Job Closed
This listing is no longer active.
We simplify talent so it can amplify your business.
Chief Information Security Officer
Location
Colombia
Posted
42 days ago
Salary
0
Seniority
Lead
Job Description
Chief Information Security Officer
Marathon Talent
• Posición: Chief Information Security Officer • Enfoque: Gobernanza, Gestión de Riesgos y Continuidad del Negocio. • Buscar un(a) CISO con trayectoria en diseño de arquitecturas resilientes en AWS y marcos de gobernanza (NIST, ISO 27001) para una Fintech que se encuentra en fase de crecimiento. La misión principal será estructurar e implementar el Sistema de Gestión de Seguridad de la Información bajo estándares como ISO 27001, asegurando que la operación nunca se detenga. • Tomar decisiones de alto nivel sobre la Política de Seguridad de la Información y su contenido. • Aprobar el resultado de las revisiones de seguridad relevantes. • Aprobar las solicitudes de excepciones que presenten valor de riesgo medio o bajo relacionadas con el Cuerpo Normativo de Seguridad de la Información. • Coordinar anualmente una valoración de riesgo para identificar nuevas amenazas y vulnerabilidades de los activos además de identificar los controles apropiados para mitigar cualquier nuevo riesgo. • Verificar que la Política de Seguridad de la Información, las Normas, los Procedimientos, Documentos Técnicos y Anexos sean revisados al menos una vez al año y de manera que los cambios en los objetivos del negocio o el entorno de riesgos queden reflejados. • Asegurarse que los terceros con quien se comparte información sean manejados de acuerdo a los estándares definidos por la compañia. • Convocar el Comité de Seguridad de la Información con objeto de informar acerca de los aspectos más relevantes de seguridad a la Dirección Corporativa. • Mantener actualizado y distribuir el Plan de Respuesta ante Incidentes • Confirmar anualmente con las diferentes unidades del negocio que cualquier nuevo canal aceptado para recibir tarjetas de crédito o débito ha sido incluido en el alcance del proceso. Cualquier cambio en el alcance debe ser actualizado en la Política de Seguridad de la Información. • Mantener actualizada la documentación de riesgos y activos de seguridad de la información. • Cuando el objeto está relacionado a Protección de Datos, deberá: o Fijar y aprobar anualmente los objetivos de nivel de riesgo de seguridad aceptable: Los objetivos deben ser vigentes y estar alineados con el propósito y la estrategia de la organización, ser medibles o estimables y coherentes con las presentes directrices. Se deberá verificar de forma anual la evolución de dichos objetivos. o Identificar a los Propietarios de los riesgos: pues son los conocedores de los riesgos inherentes y significativos del área y los activos que es responsable. • Definir y aprobar los niveles de riesgo de la organización: así como los planes de tratamiento de riesgo, asumiendo las funciones de propietario del riesgo. • Aprobar las medidas correctivas resultantes del análisis de riesgos formalizadas en el plan de tratamiento de riesgos. o • Proporcionar los recursos necesarios para asegurar el cumplimiento de los objetivos de seguridad. • Liderar el ciclo de vida de cumplimiento de PCI-DSS, desde el escaneo de vulnerabilidades hasta la auditoría anual de cumplimiento. • Establecer políticas de seguridad alineadas con el cumplimiento regulatorio. • Supervisar la implementación de tecnologías de tokenización, cifrado punto a punto. • Garantizar la seguridad en el ciclo de vida de desarrollo (backend y frontend). • Monitorear patrones de tráfico para detectar intentos de inyección, sniffing o ataques de denegación de servicio dirigidos a la pasarela.
Job Requirements
- Experiencia: ****+5 años en cargos afines.****
- 3 años en sector fintech y/o bancario.
Benefits
- Contrato indefinido + salario en COP + 100% trabajo remoto
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Dive into cybersecurity with hands-on training and real-world projects. • Work with a global team to protect applications, networks, and organizations. • Develop technical and problem-solving skills that set you apart.
