Cybersecurity Executive - Security and Exposure
What will you do?
You will be responsible for providing continuous and reliable visibility into the cloud security posture and the external exposure surface (EASM/CTEM) of Coca-Cola FEMSA in multicloud environments, translating technical findings into prioritized remediation plans, with owners, deadlines, and evidence, to reduce risk and improve compliance in a sustained manner.
Your day-to-day combines operation and analysis: you will keep the CNAPP/CSPM capability running, execute continuous discovery of exposed assets, and translate each finding into a concrete action with an owner and a date. This is not a reactive role; you build the source of truth for 'what is exposed, where, and who is responsible' for the entire Coca-Cola FEMSA operation.
Specifically:
- Operate and maintain the CNAPP/CSPM capability: detection of misconfigurations, risk scoring, recommendations, and compliance reporting
- Maintain multicloud policies and guardrails (Azure policies or equivalents), managing approved exceptions with traceability and expiration
- Execute continuous EASM/CTEM discovery (domains, DNS, certificates, public IPs) to identify exposure and shadow IT, validating each finding with owner enrichment and criticality
- Build and follow up on the remediation backlog with owners, deadlines, and evidence of closure (before/after, applied configuration, change ticket), escalating critical risks
- Produce reporting on exposure patterns and posture aligned with reference frameworks (MITRE approach) for operational and executive audiences
What we are looking for
Indispensable:
- Technical experience in cloud architectures: Azure, Kubernetes, DevSecOps
- Knowledge of SIEM tools (Sentinel, Splunk)
- Experience in process automation and Infrastructure as Code (IaC) best practices
- Knowledge of identity and access management (IAM), network security, and encryption
- 2 years of experience in similar roles
- University degree optional (Systems Engineering, Informatics, Telecommunications, or related)
Bonus points if you have:
- Technical certifications such as Azure Security, OWASP Top 10, or others related
- Previous experience operating CNAPP/CSPM platforms or EASM/CTEM tools
- Ability to document processes and collaborate with multidisciplinary teams (IT, Architecture, Security, Cells)
Why this position?
- Global impact: you provide visibility of the cloud security and exposure posture for the entire Coca-Cola FEMSA operation
- Technical autonomy: you identify, analyze, and prioritize risk findings, presenting your remediation proposals directly to the domain manager
- Cutting-edge technology: you work day-to-day with CNAPP/CSPM, EASM/CTEM, and modern cloud architectures (Azure, Kubernetes, DevSecOps)
Competencies we value
- Systemic thinking
- Organization and execution
- Transformation
- Customer orientation
- Effective relationships
- Decision making
- Strategic vision
At Coca-Cola FEMSA, diversity, equity, and inclusion are the foundation of innovation, business transversality, and sustainable growth; we strive to reflect and respect the richness of unique identities, perspectives, and talents that exist in every place. Our commitment is to offer equal opportunities to all people who wish to be part of our team, regardless of their age, ethnic or national origin, political affiliation, religion, sex, sexual orientation, gender identity or expression, or others, marital status, physical or health condition, social, migratory, or any other status that undermines human dignity. We want your experience with us to be extraordinary. If you need any type of accessibility support, please share it with the Talent Attraction team.
-Requirements-
- Minimum education: Higher education - Bachelor's degree
- 2 years of experience
- Languages: English
- Age: between 18 and 50 years
- Knowledge: Cloud
- Keywords: directivo, mando, gobierno, regencia, executive, managing, ejecutivo, escolta, guardia, vigilante, guarda, guard, vigilancia