
Cybersecurity Professional
Posted Jul 22

Posted Jul 22
This is a fully remote position, open to applicants in Mexico.
• Perform cybersecurity risk assessments for technological, business, and operational projects.
• Evaluate threats, vulnerabilities, and the effectiveness of controls to establish residual risk.
• Update and maintain cybersecurity risk registers.
• Assess risks in relation to approved risk appetite and tolerance thresholds.
• Monitor and track risk mitigation and remediation efforts until completion.
• Assist in the functioning of the Cybersecurity Risk and Control Framework (CRCF).
• Challenge the thoroughness and accuracy of risk assessments and mitigation strategies.
• Oversee compliance with cybersecurity policies, standards, and control requirements.
• Aid in exception and risk acceptance reviews.
• Support cybersecurity governance meetings and reporting processes.
• Assist with both internal and external cybersecurity audits.
• Coordinate the collection of evidence and track remediation efforts.
• Evaluate compliance with internal cybersecurity standards and regulatory obligations.
• Contribute to control assessments and gap analysis.
• Generate risk metrics, dashboards, and management reports.
• Prepare documentation for management and governance reviews.
• Raise awareness of significant cybersecurity risk exposures and emerging trends.
• Collaborate with IT, Product Security, IAM, Legal, Procurement, Privacy, and business teams.
• Provide insights on cybersecurity risk management processes and requirements.
• Facilitate discussions on risk reviews and treatment with stakeholders.
• Encourage cybersecurity awareness and informed decision-making regarding risks.
• Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Systems, Risk Management, or a related field.
• Over 10 years of experience in cybersecurity, risk management, auditing, compliance, or information security.
• Familiarity with cybersecurity risk management methodologies and control frameworks.
• Capacity to analyze intricate technical and business risks.
• Exceptional written, presentation, and communication abilities.
• Understanding of prevalent cybersecurity frameworks and regulations (e.g., NIST, ISO 27001, GDPR).
• Relevant certifications such as CompTIA Security+ or CISSP are advantageous.
• Strong analytical and problem-solving capabilities.
• Health insurance
• Flexible work arrangements
• Professional development opportunities
CrowdStrike
Triumph Enterprises, Inc.
LaunchDarkly
Staffbase
Get handpicked remote jobs straight to your inbox weekly.