Jobs Companies Levi Strauss & Co. Sr. Cyber Risk Analyst

Sobre este puesto de Sr. Cyber Risk Analyst en Levi Strauss & Co.

Levi Strauss & Co. · Presencial · Office, Mexico, D.F., Mexico

Job Location: Mexico City, Mexico

 

Calling all originals: At Levi Strauss & Co., you can be yourself — and be part of something bigger. We’re a company of people who like to forge our own path and leave the world better than we found it. Who believe that what makes us different makes us stronger. So add your voice. Make an impact. Find your fit — and your future. 

The Sr. Cyber Risk Analyst will be a member of the Cyber Risk team. The position is responsible for implementing the cyber risk operational strategy, which includes managing the Governance, Risk, and Compliance (GRC) tool, performing internal and 3rd party security risk assessments,  and driving effective alignment to the Risk Management policy. The position reports to the Manager, Cyber Risk. 

 

About the Job 

  • Program alignment to ISO 27005, CIS Top 18 Controls, and the NIST Cybersecurity Framework. 

  • Oversees initial project development surrounding new processes and integrating new processes with existing ones. Communicates these changes to impacted clients and other resources. 

  • Support the OneTrust GRC tool responsibilities, escalating any strategic or large decision-making to the risk manager.  

  • Assist in tiering the backlog of LS&Co. vendors using the defined vendor tiering criteria and perform internal and 3rd party security risk assessments. Prioritize and select controls based on risk assessment frameworks, and partner with internal stakeholders to document each control.  

  • Determine the effectiveness of in-scope controls by implementing the risk management framework aligned to ISO 27005, including management of the security risk policy, control mapping, and implementation of the risk management process in the OneTrust GRC tool. 

  • Drive the policy lifecycle management process to manage & govern policies, policy lifecycle, attestation, communication, issue and actions, policy processes, and overall governance; manage the Cyber Risk Policy and make revisions as needed. 

  • Manage the day-to-day exception process within the GRC tool for all GIS teams, while maintaining updates to procedures. 

  • Assist in the assessment and quantification of GIS identified top risks and critical assets by performing risk analysis to increase awareness and facilitate risk identification activities.  

  • Partner with regional BISOs to understand local compliance requirements and perform a risk analysis to support global compliance and other operational risk activities. 

  • Manage risk remediation plans, including setting deadlines, following up on progress, and reporting on outcomes to ensure issues are mitigated and managed, risks are accounted for, and security exceptions are tracked in accordance with frameworks, policies, and standards. 

  • Responsible for the ongoing management and maintenance of the enterprise cyber risk register, ensuring risks are consistently identified, assessed, and kept current with clear remediation tasks assigned to the appropriate owners and tracked through to resolution.

  • Assist in the development and delivery of risk reporting for senior leadership, translating the state of the risk landscape into actionable insights that drive informed decision-making at the executive level.
  • Partner with stakeholders to develop a continuous control monitoring (CCM) approach by leveraging the GRC tool to build custom workflows and metric dashboards to drive action between risk assessments. 
  • Manage and create cyber risk key risk indicators (KRIs) using OneTrust and PowerBI. 

  • Drive evidence collection and review as part of the annual PCI-DSS audit, and other compliance obligations as needed. 

 

About You 

  • BS or MA in Business, Computer Science, Information Security or a related field. 

  • Industry security certifications (i.e., CISSP, CISM, CRISC, etc.) or aspiring to receive one within a year. 

  • 3+ years of experience working in risk management, governance, and regulatory requirements related to cybersecurity with a specific focus on business outcomes and service delivery.   

  • 3+ years of experience performing internal and 3rd party risk assessments.  

  • Experience with compliance obligations such as PCI-DSS, HIPAA, and SOX 
  • 3+ years of experience with regulatory compliance and information security management frameworks (e.g., International Organization for Standardization [ISO] 27005, NIST Cybersecurity Framework, CIS Top 18, and MITRE ATT&CK. 

  • 1-3 years of experience managing a global team of associates and contractors. 

