Platacard·15 hours ago
15 hours agoBe an early applicant
Head of Information Security
Sign up free to see how well your resume matches this role.
What you'll do
- Monitor Mexican Information Security, cybersecurity, technology risk, business continuity, and related regulatory requirements applicable to The Company.
- Maintain a complete register of regulatory obligations, reporting deadlines, responsible owners, required evidence, dependencies, and current status.
- Interpret regulatory requirements and translate them into clear, actionable tasks for Information Security, Technology, Internal IT, Operations, Fraud Prevention, Business Continuity, and other responsible teams.
- Assess the impact of regulatory changes and coordinate required updates to controls, processes, policies, procedures, and reporting.
- Escalate regulatory risks, missing evidence, and potential delays before obligations become overdue.
- Own the preparation and coordination of Information Security reports, formal responses, indicators, evidence packages, and information requests submitted to Mexican regulators.
- Coordinate reporting related to CNBV, Banco de México, SPEI, and other applicable local supervisory activities within the scope of Information Security.
- Verify all submitted information against source systems and supporting evidence.
- Ensure that reports accurately identify the work performed, responsible owners, control status, findings, incidents, and remediation progress.
- Maintain a clear audit trail of data sources, reviews, approvals, submissions, and regulator correspondence.
- Prevent incomplete, unsupported, inconsistent, or misleading information from being submitted to management, auditors, or regulators.
- Act as the primary Information Security contact in Mexico for regulatory examinations, formal information requests, interviews, and follow-up activities.
What they're looking for
- At least 5 years of experience in Information Security, cybersecurity governance, technology risk, regulatory compliance, or IT audit.
- At least 3 years of experience within a regulated financial institution in Mexico.
- Direct experience working with CNBV requirements and regulatory examinations.
- Practical experience with Banco de México and SPEI-related security, audit, reporting, or compliance activities.
- Proven ownership of regulatory submissions, formal responses, evidence collection, and remediation tracking.
- Experience translating regulatory requirements into operational and technical controls.
- Experience coordinating senior stakeholders across Information Security, Technology, Legal, Compliance, Risk, Internal Audit, and Operations.
- Experience managing employees or specialist regulatory and security teams.
- Strong understanding of Information Security governance, risk management, incident response, access management, business continuity, third-party risk, logging, vulnerability management, and data protection.
- Fluent Spanish and professional working proficiency in English.
- Excellent written communication skills in both languages.
Nice to have
- Experience with PCI DSS, ISO 27001, regulatory incident reporting, business continuity, and disaster recovery.
- Professional certifications such as CISSP, CISM, CRISC, CISA, or ISO 27001 Lead Auditor.
Summarised by NextRaise from the employer’s description, which follows in full below.
Full description from employer
The primary responsibility is to ensure that the company understands its obligations, submits accurate information on time, and remains continuously prepared for regulatory reviews.
This is not primarily a security engineering role. Global Information Security and Technology teams implement technical controls. The Head of Information Security must translate Mexican regulatory requirements into clear actions, coordinate delivery across those teams, validate evidence, and remain accountable for the final regulatory outcome.
The successful candidate must combine senior regulatory judgment with disciplined execution. The role requires someone who personally verifies facts, follows issues through to completion, and does not rely on last-minute intervention from other functions.
This is not primarily a security engineering role. Global Information Security and Technology teams implement technical controls. The Head of Information Security must translate Mexican regulatory requirements into clear actions, coordinate delivery across those teams, validate evidence, and remain accountable for the final regulatory outcome.
The successful candidate must combine senior regulatory judgment with disciplined execution. The role requires someone who personally verifies facts, follows issues through to completion, and does not rely on last-minute intervention from other functions.
Challenges that await you:
- Monitor Mexican Information Security, cybersecurity, technology risk, business continuity, and related regulatory requirements applicable to The Company.
- Maintain a complete register of regulatory obligations, reporting deadlines, responsible owners, required evidence, dependencies, and current status.
- Interpret regulatory requirements and translate them into clear, actionable tasks for Information Security, Technology, Internal IT, Operations, Fraud Prevention, Business Continuity, and other responsible teams.
- Assess the impact of regulatory changes and coordinate required updates to controls, processes, policies, procedures, and reporting.
- Escalate regulatory risks, missing evidence, and potential delays before obligations become overdue.
Regulatory Reporting
- Own the preparation and coordination of Information Security reports, formal responses, indicators, evidence packages, and information requests submitted to Mexican regulators.
