Head of Data Security and Compliance

hace 1 mes


distrito federal, México Addington Place of Shoal Creek A tiempo completo
Job: Head of Data Security and Compliance

Our client is seeking a highly skilled Head of Data Security & Compliance to join our fast-growing SaaS company. This leadership role is responsible for ensuring the company’s data security, regulatory compliance, and overall protection of sensitive information. The ideal candidate will possess a deep understanding of data security best practices, compliance frameworks, and risk management strategies. Moreover, the Head of Data Compliance and Security should demonstrate a customer-centric approach, ensuring that security measures do not impede product functionality, ease of use, or hinder the sales process. This role requires a unique blend of technical expertise, strategic thinking, and business acumen.

Responsibilities
  • Ensure compliance with ISO, SOC 2, GDPR , Mexico, Ecuador, California and other relevant data privacy laws in the USA and Latam, developing and implementing policies, procedures, and controls to meet the requirements.
  • Collaborate with internal teams to establish data minimization practices, consent management processes, and procedures to address data subjects’ rights, including the right to be forgotten.
  • Work with product team to ensure that all our client’s product is best-in-class from a Data Security perspective
  • Lead and oversee audits, including SOC 1, SOC 2, and SOC 3 audits and ISO 27001 certification, ensuring compliance with control objectives and requirements.
  • Stay updated on emerging data privacy laws and regulations, such as GDPR, CCPA and PIPEDA, and assess their impact on our client’s data protection practices.
  • Lead incident response efforts, including managing data breach incidents, coordinating investigations, and executing data breach notification procedures in accordance with GDPR and other applicable regulations.
  • Conduct regular risk assessments and vulnerability assessments to identify potential weaknesses and implement appropriate controls.
  • Stay informed about emerging threats, trends, and industry developments, and proactively update security strategies to address new risks.
  • Develop and maintain documentation, such as Data Protection Impact Assessments (DPIAs), privacy policies, and procedures, to demonstrate compliance with data protection regulations.Lead incident response efforts, including managing data breach incidents, coordinating investigations, and executing data breach notification procedures in accordance with GDPR and other applicable regulations.
  • Understand cloud technologies and architectures, such as Google Cloud Platform and AWS, and apply associated security and compliance considerations in data protection strategies.
  • Apply data security principles, including encryption, anonymization, and pseudonymization techniques, to safeguard sensitive data.
  • Collaborate with cross-functional teams to embed security considerations throughout the product development lifecycle without compromising functionality or user experience.
  • Conduct thorough security assessments of new features, products, and systems to identify potential risks and recommend appropriate security controls.
  • Champion a culture of secure coding practices, security testing, and ongoing vulnerability management to ensure the product is robust and resilient.
  • Address security issues related to database technologies, ensuring secure database configurations and access controls.
  • Balance security requirements with customer expectations and usability, ensuring security measures do not create unnecessary obstacles or impede the overall user experience.
  • Engage with customers, understand their security concerns, and provide guidance on secure product usage, privacy, and data protection practices.
  • Collaborate with customer support and sales teams to address security-related inquiries, concerns, and provide expertise during the sales process.
Requirements
  • In-depth knowledge of data privacy and protection laws, regulations, and frameworks in the LatAm region, including specific knowledge of Mexico’s data protection landscape, as well as expertise in GDPR requirements, such as data minimization, right to be forgotten, consent management, etc.
  • Has experience as DPO in a fintech, highly regulated start-up or equivalent.
  • Experience with SOC 1, SOC 2, SOC 3 audits, and ISO 27001, understanding the control objectives and requirements associated with these standards.
  • Familiarity with other data privacy laws and regulations, such as GDPR, CCPA (California Consumer Privacy Act), PIPEDA (Personal Information Protection and Electronic Documents Act), and other relevant global privacy frameworks.
  • Proficiency in risk assessment methodologies and experience conducting security risk assessments to identify and mitigate potential risks to data security and compliance.
  • Ability to develop and maintain documentation, including Data Protection Impact Assessments (DPIAs), privacy policies, procedures, and other necessary documentation to ensure compliance with data protection regulations.
  • Experience in incident response and data breach notification procedures as per GDPR and other applicable regulations, including coordination with relevant stakeholders, regulatory bodies, and legal teams.
  • Proficiency in Python programming language for data analysis, automation, and security-related tasks.
  • Understanding of cloud technologies and architectures (Google Cloud Platform, MongoDB, AWS) and the associated security and compliance considerations.
  • Knowledge of data security principles, including encryption, anonymization, and pseudonymization techniques.
  • Familiarity with database technologies and associated security issues.
  • In-depth knowledge of data security frameworks, such as ISO 27001, NIST Cybersecurity Framework, or CIS Controls.
  • Strong understanding of regulatory compliance requirements, such as GDPR, CCPA, or HIPAA.
  • Demonstrated experience in developing and implementing comprehensive information security strategies.
  • Proven track record of successfully integrating security into product development lifecycles while maintaining usability and customer satisfaction.
  • Familiarity with secure coding practices, vulnerability management, and security testing methodologies.
  • Excellent communication and interpersonal skills to collaborate effectively across departments and communicate complex security concepts to non-technical stakeholders.
  • Strong analytical and problem-solving skills to identify and mitigate potential risks effectively.
  • Relevant certifications such as CISSP, CISM, or CRISC are highly desirable.
#J-18808-Ljbffr

