Security Risk and Compliance Management Specialist III
Mexico - Mexico City - Remote
Applications have closed
Rackspace
As a cloud computing services pioneer, we deliver proven multicloud solutions across your apps, data, and security. Maximize the benefits of modern cloud.
Leads the security policy management function within GRC end-to-end.
-Responsible for running policy workshops to triage policy intake request for the modification and/or creation of new policies, control standards, and procedures. This may also include troubleshooting ownership issues, or anything related to policies such as correlation to compliance frameworks, risks or general cybersecurity events and evolution.-Responsible for facilitating the annual policy attestation cycle where owners must leverage the GRC tool, Archer to sign off or modify their control statements. This includes working together with partners across the organization who need support navigating the intricacies of policy management.-Supporting all issues related to policy management.-POC for everything Policy Mgmt. within GRC and for partnering areas.-Setting long term goals and strategies to evolve policy mgmt.
Leads the Security Awareness Training (SAT) function within GRC end-to-end.
-Responsible for security onboarding for all new recruits as well as annual security refresher training. This includes maintaining current content, creation of new content, leveraging our tools for content changes and working with learning center management peers.-Lead for National Cyber Security Awareness Month. This includes creation of the schedule of events, and executing the plan – workshops, webinars, training, games, prize, tech talks etc.-Lead for hosting phishing program and campaigns to increase employee vigilance. This includes creating the plans, testing, prepping with technical areas to ensure conflicts don’t arise, analyzing the data during and after the phishing campaigns. This also includes fixing any and all issues that may arise regarding tool conflicts, false positives etc.-Familiarity with common SAT platforms such as ProofPoint, KnowBe4, OneTrust, Archer etc.-Lead for ad-hoc training and role-based training per utilized SAT platforms. Expand upon SAT program to host periodic training by function, group etc.-Support other areas who rely on security training or awareness needs.
-Responsible for running policy workshops to triage policy intake request for the modification and/or creation of new policies, control standards, and procedures. This may also include troubleshooting ownership issues, or anything related to policies such as correlation to compliance frameworks, risks or general cybersecurity events and evolution.-Responsible for facilitating the annual policy attestation cycle where owners must leverage the GRC tool, Archer to sign off or modify their control statements. This includes working together with partners across the organization who need support navigating the intricacies of policy management.-Supporting all issues related to policy management.-POC for everything Policy Mgmt. within GRC and for partnering areas.-Setting long term goals and strategies to evolve policy mgmt.
Leads the Security Awareness Training (SAT) function within GRC end-to-end.
-Responsible for security onboarding for all new recruits as well as annual security refresher training. This includes maintaining current content, creation of new content, leveraging our tools for content changes and working with learning center management peers.-Lead for National Cyber Security Awareness Month. This includes creation of the schedule of events, and executing the plan – workshops, webinars, training, games, prize, tech talks etc.-Lead for hosting phishing program and campaigns to increase employee vigilance. This includes creating the plans, testing, prepping with technical areas to ensure conflicts don’t arise, analyzing the data during and after the phishing campaigns. This also includes fixing any and all issues that may arise regarding tool conflicts, false positives etc.-Familiarity with common SAT platforms such as ProofPoint, KnowBe4, OneTrust, Archer etc.-Lead for ad-hoc training and role-based training per utilized SAT platforms. Expand upon SAT program to host periodic training by function, group etc.-Support other areas who rely on security training or awareness needs.
Required Skills
- Strong understanding of Archer GRC Tool. Development is not a must but navigation is.
- Strong communication skills, ability to navigate across departments and network with various employees across the department to solve issues, host trainings, run meetings and workshops etc.
- Supports the maturity of Governance function.
- Develops documentation related to GRC Platform.
Required Experience
- Minimum of 5-8 years of practical information security experience in developing and maintaining secure architectures for large enterprises is preferred.
- Discover your inner Racker: Racker Life
- Fluent, Bi-lingual (Spanish and English): interviews will be held in English.
- Role can work remotely in the states of Ciudad de Mexico, Jalisco, Nuevo Leon, Aguascalientes, Queretaro, Estado de Mexico and Puebla.
- This opportunity is a permanent remote job, but you need to be based in Mexico at one of the above locations.
- #LI-JR1
- #LI-Remote
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
3
0
0
Category:
Compliance Jobs
Tags: Business Intelligence Compliance Governance
Perks/benefits: Career development
Regions:
Remote/Anywhere
North America
Country:
Mexico
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Security Officer jobsInformation System Security Officer jobsInformation Security Manager jobsSenior Cybersecurity Engineer jobsInformation Security Specialist jobsSenior Cloud Security Engineer jobsSenior Network Security Engineer jobsIT Security Engineer jobsCyber Security Specialist jobsSystems Administrator jobsSecurity Consultant jobsSystems Engineer jobsSenior Information Security Analyst jobsChief Information Security Officer jobsIT Security Analyst jobsSecurity Specialist jobsSenior Cyber Security Engineer jobsInformation System Security Officer (ISSO) jobsSenior Penetration Tester jobsInformation Systems Security Engineer jobsThreat Intelligence Analyst jobsStaff Security Engineer jobsCyber Threat Intelligence Analyst jobsSecurity Operations Analyst jobsCyber Security Architect jobs
CI/CD jobsKubernetes jobsGDPR jobsJava jobsEDR jobsRMF jobsSaaS jobsForensics jobsSplunk jobsIDS jobsDoDD 8570 jobsSQL jobsIPS jobsIntrusion detection jobsBash jobsSDLC jobsActive Directory jobsThreat detection jobsCompTIA jobsITIL jobsGIAC jobsFinance jobsCRISC jobsClearance Required jobsOWASP jobs