Head of Data Security and Compliance

hace 2 meses


distrito federal, México Addington Place of Shoal Creek A tiempo completo
Job: Head of Data Security and Compliance

Our client is seeking a highly skilled Head of Data Security & Compliance to join our fast-growing SaaS company. This leadership role is responsible for ensuring the company’s data security, regulatory compliance, and overall protection of sensitive information. The ideal candidate will possess a deep understanding of data security best practices, compliance frameworks, and risk management strategies. Moreover, the Head of Data Compliance and Security should demonstrate a customer-centric approach, ensuring that security measures do not impede product functionality, ease of use, or hinder the sales process. This role requires a unique blend of technical expertise, strategic thinking, and business acumen.

Responsibilities
  • Ensure compliance with ISO, SOC 2, GDPR , Mexico, Ecuador, California and other relevant data privacy laws in the USA and Latam, developing and implementing policies, procedures, and controls to meet the requirements.
  • Collaborate with internal teams to establish data minimization practices, consent management processes, and procedures to address data subjects’ rights, including the right to be forgotten.
  • Work with product team to ensure that all our client’s product is best-in-class from a Data Security perspective
  • Lead and oversee audits, including SOC 1, SOC 2, and SOC 3 audits and ISO 27001 certification, ensuring compliance with control objectives and requirements.
  • Stay updated on emerging data privacy laws and regulations, such as GDPR, CCPA and PIPEDA, and assess their impact on our client’s data protection practices.
  • Lead incident response efforts, including managing data breach incidents, coordinating investigations, and executing data breach notification procedures in accordance with GDPR and other applicable regulations.
  • Conduct regular risk assessments and vulnerability assessments to identify potential weaknesses and implement appropriate controls.
  • Stay informed about emerging threats, trends, and industry developments, and proactively update security strategies to address new risks.
  • Develop and maintain documentation, such as Data Protection Impact Assessments (DPIAs), privacy policies, and procedures, to demonstrate compliance with data protection regulations.Lead incident response efforts, including managing data breach incidents, coordinating investigations, and executing data breach notification procedures in accordance with GDPR and other applicable regulations.
  • Understand cloud technologies and architectures, such as Google Cloud Platform and AWS, and apply associated security and compliance considerations in data protection strategies.
  • Apply data security principles, including encryption, anonymization, and pseudonymization techniques, to safeguard sensitive data.
  • Collaborate with cross-functional teams to embed security considerations throughout the product development lifecycle without compromising functionality or user experience.
  • Conduct thorough security assessments of new features, products, and systems to identify potential risks and recommend appropriate security controls.
  • Champion a culture of secure coding practices, security testing, and ongoing vulnerability management to ensure the product is robust and resilient.
  • Address security issues related to database technologies, ensuring secure database configurations and access controls.
  • Balance security requirements with customer expectations and usability, ensuring security measures do not create unnecessary obstacles or impede the overall user experience.
  • Engage with customers, understand their security concerns, and provide guidance on secure product usage, privacy, and data protection practices.
  • Collaborate with customer support and sales teams to address security-related inquiries, concerns, and provide expertise during the sales process.
Requirements
  • In-depth knowledge of data privacy and protection laws, regulations, and frameworks in the LatAm region, including specific knowledge of Mexico’s data protection landscape, as well as expertise in GDPR requirements, such as data minimization, right to be forgotten, consent management, etc.
  • Has experience as DPO in a fintech, highly regulated start-up or equivalent.
  • Experience with SOC 1, SOC 2, SOC 3 audits, and ISO 27001, understanding the control objectives and requirements associated with these standards.
  • Familiarity with other data privacy laws and regulations, such as GDPR, CCPA (California Consumer Privacy Act), PIPEDA (Personal Information Protection and Electronic Documents Act), and other relevant global privacy frameworks.
  • Proficiency in risk assessment methodologies and experience conducting security risk assessments to identify and mitigate potential risks to data security and compliance.
  • Ability to develop and maintain documentation, including Data Protection Impact Assessments (DPIAs), privacy policies, procedures, and other necessary documentation to ensure compliance with data protection regulations.
  • Experience in incident response and data breach notification procedures as per GDPR and other applicable regulations, including coordination with relevant stakeholders, regulatory bodies, and legal teams.
  • Proficiency in Python programming language for data analysis, automation, and security-related tasks.
  • Understanding of cloud technologies and architectures (Google Cloud Platform, MongoDB, AWS) and the associated security and compliance considerations.
  • Knowledge of data security principles, including encryption, anonymization, and pseudonymization techniques.
  • Familiarity with database technologies and associated security issues.
  • In-depth knowledge of data security frameworks, such as ISO 27001, NIST Cybersecurity Framework, or CIS Controls.
  • Strong understanding of regulatory compliance requirements, such as GDPR, CCPA, or HIPAA.
  • Demonstrated experience in developing and implementing comprehensive information security strategies.
  • Proven track record of successfully integrating security into product development lifecycles while maintaining usability and customer satisfaction.
  • Familiarity with secure coding practices, vulnerability management, and security testing methodologies.
  • Excellent communication and interpersonal skills to collaborate effectively across departments and communicate complex security concepts to non-technical stakeholders.
  • Strong analytical and problem-solving skills to identify and mitigate potential risks effectively.
  • Relevant certifications such as CISSP, CISM, or CRISC are highly desirable.
#J-18808-Ljbffr

