Cybersecurity Governance, Risk and Compliance Lead

hace 1 día


WorkFromHome, Colombia Quetzalintl A tiempo completo

Cybersecurity Governance, Risk and Compliance Lead - Bilingual English/Spanish We are seeking a bilingual, experienced, and highly skilled Cybersecurity Governance, Risk, and Compliance (GRC) Lead. Experience managing security awareness and training programs is also required. The ideal candidate will have a deep understanding of cybersecurity frameworks, risk management strategies, and compliance with laws, regulations, and standards, along with the ability to lead efforts to raise security awareness across the organization. This individual will be instrumental in ensuring our cybersecurity policies, practices, risk management, and training programs align with industry standards and regulatory requirements. This position is 100% remote in Colombia. Responsibilities: Governance, Risk & Compliance (GRC): Lead the design, development, implementation, and maintenance of cybersecurity governance, risk, and compliance programs in alignment with industry best practices and regulatory requirements (e.g., NIST, ISO 27001, OWASP, CCPA, HIPAA, SOC 2). Conduct risk assessments and recommend mitigation strategies to senior management. Ensure compliance with security regulations and frameworks by preparing for audits, conducting internal assessments, and addressing gaps. Collaborate with legal, compliance, and IT teams to ensure security policies and procedures meet all regulatory requirements. Develop and maintain key performance indicators (KPIs) for cybersecurity, risk management and compliance programs. Review and update cybersecurity policies and procedures regularly to address emerging threats, changes in the regulatory landscape, and organizational needs. Act as the subject matter expert on organizational security policies and procedures, offering guidance and support across departments. Security Awareness & Training: Design, implement, and manage a comprehensive security awareness program to educate employees on security best practices, emerging threats, and compliance requirements. Define engaging and informative training materials, tailored to various levels of technical expertise. Coordinate and deliver regular security awareness training communications / sessions to improve employee engagement and knowledge retention. Track training completion rates, effectiveness of the programs, and areas for improvement, utilizing metrics to continually optimize the program. Work closely with HR and leadership to integrate security awareness and compliance topics into onboarding and continuous professional development. Identify, design, plan and lead implementation of automation opportunities. Continuous improvement of the processes under your responsibility. Collaborate with cross-functional teams (including IT, operations, legal, and HR departments) to drive cybersecurity initiatives for ensuring alignment of security practices with business goals and regulatory requirements. Lead the evaluation and selection of third-party vendors or tools for risk management and security awareness. Provide expert guidance on risk management and compliance to all levels of the organization. Provide regular status reports and metrics on GRC activities, risk posture, and security awareness initiatives to senior leadership, offering actionable insights and recommendations for improvements. Manage compliance reporting requirements. Qualifications: Education: Bachelor’s degree in computer science. Post-graduate degree in cyber/information security is a plus. Certifications: CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or CISA (Certified Information Systems Auditor) preferred. Certifications in Risk Management (e.g., CRISC), GRC frameworks and Security Awareness training programs are highly desirable. Experience : 7+ years of experience in cybersecurity, with at least 3 years in a governance, risk, and compliance leadership role. Proven experience in audit and assessment processes, both internal and external, for cybersecurity programs and compliance. Proven experience in managing and delivering security awareness and training programs at an enterprise level. Hands‑on experience with security tools, risk and compliance management software, and training platforms. Experience with cloud security is a plus (Azure, AWS, Google Cloud, etc.). Strong knowledge of cybersecurity frameworks, compliance with laws/regulations/ security standards (NIST, CCPA, GDPR, PCI DSS, etc.), and risk management methodologies. Strong knowledge of security concepts, policies, and tools, as well as the ability to identify risks and plan remediation. Communication and presentation skills, with the ability to engage stakeholders. Ability to stay current and adapt quickly to new regulations, emerging security trends, tools, and technologies. Strong problem-solving and analytical skills, with the ability to manage complex security challenges. #J-18808-Ljbffr


  • Technology Risk

    hace 1 semana


    WorkFromHome, Colombia ADDI A tiempo completo

    A leading financial platform in Bogotá is seeking a Head of Technology Risk to establish and lead the 2nd Line of Defense Technology Risk & Cybersecurity function. You will develop governance frameworks, oversee incident management, and ensure compliance with regulations. The ideal candidate will have over 12 years of experience in technology risk within a...


