Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security GRC Specialist

Bitso

Information Security GRC Specialist

México

Working At Bitso

We are a diverse team that takes pride in understanding the perspectives of others. We fully embrace working remotely and we are eager to act, improve and accelerate progress inside and outside of our organization.

To drive revolutionary changes in society and make crypto useful, we delight our customers with world-class products, deep care, and intentional empathy.

Your Purpose

As our Information Security GRC Specialist, you will be an integral part of the Information Security Governance, Risk, and Compliance team. Your role is essential to ensure that company security policies, technical standards, and procedures are implemented, maintained, and continuously improved, while overseeing security risk management and compliance with applicable security standards and regulations. Additionally, you will be responsible for coordinating and supporting external/internal security assessments.

As part of the information security governance, risk, and compliance team, you will:

  • Use holistic approaches interconnecting governance, risk, and compliance through project management and the application of industry best practices, standards, and regulations.
  • Connect information security with other involved teams.
  • Drive alignment of all lines of business with the defined information security culture and governance model.
  • Use Agile approaches in your projects.
  • Focus on proactivity, quality, and excellence in your results.
  • Explore strategies and solutions for effective Governance, Risk, and Compliance (GRC) engineering in the organization.

Beyond our team, you will collaborate closely with:

  • Organizational risk, compliance, and regulatory internal and external teams to ensure proper adherence to information security compliance processes.
  • Technical groups to assist in implementing technical standards, controls, and configurations aligned with security policies, legal requirements, and audit standards.

Reports To Information Security Program Manager

Who You Are

  • Proven English proficiency. You are comfortable presenting to English-speaking audiences and creating deliverables in that language. You are able to maintain a fluid conversation in English.
  • Minimum of 5 years of experience in Information Security GRC roles.
  • At least 3 years of experience leading or coordinating internal compliance assessments, internal audits, or acting as a strategic consultant with a focus on maturity assessments.
  • At least 3 years of experience working with Mexican regulatory, cybersecurity, and information security requirements applicable to fintech or regulated financial entities.
  • You have expert knowledge of information security frameworks and best practices (e.g., ISO/IEC 27000 series, COBIT, NIST SP 800-xx, NIST CSF, and CIS).
  • You have working knowledge in scripting to read and modify simple scripts, understand JSON and YAML configuration files, use command-line tools and write basic automation tools.
  • You have working knowledge of data analysis to extract relevant information from logs and identify trends and patterns, to turn technical data into business insights.
  • You have proficiency in IT audit, compliance, and maturity assessments.
  • You hold a Certified Information Systems Auditor (CISA) certification or equivalent credentials with a strong focus on IT audit, assurance, or information security governance.
  • You hold a AWS Certified Cloud Practitioner or working knowledge with AWS Cloud Infrastructure.
  • You possess a competent understanding of the risk management process, with emphasis on risk treatment, monitoring, and control assessment phases.
  • You possess strong communication skills. These are crucial as the role involves coordinating with internal teams, external auditors, and various technical and non-technical groups. Being able to effectively communicate findings, recommendations, and remediation strategies to different levels of stakeholders is key.
  • You are detail-oriented. Given the role's responsibilities in monitoring compliance, identifying gaps, and managing security controls, attention to detail is vital. You should be meticulous in your work to ensure that effective compliance and security measures are in place.
  • You are an agile and avid learner. Information security is a rapidly evolving field, so you have a willingness to continuously learn and stay updated on the latest trends, threats, and best practices in the industry. Keeping up-to-date will help in effectively implementing security measures.
  • You are passionate about information security, and you can see beyond the technology and controls. You find confluence points and create synergies. You believe in teamwork, and you believe that by empowering an organization to protect itself, you are on the side of a noble and much-needed cause.

Nice-to-have:

  • Minimum 2 years of strategic consulting experience, particularly within financial institutions.
  • Additional certifications such as Certified ISO 27k Lead Auditor, CISSP, or PMP.
  • Working knowledge with maturity models and frameworks (e.g., CMMI), cloud security best practices, project management (PMI), and Agile methodologies (e.g., Kanban).
  • Familiarity with international regulations such as GDPR.