Security Engineer III
Fanatics Betting & GamingFanatics is building a leading global digital sports platform. We ignite the passions of global sports fans and maximize the presence and reach for our hundreds of sports partners globally by offering products and services across Fanatics Commerce, Fanatics Collectibles, and Fanatics Betting & Gaming, allowing sports fans to Buy, Collect, and Bet. Fanatics has an established database of over 100 million global sports fans. A global partner network with approximately 900 sports properties, including major national and international professional sports leagues, players associations, teams, colleges, college conferences, and retail partners. 2,500 athletes and celebrities, and 200 exclusive athletes. Over 2,000 retail locations, including its Lids retail stores. More than 22,000 employees committed to enhancing the fan experience and delighting sports fans globally.
About Us Fanatics is building a leading global digital sports platform. We ignite the passions of global sports fans and maximize the presence and reach for our hundreds of sports partners globally by offering products and services across Fanatics Commerce, Fanatics Collectibles, and Fanatics Betting & Gaming, allowing sports fans to Buy, Collect, and Bet. Through the Fanatics platform, sports fans can buy licensed fan gear, jerseys, lifestyle and streetwear products, headwear, and hardgoods; collect physical and digital trading cards, sports memorabilia, and other digital assets; and bet as the company builds its Sportsbook and iGaming platform. Fanatics has an established database of over 100 million global sports fans; a global partner network with approximately 900 sports properties, including major national and international professional sports leagues, players associations, teams, colleges, college conferences and retail partners, 2,500 athletes and celebrities, and 200 exclusive athletes; and over 2,000 retail locations, including its Lids retail stores. Our more than 22,000 employees are committed to relentlessly enhancing the fan experience and delighting sports fans globally. About the Team Launched in 2021, Fanatics Betting and Gaming is the online and retail sports betting subsidiary of Fanatics, a global digital sports platform. The Fanatics Sportsbook is available to 95% of the addressable online sports bettor market in the U.S. Fanatics Casino is currently available online in Michigan, New Jersey, Pennsylvania and West Virginia. Fanatics Betting and Gaming operates twenty-two retail sports betting locations, including the only sportsbook inside an NFL stadium at Northwest Stadium. Fanatics Betting and Gaming is headquartered in New York with offices in Denver, Leeds and Dublin. As a SECURITY ENGINEER III at Fanatics Betting & Gaming (FBG), your knowledge and experience in designing, implementing and maintaining security measures will help the organization stay ahead of security risks and protect company assets. This role sits within the Information Security department and reports to the Manager, Security Engineering. Responsibilities: - Continuous evaluation of several security tools including but not limited to Data Loss Prevention, Vulnerability Management, Identity and Access Management, Web Application Firewall, Email Protection and Endpoint Protection. - Evaluate and implement a Security, Orchestration, Automation and Response software. - Develop and maintain a library of scripts to be leveraged to automate threat hunting, detection, and digital forensics efforts. - Design, implement and refine security detection mechanisms to improve operational efficiency and observability. - Effectively maintain a cloud based SIEM by ensuring relevant logs are ingested and alerts are tuned. - Tasked with leveraging expertise in the area of incident response, this role may also function as the lead incident responder. - Stay up-to-date on the latest threats, vulnerabilities, and security trends to ensure that our organization is prepared to address emerging threats. - Conduct security awareness training by conducting internal phishing campaigns. - Collaborate with internal teams to ensure that secure implementation guidelines are followed. - Participate in an on-call rotation to provide 24/7 support for critical incident escalations. Qualifications: - Minimum of 5 years of experience as a security engineer or in a similar role - Proficient in incident response, threat hunting and cloud security, with a focus on AWS. - Proficient in purple team operations with expertise in offensive and defensive strategy. - Experience with identity management protocols (e.g., OAuth, SAML, OpenID Connect). - Experience automating incident response playbooks leveraging SOAR solutions. - Experience with Cloudflare Datadog, Wiz and Tines is preferred. - Ability to communicate effectively with technical and non-technical stakeholders - Proven experience drafting documentation such as standards, policies and architecture diagrams. - Ability to collaborate and work in a team environment - Demonstrated experience leveraging Infrastructure as code tools such as Terraform or Ansible is a plus. - Foundational knowledge in agile methodologies with ability to successfully collaborate with multiple stakeholders. - Experience with scripting languages such as Python or Bash is required - Relevant certifications such as OSCP, SSCP, or GSEC are a plus Salary Range: $147,250 - $193,750 USD per year The base salary for this role is based on job-related knowledge, skills, and experience and may vary depending on the successful candidate’s geographic location. Depending on the role, your interview and onboarding experience may include in-person components, such as onsite interviews or Launching into Better: LIVE—a multi-day cultural immersion in New York City for full-time, non-seasonal hires. These sessions are designed to build connection and bring our culture to life, though specific travel and participation requirements will be confirmed based on your role and location. Your recruiter will provide clear guidance at each stage of the process. For information about our benefits, please visit https://benefitsatfanatics.com/ Ranges will change based on country and state of residence, which are reflected in Geographical Zones defined by Fanatics Betting and Gaming. The range incorporates all of our Geographical Compensation Zones and is subject to change as the Zone associated with the actual offer is confirmed. In addition to the base and bonus, full-time employment, and more. For information about our benefits, please visit https://benefitsatfanatics.com/ Salary Range $147,250—$193,750 USD
Senior Cloud Security Engineer
WorkstreetBest-in-class trust services for high-growth companies. Vanta’s biggest services partner.
