SlipstreamJobsFresh Startup & VC-Backed Jobs

GRC Sr Analyst - SPEI

Pomelo - Mexico City, Mexico - Hybrid

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Pomelo is a leading fintech infrastructure company in Latin America, enabling businesses to launch and manage credit, debit, and prepaid cards with world-class security standards. The InfraSec team is seeking a GRC Senior Analyst to lead governance, risk, and compliance initiatives in Mexico. Key responsibilities include: • Lead implementation and maintenance of PCI DSS v4, ISO 27001, and SOC 2 Type II compliance, including internal/external audits and certification processes. • Manage the company's GRC program: maintain risk registers, develop treatment plans, track KRIs, and report status to management. • Oversee third-party risk management (TPRM): conduct vendor assessments, due diligence reviews, and remediation tracking. • Identify and implement automation and AI solutions for GRC: continuous control monitoring, risk detection, and evidence generation at scale. • Serve as Information Security Officer (OSI) for Banco de México under SPEI Circular 14/2017 regulations. • Conduct quarterly reviews of technology infrastructure and electronic channels, including privileged access monitoring, to detect anomalies. • Validate security incident management processes (identification, protection, detection, response, recovery) and report to audit and risk committees. • Evaluate security controls in AWS and SaaS environments; manage cryptographic keys and card-processing controls (HSM, PCI PIN). • Design and maintain security policies, standards, and procedures; support data privacy and security awareness initiatives. Required qualifications: • 5+ years in GRC or information security roles. • Strong knowledge of PCI DSS, ISO 27001, SOC 2 Type II, and familiarity with NIST CSF. • Direct experience with Banco de México Circular 14/2017 in SPEI-participating organizations. • Valid e.firma and Mexico residency (availability during Banco de México business hours). • Experience in TPRM, risk management, security audits, and risk register maintenance. • Understanding of AWS infrastructure and SaaS models for control evaluation and auditing. • Knowledge of cryptographic key management and associated controls (HSM, PCI PIN); familiarity with fintech and card processing. • Strong communication skills to translate technical risks into business language for management reporting. • Interest or experience in automation and AI applied to GRC. • Desired: CISSP, CISM, CISA, or ISO 27001 LA certifications. Pomelo offers innovation leadership, regional collaboration across Latin America, tangible impact in a dynamic industry, practical learning culture, and authentic hybrid flexibility.

Similar roles