What You Will Do

  • Maintain and continuously improve the Information Security GRC Program.
  • Act as a key liaison with regulatory authorities on information security–related topics.
  • Support the adoption and consistent implementation of security policies, standards, and procedures across all lines of business.
  • Assess and validate compliance with applicable regulatory, contractual, and information security requirements.
  • Conduct regular information security and maturity assessments of Bitso's information security controls, and follow up on treatment plans across the organization.
  • Continually validate the organization against the internal information security governance framework to ensure compliance, monitor for non-conformities, and prepare reports and metrics with recommended remediation strategies.
  • Collaborate with internal and external security audits, proactive technical assessments, and tracking findings and recommendations for appropriate action will be crucial aspects of your responsibilities.
  • Guide and support non–security engineering teams, liaise with cross-functional stakeholders as needed, and ensure the quality, consistency, and effectiveness of information security programs and projects.
  • Shift from manual compliance assessments to an automated, continuous, and integrated practice, embedding compliance directly into the technical stack.

Research in Diversity, Equity, and Inclusion suggests that individuals may hesitate to apply for jobs if they do not meet all the listed criteria. At Bitso, we value diversity and your unique strengths could be just what we're looking for. If this role excites you but you don't match every point in the description, we still want to hear from you.

#LI-Remote

Who We Are

With over 9 million users, Bitso is the leading cryptocurrency platform in Latin America. We are developing the cryptocurrency ecosystem in the region and enabling financial inclusion. We believe crypto is the future of finance, and we're committed to making it useful by providing equal access to safe and intuitive financial products.

When we hire people for our team, we specifically test for the following traits in addition to our cultural values:

  • Mission-Driven: We seek individuals who are passionate about crypto and Bitso's mission and resilient in facing industry challenges
  • High Sense of Urgency: We prioritize candidates who demonstrate a high sense of urgency and responsibility.
  • Exceptional Hard Skills: We seek individuals who possess exceptional skills in their respective fields, with no room for mediocrity.
  • Self-Management: We look for individuals who can independently manage their work, career, and professional development.
Compensation & Benefits

At Bitso, you are taking the front seat on the edge of crypto innovation, creating the next generation of crypto-powered products.

So for those willing to commit, adapt and pioneer the most important change of the century we offer:

  • Me Time program, including unlimited paid time off.
  • Remote-first work environment.
  • Employee Stock Option program.
  • Zero trading fees through our Bitso Alpha app.
  • Extended Family Leave Policy: all birthing parents, non-birthing parents and adopting parents are eligible for a 4-months leave.
  • Premium health, dental and life insurances in Mexico, Gibraltar, Colombia, USA, Brazil and Argentina.

Want to leave an undoubtedly legacy with us? Fasten your seatbelt and join this spaceship, where you will find exponential growth and the opportunity to thrive!

Vacancy posted 8 hours ago
Similar jobs that could be interesting for youBased on the Information Security GRC Specialist in United States vacancy
  • $11 - $14 per hour

     ...and access governance controls Perform security testing, access audits, and remediation...  ...collect, keep, and process your private information, please review Insight Global's...  ...authorization concepts • Knowledge of GRC Access Control modules including Access... 
    Suggested

    Insight Global

    Atlanta, GA
    3 days ago
  •  ...Senior Level Information Security Analyst Role Summary: Senior level information security analyst performing steady state governance work supporting...  ...without formal authority Governance, Risk, and Controls (GRC), cybersecurity, information security, or IT risk management... 
    Suggested

    Mindlance

    Charlotte, NC
    4 days ago
  • $138.4k - $235.6k

     ...Overview This role reports to VP, Technology GRC and Deputy CISO and has accountability for maturing SOX ITGC oversight,...  ...Advisory Services ~ Serve as a trusted advisor to IT, Information Security and Engineering on technology risk, control design, and regulatory... 
    Suggested
    Remote work

    RealPage

    United States
    20 hours ago
  •  ...Manager, Governance, Risk & Compliance (GRC) - Cybersecurity do at Swire Coca-Cola?...  ...Coca-Cola is seeking a Sr. Manager, IT Security - GRC to lead and mature our cybersecurity...  ...Requirements ~ Bachelor's Degree in Information Security, Information Technology, Risk... 
    Suggested
    Visa sponsorship
    Work visa

    Swire Coca Cola USA

    Draper, UT
    9 hours ago
  • $102.5k - $187.9k

     ...growth across SAP and Governance, Risk, and Compliance (GRC), EY is seeking SAP Security and GRC professionals who understand risk management challenges...  ...~ A bachelor’s degree in computer science, information systems, information security, or a related field (preferred... 
    Suggested
    Summer holiday
    Flexible hours
    Shift work

