Bitso is hiring a
Web3 Information Security GRC Specialist

Compensation: $106k - $150k estimated

Location: México

Working At Bitso

We are a diverse team that takes pride in understanding the perspectives of others. We fully embrace working remotely and we are eager to act, improve and accelerate progress inside and outside of our organization.

To drive revolutionary changes in society and make crypto useful, we delight our customers with world-class products, deep care, and intentional empathy.

<span >

As our Information Security GRC Specialist, you will be an integral part of the Information Security Governance, Risk, and Compliance team. Your role is essential to ensure that company security policies, technical standards, and procedures are implemented, maintained, and continuously improved, while overseeing security risk management and compliance with applicable security standards and regulations. Additionally, you will be responsible for coordinating and supporting external/internal security assessments.

As part of the information security governance, risk, and compliance team, you will:

  • Use holistic approaches interconnecting governance, risk, and compliance through project management and the application of industry best practices, standards, and regulations.
  • Connect information security with other involved teams.
  • Drive alignment of all lines of business with the defined information security culture and governance model.
  • Use Agile approaches in your projects.
  • Focus on proactivity, quality, and excellence in your results.
  • Explore strategies and solutions for effective Governance, Risk, and Compliance (GRC) engineering in the organization.

Beyond our team, you will collaborate closely with:

  • Organizational risk, compliance, and regulatory internal and external teams to ensure proper adherence to information security compliance processes.
  • Technical groups to assist in implementing technical standards, controls, and configurations aligned with security policies, legal requirements, and audit standards.

 

Reports To
Information Security Program Manager

Who You Are 

  • Proven English proficiency. You are comfortable presenting to English-speaking audiences and creating deliverables in that language. You are able to maintain a fluid conversation in English.
  • Minimum of 5 years of experience in Information Security GRC roles.
  • At least 3 years of experience leading or coordinating internal compliance assessments, internal audits, or acting as a strategic consultant with a focus on maturity assessments.
  • At least 3 years of experience working with Mexican regulatory, cybersecurity, and information security requirements applicable to fintech or regulated financial entities.
  • You have expert knowledge of information security frameworks and best practices (e.g., ISO/IEC 27000 series, COBIT, NIST SP 800-xx, NIST CSF, and CIS).
  • You have working knowledge in scripting to read and modify simple scripts, understand JSON and YAML configuration files, use command-line tools and write basic automation tools.
  • You have working knowledge of data analysis to extract relevant information from logs and identify trends and patterns, to turn technical data into business insights.
  • You have proficiency in IT audit, compliance, and maturity assessments.
  • You hold a Certified Information Systems Auditor (CISA) certification or equivalent credentials with a strong focus on IT audit, assurance, or information security governance.
  • You hold a AWS Certified Cloud Practitioner or working knowledge with AWS Cloud Infrastructure. 
  • You possess a competent understanding of the risk management process, with emphasis on risk treatment, monitoring, and control assessment phases.
  • You possess strong communication skills. These are crucial as the role involves coordinating with internal teams, external auditors, and various technical and non-technical groups. Being able to effectively communicate findings, recommendations, and remediation strategies to different levels of stakeholders is key.
  • You are detail-oriented. Given the role's responsibilities in monitoring compliance, identifying gaps, and managing security controls, attention to detail is vital. You should be meticulous in your work to ensure that effective compliance and security measures are in place.
  • You are an agile and avid learner. Information security is a rapidly evolving field, so you have a willingness to continuously learn and stay updated on the latest trends, threats, and best practices in the industry. Keeping up-to-date will help in effectively implementing security measures.
  • You are passionate about information security, and you can see beyond the technology and controls. You find confluence points and create synergies. You believe in teamwork, and you believe that by empowering an organization to protect itself, you are on the side of a noble and much-needed cause.


Nice-to-have:

  • Minimum 2 years of strategic consulting experience, particularly within financial institutions.
  • Additional certifications such as Certified ISO 27k Lead Auditor, CISSP, or PMP.
  • Working knowledge with maturity models and frameworks (e.g., CMMI), cloud security best practices, project management (PMI), and Agile methodologies (e.g., Kanban).
  • Familiarity with international regulations such as GDPR.

