Description
Job Summary:
We are seeking a dynamic professional with solid experience in cybersecurity and regulatory compliance to represent the local Information Security function.
Key Highlights:
1. Redefining global digital protection as a Google Premier Partner.
2. Collaborating on IT/OT security projects and audits (ISO 27001, TISAX).
3. Promoting cybersecurity awareness and training campaigns.
**Description:**
----------------
At Iris, we don’t just build companies—we forge leaders in technological innovation. Our mission focuses on redefining our clients’ future through cutting-edge technologies (Cloud, Cybersecurity, Data, AI). We are driven by ambition, excellence, innovation, transparency, empathy, and trust.
Through Ciberia, we are redefining global digital protection as Google’s Premier Partner for Cybersecurity across EMEA and LATAM. With operations in five countries and borderless ambition, we offer an environment where intelligent cybersecurity and professional judgment converge to transform international-scale projects.
We seek a dynamic professional with solid experience in cybersecurity and regulatory compliance who can represent the Information Security function locally, serving as the direct point of contact between regional operations and global teams. Their mission will be to adapt and implement corporate security policies, ensure compliance, and actively contribute to maturing the local IT/OT security ecosystem.
**Key Responsibilities**
* Align and implement corporate security policies, standards, and controls at the local level.
* Support execution of OT (Operational Technology) security projects in industrial and production environments, closely collaborating with plant managers, automation, and maintenance teams.
* Collaborate on IT security projects, performing security architecture reviews.
* Lead or coordinate local certification and audit processes (ISO 27001, TISAX, IATF 16949, or other relevant frameworks).
* Monitor, report, and support cybersecurity incident management, acting as the first regional escalation point.
* Participate in security risk assessments and propose mitigation plans aligned with corporate strategy.
* Promote and execute cybersecurity awareness and training campaigns for local employees.
* Collaborate on preparing security reports, metrics, and KPIs for tracking and reporting to headquarters (HQ).
**Requirements:**
---------------
* Advanced knowledge in one or more of the following areas:
* Industrial cybersecurity (OT): network segmentation, industrial firewalls, DMZ, IT/OT segregation.
* Policy management and compliance: implementation and monitoring of ISO 27001, TISAX, and similar frameworks.
* Corporate information security (IT): vulnerability management, access management, monitoring and incident response.
* Proficiency with security management tools such as Microsoft Defender Suite, Splunk, Palo Alto, or equivalents.
* Knowledge of industrial network architecture, Identity Management, and access control (Zero Trust, RBAC).
* Basic knowledge or experience with auditing methodologies and reporting/ticketing tools (Power BI, Advanced Excel, ServiceNow, Jira).
**Education and Certifications Valued**
* Minimum education: Bachelor’s degree in Computer Engineering, Telecommunications, Industrial Electronics, or related field.
* Professional experience: Minimum 3–5 years in information security roles, including at least 1–2 years in industrial or hybrid IT/OT environments.
**Desirable Certifications:**
* General security: CISSP, CISM, CISA, ISO 27001 Lead Implementer/Auditor.
**Languages:**
* Professional-level English (minimum B2\-C1\).
* Nice to have – Advanced Spanish proficiency.
**Availability:**
* Willingness to travel occasionally to plants or regional offices.
**Key Competencies**
* Analytical ability and critical thinking.
* Practical, solution-oriented, and results-driven approach.
* Effective communication with technical and business teams.
* Autonomy, integrity, and commitment to continuous improvement.