Senior Security Lead

Company
Description
Job Summary: We are seeking a passionate Senior Cybersecurity Lead to lead the evolution of our cybersecurity function and drive security improvements in product development, while managing certifications and risk. Key Highlights: 1. Lead the cybersecurity strategy and a growing team 2. Participate in the Risk Committee and ensure regulatory compliance 3. Serve as the key technical point of contact for high-level clients and stakeholders At Toku, we are looking for a **Senior Cybersecurity Lead**, passionate about cybersecurity, to lead the evolution of this area. Since 2022, we have advanced key certifications (PCI since 2022, ISO 27001 since this year), and now we seek someone to further deepen cybersecurity practices and embed them into the daily work of a team of over 100 software engineers focused on product. We seek someone with strong technical vision, the ability to prioritize effectively and communicate those priorities clearly, and the capability to engage both clients and senior internal stakeholders. You will join Toku’s Risk Committee. We seek a motivated individual eager to join a high-performing team that continuously seeks ways to improve our security practices. We value curious, proactive people who adapt quickly to change, think creatively, enjoy teamwork, and are not afraid to experiment and challenge the status quo. **Responsibilities**: * Lead the design, definition, and implementation of security strategy and improvements in product development. * Lead a growing cybersecurity team, currently consisting of 2 people. * Define and implement internal security policies (physical, operational, and information security). * Manage acquisition and renewal of certifications (PCI, ISO 27001, and its continuous improvement plan). * Ensure compliance with Chile’s new cybersecurity law and current regulations in Brazil and Mexico. * Manage the recurring penetration testing and vulnerability assessment program (semi-annual or more frequent), defining who performs them and why. * Drive company endpoint security. * Manage and mitigate risks, actively participating in the company’s Risk Committee. * Serve as the technical point of contact for cybersecurity matters with clients and internal teams, including direct communication with the CTO and monthly meetings with the CEO and Senior VP. **Ideal Profile**: * \+5 years of experience. * Solid technical knowledge of payments and money flow (ideally in Chile, Brazil, and/or Mexico): cards, processing, payment methods, etc. * Experience obtaining and/or maintaining PCI, ISO 27001, or similar certifications. * Experience creating and implementing internal security policies. * Excellent communication skills and ability to collaborate effectively in teams. * Ability to drive cultural and organizational change. * Motivation and passion for technology and cybersecurity. * Autonomy, adaptability, and full-time availability.
Posted by

Sofía Muñoz
MyJob · HR