Security Risk and Compliance Management Specialist III
Mexico - Mexico City - Remote
Rackspace
As a cloud computing services pioneer, we deliver proven multicloud solutions across your apps, data, and security. Maximize the benefits of modern cloud.
Leads the security policy management function within GRC end-to-end.
-Responsible for running policy workshops to triage policy intake request for the modification and/or creation of new policies, control standards, and procedures. This may also include troubleshooting ownership issues, or anything related to policies such as correlation to compliance frameworks, risks or general cybersecurity events and evolution.-Responsible for facilitating the annual policy attestation cycle where owners must leverage the GRC tool, Archer to sign off or modify their control statements. This includes working together with partners across the organization who need support navigating the intricacies of policy management.-Supporting all issues related to policy management.-POC for everything Policy Mgmt. within GRC and for partnering areas.-Setting long term goals and strategies to evolve policy mgmt.
Leads the Security Awareness Training (SAT) function within GRC end-to-end.
-Responsible for security onboarding for all new recruits as well as annual security refresher training. This includes maintaining current content, creation of new content, leveraging our tools for content changes and working with learning center management peers.-Lead for National Cyber Security Awareness Month. This includes creation of the schedule of events, and executing the plan – workshops, webinars, training, games, prize, tech talks etc.-Lead for hosting phishing program and campaigns to increase employee vigilance. This includes creating the plans, testing, prepping with technical areas to ensure conflicts don’t arise, analyzing the data during and after the phishing campaigns. This also includes fixing any and all issues that may arise regarding tool conflicts, false positives etc.-Familiarity with common SAT platforms such as ProofPoint, KnowBe4, OneTrust, Archer etc.-Lead for ad-hoc training and role-based training per utilized SAT platforms. Expand upon SAT program to host periodic training by function, group etc.-Support other areas who rely on security training or awareness needs.
-Responsible for running policy workshops to triage policy intake request for the modification and/or creation of new policies, control standards, and procedures. This may also include troubleshooting ownership issues, or anything related to policies such as correlation to compliance frameworks, risks or general cybersecurity events and evolution.-Responsible for facilitating the annual policy attestation cycle where owners must leverage the GRC tool, Archer to sign off or modify their control statements. This includes working together with partners across the organization who need support navigating the intricacies of policy management.-Supporting all issues related to policy management.-POC for everything Policy Mgmt. within GRC and for partnering areas.-Setting long term goals and strategies to evolve policy mgmt.
Leads the Security Awareness Training (SAT) function within GRC end-to-end.
-Responsible for security onboarding for all new recruits as well as annual security refresher training. This includes maintaining current content, creation of new content, leveraging our tools for content changes and working with learning center management peers.-Lead for National Cyber Security Awareness Month. This includes creation of the schedule of events, and executing the plan – workshops, webinars, training, games, prize, tech talks etc.-Lead for hosting phishing program and campaigns to increase employee vigilance. This includes creating the plans, testing, prepping with technical areas to ensure conflicts don’t arise, analyzing the data during and after the phishing campaigns. This also includes fixing any and all issues that may arise regarding tool conflicts, false positives etc.-Familiarity with common SAT platforms such as ProofPoint, KnowBe4, OneTrust, Archer etc.-Lead for ad-hoc training and role-based training per utilized SAT platforms. Expand upon SAT program to host periodic training by function, group etc.-Support other areas who rely on security training or awareness needs.
Required Skills
- Strong understanding of Archer GRC Tool. Development is not a must but navigation is.
- Strong communication skills, ability to navigate across departments and network with various employees across the department to solve issues, host trainings, run meetings and workshops etc.
- Supports the maturity of Governance function.
- Develops documentation related to GRC Platform.
Required Experience
- Minimum of 5-8 years of practical information security experience in developing and maintaining secure architectures for large enterprises is preferred.
- Discover your inner Racker: Racker Life
- Fluent, Bi-lingual (Spanish and English): interviews will be held in English.
- Role can work remotely in the states of Ciudad de Mexico, Jalisco, Nuevo Leon, Aguascalientes, Queretaro, Estado de Mexico and Puebla.
- This opportunity is a permanent remote job, but you need to be based in Mexico at one of the above locations.
- #LI-JR1
- #LI-Remote
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
0
0
0
Category:
Compliance Jobs
Tags: Business Intelligence Compliance Governance
Perks/benefits: Career development Team events
Regions:
Remote/Anywhere
North America
Country:
Mexico
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Security Specialist jobsInformation System Security Officer jobsInformation Security Officer jobsSenior Cloud Security Engineer jobsInformation Security Manager jobsSenior Cybersecurity Engineer jobsIT Security Engineer jobsSenior Network Security Engineer jobsCyber Security Specialist jobsSenior Information Security Analyst jobsSystems Engineer jobsSystems Administrator jobsSecurity Consultant jobsSecurity Specialist jobsSenior Cyber Security Engineer jobsIT Security Analyst jobsChief Information Security Officer jobsInformation System Security Officer (ISSO) jobsSenior Penetration Tester jobsInformation Systems Security Engineer jobsThreat Intelligence Analyst jobsSecurity Operations Analyst jobsSenior Information Security Engineer jobsCyber Threat Intelligence Analyst jobsStaff Security Engineer jobs
Top Secret jobsJava jobsMalware jobsGDPR jobsSplunk jobsEDR jobsRMF jobsSaaS jobsSDLC jobsForensics jobsIDS jobsSQL jobsBash jobsIPS jobsIntrusion detection jobsThreat detection jobsDoDD 8570 jobsFinance jobsActive Directory jobsCRISC jobsITIL jobsCompTIA jobsGIAC jobsTerraform jobsDocker jobs
OWASP jobsClearance Required jobsSANS jobsOSCP jobsSOC 2 jobsCCSP jobsUNIX jobsHIPAA jobsPolygraph jobsBanking jobsIndustrial jobsAnsible jobsJavaScript jobsVPN jobsData Analytics jobsTCP/IP jobsSAP jobsDNS jobsSOX jobsIT infrastructure jobsJira jobsCISO jobsMachine Learning jobsSOAR jobsNIST 800-53 jobs