  • distrito federal, México Utopia Living A tiempo completo

    We are seeking a highly skilled and motivated Hospitality Quality and Compliance Strategist / Head of Product. This role requires a professional with extensive product creation and operational experience in hospitality projects, capable of assessing and influencing design from an operational perspective and building the luxurious product from scratch,...


  • distrito federal, México Chubb Ltd. A tiempo completo

    Team Leadership and Management:  Lead and oversee a medium team, ensuring their professional development, motivation, and high performance.  Provide coaching, guidance, and technical expertise to team members, promoting a culture of continuous learning and growth.  Establish clear goals and expectations, monitor progress, and provide regular feedback to...


  • distrito federal, México Gerresheimer A tiempo completo

    Gerresheimer Querétaro S.A. in Mexico produces primary glass packaging for pharmaceutical use. Type I glass is produced in clear and amber glass. The broad product range includes ampoules, serum vials, screw thread vials, ready-to-fill syringes and cartridges. Job Description Attract talent based on job descriptions for each area. Provide attention and...


  • distrito federal, México Amazon A tiempo completo

    Governance Risk and Compliance Manager, AWS Security Job ID: 2696776 | Amazon Web Services Australia Pty Ltd Amazon Web Services (AWS) is the leading cloud service provider, providing virtualised infrastructure, storage, networking, messaging, and many other services to customers all over the world. AWS runs a globally distributed environment, operating at...

  • Head of Payroll

    hace 2 meses


    distrito federal, México Magnocampo A tiempo completo

    Objective To ensure accurate payroll calculation, proper analysis of information, and timely payments to employees, complying with tax, state, and social security obligations in accordance with the current legal framework. Profile Bachelor's degree in Public Accounting or Business Administration (graduate). Minimum 4 years of experience as Payroll Manager....


  • distrito federal, México Gerresheimer AG A tiempo completo

    Job Description Attract talent based on job descriptions for each area. Provide attention and follow-up to internal clients to fill vacancies in their areas. Select recruitment sources to effectively publish vacancies. Interview potential candidates and channel them to the next level of interview. Ensure compliance with the recruitment and selection process,...


  • distrito federal, México Citi A tiempo completo

    The Chief Information Security Officer (CISO) is a senior executive responsible for establishing and maintaining the bank’s information security strategy and ensuring that all information assets and technologies are adequately protected. The CISO plays a critical role in safeguarding the bank's data, ensuring compliance with local regulations, and...

  • Head of Education

    hace 2 meses


    distrito federal, México Platzi A tiempo completo

    About us Platzi is the largest technology school in the Hispanic world with over 5 million students and 4,000 companies trusting us to deliver effective online education. Our mission is to make Latin America a technology superpower by training companies and individuals in areas such as AI, Cybersecurity, English, Programming, and Leadership. As an industry...


