SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Pomelo is a leading fintech infrastructure company in Latin America, enabling businesses to launch and manage credit, debit, and prepaid cards with world-class security standards. The InfraSec team is seeking a GRC Senior Analyst to lead governance, risk, and compliance initiatives in Mexico.
Key responsibilities include:
• Lead implementation and maintenance of PCI DSS v4, ISO 27001, and SOC 2 Type II compliance, including internal/external audits and certification processes.
• Manage the company's GRC program: maintain risk registers, develop treatment plans, track KRIs, and report status to management.
• Oversee third-party risk management (TPRM): conduct vendor assessments, due diligence reviews, and remediation tracking.
• Identify and implement automation and AI solutions for GRC: continuous control monitoring, risk detection, and evidence generation at scale.
• Serve as Information Security Officer (OSI) for Banco de México under SPEI Circular 14/2017 regulations.
• Conduct quarterly reviews of technology infrastructure and electronic channels, including privileged access monitoring, to detect anomalies.
• Validate security incident management processes (identification, protection, detection, response, recovery) and report to audit and risk committees.
• Evaluate security controls in AWS and SaaS environments; manage cryptographic keys and card-processing controls (HSM, PCI PIN).
• Design and maintain security policies, standards, and procedures; support data privacy and security awareness initiatives.
Required qualifications:
• 5+ years in GRC or information security roles.
• Strong knowledge of PCI DSS, ISO 27001, SOC 2 Type II, and familiarity with NIST CSF.
• Direct experience with Banco de México Circular 14/2017 in SPEI-participating organizations.
• Valid e.firma and Mexico residency (availability during Banco de México business hours).
• Experience in TPRM, risk management, security audits, and risk register maintenance.
• Understanding of AWS infrastructure and SaaS models for control evaluation and auditing.
• Knowledge of cryptographic key management and associated controls (HSM, PCI PIN); familiarity with fintech and card processing.
• Strong communication skills to translate technical risks into business language for management reporting.
• Interest or experience in automation and AI applied to GRC.
• Desired: CISSP, CISM, CISA, or ISO 27001 LA certifications.
Pomelo offers innovation leadership, regional collaboration across Latin America, tangible impact in a dynamic industry, practical learning culture, and authentic hybrid flexibility.