Cybersecurity Compliance Lead
hace 4 días
The Governance, Risk, and Compliance (GRC) team handles a wide range of cross-functional activities, from security compliance certifications and audits, to risk management, inbound and outbound due diligence, security awareness, policy and procedures, and more.
Each of these ongoing parallel activities entails interpreting and setting requirements, assessing the effectiveness of security controls, risk-based decision making, cross-functional collaboration and communication, and staying up-to-date on security best practices and how changes in the evolving threat landscape need to inform our strategy.
The Cybersecurity Compliance Lead is a hands-on and high energy program leader who can operate independently in achieving our team objectives. The team’s primary objective is to assist in overseeing the Security Compliance program enterprise wide.
**Responsibilities**
- Assess effectiveness, scalability and reliability of security controls and automate assessments in enterprise or cloud environments
- Monitor and ensure compliance with new regulatory requirements, information system security policy and procedures
- Manage security compliance programs and examinations while working to standardize and optimize controls and procedures across SoFi
- Define and execute existing or new compliance initiatives (SOC1, SOC2, ISO27001, PCI, FedRamp)
- Assess and track compliance with regulatory and legal requirements relevant to the SoFi business such as GLBA, FINRA, State
- Cybersecurity requirements (i.e., NYDFS, Colorado Security Act etc..) and contractual commitments
- Maintain security diligence programs for investors, partners, and prospective partners.
- Lead the escalation and resolution of risk and compliance issues with appropriate leadership cross functionally
- Metrics driven, understands, develops and delivers meaningful risk-based operational metrics, dashboards and reports to a wide audience demonstrating our current program state and adherence to frameworks and standards
**Minimum qualifications**
- BS degree in Computer Information Systems or related field
- 7+ years of experience with security-related regulatory compliance for financial services
- Strong leadership skills
- Experience managing PCI DSS, ISO 27001, SSAE18, or other compliance standards and framework programs
- Strong knowledge of security risk management and running audits/certification programs
- Knowledge of, or experience working with, Cloud technologies/environments, AWS or other related cloud experience
- Self-starter with strong interpersonal and communication skills
- Demonstrate ability to assimilate new knowledge quickly
- Comfortable working in a fast-paced, dynamic environment
**Preferred qualifications**
- Big 4, or management/IT consulting experience
- Relevant certification (e.g., CISA, CISSP) or equivalent expertise
- Have a detailed knowledge of NIST
800-53/800-37
, CNSSI 1253, SOC1, SOC 2, PCI, or ISO 27001 standards and understanding of evaluating the design and effectiveness of IT controls working directly with auditors for these types of assessments
- Ability to review technical reports and provide risk mitigation solutions from activities such as Penetration Testing, Vulnerability
- Understanding of AWS cloud computing services/deployment architecture (IaaS, PaaS, SaaS) through experience in operating them or obtaining certifications
- Location
San José, San Jose
- Department
Recruiting
- Employment Type
Full-Time
- Minimum Experience
Manager/Supervisor
- Compensation
USD $
-
Cybersecurity Compliance Lead
hace 1 día
San José, San José, Costa Rica Ex2 Outcoding A tiempo completoThe Governance, Risk, and Compliance (GRC) team handles a wide range of cross-functional activities, from security compliance certifications and audits, to risk management, inbound and outbound due diligence, security awareness, policy and procedures, and more.Each of these ongoing parallel activities entails interpreting and setting requirements, assessing...
-
Compliance and Governance Lead
hace 1 día
San José, San José, Costa Rica Ex2 Outcoding A tiempo completoCybersecurity is a top priority at Ex2 Outcoding, and we are seeking an experienced Compliance and Governance Lead to join our Governance, Risk, and Compliance team. As a Cybersecurity Compliance Lead, you will be responsible for overseeing the development and implementation of our security compliance program, ensuring that we meet all relevant regulatory...
-
Cybersecurity Compliance Program Leader
hace 1 día
San José, San José, Costa Rica Ex2 Outcoding A tiempo completoThe Ex2 Outcoding Governance, Risk, and Compliance team plays a critical role in ensuring the security and integrity of our organization. The Cybersecurity Compliance Lead is a key member of this team, responsible for overseeing the development and implementation of our security compliance program.The ideal candidate will have a strong background in...
-
Senior Cybersecurity Professional
hace 5 días
San Francisco, Heredia, Costa Rica Stryker A tiempo completoAbout the Opportunity:Stryker is seeking a seasoned Information Security Management Specialist to lead our cybersecurity assurance efforts. As a Cyber Security Assurance Associate Manager, you will be responsible for leading a team of security analysts in identifying and mitigating risks to our information technology systems.In this role, you will have the...
-
Cybersecurity Expert
hace 3 días
San Francisco, Heredia, Costa Rica Stryker Corporation A tiempo completoCybersecurity Expert WantedWe are seeking a highly skilled Cybersecurity Expert to join our team. As a Cybersecurity Expert, you will be responsible for providing leadership, vision, and a strong understanding of typical infrastructure platforms and general security principles.You will work to ensure the security of the Stryker assets by meeting...
-
Cybersecurity Compliance and Risk Expert
hace 5 días
San José, San José, Costa Rica Experian A tiempo completoJob OverviewWe are seeking an experienced Cybersecurity Compliance and Risk Expert to join our team at Experian. As a key member of our security team, you will be responsible for ensuring the confidentiality, integrity, and availability of our customers' data.About the RoleThis role involves creating, maintaining, and communicating lists of applicable...
