Cybersecurity and Information Leader - Medellín
Must-have:CloudE-CommerceSecuritySeniorPrincipal
Machine translation — original language: Spanish.Show original
Cybersecurity and Information Leader
Keywords: Cybersecurity and Information Leader
- Cybersecurity
- Information Security
- Information Security
- Cloud Security
- DevSecOps
- PCI DSS
- ISO 27001
- NIST
- Data Protection
- High Transactionality
- Colombia
A Cybersecurity and Information Leader with senior experience in the design and execution of information security strategies, protection of sensitive data, and risk governance in high transactionality environments is required. The main mission of this role is to design, govern, and execute the corporate information security and cybersecurity strategy, aligned with business and technology objectives, guaranteeing the confidentiality, integrity, availability, and resilience of the technological platform and corporate information.
Responsibilities:
- Design, govern, and execute the corporate information security and cybersecurity strategy.
- Ensure the confidentiality, integrity, availability, and resilience of the technological platform and corporate information.
- Lead the protection of sensitive customer data, transactions, loyalty programs, and critical services.
- Guarantee compliance with international regulations and standards such as PCI DSS, ISO 27001, NIST, and GDPR/LPDP.
- Manage advanced projects in cloud security, DevSecOps, and generative AI applied to security.
- Actively participate in audits and certification processes.
- Design and implement Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP).
- Build and foster a cybersecurity culture through campaigns, drills, and training.
- Supervise cyber defense and security operations, including vulnerability management and incident response.
- Implement security practices in the software development life cycle (Security in SDLC).
- Ensure the security of payment gateways and supervise anti-fraud monitoring.
Requirements:
- University professional in Systems Engineering, Information Security, Information Security, Cybersecurity, Telecommunications, Technological Risks, or related fields.
- Proven experience in leading cybersecurity and information security teams.
- Expert knowledge in cloud security (cloud native), DevSecOps, IAM, PCI DSS, ISO 27001, NIST, GDPR / LPDP, Data protection, BCP / DRP, Cyber defense, and security operations.
- Experience in vulnerability management, ethical hacking / pentesting, security in SDLC, payment gateway security, and anti-fraud monitoring.
- Knowledge of generative AI applied to security.
- Advanced level of English proficiency.
- Experience in high transactionality environments.
- Experience in the technology and financial and transactional services sector.
- Knowledge of retail and loyalty programs as well as digital services.
- Availability to work in-person in Colombia.
Technical skills:
- Cloud security
- DevSecOps
- IAM
- PCI DSS
- ISO 27001
- NIST
- GDPR / LPDP
- Data protection
- BCP / DRP
- Cyber defense
- Vulnerability management
- Ethical hacking
- Pentesting
- Security in SDLC
- Payment gateway security
- Anti-fraud monitoring
- Generative AI security
- English
Interpersonal skills:
- Leadership
- Communication
- Strategic thinking
- Problem solving
- Risk management