As Director of Cyber Risk, and Digital Resilience for LATAM, you will lead the regional strategy and implementation of cybersecurity and resilience programs across regulated financial institutions in Latin America. This includes aligning global cyber frameworks with local regulatory expectations, overseeing cyber risk management, and ensuring operational readiness and compliance.
Essential Responsibilities:
- Provide expert advice and strategic counsel to senior executives, shaping the development of multi-year risk management and security governance strategies that align with business goals and long-term organizational objectives.
- Determine the most effective methods and strategies for addressing complex security risks, driving innovation through collaboration with cross-functional teams to shape the organization’s security risk management and governance landscape.
- Identify and resolve unique, high-impact security risks, applying deep expertise to situations of substantial significance, and develop innovative solutions that influence and strengthen the organization’s security framework.
- Drive the future risk management and security governance roadmap, shaping the security vision that supports business growth and mitigates risk to provide a competitive advantage.
- Lead the development and execution of key components of the multi-year security strategy, contributing to the broader security agenda within the organization.
- Inspire and motivate team(s) to pursue innovative solutions, ensuring alignment with the overall security strategy and business objectives, while fostering a culture of excellence and continuous improvement.
Minimum Qualifications:
- Minimum of 15 years of relevant work experience and a Bachelor's degree or equivalent experience.
Strategic Alignment & Governance
- Ensure the alignment of global cybersecurity strategies, frameworks, and policies with local and regional regulatory requirements, particularly in high-regulation environments such as LATAM.
- Bridge global objectives with in-country execution by enabling the adoption of enterprise-wide programs within local regulatory and operational constraints.
- Advise senior executives and board-level stakeholders on cyber governance maturity and alignment with business strategy.
Operational Security Leadership
- Act as the designated Information Security Officer for regulated financial entities, fulfilling local legal and supervisory expectations.
- Serve as the Entity Service Owner for intra-group technology services, with oversight of service level adherence, security control effectiveness, and compliance at the point of delivery.
Cyber Resilience Program Leadership
- Lead the design, execution, and continuous evolution of cyber resilience programs, ensuring robust preparedness through business impact analyses, recovery strategies, and end-to-end testing.
- Deliver tangible evidence of operational readiness, integrated with IT disaster recovery, business continuity, and third-party resilience plans.
- Ensure alignment with global resilience standards and evolving regulatory expectations, including regional LATAM frameworks.
Regulatory Compliance & Readiness
- Maintain an authoritative inventory of cybersecurity regulatory obligations across LATAM and global markets.
- Proactively ensure that controls are designed, implemented, and tested to meet external audit and supervisory examination standards.
- Partner with Legal, Compliance, and Risk teams to anticipate regulatory changes and adjust cybersecurity posture accordingly.
Cyber Risk Management & Control Operation
- Operate and continuously improve first-line cybersecurity controls across infrastructure, applications, and third-party services.
- Monitor control effectiveness, identify risks and control deficiencies, and lead remediation planning in coordination with second and third lines of defense.
- Represent cybersecurity in key governance forums, including entity-level risk committees, IT steering groups, and audit/regulatory readiness sessions.
Incident Preparedness & Security Advocacy
- Direct and participate in incident response planning, simulations, tabletop exercises, and post-incident reviews.
- Serve as the first point of escalation for local cybersecurity incidents, coordinating response with global SOCs, legal teams, and regulators as necessary.
- Foster a culture of cyber awareness across business and technology functions through targeted communications, training, and leadership engagement.
What you need to bring
- 15+ years of experiencein cybersecurity, ICT risk, or operational resilience in theLatin American financial sector.
- Proven track record leadingsecurity and risk functions in regulated financial institutions, including engagement with BACEN, CNBV, CMF, SUSEP, or SFC.
- Strong understanding offinancial regulatory ecosystems, cross-border data protection laws (e.g., LGPD), and banking/insurance sector dynamics.
- Demonstrated ability to manage complex regulatory environments and lead teams across geographies and languages.
- Executive-level communication skills and board-facing experience are essential.
Preferred Certifications
- CISSP, CISM, CRISC, or similar cybersecurity credentials
- DRI/BCI Business Continuity certifications
- ITIL, ISO 27001 Lead Auditor, or equivalent regulatory frameworks
- Familiarity with NIST CSF, COBIT, and regional cloud/data protection laws
Our Benefits:
Any general requests for consideration of your skills, please