···
Log in / Register

Senior Cybersecurity Engineer

MyJob
Full-time
Onsite
No experience limit
No degree limit
PA239-Parada 3 / Museo Militar, Santiago, 8340126, Metropolitan Region, Chile
Favourites
Share
Some content was automatically translatedView Original

Description

Job Summary: We are seeking a Senior Cybersecurity Engineer to ensure operational governance of the IT/OT cybersecurity GRC program and manage regulatory compliance. Key Highlights: 1. Ensure operational governance of the IT/OT cybersecurity GRC program 2. Manage regulatory compliance and cyber risk management 3. Join a committed, enthusiastic, and creative team **Date:** May 28, 2026 **Location:** Santiago, RM, Chile, 7550107 **Company:** Arauco ***Senior Cybersecurity Engineer*** ***At ARAUCO, we recognize each person through their individuality and diversity. We believe every individual’s contribution is unique, and teams become enriched when they integrate diverse perspectives and capabilities. We consider inclusion and diversity as fundamental to meeting present and future challenges******.*** ARAUCO is seeking professionals with a degree in Computer Engineering, Systems Engineering, Telecommunications Engineering, or a related field, with at least 3 years of experience in Compliance, Audit, or Cybersecurity roles, to join our Santiago Corporate Office as a **Senior Cybersecurity Engineer**. The primary **objective of this position** is to ensure operational governance of the IT/OT cybersecurity GRC program, being responsible for building and maintaining the regulatory framework, ensuring ISMS compliance, managing cyber risks, and fulfilling applicable regulatory obligations—supporting the GRC Manager in decision-making with timely and reliable information. **Key Responsibilities:** * Serve as the owner for developing, reviewing, and updating the full set of IT/OT cybersecurity policies, standards, and procedures. Validate alignment of each document with corporate reference frameworks (ISO 27001, IEC 62443, NIST CSF, NERC\-CIP) and prepare them for approval by the GRC Manager. * Ensure regulatory compliance of the ISMS (ISO 27001, IEC 62443, NERC\-CIP, NIST): manage the full internal and external audit lifecycle, prepare required documentation, support the audit process, and formally track all findings to closure. * Manage and maintain the IT/OT cyber risk management process: coordinate risk identification, assessment, and treatment; keep the risk register updated; and track execution of treatment plans by responsible departments. Coordinate the TPRM process jointly with the external service provider. Report status to the GRC Manager for review and approval. * Populate and maintain the CISO Dashboard of KPIs/KRIs: collect compliance data, control status, and risk information from various departments; consolidate metrics; and prepare inputs used by the GRC Manager for executive reporting to the CISO. * Support management of cybersecurity regulatory obligations: administer the compliance calendar (National Cybersecurity Framework Law, Personal Data Protection Law, NERC\-CIP, IEC 62443\), monitor deadlines, and coordinate legal aspects with Legal and the DPO. Prepare background documentation enabling the GRC Manager to submit notifications to regulatory bodies where required. * Review cybersecurity and data protection clauses in supplier and customer contracts, acting as the technical counterpart to the Legal Department. * Prepare periodic regulatory status reports for the GRC Manager: covering gaps, compliance status, and non-compliance risks with potential impact on sanctions or reputation. **Requirements:** * Degree in Computer Engineering, Systems Engineering, Telecommunications Engineering, or a related field (Mandatory). * 3–5 years of experience in Compliance, Audit, or Cybersecurity roles, with demonstrable experience in cybersecurity regulation or critical infrastructure (Mandatory). * National Cybersecurity Framework Law (Law No. 21\.663 or equivalent regional law); Personal Data Protection Law (Law No. 21\.719 or equivalent regional law); IEC 62443 — in-depth knowledge for OT application; NERC\-CIP — applied knowledge; ISO 27001; NIST CSF (Mandatory). * ISO 27001 Lead Implementer certification (Desirable). * Postgraduate studies, diploma, or master’s degree in Compliance, Cybersecurity, or Data Privacy (Desirable). * CRISC and IEC 62443 Certificate (ISA) (Desirable). * Prior experience in cybersecurity or privacy regulatory consulting (Desirable). * Availability to work at the El Golf Corporate Office, Santiago. ***At ARAUCO, we work daily to develop renewable forest products that improve people’s lives—a mission that challenges us to build committed, enthusiastic, and creative teams. We are a global company with over 50 years of history, operating and serving customers across multiple countries, united by a shared organizational culture. Thus, we strive to foster the necessary conditions to attract and develop talent within work environments grounded in respect, collaboration, and continuous communication.***

Source:  indeed View original post
Sofía Muñoz
MyJob · HR

Company

MyJob
Sofía Muñoz
MyJob · HR
Cookie
Cookie Settings
Our Apps
Download
Download on the
APP Store
Download
Get it on
Google Play
© 2025 Servanan International Pte. Ltd.