  • distrito federal, México Centorrx A tiempo completo

    Job Description Attract talent based on job descriptions for each area. Provide attention and follow-up to internal clients to fill vacancies in their areas. Select recruitment sources to effectively publish vacancies and interview potential candidates, channeling them to the next level of interview. Ensure compliance with the recruitment and selection...

  • Head of Sales

    hace 2 meses


    distrito federal, México Voyagu A tiempo completo

    Voyagu is a dynamic and innovative tech-enabled travel agency based in the US, focused on delivering exceptional air travel services to premium clients. With operational hubs in Mexico City and Warsaw, and a commitment to providing the best customer experience in the industry, we are poised for significant growth and transformation. We are looking for a...


  • distrito federal, México IBM A tiempo completo

    Introduction Information and Data are some of the most important organizational assets in today’s businesses. As a Security Consultant, you will be a key advisor for IBM’s clients, analyzing business requirements to design and implement the best security solutions for their needs. You will apply your technical skills to find the balance between enabling...

  • Head of Marketing

    hace 1 mes


    distrito federal, México Cambridge University Press & Assessment A tiempo completo

    Head of Marketing Salary: Competitive Location: Mexico City, Mexico Contract: Permanent, Full time, Hybrid Do you have a proven track record in B2B and B2C marketing? Lead with us and drive change in the education space! We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud part of the...


  • distrito federal, México TripleTen A tiempo completo

    Description TripleTen is a service that empowers individuals, regardless of their prior experience, to embark on the exciting and challenging journey of mastering IT professions such as software engineering, data analysis, data science, business intelligence analytics, and QA engineering in a feasible and accessible way, ultimately leading to employment...

  • HSBC | LAM Risk

    hace 3 semanas


    distrito federal, México HSBC A tiempo completo

    Role purpose Support the Chief of Staff, Risk and Compliance LAM/MX Head driving strategic initiatives across the function and maintain proper Risk & Compliance governance across LAM. Chief of Staff oversees Transformation, Governance, Business Management, Functional Execution, Integral Risk Management Unit, Control Office, Innovation and Criminal...


  • distrito federal, México Citi A tiempo completo

    The Chief Information Security Officer (CISO) is a senior executive responsible for establishing and maintaining the bank’s information security strategy and ensuring that all information assets and technologies are adequately protected. The CISO plays a critical role in safeguarding the bank's data, ensuring compliance with local regulations, and...

  • Head of Marketing

    hace 1 mes


    distrito federal, México Cambridge University Press A tiempo completo

    Job Title: Head of Marketing Salary: Competitive Location: Mexico City, Mexico Contract: Permanent, Full time, Hybrid Do you have a proven track record in B2B and B2C marketing? Lead with us and drive change in the education space! We are Cambridge University Press & Assessment, a world-leading academic publisher and assessment organisation and a proud...

  • Head of Publishing

    hace 2 meses


    distrito federal, México Teads A tiempo completo

    Teads is looking for a driven and experienced Head of Publishing for Ispe Latam based in Mexico to manage the strategic growth of our premium publisher partners. You will be responsible for the development of Teads’ technology partnerships with digital publishers across web and CTV. The ideal candidate for this position will have extensive experience with...


  • distrito federal, México Perez-Llorca A tiempo completo

    Head of Financial Accounting and Taxation We are looking for a Head of financial accountig and taxation for our office in Mexico. Requirements Certified public accountant of Mexico. ACCA Diploma in International Financial Reporting Standards (IFRS). More than six years of Big 4 audit experience (manager level or equivalent). More than two years of...

  • HSBC | Head of Data

    hace 3 semanas


    distrito federal, México HSBC A tiempo completo

    Role Purpose Responsible for the Data & Analytics team, including Data Science, Business Intelligence, and Data Engineering, encompassing infrastructure, quality, and control. Principal Responsibilities and Accountabilities Provide strategic leadership, team management, and technical oversight regarding data science, business intelligence, and data...


  • Federal, México HAYS A tiempo completo

    Cybersecurity Compliance - Working practices comply with the Group’s Cybersecurity policy framework and assist the teams' understanding of risk exposures to the Group. - Development and ongoing maintenance of cybersecurity policies and processes together with support and review of procedures for the delivery and adherence to aforementioned policies &...