• Engineer Security via IaC: Design and maintain reusable Terraform modules for IAM, networking, and logging. • Build Cloud Architecture: Deploy and manage AWS multi-account structures and Azure Hub-Spoke/Landing Zone architectures. • Own Identity & Access: Implement least-privilege IAM and automate identity lifecycles. • Direct Remediation: Own the remediation of vulnerabilities through engineering changes and patch automation. • Automate Security Ops: Develop automated remediation workflows. • Configure Native Security Stacks: Implement AWS GuardDuty, Azure Sentinel, etc. • Network & Encryption Engineering: Design VPCs, security groups, and implement WAFs. • Technical Compliance Implementation: Hands-on implementation of NIST 800-53 controls.
Senior Corporate Security Engineer
NexthinkUnparalleled Visibility Into Issue Detection, Diagnosis, and Remediation
Company Description Nexthink is the leader in digital employee experience management software. The company provides IT leaders with unprecedented insight allowing them to see, diagnose and fix issues at scale impacting employees anywhere, with any application or network, before employees notice the issue. As the first solution to allow IT to progress from reactive problem solving to proactive optimization, Nexthink enables its more than 1,300 customers to provide better digital experiences to more than 18 million employees. Dual headquartered in Lausanne, Switzerland and Boston, Massachusetts, Nexthink has 9 offices worldwide. #LI-Hybrid Job Description As a Senior Corporate Security Engineer at Nexthink, you will be responsible for the security of our internal environment. You won't just be monitoring logs; you will be architecting the security fabric that enables our rapid growth. Working in close partnership with IT, business teams and, partnering with our Cloud and Application Security teams, you will secure the identity, devices, and applications used by "Nexthinkers" worldwide. You will own the security of a complex SaaS ecosystem, and lead detection and response for the corporate environment. What You Will Do Identity-Centric Security Architecture - Contribute to the design and support the implementation of passwordless authentication and Zero Trust principles. - Manage secure provisioning and lifecycle management, ensuring least-privilege access across all business systems. - Partner with HR and IT to streamline onboarding/offboarding workflows, ensuring timely access revocation and auditability. Endpoint & Infrastructure Security - Define and enforce security baselines for our diverse fleet of endpoints (Windows, macOS) and mobile devices via MDM (Intune/Jamf). - Manage and tune EDR/XDR solutions to ensure high-fidelity detection on workstations and servers (Windows, Linux, macOS). - Secure the corporate Azure footprint, ensuring proper configuration of subscriptions, networking, and resources distinct from our production product environment. - Proactively identify and mitigate security risks in our corporate environment, conducting regular security assessments and vulnerability scans. - Coordinate vulnerability management and patch management - Collaborate with IT to automate endpoint compliance checks and remediation workflows. Security Engineering - Support the development and maintenance of Infrastructure-as-Code. - Ensure hardening and compliance of endpoints and servers. SaaS Security & Integration - Assess and secure third-party SaaS integrations (e.g., Salesforce apps, browser extensions, productivity tools) to prevent data leakage and over-privileged access. - Collaborate with Legal and Compliance to vet new vendors and tools. - Configure and maintain CASB and DLP policies to safeguard sensitive corporate data without hindering productivity. Detection, Response & Automation - Lead incident response activities for corporate security events (phishing, malware, lost devices). - Develop automation scripts (Python/PowerShell) and workflows (SOAR) to automate manual security tasks, evidence collection, and response actions. - Proactively hunt for threats within the corporate network and identity providers. - Develop incident response playbooks including technology specific procedures and forensics collection Audits and Compliance - Design and implement security controls to safeguard corporate resources, including endpoints, data storage, networking, computing and identity and access management. - Support and automate evidence collection for