    EY

    Chicago, IL
    2 days ago
  • $400 per month

     ...seeking a detail-oriented and proactive Sr. Security GRC Manager to join our team. This role is...  ...identifying, assessing, and mitigating information technology and information security...  ...effectively managing IT/IS risks, the specialist will help maintain our company's reputation... 
    Contract work
    Remote work
    Work from home
    Flexible hours

    PayNearMe

    Santa Clara, CA
    4 days ago
  •  ...Job: SAP GRC Security Consultant Location: Atlanta GA Duration: 12 months Rate: $80 on C2C Only USC...  ...systems/devices used to safeguard the organization's information assets. Also responsible for analyzing the information security... 
    Contract work

    Concord IT Systems

    Atlanta, GA
    4 days ago
  • $65 - $80 per hour

     ...Irvine TechNology Corporation is hiring a TPRM Security Analyst to join their Information Security GRC team in a remote capacity. This contract role plays a critical part in assessing vendor cybersecurity posture and managing compliance with regulatory frameworks. The... 
    Hourly pay
    Contract work
    Remote work

    Irvine Technology

    Long Beach, CA
    4 days ago
  •  ...Senior Information Security Specialist Rush Street Interactive (NYSE: RSI) is a market leader in online casino and sports betting, currently operating...  ...incidents, breaches, and investigations Partner with GRC and Legal teams as a technical expert to ensure compliance... 
    Remote work

    Rush Street Gaming

    United States
    8 hours ago
  •  ...Information Security Specialist Remote (CET ±2h) | Fluent German (C1/C2) & English required Note: While we prefer a full-time commitment, we also...  ...this role ~3+ years of hands-on information security and GRC experience, ideally with Big 4 consulting or in-house... 
    Full time
    For contractors
    Work at office
    Local area
    Remote work
    Home office

    Secfix

    United States
    21 hours ago
  •  ...our top financial customers is seeking a Senior Information Security Analyst with expertise in ServiceNow GRC. As a Senior Information Security Analyst you will...  ...Certifications: ~ ServiceNow Certified Implementation Specialist, - GRC (preferred) ~ Certified Information... 

    Insight Global

    Minneapolis, MN
    6 days ago
  •  ...Senior Security Analyst – GRC The Senior Security Analyst – GRC (Governance, Risk and Compliance) is a member of the IT Security team and...  ...and automation of core functions supporting the Information Security program. This person will work to support the continued... 

    1872 Consulting

    Chicago, IL
    1 day ago
  •  ...To support the organization's security initiatives, the remote Senior Security GRC Analyst will manage the Information Security Program, conduct compliance audits, and collaborate with various stakeholders to enhance security practices and policies. Key responsibilities... 
    Remote work

    Virtual Vocations Inc

    United States
    4 days ago
  •  ...Role : Data Governance & Security Specialist They are open to candidates being local to any of...  ...hands-on technical leadership, ensuring information assets are well-protected, properly...  ...General Counsel, Security Architecture, and GRC teams to ensure governance strategies... 
    Full time
    Work at office
    Local area
    Remote work
    Relocation package

    AceStack LLC

    United States
    7 hours ago
  •  ...Information Security Specialist Lead Experian is a global data and technology company, powering opportunities for people and businesses around the...  ...risks (risk types and risk register entries) in Archer GRC platform. Monitor and stay informed about internal and... 
    Local area
    Remote work
    Work from home
    Flexible hours

    Experian

    United States
    8 hours ago
  • $115k - $125k

     ...Overview: Sr. Information Security GRC Analyst Location: Tire Rack South Bend, IN (On-Site) Department: Information Security Employment Type: Full-Time Salary Range: $115,000-$125,000 annually About the Role Tire Rack is seeking a Senior Information... 
    Full time
    Monday to Friday

    Discount Tire

    Edwardsburg, MI
    3 days ago
  •  ...every day. This role sits within theInformation Security Governance, Risk and Compliance (GRC) team, which reports directly into the CISO organization...  ...policy and control framework that governs information security across Chatham. This team works cross-functionally... 
    Contract work
    Immediate start

    Chatham Financial

    Kennett Square, PA
    1 day ago
  •  ...Title: Information Security GRC Analyst Location: Remote, EST Time Duration: 7+ Months JOB DESCRIPTION Responsibilities: Support the development and implementation of an enterprise-wide business continuity program. Execute tasks associated... 
    Remote work

    Trilyon, Inc.

