Lead Information Security Specialist
Experian · Heredia
Job description
About the role
Reporting to the Head of Information Security Policy and Standards, you will lead the identification, documentation, and implementation of Experian’s security risk and controls framework across the enterprise. The role ensures a sound security posture by designing and applying risk‑based controls and collaborating with business partners worldwide.
Key responsibilities
- Lead the security risk and control modularisation strategy, working with regional business units, central security, and IT control owners to populate the controls library.
- Maintain and update the integrated risk and control framework in line with policies, standards, industry practice, and regulations.
- Review and challenge first‑line business unit control activities, ensuring alignment with control standards and goals.
- Identify, document, and report control gaps, providing remediation recommendations.
- Compile management reports, summary analyses, and detailed presentations on the risk and controls program.
- Develop and deliver workshop content for controls implementation with owners across the enterprise.
- Map information security controls to applicable risks in the Archer GRC platform.
- Monitor internal and external risk indicators and feed them into control assurance activities.
- Standardise and automate risk and controls processes, capture stakeholder feedback, and improve engagement models.
- Support strategic projects as a subject‑matter expert for the Information Security Governance team.
Required profile
- Bachelor’s degree in Computer Science, Management Information Systems or a related field, or equivalent experience.
- 5+ years of hands‑on experience designing, implementing, and evaluating security controls.
- Proven experience with GRC tools, preferably Archer.
- Strong understanding of industry best practices such as NIST, ISO, COBIT, CMMI, OWASP and ITIL.
- In‑depth knowledge of governance, risk, and controls principles.
Required skills
- Archer GRC platform
- NIST framework
- ISO 27001/ISO standards
- COBIT
- CMMI
- OWASP
- ITIL
- Security control design, implementation and evaluation
- Risk and control mapping
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Costa Rica.
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 1 month ago
Expires 3 weeks from now
32 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Experian
Heredia
Related job offers
-
IT Server Administrator & Technical Support Engineer
Information Technology Support Heredia -
Data Reporting & Analytics Consultant IV
Korn Ferry Heredia -
Software Development Engineer in Test (SDET)
TradeStation Heredia -
Engineering Manager – Intern Programs & Quality
OfficeSpace Software -
Technical Support Engineer – Kasten
Veeam Software San José District