About this Cybersecurity Manager role at CIMMYT
CIMMYT is a cutting-edge, non-profit, international organization dedicated to solving tomorrow’s problems today. It is entrusted with fostering improved quantity, quality, and dependability of production systems and basic cereals such as maize, wheat, triticale, sorghum, millets, and associated crops through applied agricultural science, particularly in the Global South, through building strong partnerships. This combination enhances the livelihood trajectories and resilience of millions of resource-poor farmers, while working towards a more productive, inclusive, and resilient agrifood system within planetary boundaries. CIMMYT is a core CGIAR Research Center, a global research partnership for a food-secure future, dedicated to reducing poverty, enhancing food and nutrition security, and improving natural resources. For more information, visit https://www.cimmyt.org/
We are seeking an experienced, hands-on Cybersecurity Manager to lead the protection of the information assets underpinning its global research operations.
The postholder leads CIMMYT's information security function and its Information Security Management System, aligned to ISO/IEC 27001:2022, with operational ownership of the Center's security platforms and of the team that runs them.
Key Responsibilities:
- Lead CIMMYT's information security function, and manage, coach and develop the cybersecurity team, including objective setting, evidence-based performance assessment, technical mentoring and cross-cover.
- Operate and continuously improve the Information Security Management System aligned to ISO/IEC 27001:2022 and NIST CSF v2.0, maintaining the supporting standards, procedures and the evidence that demonstrates the controls operate as documented.
- Prepare and present risk and control items, and follow through on decisions and actions arising.
- Perform and oversee hands-on configuration, integration, tuning and troubleshooting across the security platform estate, endpoint detection and response, identity and privileged access management, vulnerability management, encryption, SIEM and log management, and network security.
- Own vulnerability and patch management: scan coverage, remediation targets by severity, exception handling and verified closure.
- Own security incident response end to end , detection and triage, containment decisions, documented timelines, root cause analysis, post-incident review and corrective actions.
- Validate control effectiveness before controls are declared in place, including testing for bypass routes, and maintain the technical evidence that supports that conclusion.
- Own identity and access governance.
- Support internal audit, external audit and donor due diligence.
- Manage security suppliers and licences and renewals.
- Coordinate security standards and support with regional IT specialists across country offices, and run the organization-wide security awareness programme.
- Report monthly on security posture, risk and control performance through agreed metrics.
Requirements
- Bachelor’s degree in computer science, Information Technology, Information Security or a related field. A master's degree is an advantage.
- A security certification is required: CISSP, CISM, ISO/IEC 27001 Lead Implementer or Lead Auditor, or equivalent. Technical platform certifications are an advantage
- +8 years of professional experience in information security, of which at least three years managing or supervising a technical team.
- Practical experience implementing and operating an ISO/IEC 27001 management system, including Annex A control mapping, Statement of Applicability, and the production of audit evidence.
- Experience managing security vendors, contracts, licences and budgets.
- Experience in a multi-country or distributed organization is an advantage; experience in international research, development or non-profit organizations is a further advantage.
Benefits
CIMMYT offers an attractive remuneration package and support for continuous professional development. In addition to the provisions of the Mexican Labor Law our package of benefits includes year-end bonus (40 days), vacation premium (56%), life and medical insurance, supermarket coupons, savings fund, social Mexican benefits (IMSS, SAR / Infonavit).
Please note only short-listed candidates will be contacted.
Foreign national candidates must have legal documents to work in Mexico.
This position will remain open until filled.
CIMMYT is an equal opportunity employer. It fosters a multicultural work environment that values gender equality, teamwork, and respect for diversity.