  • Knowledge of cybersecurity principles, including risk assessment and management, threat and vulnerability management, incident response, and identity and access management 

  • Technical proficiency with security-related systems and applications 

  • Experience in developing, documenting and maintaining security procedures 

  • Excellent analytical and problem-solving skills (ability to find innovative ways to resolve problems) 

  • Proven ability to collect, manage, and present data, metrics, and KPIs that tell the story of the company’s security posture. 

  • Excellent communication skills in the new world of remote & on-line working and highly collaborative with the ability to influence across the matrix and to build connections to enable success 

LOCATION

Mexico, D.F., Mexico

FULL TIME/PART TIME

Full time

Current LS&Co Employees, apply via your Workday account.

¿Listo para postularte en Levi Strauss & Co.?
Postúlate en Levi Strauss & Co.

Sobre Levi Strauss & Co.

Our common thread: We're originals. From day one, we've been doing it our way — creating our own drumbeat and building something that's different from the rest. That's why we're looking for people who are excited about finding their career fit and transforming the future. Because at Levi Strauss & Co., you can do what you love while staying true to who you are.

Ver todos los empleos en Levi Strauss & Co. →

Empleos similares

Wayve
GRC Assurance Manager
Wayve
⚡ Postúlate pronto London Presencial
● Nuevo 👁 Visto ✓ Postulado hace 1h
Diligent Corporation
Delivery Analyst (GRC)
Diligent Corporation
⚡ Postúlate pronto Budapest, Hungary Híbrido
● Nuevo 👁 Visto ✓ Postulado hace 2h
JASARA PMC
Senior Manager - Project Controls (Planning, Risk & Business Reporting)
JASARA PMC
⚡ Postúlate pronto Riyadh, Riyadh Province, Saudi... Presencial
● Nuevo 👁 Visto ✓ Postulado hace 2h
Roblox
Senior Security GRC Analyst
Roblox
⚡ Postúlate pronto San Mateo, CA, United States Presencial $209,250–$271,710
● Nuevo 👁 Visto ✓ Postulado hace 3h
Paytm
Manager - Market Risk ( Broking industry preferred)
Paytm
⚡ Postúlate pronto Mumbai, Maharashtra Presencial
● Nuevo 👁 Visto ✓ Postulado hace 4h
Bank of America
Business Control Manager - Risk and Regulatory Issues Manager
Bank of America
⚡ Postúlate pronto Charlotte Presencial
● Nuevo 👁 Visto ✓ Postulado hace 4h
Davy
Risk Reporting Junior Analyst - 12-18m FTC
Davy
⚡ Postúlate pronto Dublin, County Dublin, Ireland Presencial
● Nuevo 👁 Visto ✓ Postulado hace 7h
Avetta, LLC
Product Manager - Compliance and Risk Products
Avetta, LLC
⚡ Postúlate pronto US - Remote Híbrido $87,500–$180,000
● Nuevo 👁 Visto ✓ Postulado hace 9h
SC
Manager, Line 1 Risk and Compliance - Asset Services
SS&C Technologies
⚡ Postúlate pronto Sydney, Australia Híbrido
● Nuevo 👁 Visto ✓ Postulado hace 10h

Regístrate para recibir sugerencias adaptadas a los empleos que abres y las búsquedas que guardas.

Más empleos en Levi Strauss & Co.

Ver todos los empleos en Levi Strauss & Co. →

Postúlate ahora
🤖

Un momento — para

JobsRadar se creó para personas reales que están pasando un mal momento en su búsqueda de empleo — no para solicitudes automatizadas. Estás haciendo clic demasiado rápido y ahora estás bloqueado temporalmente.

Vuelve más tarde. Si de verdad estás buscando empleo, cuentas con nosotros — solo compórtate como una persona.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Toma ventaja en tu búsqueda de empleo.

Únete a nuestro canal de Telegram para lo que te ayuda a conseguir el puesto — referencias salariales, el pulso semanal del mercado y avisos de nuevas funciones. Sin spam, solo señal.

Únete al canal — es gratis