 

What You Will Do 

  • Maintain and continuously improve the Information Security GRC Program.
  • Act as a key liaison with regulatory authorities on information security–related topics.
  • Support the adoption and consistent implementation of security policies, standards, and procedures across all lines of business.
  • Assess and validate compliance with applicable regulatory, contractual, and information security requirements.
  • Conduct regular information security and maturity assessments of Bitso’s information security controls, and follow up on treatment plans across the organization.
  • Continually validate the organization against the internal information security governance framework to ensure compliance, monitor for non-conformities, and prepare reports and metrics with recommended remediation strategies.
  • Collaborate with internal and external security audits, proactive technical assessments, and tracking findings and recommendations for appropriate action will be crucial aspects of your responsibilities.
  • Guide and support non–security engineering teams, liaise with cross-functional stakeholders as needed, and ensure the quality, consistency, and effectiveness of information security programs and projects.
  • Shift from manual compliance assessments to an automated, continuous, and integrated practice, embedding compliance directly into the technical stack.

 

Research in Diversity, Equity, and Inclusion suggests that individuals may hesitate to apply for jobs if they do not meet all the listed criteria. At Bitso, we value diversity and your unique strengths could be just what we're looking for. If this role excites you but you don't match every point in the description, we still want to hear from you.

#LI-Remote

<div class="content-conclusion">

Who We Are

With over 9 million users, Bitso is the leading cryptocurrency platform in Latin America. We are developing the cryptocurrency ecosystem in the region and enabling financial inclusion. We believe crypto is the future of finance, and we’re committed to making it useful by providing equal access to safe and intuitive financial products.

When we hire people for our team, we specifically test for the following traits in addition to our cultural values:

  • Mission-Driven: We seek individuals who are passionate about crypto and Bitso’s mission and resilient in facing industry challenges

  • High Sense of Urgency: We prioritize candidates who demonstrate a high sense of urgency and responsibility.

  • Exceptional Hard Skills: We seek individuals who possess exceptional skills in their respective fields, with no room for mediocrity.

  • Self-Management: We look for individuals who can independently manage their work, career, and professional development.

Compensation & Benefits

At Bitso, you are taking the front seat on the edge of crypto innovation, creating the next generation of crypto-powered products.

So for those willing to commit, adapt and pioneer the most important change of the century we offer:

  • Me Time program, including unlimited paid time off.
  • Remote-first work environment.
  • Employee Stock Option program.
  • Zero trading fees through our Bitso Alpha app.
  • Extended Family Leave Policy: all birthing parents, non-birthing parents and adopting parents are eligible for a 4-months leave.
  • Premium health, dental and life insurances in Mexico, Gibraltar, Colombia, USA, Brazil and Argentina.
  • Monthly stipend for gym memberships, relaxation activities, sports equipment, cooking classes, books, entertainment and more.

Want to leave an undoubtedly legacy with us? Fasten your seatbelt and join this spaceship, where you will find exponential growth and the opportunity to thrive!

  • These are the applicable requisites, although equivalent competencies in any of the above will also be considered.
  • To see our Privacy Policy please click here.

Apply Now:

Compensation: $106k - $150k estimated

Location: México


Benefits: Medical Insurance


Receive similar jobs:

México

Web3 Security Expert Jobs

Job Position and Company Location Tags Posted Apply

Remote

Apply
United States
Apply
Lisbon, Portugal
Apply

Remote

Apply

Remote

Apply

Remote

Apply

Remote

Apply
Montreal, Canada
Apply

Remote

Apply

Recommended Web3 Security Experts for this job

/@razali

Razali



See Profile
/@rizal177

Rizal177



See Profile
/@navinder

Navinder



See Profile
/@eytanlvy

Eytanlvy



See Profile
/@anawark

Anawark



See Profile
Cover Letter / AI Interview