  • distrito federal, México NTT DATA A tiempo completo

    Req ID: 289483 NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking an Information Security Manager to join our team in Mexico City, Ciudad de México (MX-CMX), Mexico (MX). Role...


  • distrito federal, México LAAgencia A tiempo completo

    Head of Data Platforms Practice About our Team The Data Technology Consulting Practice is responsible for building modern and innovative technology services that enable our customers to successfully realize value from data. Currently, the Practice focuses on four data technology domains: Data strategy: How to deliver a structured approach to design and...


  • distrito federal, México NTT DATA, Inc. A tiempo completo

    NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking an Information Security Manager to join our team in Mexico City, Ciudad de México (MX-CMX), Mexico (MX). Role Responsibilities: Ensure...


  • distrito federal, México Utopia Living A tiempo completo

    We are seeking a highly skilled and motivated Hospitality Quality and Compliance Strategist / Head of Product. This role requires a professional with extensive product creation and operational experience in hospitality projects, capable of assessing and influencing design from an operational perspective and building the luxurious product from scratch,...


  • distrito federal, México Chubb Ltd. A tiempo completo

    Team Leadership and Management:  Lead and oversee a medium team, ensuring their professional development, motivation, and high performance.  Provide coaching, guidance, and technical expertise to team members, promoting a culture of continuous learning and growth.  Establish clear goals and expectations, monitor progress, and provide regular feedback to...

  • Head of Sales

    hace 1 mes


    distrito federal, México city of San Elizario A tiempo completo

    After closing a seed round of 5.5. million USD in July 2024, Aviva is looking for a Head of Sales to lead and build a high-performing sales org all across Mexico.As Head of Sales you own a core pillar of Aviva’s go-to-market strategy, as our sales teams function as the pioneers and the “human bridge” that bring premium financial services to...


  • distrito federal, México Gerresheimer A tiempo completo

    Gerresheimer Querétaro S.A. in Mexico produces primary glass packaging for pharmaceutical use. Type I glass is produced in clear and amber glass. The broad product range includes ampoules, serum vials, screw thread vials, ready-to-fill syringes and cartridges. Job Description Attract talent based on job descriptions for each area. Provide attention and...

  • Data Architect SR

    hace 1 mes


    distrito federal, México Data Privacy A tiempo completo

    NEORIS is seeking a Data Architect to ensure that technology solutions for data are aligned with business needs and comply with established guidelines and security regulations. The role involves directing the technical implementation of projects and proposing transitional architectures for incremental value delivery. Additionally, the architect will oversee...


  • distrito federal, México NTT DATA A tiempo completo

    Network Security Specialist - Cloudflare NTT DATA helps clients transform through consulting, industry solutions, business process services, IT modernization, and managed services. NTT DATA strives to hire exceptional, innovative, and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking...

