ISO Security Officer
Banco PopularAbout the role
Job Type
Full-time
General Description
Provide technical leadership in the creation, establishment, and maintenance of the information technology/security risk framework, processes, and controls, taking into consideration the overall business strategy, legal/regulatory requirements, and other best practices. Perform security assessment to applications, systems, and vendors. Manage the various risks, which may threaten the very success of the organization and propose methodologies to eliminate or minimize them.
Essential Duties and Responsibilities
- Leads the security investigations related to applications, user account, and vendors.
- Manage, review, analyze, design and support Incident Response (End-to-end) processes according to industry’s best practices and applicable regulations.
- Align Incident Response Processes with legal, regulatory, and contractual requirements that conforms with security framework, standards, and applicable regulations.
- Implement regulatory changes to processes in the corporation related to cybersecurity incidents.
- Ability to explain security controls, regulatory requirements, and guidance to security management.
- Discuss and follow up action plans to address recommendations from internal processes. Provides periodic status reports, including outstanding issues.
- Facilitates and monitors performance of remediation tasks, changes related to mitigation factors & reports on findings.
Essential Duties and Responsibilities (cont.)
- Provided feedback during the Development, review, and update of Policies, Standards, and Procedures related to Information Security.
- Create concise and comprehensive reports related to Incident Response Metrics, including recommendations for addressing any identified control weaknesses in the response process.
- Promote awareness of applicable regulatory standards, upstream risks, and industry best practices across the company.
- Project Management/Coordination experience is a must.
- Escalate issues to senior leadership outstanding issues that requires immediate action from different stakeholders of the company.
- Collaborate with technical teams on cyber incidents/events.
- Other duties and responsibilities.
Education
Bachelor's Degree in Computer Engineering or Computer ScienceBachelor's Degree from an accredited University/College in Information Systems or related fieldsExperience
Three+ (3) years of Incident Response/Handling and cloud related experience in a complex technology environment.
Certifications / Licenses
Certifications and Licenses are preferred but no required.
Knowledge, Skills and Abilities (KSA's)
- Strong business acumen: ability to understand the needs and concerns of business stakeholders and colleagues and respond promptly and effectively to stakeholder requests. Ability to conduct analysis on work procedures, business results and recommends changes to improve the effectiveness of the business's management.
- Strong technical acumen: knowledge of Information Security and Information Technology concepts. Ability to write technical instructions using programs and technology. Robust knowledge of applicable local and federal laws, regul
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s