  • WorkFromHome, Colombia Edgeuno A tiempo completo

    About EdgeUno EdgeUno empowers the next era of digital connectivity across Latin America. With one of the region’s most interconnected data centers and network platforms, we support mission‑critical workloads for enterprises, ISPs, hyperscalers, and digital platforms. Our culture is built on ownership, agility, technical excellence, and accountability....


  • WorkFromHome, Colombia Scotiabank A tiempo completo

    A leading financial institution is looking for a Cybersecurity Specialist to ensure compliance with security standards and manage risk assessments. The ideal candidate has over 3 years of experience in Information Security and Cybersecurity, with strong communication skills in English and knowledge of financial regulations. This role is based in Bogotá,...

  • Senior GRC

    hace 1 semana


    WorkFromHome, Colombia AspenView Technology Partners A tiempo completo

    A leading IT services firm in Colombia is seeking a Senior GRC & Security Assurance Specialist to oversee cybersecurity governance and ensure compliance with global standards. You will lead risk assessments, manage third-party risks, and develop comprehensive security policies. The ideal candidate should have 6–8+ years in GRC or Cyber Risk Management,...

  • Senior Cybersecurity

    hace 1 día


    WorkFromHome, Colombia Linda Mar Associates A tiempo completo

    We are looking for a senior cybersecurity leader to oversee and grow our security and compliance service line. This person will lead a team of security engineers, pentesters, and security researchers, while directly engaging with clients to deliver high-quality advisory, compliance, and audit support. This role is ideal for someone with CISO-level...

  • Senior GRC

    hace 4 días


    WorkFromHome, Colombia AspenView Technology Partners, Inc. A tiempo completo

    A technology services company in Colombia is seeking a Senior GRC & Security Assurance Specialist to lead cybersecurity governance efforts. The role involves designing and implementing frameworks, managing audits, and ensuring compliance with global standards. Ideal candidates will have over 6 years of experience and relevant certifications like CISA. The...

  • Compliance Lead

    hace 4 días


    WorkFromHome, Colombia Truelogic Software A tiempo completo

    Compliance Lead - Marketing at Truelogic Software Truelogic is a leading provider of nearshore staff augmentation services headquartered in New York, delivering top-tier technology solutions to companies of all sizes. Our client is a challenger holding company built to transform marketing. Job Summary As a Compliance Lead, you will oversee and manage all...


  • WorkFromHome, Colombia Cerebras A tiempo completo

    Location Colombia Employment Type Full time Location Type Remote Department Bank About Addi We are a leading financial platform, building the future of payments, shopping, and banking—a world where consumers and merchants can transact effortlessly and grow together. Today, we serve over 2 million customers and partner with more than 20,000 merchants,...

  • Risk Analytics

    hace 4 días


    WorkFromHome, Colombia Scotiabank A tiempo completo

    A global financial institution is seeking a Risk Reporting & Analytics professional to support business strategies and ensure compliance. The role requires bilingual fluency in Spanish and English, along with strong proficiency in Agile and Project Management methodologies. Responsibilities include resolving complex financial problems, maintaining risk...


  • WorkFromHome, Colombia Linda Mar Associates A tiempo completo

    A cybersecurity consulting firm is seeking a Senior Cybersecurity Specialist to lead a team and oversee compliance and security practices. This hybrid role located in Bogotá, D.C. requires expertise in SOC 2, ISO 27001, PCI DSS, and HIPAA, with responsibilities including managing security audits and client communications. Candidates should have 5–7 years...