EX Squared logo

Information Security & IT Risk Manager (GRC)

EX Squared
Posted 7 hours ago
MexicoHybridEngineering & Development
Is this job info correct?

At EX Squared LATAM, we partner with leading organizations across global and regional markets to connect exceptional professionals with high-impact career opportunities.



Our client is a leading global organization in the professional services and consulting industry, supporting businesses with complex technology, risk, compliance, and transformation initiatives.



For this position, EX Squared LATAM is supporting our client with the recruitment and selection process.
The selected professional will be hired directly by the client under their local payroll in Mexico, becoming part of their internal team.


Role Overview

We’re currently looking for an Information Security & IT Risk Manager (GRC) to lead and strengthen Information Security and IT Risk Management initiatives within a complex, global environment.



This role combines IT risk management, information security governance, GRC, data and analytics, and stakeholder leadership. The ideal candidate will bring strong experience managing risk programs, establishing governance practices, translating data into executive-level insights, and working with international teams.



Location

Mexico. Candidates located in Mexico City or Guadalajara are highly preferred.

  • For professionals based in Mexico City or Guadalajara, the position follows a hybrid model with onsite attendance approximately 2–3 days per week.
  • Candidates based in other cities in Mexico may be considered for a remote arrangement; however, Mexico City and Guadalajara profiles will receive priority.



Contract Duration

Permanent, direct employment with the client.

This is a 100% payroll position in Mexico.



Working Hours

Monday through Friday, 8:00 a.m. to 5:00 p.m.



Language Requirement

Advanced English – C1 level.

The role requires regular interaction with teams and senior stakeholders in the United States.



What you'll do

  • Lead and oversee IT and Information Security Risk Management programs, including risk identification, assessment, mitigation, monitoring, and remediation.
  • Drive structured risk assessments and define mitigation strategies aligned with business objectives.
  • Serve as a trusted advisor to leadership, providing clear, risk-based recommendations and executive-level insights.
  • Develop and strengthen risk governance practices aligned with recognized frameworks such as ISO 27001 and NIST.
  • Define and align risk strategy, appetite, tolerance, KPIs, and KRIs.
  • Support audit, compliance, and internal control activities.
  • Oversee risk data management, ensuring appropriate data quality, governance, integrity, and lifecycle management.
  • Lead the development and improvement of enterprise risk reporting and analytics capabilities.
  • Leverage technologies such as Databricks and enterprise reporting platforms to support large-scale data processing, analytics, and risk reporting.
  • Promote automated data pipelines, reporting processes, predictive analytics, and proactive risk management.
  • Lead cross-functional transformation and continuous improvement initiatives.
  • Build strong relationships with technical, business, and leadership stakeholders.
  • Guide, mentor, and collaborate with team members across different functions and geographies.



What you'll bring

  • Strong professional experience in Information Security, IT Risk Management, GRC, or related leadership roles.
  • Solid understanding of risk management, compliance frameworks, internal controls, and information security governance.
  • Experience working with frameworks such as ISO 27001, NIST, CIS, and/or COBIT.
  • Experience defining, managing, and improving enterprise-level risk management processes.
  • Strong understanding of data governance and data lifecycle management.
  • Experience working with Big Data, data science, data engineering, analytics, or enterprise reporting environments.
  • Exposure to technologies such as Databricks, Qlik, Teradata, Power BI, or similar platforms.
  • Strong stakeholder management and influencing skills, including interaction with senior leadership.
  • Excellent analytical, problem-solving, and communication skills.
  • Ability to manage multiple priorities, initiatives, and stakeholders in a dynamic environment.
  • Bachelor’s degree in Information Technology, Computer Science, or a related field.



What will make you stand out

  • Certifications such as CISSP, CISM, CRISC, or ISO 27001.
  • Certifications or formal training related to Databricks, Power BI, Qlik, Teradata, or Data Analytics.
  • Experience combining traditional GRC and cybersecurity risk management with data-driven or predictive analytics.
  • Experience leading transformation, automation, or continuous improvement initiatives.
  • Strong executive communication skills and the ability to translate complex technical and risk information into clear business recommendations.
  • A proactive, self-driven, and value-oriented leadership approach.



Why this opportunity?

This is an opportunity to join a large, globally recognized organization in the professional services and consulting industry, working with multidisciplinary and international teams on complex Information Security and IT Risk initiatives.

The role offers significant exposure to global stakeholders, sophisticated risk and analytics environments, and opportunities for continued professional development and internal career growth.



What the Client Offers

  • Career growth opportunities.
  • Meal/grocery vouchers.
  • Savings fund.
  • Remote-work allowance, when applicable.


Selection Process

The selection process is expected to include:

  • Initial interview with the local/direct leader.
  • Technical interviews with the U.S.-based team, typically involving two interviewers per session.
  • Final interview with the U.S. Area Director.
  • Background check.


Eligibility Note

This opportunity is available to candidates currently residing in Mexico.

Candidates located in Mexico City and Guadalajara are strongly preferred due to the hybrid working model. Candidates located elsewhere in Mexico may also be considered for remote work depending on profile and business requirements.


Ready for your next career opportunity?

Apply through EX Squared LATAM and take the next step toward joining a global organization where Information Security, technology, risk management, and data-driven decision-making come together.

Similar jobs