Information Security GRC Specialist
Bitso
IT
Mexico
Posted on Mar 6, 2026
Working At Bitso
We are a diverse team that takes pride in understanding the perspectives of others. We fully embrace working remotely and we are eager to act, improve and accelerate progress inside and outside of our organization.
To drive revolutionary changes in society and make crypto useful, we delight our customers with world-class products, deep care, and intentional empathy.
Your Purpose
As our Information Security GRC Specialist, you will be an integral part of the Information Security Governance, Risk, and Compliance team. Your role is essential to ensure that company security policies, technical standards, and procedures are implemented, maintained, and continuously improved, while overseeing security risk management and compliance with applicable security standards and regulations. Additionally, you will be responsible for coordinating and supporting external/internal security assessments.
As part of the information security governance, risk, and compliance team, you will:
Information Security Program Manager
Who You Are
Who We Are
With over 9 million users, Bitso is the leading cryptocurrency platform in Latin America. We are developing the cryptocurrency ecosystem in the region and enabling financial inclusion. We believe crypto is the future of finance, and we’re committed to making it useful by providing equal access to safe and intuitive financial products.
When we hire people for our team, we specifically test for the following traits in addition to our cultural values:
At Bitso, you are taking the front seat on the edge of crypto innovation, creating the next generation of crypto-powered products.
So for those willing to commit, adapt and pioneer the most important change of the century we offer:
We are a diverse team that takes pride in understanding the perspectives of others. We fully embrace working remotely and we are eager to act, improve and accelerate progress inside and outside of our organization.
To drive revolutionary changes in society and make crypto useful, we delight our customers with world-class products, deep care, and intentional empathy.
Your Purpose
As our Information Security GRC Specialist, you will be an integral part of the Information Security Governance, Risk, and Compliance team. Your role is essential to ensure that company security policies, technical standards, and procedures are implemented, maintained, and continuously improved, while overseeing security risk management and compliance with applicable security standards and regulations. Additionally, you will be responsible for coordinating and supporting external/internal security assessments.
As part of the information security governance, risk, and compliance team, you will:
- Use holistic approaches interconnecting governance, risk, and compliance through project management and the application of industry best practices, standards, and regulations.
- Connect information security with other involved teams.
- Drive alignment of all lines of business with the defined information security culture and governance model.
- Use Agile approaches in your projects.
- Focus on proactivity, quality, and excellence in your results.
- Explore strategies and solutions for effective Governance, Risk, and Compliance (GRC) engineering in the organization.
- Organizational risk, compliance, and regulatory internal and external teams to ensure proper adherence to information security compliance processes.
- Technical groups to assist in implementing technical standards, controls, and configurations aligned with security policies, legal requirements, and audit standards.
Information Security Program Manager
Who You Are
- Proven English proficiency. You are comfortable presenting to English-speaking audiences and creating deliverables in that language. You are able to maintain a fluid conversation in English.
- Minimum of 5 years of experience in Information Security GRC roles.
- At least 3 years of experience leading or coordinating internal compliance assessments, internal audits, or acting as a strategic consultant with a focus on maturity assessments.
- At least 3 years of experience working with Mexican regulatory, cybersecurity, and information security requirements applicable to fintech or regulated financial entities.
- You have expert knowledge of information security frameworks and best practices (e.g., ISO/IEC 27000 series, COBIT, NIST SP 800-xx, NIST CSF, and CIS).
- You have working knowledge in scripting to read and modify simple scripts, understand JSON and YAML configuration files, use command-line tools and write basic automation tools.
- You have working knowledge of data analysis to extract relevant information from logs and identify trends and patterns, to turn technical data into business insights.
- You have proficiency in IT audit, compliance, and maturity assessments.
- You hold a Certified Information Systems Auditor (CISA) certification or equivalent credentials with a strong focus on IT audit, assurance, or information security governance.
- You hold a AWS Certified Cloud Practitioner or working knowledge with AWS Cloud Infrastructure.
- You possess a competent understanding of the risk management process, with emphasis on risk treatment, monitoring, and control assessment phases.
- You possess strong communication skills. These are crucial as the role involves coordinating with internal teams, external auditors, and various technical and non-technical groups. Being able to effectively communicate findings, recommendations, and remediation strategies to different levels of stakeholders is key.
- You are detail-oriented. Given the role's responsibilities in monitoring compliance, identifying gaps, and managing security controls, attention to detail is vital. You should be meticulous in your work to ensure that effective compliance and security measures are in place.
- You are an agile and avid learner. Information security is a rapidly evolving field, so you have a willingness to continuously learn and stay updated on the latest trends, threats, and best practices in the industry. Keeping up-to-date will help in effectively implementing security measures.
- You are passionate about information security, and you can see beyond the technology and controls. You find confluence points and create synergies. You believe in teamwork, and you believe that by empowering an organization to protect itself, you are on the side of a noble and much-needed cause.
- Minimum 2 years of strategic consulting experience, particularly within financial institutions.
- Additional certifications such as Certified ISO 27k Lead Auditor, CISSP, or PMP.
- Working knowledge with maturity models and frameworks (e.g., CMMI), cloud security best practices, project management (PMI), and Agile methodologies (e.g., Kanban).
- Familiarity with international regulations such as GDPR.
- Maintain and continuously improve the Information Security GRC Program.
- Act as a key liaison with regulatory authorities on information security–related topics.
- Support the adoption and consistent implementation of security policies, standards, and procedures across all lines of business.
- Assess and validate compliance with applicable regulatory, contractual, and information security requirements.
- Conduct regular information security and maturity assessments of Bitso’s information security controls, and follow up on treatment plans across the organization.
- Continually validate the organization against the internal information security governance framework to ensure compliance, monitor for non-conformities, and prepare reports and metrics with recommended remediation strategies.
- Collaborate with internal and external security audits, proactive technical assessments, and tracking findings and recommendations for appropriate action will be crucial aspects of your responsibilities.
- Guide and support non–security engineering teams, liaise with cross-functional stakeholders as needed, and ensure the quality, consistency, and effectiveness of information security programs and projects.
- Shift from manual compliance assessments to an automated, continuous, and integrated practice, embedding compliance directly into the technical stack.
Who We Are
With over 9 million users, Bitso is the leading cryptocurrency platform in Latin America. We are developing the cryptocurrency ecosystem in the region and enabling financial inclusion. We believe crypto is the future of finance, and we’re committed to making it useful by providing equal access to safe and intuitive financial products.
When we hire people for our team, we specifically test for the following traits in addition to our cultural values:
- Mission-Driven: We seek individuals who are passionate about crypto and Bitso’s mission and resilient in facing industry challenges
- High Sense of Urgency: We prioritize candidates who demonstrate a high sense of urgency and responsibility.
- Exceptional Hard Skills: We seek individuals who possess exceptional skills in their respective fields, with no room for mediocrity.
- Self-Management: We look for individuals who can independently manage their work, career, and professional development.
At Bitso, you are taking the front seat on the edge of crypto innovation, creating the next generation of crypto-powered products.
So for those willing to commit, adapt and pioneer the most important change of the century we offer:
- Me Time program, including unlimited paid time off.
- Remote-first work environment.
- Employee Stock Option program.
- Zero trading fees through our Bitso Alpha app.
- Extended Family Leave Policy: all birthing parents, non-birthing parents and adopting parents are eligible for a 4-months leave.
- Premium health, dental and life insurances in Mexico, Gibraltar, Colombia, USA, Brazil and Argentina.
- These are the applicable requisites, although equivalent competencies in any of the above will also be considered.
- To see our Privacy Policy please click here.