Cybersecurity Governance, Risk and Compliance Lead

hace 1 semana


Bogotá, Bogotá D.E., Colombia Alexandra Lozano Immigration Law PLLC A tiempo completo
Overview

We are seeking a bilingual, experienced, and highly skilled Cybersecurity Governance, Risk, and Compliance (GRC) Lead. Experience managing security awareness and training programs is also required.

The ideal candidate will have a deep understanding of cybersecurity frameworks, risk management strategies, and compliance with laws, regulations, and standards, along with the ability to lead efforts to raise security awareness across the organization.

This individual will be instrumental in ensuring our cybersecurity policies, practices, risk management, and training programs align with industry standards and regulatory requirements.

This position is 100% remote in Colombia.

Responsibilities
  1. Governance, Risk & Compliance (GRC):
    1. Lead the design, development, implementation, and maintenance of cybersecurity governance, risk, and compliance programs in alignment with industry best practices and regulatory requirements (e.g., NIST, ISO 27001, OWASP, CCPA, HIPAA, SOC 2).
    2. Conduct risk assessments and recommend mitigation strategies to senior management.
    3. Ensure compliance with security regulations and frameworks by preparing for audits, conducting internal assessments, and addressing gaps.
    4. Collaborate with legal, compliance, and IT teams to ensure security policies and procedures meet all regulatory requirements.
    5. Develop and maintain key performance indicators (KPIs) for cybersecurity, risk management and compliance programs.
    6. Review and update cybersecurity policies and procedures regularly to address emerging threats, changes in the regulatory landscape, and organizational needs.
    7. Act as the subject matter expert on organizational security policies and procedures, offering guidance and support across departments.
  2. Security Awareness & Training:
    1. Design, implement, and manage a comprehensive security awareness program to educate employees on security best practices, emerging threats, and compliance requirements.
    2. Define engaging and informative training materials, tailored to various levels of technical expertise.
    3. Coordinate and deliver regular security awareness training communications / sessions to improve employee engagement and knowledge retention.
    4. Track training completion rates, effectiveness of the programs, and areas for improvement, utilizing metrics to continually optimize the program.
    5. Work closely with HR and leadership to integrate security awareness and compliance topics into onboarding and continuous professional development.
  3. Leadership, Collaboration & Reporting:
    1. Identify, design, plan and lead implementation of automation opportunities.
    2. Continuous improvement of the processes under your responsibility.
    3. Collaborate with cross-functional teams (including IT, operations, legal, and HR departments) to drive cybersecurity initiatives for ensuring alignment of security practices with business goals and regulatory requirements.
    4. Lead the evaluation and selection of third-party vendors or tools for risk management and security awareness.
    5. Provide expert guidance on risk management and compliance to all levels of the organization.
    6. Provide regular status reports and metrics on GRC activities, risk posture, and security awareness initiatives to senior leadership, offering actionable insights and recommendations for improvements.
    7. Manage compliance reporting requirements.
Qualifications
  1. Bilingual (English - Spanish) B2/C1.
  2. Education:
    1. Bachelor's degree in computer science. Post-graduate degree in cyber/information security is a plus.
  3. Certifications:
    1. CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or CISA (Certified Information Systems Auditor) preferred.
    2. Certifications in Risk Management (e.g., CRISC), GRC frameworks and Security Awareness training programs are highly desirable.
  4. Experience:
    1. 7+ years of experience in cybersecurity, with at least 3 years in a governance, risk, and compliance leadership role.
    2. Proven experience in audit and assessment processes, both internal and external, for cybersecurity programs and compliance.
    3. Proven experience in managing and delivering security awareness and training programs at an enterprise level.
    4. Hands-on experience with security tools, risk and compliance management software, and training platforms.
    5. Experience with cloud security is a plus (Azure, AWS, Google Cloud, etc.).
  5. Skills & Competencies:
    1. Strong knowledge of cybersecurity frameworks, compliance with laws/regulations/ security standards (NIST, CCPA, GDPR, PCI DSS, etc.), and risk management methodologies.
    2. Strong knowledge of security concepts, policies, and tools, as well as the ability to identify risks and plan remediation.
    3. Communication and presentation skills, with the ability to engage stakeholders.
    4. Ability to stay current and adapt quickly to new regulations, emerging security trends, tools, and technologies.
    5. Strong problem-solving and analytical skills, with the ability to manage complex security challenges.
#J-18808-Ljbffr

  • Bogotá, Bogotá D.E., Colombia Horatio A tiempo completo

    Information Security and Compliance Lead (BOG)Horatio Bogota, D.C., Capital District, ColombiaPosition Summary:The Information Security and Compliance Lead is responsible for ensuring that Hire Horatio's information technology (IT) systems and processes comply with relevant laws, regulations, and standards.Responsibilities:- Monitor and interpret regulatory...


  • Bogotá, Bogotá D.E., Colombia ENGINEERINGUK A tiempo completo

    Key Responsibilities:As a Compliance and Risk Manager, you will be responsible for ensuring that our company's operations across South America are in compliance with all relevant laws and regulations. This includes managing regulatory relationships, ensuring adherence to compliance obligations, and acting as a key advisor to internal and external...


  • Bogotá, Bogotá D.E., Colombia Horatio A tiempo completo

    **Job Description**We are seeking a talented Compliance Lead for IT Systems to join our team in Bogota.**Responsibilities and Requirements**Develop and implement policies and procedures for IT governance and risk management, including identifying, assessing, and mitigating risks.Provide guidance, training, and support to other members of the organization on...