-
Cybersecurity Advisor
hace 2 días
San José, Costa Rica Kimberly-Clark A tiempo completoCybersecurity Advisor **Cybersecurity Advisor** **Key Accountabilities**: This role will provide you the opportunity to lead key activities to progress in your career, these responsibilities include some of the following: - Determines security requirements by evaluating business strategies and requirements. - Work closely with IT Business Partners and...
-
Chief Cybersecurity Architect
hace 2 días
San Francisco, Heredia, Costa Rica Auxis A tiempo completoJob SummaryAuxis is seeking a highly skilled and experienced Chief Cybersecurity Architect to lead our team of security professionals in designing and implementing robust cybersecurity solutions. This role will oversee the provisioning, deployment, configuration, and administration of network and security-related hardware and software.Key...
-
Cybersecurity Advisor
hace 4 semanas
San José, San José, Costa Rica Kimberly-Clark A tiempo completoCybersecurity Advisor**Cybersecurity Advisor****Key Accountabilities**:This role will provide you the opportunity to lead key activities to progress in your career, these responsibilities include some of the following:- Determines security requirements by evaluating business strategies and requirements.- Work closely with IT Business Partners and Enterprise...
-
Sr. Cybersecurity Engineer
hace 4 semanas
San Francisco, Heredia, Costa Rica Sysco Costa Rica A tiempo completoAs a cyber engineer, you will be responsible for developing and implementing security measures to safeguard computer systems, networks, and data against cyber threats.You will work closely with other IT professionals to design and deploy secure solutions.**Responsibilities**- **Cybersecurity Strategy**: Develop and implement cybersecurity strategies,...
-
Cybersecurity Engineer I
hace 4 días
San José, Costa Rica Emerson A tiempo completo**Duties and Responsibilities** - Provide technical support for PWCS and Ovation software & hardware products. - Foster a positive environment for work and professional growth. - Work as a team player within the CCE to address basic customer cybersecurity questions and technical issues, and basic Ovation related inquiries. - Maintain or improve customer...
-
Cybersecurity Specialist
hace 4 días
San José, San José, Costa Rica Vs-Staffing A tiempo completoJob DescriptionWe are seeking a highly skilled Cybersecurity Specialist to join our team at Vs-Staffing. As a Site Reliability Engineer, you will be responsible for leading the response to security incidents through identification, containment, analysis, and mitigation strategies to minimize impact.The ideal candidate will have a comprehensive understanding...
-
Cybersecurity Architect and a Grc Manager
hace 2 días
San Pedro, Costa Rica YNV Group A tiempo completoOverview: Tek is seeking a highly skilled and experienced Cybersecurity Architect and GRC Manager with expertise in Governance, Risk, and Compliance (GRC) to join our dynamic team. The role revolves around offering expert guidance and support in cybersecurity architecture and Governance, Risk, and Compliance (GRC) as a service tailored to meet the unique...
-
Cybersecurity Engineer
hace 2 días
San José, Costa Rica Moody's Investors Service A tiempo completoThe Cybersecurity team is globally responsible for helping the organization balance risk by aligning policies and procedures with Moody’s business and regulatory requirements. The team is responsible for the development, enforcement and monitoring of security controls, policies and procedures, disaster recovery programs, GRC (Governance, Risk and...
-
Cybersecurity Engineer
hace 4 semanas
San José, Costa Rica Moody's Investors Service A tiempo completoThe Cybersecurity team is globally responsible for helping the organization balance risk by aligning policies and procedures with Moody’s business and regulatory requirements. The team is responsible for the development, enforcement and monitoring of security controls, policies and procedures, disaster recovery programs, GRC (Governance, Risk and...
-
Chief Information Security Officer
hace 3 semanas
San José, Costa Rica Canonical - Jobs A tiempo completoThis CISO role is for a global cybersecurity leader with a passion for Linux and open source to help define the way Canonical secures its corporate infrastructure, designs its products and assures regulatory compliance. This role will be responsible for the end to end definition and implementation of the cybersecurity and compliance program. They will...
-
Cybersecurity Automation Specialist
hace 5 días
San José, San José, Costa Rica Splunk A tiempo completoJob OverviewWe are seeking an experienced Cybersecurity Automation Specialist to join our Splunk Security Center of Excellence team. The ideal candidate will have a strong background in Cybersecurity technologies and experience in tool integrations and software development.Main ResponsibilitiesKey TasksImprove existing automation and search initiatives to...
-
Cybersecurity Engineer
hace 3 semanas
San José, San José, Costa Rica Moody'S Investors Service A tiempo completoThe Cybersecurity team is globally responsible for helping the organization balance risk by aligning policies and procedures with Moody's business and regulatory requirements.The team is responsible for the development, enforcement and monitoring of security controls, policies and procedures, disaster recovery programs, GRC (Governance, Risk and Compliance)...
-
Cybersecurity Engineer
hace 2 días
San José, Costa Rica ZM Financial Systems A tiempo completoImagine what we can DEVELOP with you True leaders are always learning. Moody’s is home to information architects, thinkers, builders, and passionate problem solvers, a collection of diverse viewpoints working together to bring out our best. Join us. Forward Together.- - Moody’s Shared Services are the front line professionals including Finance,...
-
Cybersecurity Engineer
hace 13 horas
San José, Costa Rica Moody's Corporation A tiempo completo**What Moody's Corporation Has to Offer**: Moody's is an essential component of the global capital markets, providing credit ratings, research, tools and analysis that contribute to transparent and integrated financial markets. Moody's supports independent thought and promotes a work environment that values and maximizes the contributions of all employees....