  • Head of Finance

    hace 1 mes


    distrito federal, México 畐灬潰 A tiempo completo

    (Full Time) Head of Finance at Pulppo (United States) | BEAMSTART Jobs Head of Finance Pulppo United States Date Posted: 08 Feb, 2023 Work Location: Mexico City, Mexico, United States Salary Offered: $1 — $100000 yearly Job Type: Full Time Experience Required: 3+ years Remote Work: No Stock Options: No Vacancies: 1 available We are looking for: Head of...

  • Head of Payroll

    hace 4 semanas


    distrito federal, México Magnocampo A tiempo completo

    Objective To ensure accurate payroll calculation, proper analysis of information, and timely payments to employees, complying with tax, state, and social security obligations in accordance with the current legal framework. Profile Bachelor's degree in Public Accounting or Business Administration (graduate). Minimum 4 years of experience as Payroll Manager....


  • distrito federal, México Diageo A tiempo completo

    Head of Business Intelligence Tower Locations: Mexico City, Mexico Time Type: Full time Posted On: Posted 2 Days Ago Job Description: Diageo is the world’s leading premium drinks company with an outstanding collection of brands, such as Johnnie Walker, Smirnoff, Baileys, Captain Morgan, Tanqueray, and Guinness. With over 200 brands in 180 countries...


  • distrito federal, México Alcon A tiempo completo

    Legal & Compliance Head Mexico Location: Mexico City (Hybrid) At Alcon, we are driven by the meaningful work we do to help people see brilliantly. We innovate boldly, champion progress, and act with speed as the global leader in eye care. Here, you’ll be recognized for your commitment and contributions and see your career like never before. Together, we...

  • Security Specialist

    hace 1 mes


    distrito federal, México NTT DATA, Inc. A tiempo completo

    Network Security Specialist - Cloudflare Date: Oct 4, 2024 Location: Remote, MEX, MX Company: NTT DATA Services NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. Location: 100% remote, anywhere in Mexico ...


  • distrito federal, México Gerresheimer AG A tiempo completo

    Job Description Attract talent based on job descriptions for each area. Provide attention and follow-up to internal clients to fill vacancies in their areas. Select recruitment sources to effectively publish vacancies. Interview potential candidates and channel them to the next level of interview. Ensure compliance with the recruitment and selection process,...


  • distrito federal, México Citi A tiempo completo

    The Chief Information Security Officer (CISO) is a senior executive responsible for establishing and maintaining the bank’s information security strategy and ensuring that all information assets and technologies are adequately protected. The CISO plays a critical role in safeguarding the bank's data, ensuring compliance with local regulations, and...

  • Regional Head of Schools

    hace 2 semanas


    distrito federal, México Balearesint A tiempo completo

    We are seeking a visionary leader with significant experience in education to join us as Regional Head of Schools at an exciting stage of development for the Group. This is an exciting opportunity which would suit an experienced Principal, Headteacher or senior school leader with extensive experience in a variety of international school settings. The...


  • distrito federal, México Diageo A tiempo completo

    Diageo is the world’s leading premium drinks company with an outstanding collection of brands, such as Johnnie Walker, Smirnoff, Baileys, Captain Morgan, Tanqueray and Guinness. With over 200 brands in 180 countries and a global network of entrepreneurial individuals, our teams blend a diverse range of experience, knowledge and skills. We connect customers...


  • distrito federal, México CitiGroup A tiempo completo

    The Chief Information Security Officer (CISO) is a senior executive responsible for establishing and maintaining the bank’s information security strategy and ensuring that all information assets and technologies are adequately protected. The CISO plays a critical role in safeguarding the bank's data, ensuring compliance with local regulations, and...

  • Senior Risk

    hace 1 mes


    distrito federal, México Nestlé A tiempo completo

    We are a team of IT professionals from many countries and diverse backgrounds, each with unique missions and challenges in the biggest health, nutrition and wellness company of the world. We innovate every day through forward-looking technologies to create opportunities for Nestlé’s digital challenges with our consumers, customers and at the workplace. We...