Description
Job Summary:
This role involves managing cyber risks and vulnerabilities at a corporate level, ensuring regulatory compliance and informed business decisions.
Key Responsibilities:
1. Manage corporate cyber risks and vulnerabilities
2. Ensure regulatory compliance and informed decision-making
3. Lead remediation plans and manage security controls
**Job Description**
----------------------
Manage corporate cyber risks and vulnerabilities, ensuring regulatory compliance and informed business decisions.
Asset and risk identification: Establish and maintain the corporate information asset inventory and threat/vulnerability catalog, defining the group's risk context.
Risk assessment and analysis: Calculate inherent and residual risk considering probability, impact, and criticality, applying the corporate methodology to prioritize based on business impact.
Vulnerability discovery and scanning: Coordinate scanning cycles across infrastructure, applications, cloud, and endpoints, ensuring full coverage of the group's technology estate.
Vulnerability prioritization: Classify findings by severity (CVSS/EPSS), exposure, asset criticality, and threat context to focus remediation efforts on what most impacts the business.
Risk treatment and remediation: Define treatment strategies (mitigate, transfer, accept, or avoid), lead remediation plans with responsible units, and manage exception workflows as required.
Control management and hardening: Verify implementation of technical and secure configuration controls (CIS Benchmarks, hardening, patching) on in-scope systems.
Regulatory and standards compliance: Ensure adherence to PCI\-DSS, personal data regulations, ISO 27001, and NIST, maintaining corporate scopes and certifications.
Executive monitoring and reporting: Continuously monitor risk evolution, KRIs, remediation KPIs, and vulnerability SLAs, reporting to committees and senior leadership with an emphasis on actionable decisions.
Security culture and human factor: Drive the corporate Training & Awareness program and associated disciplinary model for Ethical Phishing, strengthening the first line of defense.
**Candidate Requirements**
--------------------------
* Bachelor's degree in Computer Science, Cybersecurity, Systems Engineering, or related fields.
* 3–5 years of experience in cyber risk, compliance, or vulnerability management roles.
* CISM, CRISC, ISO 27001 certifications.
* Familiarity with ISO 27001/27005, NIST, PCI\-DSS, CIS Controls, personal data regulations, and GRC software.
* Intermediate-to-advanced Excel skills.
* Copilot said: Experience in management reporting and tracking executive metrics.
This opportunity is open to persons with disabilities.
**Selection Process**
------------------------
The selection process is conducted via Aira — a recruitment platform designed to enhance your application experience.
To apply, you only need to:
1\. Apply to the position
2\. Check your email
3\. Log in to Aira and complete the requested questions and/or assessments
Then, if your profile matches our requirements, we will contact you by email (via Aira) to proceed to the in-person stage.
**About Us**
------------------
We are over 90,000 people who, every day, dedicate our passion and energy to fulfilling our Purpose: “Simplify and Enjoy Life More.” This Purpose lives today through our physical and digital ecosystem across all our companies (Falabella Retail, Sodimac, IKEA, Tottus, Mallplaza, Falabella Inmobiliario, Falabella.com, Linio, Falabella Financiero, Banco Falabella, Falabella Soriana, Seguros Falabella, Fazil, Fpay, and Falabella Corporativo) and countries (Argentina, Brazil, Chile, China, Colombia, India, Mexico, Peru, and Uruguay).
We value diverse perspectives because we understand that diversity is the key to our innovation. We aim to go beyond any limit, constantly challenge ourselves, enjoy doing what we love, and leave a lasting impact on everything we do. And we know there is one way to achieve this: as ONE TEAM.
Explore more opportunities to experience the \#ExperienciaFalabella at https://muevete.falabella.com/