information Security compliance training and awareness programs to employees, management, and relevant stakeholders to ensure a culture of compliance and risk management.
- Compliance Monitoring and Reporting: Establish systems and processes to monitor compliance with Information Security policies, regulations, and standards. Regularly provide updates to executive management on the key performance indicators and risk levels. Provide information requirements to certification entities required for Information Security and Sustainability process to ensure growth strategic goals are achieved.
- Third-Party Due Diligence: Assess and manage Information Security risks associated with third-party relationships, such as vendors, suppliers, and partners. Implement due diligence processes and ongoing monitoring to comply with Information Security Requirements for Suppliers policy.
- Data Protection and Privacy: Oversee and coordinate data protection and privacy compliance with GDPR and other privacy relevant regulations. Ensure data handling practices are in line with legal requirements.
- Audit Management: Prepare and support Information Security regular audits, whether internal or external. Ensure that the organization is always prepared to comply with audit requirements, minimizing disruptions and potential penalties. Monitor the correct implementation of Information Security controls across Nemak. Ensure remediation programs are in place.
- Access Management: Develop strategies to ensure that the access management practice operates with industry best practices for key critical systems like SAP, Success Factors and key platforms. Define security frameworks to improve security models in SAP and supported platforms. Manage the Security Architecture in SAP and SAP GRC ensuring controls are in place and evidences are produced.

Position Requirements
- Career: Computer Systems Engineering, Law, Business Administration
- Experience: 5- 8 years’ experience in Audit and Compliance, Risk Management, Internal Control Management, Data Privacy and Security, IT Systems Management, Multicultural experience.
- Certifications: Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC).
- Strong knowledge of industry standards, regulations, and frameworks (e.g., ISO 27001, NIST, GDPR).
- Behavioral Skills: Analysis and problem solving, Drive, Multitasking, Manage and energize teams, Common sense and urgency, Leadership, Work under pressure, Desire for new challenges, Embrace change, Excellent communication skills, Challenge the status quo, Proactive, Analytic, Self-learner, Desire for innovation, Positive.
- Strong project management skills with the ability to prioritize and manage multiple initiatives simultaneously.
- Strong communication and leadership skills, with the ability to collaborate effectively with cross-functional teams and senior management.
- Advanced English and Spanish.
- At Nemak, Diversity, Equity and Inclusion



  • Monterrey, México Nearshore Cyber A tiempo completo

    **Location: Monterrey or Matamoros, Mexico**:**Applications from persons not living in Mexico will NOT be accepted.**Information Security Risk Assessors report continuously on the state of risk, providing visibility and helping business leaders and risk managers understand where risk resides and where improvements must be made to protect the business. Such...


  • Monterrey, México Nemak A tiempo completo

    **Objective** Ensure the security and compliance of SAP and IT critical systems within the organization by safeguarding sensitive information, managing access controls, and implementing measures to adhere to regulatory requirements. This role involves collaborating with various stakeholders, conducting audits, and implementing security best practices,...

  • Ot Risk

    hace 2 semanas


    Monterrey, México Axen A tiempo completo

    DescriptionAt AXEN IT Consulting we are growing exponentially with clients with great growth projections, We have more than 25 years of experience in the information technology services market, Focused on our growth and at the same time offering improvement plans to our talent, We are currently looking for " OT Risk & Compliance " with the profile:...


  • Monterrey, México Canonical - Jobs A tiempo completo

    The Information Systems (IS) Compliance Manager leads our work to achieve relevant certifications such as SOC2 as well as compliance with regulatory frameworks such as GDPR, SOC2 and other relevant standards.This role is to ensure that Canonical conducts its business processes in compliance with laws and regulations, international standards, and accepted...

  • Governance, Risk

    hace 1 semana


    Monterrey, México Microtalent Is Becoming Inspyr Global Solutions A tiempo completo

    Descripción del trabajo Get AI-powered advice on this job and more exclusive features. Location: Monterrey, N.L. (Hybrid – 3 days onsite) Employment type: Direct Hire – Full-time, with all benefits required by Mexican law Salary range: Competitive and negotiable based on experience Language: Bilingual (Advanced English – excellent verbal and written...


  • Monterrey, México Endava A tiempo completo

    **Company Description**Technology is our how. And people are our why. For over two decades, we have been harnessing technology to drive meaningful change.By combining world-class engineering, industry expertise and a people-centric mindset, we consult and partner with leading brands from various industries to create dynamic platforms and intelligent digital...


  • Monterrey, México Nearshore Cyber A tiempo completo

    **Location: Monterrey or Matamoros, Mexico**:** Applications from persons not living in Mexico will NOT be accepted.**The role also requires an understanding of business goals/strategy and operational requirements in a fast-paced environment.Throughout the roles key responsibilities, the Information Security Engineer must always consider opportunities to...


  • Monterrey, México Nemak A tiempo completo

    Descripción del trabajo Objetivo Professional dedicated to safeguard sensitive information, manage access controls, and implement measures to adhere to regulatory requirements. Through collaboration with various stakeholders, conducting audits, and implementing SAP security best practices, this role is pivotal in maintaining the integrity and security of...


  • Monterrey, México SWBC A tiempo completo

    SWBC is seeking a talented individual to assist the Offices of Corporate Information Security and Corporate Physical Security in the management and exaction of information and physical security controls to protect company owned and controlled assets, information, personnel, and property. Manage the first line of defense that is our Physical Security presence...


  • Monterrey, México Canonical A tiempo completo

    In security risk management we aim to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security risk management team is the primary owner of the strategy and practices of how we identify, track and reduce our security risk across everything we do. To support this we use...