- Coordinate reporting related to CNBV, Banco de México, SPEI, and other applicable local supervisory activities within the scope of Information Security.
- Verify all submitted information against source systems and supporting evidence.
- Ensure that reports accurately identify the work performed, responsible owners, control status, findings, incidents, and remediation progress.
- Maintain a clear audit trail of data sources, reviews, approvals, submissions, and regulator correspondence.
- Prevent incomplete, unsupported, inconsistent, or misleading information from being submitted to management, auditors, or regulators.
Regulatory Engagement and Examinations
- Act as the primary Information Security contact in Mexico for regulatory examinations, formal information requests, interviews, and follow-up activities.
- Coordinate responses with the Global CISO, Legal, Compliance, Risk, Internal Audit, Technology, and other relevant stakeholders.
- Prepare Company representatives for regulatory meetings and ensure that answers are consistent, accurate, and supported by evidence.
- Track all commitments made to regulators until formally completed.
- Maintain readiness throughout the year rather than preparing only after an examination or request begins.
Audit and Assurance
- Lead Information Security preparation for internal audits, regulatory reviews, SPEI assessments, PCI DSS activities, and other assurance exercises applicable to Mexico.
- Maintain an evidence repository that is complete, current, and easy to validate.
- Review evidence before submission and challenge unsupported statements or incomplete control descriptions.
- Convert findings into remediation plans with clear owners, actions, deadlines, dependencies, and acceptance criteria.
- Monitor remediation and escalate overdue or blocked actions.
- Ensure that Information Security audit and regulatory activities remain owned by the Local CISO and do not require another function to take over coordination.
Information Security Governance
- Represent Information Security before local management and control functions.
- Provide clear reporting on regulatory exposure, control gaps, audit findings, incidents, remediation, and material risks.
- Coordinate local implementation of the global Information Security Program.
- Ensure that local regulatory requirements are reflected in The Company’s Information Security documentation.
- Review local-language policies, procedures, standards, and regulatory responses to ensure that they preserve the original requirements and control meaning.
- Support regulatory aspects of information security incidents, including assessment of reporting obligations, evidence collection, and coordination of formal notifications.
Team and Stakeholder Management
- Manage the local Information Security regulatory function with clear responsibilities, measurable objectives, and regular performance reviews.
- Build effective working relationships with Compliance, Legal, Internal Audit, Risk, Technology, Operations, Fraud Prevention, Business Continuity, and global Information Security teams.
- Assign work based on actual responsibilities and demonstrated workload.
- Address underperformance promptly and document management actions.
- Request additional resources only when supported by a clear scope, workload, capability gap, and expected outcome.
How Success Will Be Measured
- Regulatory reports are complete, accurate, approved, and supported by source-system evidence.
- All regulatory obligations and findings have documented owners, actions, deadlines, status, and evidence.
- Risks and blockers are escalated before they affect delivery.
- The Company remains ready for regulatory and audit reviews without emergency preparation.
- Engineering and operational teams receive clear, actionable requirements rather than copied regulatory text.
- Remediation activities progress without repeated intervention from the Global CISO.
- Local Information Security responsibilities are managed independently and transparently.
What makes you a great fit:
- At least 5 years of experience in Information Security, cybersecurity governance, technology risk, regulatory compliance, or IT audit.
- At least 3 years of experience within a regulated financial institution in Mexico.
- Direct experience working with CNBV requirements and regulatory examinations.
- Practical experience with Banco de México and SPEI-related security, audit, reporting, or compliance activities.
- Proven ownership of regulatory submissions, formal responses, evidence collection, and remediation tracking.
- Experience translating regulatory requirements into operational and technical controls.
- Experience coordinating senior stakeholders across Information Security, Technology, Legal, Compliance, Risk, Internal Audit, and Operations.
- Experience managing employees or specialist regulatory and security teams.
- Strong understanding of Information Security governance, risk management, incident response, access management, business continuity, third-party risk, logging, vulnerability management, and data protection.
- Fluent Spanish and professional working proficiency in English.
- Excellent written communication skills in both languages.
Preferred Qualifications
- Experience with PCI DSS, ISO 27001, regulatory incident reporting, business continuity, and disaster recovery.
- Professional certifications such as CISSP, CISM, CRISC, CISA, or ISO 27001 Lead Auditor.
Company
Platacard
Mexico
Company facts come from this company's own listings. We only show what the postings themselves carry.