  • Bogotá, Bogotá D.E., Colombia myGwork - LGBTQ+ Business Community A tiempo completo

    Role Overview:The Regulatory Compliance Consultant will be responsible for ensuring our operations in South America comply with legal, regulatory, and tax frameworks. This involves managing regulatory relationships, ensuring adherence to compliance obligations, and serving as a key advisor to internal and external stakeholders.Responsibilities:Regulatory...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    The IT Governance and Compliance Specialist is responsible for ensuring the effective governance and compliance of IT processes within Scotiabank.This includes collaborating with peers across all business lines and technology functions to identify and mitigate risks associated with IT processes.Your key responsibilities will include:Developing and...


  • Bogotá, Bogotá D.E., Colombia Johnson And Johnson A tiempo completo

    **Key Responsibilities**The PMO Governance Analyst will be responsible for:Ensuring Project Compliance: Conduct regular audits and reviews of project documentation to ensure compliance with governance standards.Supporting Resource Allocation: Assist in the development and implementation of resource allocation and utilization processes.Maintaining Governance...


  • Bogotá, Bogotá D.E., Colombia Energizer Holdings A tiempo completo

    Key ResponsibilitiesProject/Program Management:Apply project management discipline to all significant ethics and compliance initiatives, including appropriate documentation and tracking reportsCoordinate the implementation of ethics and compliance initiativesLead project teams in implementing complex, cross-functional ethics and compliance...

  • Governance Specialist

    hace 6 días


    Bogotá, Bogotá D.E., Colombia Johnson And Johnson A tiempo completo

    **Job Overview**At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver...


  • Bogotá, Bogotá D.E., Colombia Citi A tiempo completo

    Job DescriptionServes as a senior compliance risk officer responsible for establishing internal strategies, policies, procedures, processes, and programs to prevent violations of law, rule, or regulation. In addition, engages with the ICRM product and function coverage teams, in order to partner to develop and apply CRM program solutions that meet business...


  • Bogotá, Bogotá D.E., Colombia Horatio A tiempo completo

    **Job Overview**Horatio is seeking an experienced Information Security and Compliance Lead to join our team in Bogota. As a key member of our IT department, you will be responsible for ensuring the security and compliance of our information technology systems and processes.**Responsibilities**Develop and implement policies and procedures for IT governance...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    About the Role:We are seeking an experienced Information Technology professional to lead our Security Assurance team within Security Risk Governance.This role requires strong verbal and written communication skills, particularly report writing ability.The ideal candidate will possess advanced presentation and communication skills and be bi-lingual in English...


  • Bogotá, Bogotá D.E., Colombia Citi A tiempo completo

    Compliance Risk Management Position SummaryThe position is responsible for managing and implementing Compliance risk management strategies, policies, and procedures across Citi. This includes providing expert advice and guidance to stakeholders on Compliance laws, rules, regulations, risks, and typologies.Responsibilities:Manage and implement Compliance risk...


  • Bogotá, Bogotá D.E., Colombia Johnson And Johnson A tiempo completo

    We are seeking an experienced Accounting Specialist to join our Global Services (GS) team at Johnson & Johnson. As a key member of our team, you will be responsible for ensuring the quality and accuracy of our financial data, while maintaining compliance with regulatory requirements and internal controls.Responsibilities:* Develop and execute audit plans to...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    About UsScotiabank's ScotiaTech is a technology hub in Bogota, driving innovation and creativity in a fast-paced environment. We're committed to results, inclusivity, diversity, and high performance.Job DescriptionThe Technology Control Testing team plays a vital role in Scotiabank's Three Lines of Defense Framework, providing First Line of Defense for all...


  • Bogotá, Bogotá D.E., Colombia Positivo S+ Latam A tiempo completo

    Job DescriptionWe are seeking a skilled Cybersecurity Risk Management Professional to join our team at Positivo S+ Latam.The ideal candidate will have expertise in information security and be able to assess potential risks and develop mitigation strategies.Key ResponsibilitiesThis role will involve providing technical support and information security...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    About the RoleThe Senior Manager Communications Surveillance position is responsible for managing the execution of GBM Communication Supervision Procedures, planning the resources required to perform the review alerts. The ideal candidate will ensure compliance with the Code of Conduct, internal policies & procedures, Global FX Code, industry standards and...


  • Bogotá, Bogotá D.E., Colombia Johnson And Johnson A tiempo completo

    **Role Summary**We are searching for a highly skilled PMO Governance Analyst to join our team at Johnson & Johnson. The successful candidate will be responsible for supporting the Project Management Office (PMO) in ensuring adherence to project management standards and governance frameworks.The key responsibilities of this role include:Governance Process...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    About the RoleThis exciting opportunity exists within our Global Technology Services team, where you will play a key role in ensuring the ongoing success of our organization by identifying and mitigating risks associated with technology systems and processes.Main ResponsibilitiesWork closely with cross-functional teams to develop and implement strategic...


  • Bogotá, Bogotá D.E., Colombia myGwork - LGBTQ+ Business Community A tiempo completo

    Job Description:As a Regulatory Compliance Consultant, you will be responsible for ensuring our operations in South America comply with legal, regulatory, and tax frameworks. This involves managing regulatory relationships, ensuring adherence to compliance obligations, and serving as a key advisor to internal and external stakeholders.Key...


  • Bogotá, Bogotá D.E., Colombia Munich Re A tiempo completo

    We are seeking a Corporate Governance Professional to join our team in South America. As a Corporate Governance Professional, you will be responsible for ensuring compliance with legal, regulatory, and corporate governance requirements.About the RoleEnsure full compliance with legal, regulatory, and corporate governance requirements across South...