audits. Culture & Collaboration - Act as the primary security liaison to the IT Department and business teams, helping them build security into their operations (DevSecOps for IT). - Design and deliver technical security training and awareness campaigns for engineering and business teams. Qualifications - 5-8 years of hands-on experience in Corporate Security, IT Security Engineering, or a SOC role in a cloud-first environment. - Endpoint Mastery: Experience hardening operating systems (macOS/Windows) and managing security via MDM/UEM tools. - Vulnerability management: Proven experience in helping IT and business teams patching systems and infrastructures. - Coding Skills: Proficiency in Python and Terraform for automating APIs and security workflows. - Security Ops: Proven experience with EDR tools and SIEM log analysis. - Communication: Fluent in English with the ability to explain complex risks to non-technical stakeholders. - Proven ability to influence and drive security best practices across non-security teams. - Experience with security awareness training platforms and phishing simulation tools. Bonus Points - Identity Expertise: Deep technical knowledge of Okta and Microsoft Entra ID (Authentication policy, Conditional Access, SSO, SCIM, OIDC/SAML). - Experience implementing FIDO2/WebAuthn (Passwordless). - Proficient in PowerShell. - Familiarity with compliance standards (ISO 27001/27701, SOC 2, FedRAMP) - Experience securing Cloud Infrastructure (Azure/AWS) specifically for internal/corporate workloads. Why Join Nexthink Security? - Impact: You will report directly into the CISO organization and have a tangible impact on the daily lives of employees and the safety of the company. - Opportunity to work on cutting-edge security projects, with visibility and support from executive leadership. - Technology: We use top-tier security stacks. You won't be fighting with legacy on-premise hardware; we are cloud-native. - Culture: We value "Security as an Enabler," not a blocker. You will work in a supportive, highly technical environment in our Madrid hub Additional Information We are the pioneers and trailblazers of a global IT Market Category (DEX) that is shaping the future of how the world works, giving our customers' IT Teams total digital visibility across their enterprise. Our innovative solutions integrate real-time analytics, automation, and employee feedback across all endpoints. This enables our IT teams to solve complex technical challenges, create ever more productive workplaces, and deliver happy, satisfied employees in the digital workplace. With over 1000 employees across 5 continents, Nexthink operates as One Team, connecting, collaborating and innovating to continuously grow. We call our employees 'Nexthinkers' and our commitment to diversity, inclusion, and equity is second to none. We currently have over 75 nationalities working with us, from all cultures and backgrounds, speaking many different languages. If you are looking for a change and like a nice atmosphere, lots of challenges, and having fun while working, this is a great opportunity for you! Check what we offer: - Permanent Contract and a competitive compensation package. - Office location in 9m ARR, Rue de Caumartin. - Health insurance employee-employer paid options covering medical, dental, and optical treatments, hospitalization, and equipment and 100% employer-paid life insurance. - Hybrid work model balancing office and remote work, with a structured approach for new hires to foster connections and onboarding. - Flexible Hours and unlimited vacation (employees have unlimited paid time off on top of the 25 days of holidays we offer), RTT days, and 3 extra days for volunteering. - Free access to professional training platforms to explore your interests and enhance your skills. - 50% reimbursement on your Pass Navigo, making travel to and from work more affordable and sustainable. - 16 weeks of fully paid leave for primary caregivers, extendable up to 8 additional months unpaid, and 6 weeks of fully paid leave for secondary caregivers. - Reimbursement for fitness, gym memberships, and sports participation up to 25 EUR/month. - Bonuses for referring successful hires after three months of continuous employment. Please note that not all the benefits listed above are available for temporary, contract, and internship roles. To ensure you have the most up-to-date information, we recommend checking with your Recruitment Partner.



