Cybersecurity Compliance Lead

hace 3 semanas


San José, San José, Costa Rica Ex2 Outcoding A tiempo completo

The Governance, Risk, and Compliance (GRC) team handles a wide range of cross-functional activities, from security compliance certifications and audits, to risk management, inbound and outbound due diligence, security awareness, policy and procedures, and more.
Each of these ongoing parallel activities entails interpreting and setting requirements, assessing the effectiveness of security controls, risk-based decision making, cross-functional collaboration and communication, and staying up-to-date on security best practices and how changes in the evolving threat landscape need to inform our strategy.
The Cybersecurity Compliance Lead is a hands-on and high energy program leader who can operate independently in achieving our team objectives.
The team's primary objective is to assist in overseeing the Security Compliance program enterprise wide.
**Responsibilities**
- Assess effectiveness, scalability and reliability of security controls and automate assessments in enterprise or cloud environments
- Monitor and ensure compliance with new regulatory requirements, information system security policy and procedures
- Manage security compliance programs and examinations while working to standardize and optimize controls and procedures across SoFi
- Define and execute existing or new compliance initiatives (SOC1, SOC2, ISO27001, PCI, FedRamp)
- Assess and track compliance with regulatory and legal requirements relevant to the SoFi business such as GLBA, FINRA, State
- Cybersecurity requirements (i.e., NYDFS, Colorado Security Act etc..) and contractual commitments
- Maintain security diligence programs for investors, partners, and prospective partners.
- Lead the escalation and resolution of risk and compliance issues with appropriate leadership cross functionally
- Metrics driven, understands, develops and delivers meaningful risk-based operational metrics, dashboards and reports to a wide audience demonstrating our current program state and adherence to frameworks and standards

**Minimum qualifications**
- BS degree in Computer Information Systems or related field
- 7+ years of experience with security-related regulatory compliance for financial services
- Strong leadership skills
- Experience managing PCI DSS, ISO 27001, SSAE18, or other compliance standards and framework programs
- Strong knowledge of security risk management and running audits/certification programs
- Knowledge of, or experience working with, Cloud technologies/environments, AWS or other related cloud experience
- Self-starter with strong interpersonal and communication skills
- Demonstrate ability to assimilate new knowledge quickly
- Comfortable working in a fast-paced, dynamic environment

**Preferred qualifications**
- Big 4, or management/IT consulting experience
- Relevant certification (e.g., CISA, CISSP) or equivalent expertise
- Have a detailed knowledge of NIST
800-53/800-37
, CNSSI 1253, SOC1, SOC 2, PCI, or ISO 27001 standards and understanding of evaluating the design and effectiveness of IT controls working directly with auditors for these types of assessments
- Ability to review technical reports and provide risk mitigation solutions from activities such as Penetration Testing, Vulnerability
- Understanding of AWS cloud computing services/deployment architecture (IaaS, PaaS, SaaS) through experience in operating them or obtaining certifications
- Location

San José, San Jose
- Department

Recruiting
- Employment Type

Full-Time
- Minimum Experience

Manager/Supervisor
- Compensation

USD $



  • San José, San José, Costa Rica Atomic Hr A tiempo completo

    We connect talented tech professionals in Latin America and Canada with remote career opportunities at innovative startups worldwide.We specialize in finding roles that align with your skills, experience, and career goals.Our personalized approach ensures you're matched with companies that value your contributions and offer opportunities for growth.Whether...


  • San José, San José, Costa Rica Ex2 Outcoding A tiempo completo

    As a Cybersecurity Compliance Lead at Ex2 Outcoding, you'll play a critical role in ensuring the company's security compliance program is effective and up-to-date. This includes monitoring regulatory requirements, assessing security controls, and developing strategies to mitigate risks.ResponsibilitiesMaintain security diligence programs for investors,...


  • San José, San José, Costa Rica Canonical - Jobs A tiempo completo

    Job DescriptionThis CISO role is for a global cybersecurity leader with a passion for Linux and open source to help define the way Canonical secures its corporate infrastructure, designs its products, and assures regulatory compliance.The role will be responsible for end-to-end definition and implementation of the cybersecurity and compliance program. They...


  • San José, San José, Costa Rica Ynv Group A tiempo completo

    Company OverviewYnv Group is a dynamic organization that provides expert guidance and support in cybersecurity architecture and Governance, Risk, and Compliance (GRC) to various clients.We empower organizations with strong cybersecurity capabilities by offering comprehensive advisory, implementation, and managed services tailored to meet their unique needs.


  • San José, San José, Costa Rica Emerson A tiempo completo

    Job Summary:This role involves working with the security team to develop and implement compliance initiatives that enhance the organization's overall security posture. Key responsibilities include operating compliance programs, conducting control gap assessments, and collaborating on awareness activities related to information security frameworks.Main...


  • San José, San José, Costa Rica beBee Careers A tiempo completo

    About the Role:We are seeking a highly skilled Cybersecurity Sustainability Lead to join our team. This individual will be responsible for maintaining the overall security posture and improving security services in our IT and cloud environments.Responsibilities:Lead a team of security engineers who are passionate about enterprise and cloud security,...


  • San José, San José, Costa Rica Equifax A tiempo completo

    At Equifax, we empower you to achieve your true potential by charting new paths, developing new skills, and collaborating with bright minds. As a Security Deviations Analyst Entry, you will be an active member of the Security Governance and Compliance team, supporting security governance and compliance activities globally and ensuring business success...


  • San José, San José, Costa Rica beBee Careers A tiempo completo

    Job Summary">We are seeking a highly skilled Cybersecurity Specialist to join our team. The ideal candidate will have a minimum of 8 years of experience in information security roles, supporting security programs and engineering/architecture in complex enterprise environments.">Key Responsibilities">Our Cybersecurity Specialist will be responsible for the...

  • Cybersecurity Expert

    hace 7 días


    San José, San José, Costa Rica Kimberly-Clark A tiempo completo

    At Kimberly-Clark, we are seeking a talented Cybersecurity Advisor to join our team.Cybersecurity plays a critical role in protecting our organization's digital assets and ensuring the confidentiality, integrity, and availability of sensitive information. This role will provide you with the opportunity to lead key activities that progress your career,...


  • San José, San José, Costa Rica Mondelez International A tiempo completo

    About the Role:As a senior cybersecurity professional, you will play a pivotal role in ensuring the alignment of vendor activities with internal security policies at Mondelez International. This position requires a deep understanding of security frameworks, risk management, and compliance standards, coupled with excellent communication skills to effectively...