Technological Risk Manager

Posted:
10/18/2024, 11:01:10 AM

Location(s):
Mexico City, Mexico

Experience Level(s):
Mid Level ⋅ Senior

Field(s):
IT & Security

Orion Innovation is a premier, award-winning, global business and technology services firm.  Orion delivers game-changing business transformation and product development rooted in digital strategy, experience design, and engineering, with a unique combination of agility, scale, and maturity.  We work with a wide range of clients across many industries including financial services, professional services, telecommunications and media, consumer products, automotive, industrial automation, professional sports and entertainment, life sciences, ecommerce, and education.

Título de la vacante: Technological Risk Manager

Requisitos:

  • Escolaridad: Licencatura en Informatica, Admin. Empresas, Finanzas, Actuaria o Afin
  • Experiencia y/o conocimientos necesarios: Administración de Riesgos Tecnologicos
  • Años de experiencia mínimo requerida: + 5 años
  • Nivel de inglés: Avanzado

 

Competencias requeridas:

  • 5+ years of experience in a combination of risk management, compliance, or information security roles in the Technology domain in the financial, consultancy or pharmaceutical industry successfully managing internal control, audit risk or operational risk programs
  • Broad experience in large and complex business environments with a successful track record working directly with senior level management with at least 3 years of experience in one or more of the following domains: access control, telecom and network security, risk management, software development security, cryptography, security architecture and design, banking regulations, technology or security audit, technology, or security compliance
  • Demonstrated ability to apply Technology related knowledge and experience in solving compliance issues. Familiar with a broad range of technical concepts such as logical access control, agile development process, secure coding principles, security architecture, information security, network security, and data privacy
  • Experience performing information security audits or risk assessments
  • Clear understanding of risk management practices in general and security risk management best practices and methodologies specifically
  • Ability to communicate in a clear and concise manner with all levels of an organization and convey complicated technology and security concepts to technical and non-technical stakeholders.
  • Has the ability to operate with a limited level of direct supervision. Can exercise independence of judgement and autonomy
  • Excellent project management and organizational skills with the ability to meet deadlines and quickly establish clear priorities. Excellent interpersonal, communication, and presentation skills, including formal report writing experience
  • Fluent in Spanish and English

 

Highly Desirable

  • Experience in the financial industry is preferred, particularly in payments systems such as SPEI, SPID, TEF, SWIFT, and products such as Direct Debit and Checks. Knowledge of SPEI, SPID and Indeval operational risk and information security requirements, and cash equities best execution algorithm
  • Knowledge of article 86 of the General Dispositions applicable to Credit Institutions, and article 142 of the General Dispositions applicable to Brokerage Houses
  • Knowledge of information security risk management frameworks and compliance practices, including ISO 31000, ISO 2700x, NIST 800 series, SOC, and OWASP
  • Well-versed in risk analysis methodologies such as NIST, OCTAVE, and FAIR
  • Relevant risk, control, or information security certifications

o             ISACA - Certification in Risk and Information Systems Control (CRISC)

o             COSO – Enterprise Risk Management Certificate

o             IIA - Certification in Risk Management Assurance (CRMA)

o             COSO – Internal Control Certificate

o             ISACA - Certified Information Systems Auditor (CISA)

o             (ISC)2 - Certified Information Systems Security Professional - Architecture (CISSP)

o             (ISC)2 - Certified Information Systems Security Professional (CISSP)

o             (ISC)2 - Information Systems Security Management Professional (ISSMP)

o             EC-Council - Security 5 Certification

o             ISACA - Certified Information Security Manager (CISM)

o             IIA - Certified Internal Auditor (CIA)

  • Expertise in financial policies and procedures, U.S. GAAP/IFRS and SOX requirements
  • Significant external/internal audit experience in a big four accounting firm and/or in a large global corporation

 

 

Funciones general: Administrar Riesgos Tecnologicos

Ubicación de la vacante: Hibrido (asistir 3 veces por semana a sitio en Miguel Hidalgo, CDMX)

Horario de la vacante: lunes a viernes de 8:30 a 18hrs

 

Ofrecemos:

  • Sueldo Competitivo de Acuerdo a Experiencia.
  • Prestaciones de ley y superiores
  • Seguro de Gastos Médicos Mayores
  • Seguro de vida

 

Si cumples con el perfil, postúlate por este medio, envíanos tu CV  y nos pondremos en contacto contigo.

 

¡Gracias por tu interés en unirte a nuestro equipo!

 

"En Gonet México, queda estrictamente prohibido solicitar certificados médicos de no embarazo y Virus de Inmunodeficiencia Humana (VIH) como requisitos para el ingreso, permanencia o ascenso en el empleo. Tampoco se discriminará a ninguna persona por motivos de raza, religión, orientación sexual, condición física o socioeconómica, ni por ningún otro motivo”

Orion is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, gender identity or expression, pregnancy, age, national origin, citizenship status, disability status, genetic information, protected veteran status, or any other characteristic protected by law.

Candidate Privacy Policy

Orion Systems Integrators, LLC and its subsidiaries and its affiliates (collectively, “Orion,” “we” or “us”) are committed to protecting your privacy. This Candidate Privacy Policy (orioninc.com) (“Notice”) explains:

  • What information we collect during our application and recruitment process and why we collect it;
  • How we handle that information; and
  • How to access and update that information.

Your use of Orion services is governed by any applicable terms in this notice and our general Privacy Policy.