Experian

Data and technology

InformationSecuritySpecialistLead

Heredia, Heredia, Costa Rica FULL TIME
The Brief

“Information Security Specialist Lead at Experian. Skills: Information Security, Risk management, GRC tools. Lead security risk and controls strategies. Engage with Regional BU and Centralized security and IT control owners”

What You'll Achieve.

Ensuring a sound security posture; Meet cybersecurity and risk requirements

Industry & Context.

Data and technology
Problems you'll solve

Provide recommendations for remediation

What They're Looking For.

Must Have

5+ years of experience performing IT Audit, Information Security control assessments, Experience with GRC tools, such as Archer, Knowledge of information security frameworks such as ISO 27001/2, NIST CSF, PCI DSS, and HIPAA, Knowledge of information security risk management management/analysis frameworks such as Open FAIR, NIST 800-37, NIST 800-39, Knowledge of governance, risk, and controls principles and operational impacts of cybersecurity lapses, Knowledge of IT technologies and methods to secure them with a knowledge of Cloud security, Proficient in security control design, implementation, and evaluation, Proficient in performing impact/risk assessment, Experience facilitating small to medium size group meetings with senior leadership audiences, Bachelor's degree in computer science, management information systems or relevant field or equivalent demonstrable experience

Nice to Have

A working knowledge of AWS cloud environment is beneficial, Guide the Risk and Control teams continuing maturity using new technologies such as AI and ML, CISA, CISM, CRISC, CISSP, ISO 27001 Lead Auditor, or comparable certifications

What You'll Do.

Lead security risk and controls strategies

Engage with Regional BU and Centralized security and IT control owners

Populate the controls library

Maintain and update the integrated risk and controls framework

Review control activities

Ensure alignment with requirements

and report control activity gaps

Provide recommendations for remediation

Compile management reports

Develop and present content for controls implementation workshops

Ensure information security controls are aligned and mapped to applicable risks

Monitor and stay informed about internal and external risk indicators

Provide risk indicators as inputs to control assurance

Contribute to the efficiency of the risk and controls program

Standardize processes and methodologies

Capture stakeholder feedback

How You'll Work.

Team & Collaboration

Collaborating with partners across all Security and IT teams; Engaging with Regional BU and Centralized security and IT control owners; Facilitating small to medium size group meetings with senior leadership audiences

Communication Scope

Compile management reports; Summary analysis; Detailed presentations; Develop and present content for controls implementation workshops

Free ATS check

Applying for this Information Security Specialist Lead role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on SmartRecruiters

  • SmartRecruiters often includes a video screening step — check camera and mic permissions.
  • Link your GitHub or portfolio directly in the profile section for technical roles.
  • Applications may be reviewed by AI scoring before reaching a recruiter — use keywords from the job description.

ANONYMOUS · UNFILTERED

What do employees actually say about Experian?

Real rants from real employees. Read before you apply.

Read Company Rants →