    United States
    4 days ago
  • $155k - $165k

     ...Senior Information Security GRC Analyst Remote, US Branch is on a mission to empower workers with financial freedom. We do this by helping companies accelerate payments and providing working Americans with accessible, free financial services. We're committed to... 
    Daily paid
    Remote work
    Home office
    Flexible hours

    Branch

    United States
    3 days ago
  • $99k - $136.5k

     ...business objectives. Transforms complex information and documentation into simple concepts...  ...risks and enhance loanDepot's overall security posture. Stays informed about the latest...  ...' experience working in Cybersecurity GRC, policy development, risk management, or... 
    Local area

    loanDepot

    Plano, TX
    4 days ago
  • $94.1k - $164.8k

     ...Job Summary: The Information Security GRC Analyst III managed day to day, short and long term information security risks and ensures activities are within risk tolerance and in compliance with approved risk management policies, procedures and limits. Essential... 
    Temporary work
    Work experience placement
    Work at office

    CareSource

    Dayton, OH
    3 days ago
  • $90k - $135k

     ...expected. Our team members are empowered to take ownership, make informed decisions, and make a meaningful impact as the bank...  ...your best. Together we win! THE OPPORTUNITY The Senior GRC Information Security Analyst role will be part of the Information Security Governance... 
    Local area
    Immediate start
    Flexible hours

    Banc of California

    Santa Ana, CA
    1 day ago
  •  ...Position Summary Design, implement, audit, and maintain governance, risk management, and compliance (GRC) controls for Purpose Financials information security program. This role is the operational backbone of our compliance posture owing to SOC 2 Type II readiness... 
    Contract work
    Casual work
    Work at office

    Purpose Financial

    Greenville, SC
    5 days ago
  • $60 - $65 per hour

     ...Information Security GRC Analyst Job Type: Contract Contract Length: 6 months Pay Range: $60-$65/hr Start Date: ASAP Location: Remote (EST) About the Opportunity Our client, a leader in the Cloud Infastructure industry, is looking for a skilled Information Security GRC... 
    Contract work
    For contractors
    Immediate start
    Remote work

    DeWinter Group

    San Jose, CA
    4 days ago
  •  ...and mitigation of risks are fundamental components of our information assurance and cyber security program. This position leads the IT security risk and...  ...requirements (e.g. PCI DSS) and IT best practices. GRC Risk Analyst Skills & Requirements: ? 7-10 years... 
    Work experience placement

    Kaav Inc.

    Boca Raton, FL
    5 days ago
  • $96.56k - $124.96k

     ...GRC Information Security Systems Analyst (Minneapolis, MN) (#4073) Join Dorsey’s Information Security team as aGRC Information Security Systems Analystto help safeguard our firm and clients by driving high-impact security initiatives across audits, risk, governance,... 
    Contract work
    Temporary work
    Currently hiring
    Work at office
    Worldwide
    Flexible hours

    Dorsey & Whitney

    Minneapolis, MN
    2 days ago
  • $80k - $100k

     ...Commitment to our Communities, and Protecting Customer Information. The Information Security Operations Specialist - Incident Response supports the operational...  ...governance and awareness. Coordinate with GRC work efforts to ensure insider risk processes meet... 
    Full time
    Temporary work
    Part time
    Local area
    Flexible hours

    Farm Credit East

    Enfield, CT
    20 hours ago
  •  ...MANTECH seeks a motivated, career and customer-oriented SCI Security Specialist II to join our team in El Segundo, CA . The SCI...  ...collateral program functions including physical, personnel, information and industrial security. The position will provide “day-to-... 
    Civilian Contractor
    Full time
    Contract work
    Work at office
    Local area

    MANTECH

    Los Angeles, CA
    1 day ago
  •  ...seeking a candidate to serve as a Data Security and Privacy Specialist to assist with the development,...  ...Contracts for Clients and Vendors : Provide information security and data privacy expertise...  ...security, information security, or GRC (Governance, Risk, and Compliance) role... 
    Contract work

    Insight Global

    Dunwoody, GA
    1 day ago
  •  ...IT Security Analyst – GRC Focus The Security Analyst will focus on client questionnaires, client assessments, and client engagement documents...  ...issues. Key areas of focus will be client data security, information governance and compliance. Work performed by this... 

    1872 Consulting

    Chicago, IL
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security GRC Specialist. Be the first to apply!