Cybersecurity Manager (Huila)

Cybersecurity Manager (Huila)

26 sep
|
Lean Tech
|
Huila

26 sep

Lean Tech

Huila

Company Overview:Integral Technology Services is a rapidly expanding organization situated in Medellín, Colombia.
We pride ourselves on possessing one of the most influential networks within software development and IT services for the entertainment, financial, and logistics sectors.
Our corporate projections offer a multitude of opportunities for professionals to elevate their careers and experience substantial growth.
Joining our team means engaging with expansive engineering teams across Latin America, Philippines and the United States, contributing to cutting‐edge developments in multiple industries.Position Title: CyberSecurity ManagerCategory: Cybersecurity & Risk ManagementSeniority: SeniorLocation: LATAM (Colombia Preferred)What you will be doing:You will be the first dedicated security hire and the single owner of our security posture.
Nobody else is going to do this for you, and nobody else is going to do it for you, you set the program, you run it, you maintain compliance, you're accountable for it.Your first-year headline objective: get the company to a clean SOC 2 Type II certification report.
Everything else supports that or protects the company while you do it.
Once certification is achieved, you will be fully responsible for always maintaining it.This is a hands‐on role.
You will write Terraform, tune AWS security controls, build policies, run tabletops, enforce personnel compliance, chase evidence, and sit on customer security calls — often in the same week.
If you want a role where you manage a team and review dashboards, this isn't it yet.
If you want to build a real security program from scratch and own the outcome, it is.Key Responsibilities.SOC 2 certification (the priority)Define scope and trust services criteria; run the readiness/gap assessmentClose control gaps across engineering, AWS Cloud, IT, HR, and operationsSelect and manage the audit firm; own the relationship and timelineDrive Type I, then manage the observation window through to Type IIBuild the program so year‐two renewal is routine, not a fire drillDrataFull ownership as administrator: control mapping, monitoring coverage, and evidence automationPolicy lifecycle — author, version, publish, and enforce annual attestationPersonnel onboarding/offboarding controls, enforcing personnel compliance, access reviews,



and background check trackingVendor and risk registers kept genuinely current, not backfilled the week before an auditAWS cloud securityIAM least privilege, role hygiene, and elimination of long‐lived credentialsAWS Organizations, SCPs, and account separation between environmentsGuardDuty, Security Hub, Config, CloudTrail, and centralized log retentionEncryption at rest and in transit; KMS key management and rotationVPC design, network segmentation, security group review, WAFSecrets management, S3 and RDS access controls, and public‐exposure preventionBackup, restore testing, and disaster recovery with defined RTO/RPOPatch and vulnerability management with remediation SLAs that are actually metApplication security (with Engineering)Owning Aikido for repository scanning and vulnerability resolution with engineeringBi‐annual pentesting with AikidoEmbed SAST, DAST, dependency, and IaC scanning into CI/CDSecure SDLC standards, security review of designs, and developer guardrailsCoordinate annual penetration testing and drive remediation to closureAudit logging and monitoring of PHI access inside our productsHIPAA and healthcare‐specific complianceServe as our designated HIPAA Security OfficialMaintain the HIPAA Security Rule risk analysis and risk management planBAA governance in both directions — customers and subprocessors42 CFR Part 2 controls for substance use disorder recordsBreach assessment and notification procedures, with defined timelinesTrack applicable state privacy laws affecting our customer baseIdentity, endpoints, and internal IT securitySSO and enforced MFA across all business systemsMDM, disk encryption, and endpoint protection on every company deviceQuarterly access reviews and least‐privilege enforcement on internal toolsPhysical securityOffice access control, visitor procedures, and badge/key managementCamera coverage, clean desk standards,



and secure device and document disposalRemote and home‐office security standards for our distributed staffDocument inherited AWS data center controls for audit purposesIncident responseWrite and maintain the IR plan; define severity levels and escalation pathsRun tabletop exercises at least semiannually, including a ransomware and a PHI‐exposure scenarioLead investigations and post‐incident reviewsSecurity awareness and customer trustAnnual training plus ongoing phishing simulations, with completion enforcementOwn security questionnaires, RFP responses, and customer security calls — fast turnaround here directly wins dealsMaintain our public trust page and customer‐facing security documentationRequired Skills & Experience5 – 7 years in security, with meaningful hands‐on ownership rather than pure oversightDegree in computer science or related field.Deep, practical AWS security experience in a production environmentYou have taken at least one compliance audit (SOC 2, ISO *****, HITRUST, or similar) from gap assessment through to issued reportWorking knowledge of HIPAA and handling PHI in a SaaS environmentComfort in infrastructure as code (Terraform preferred) and scripting to automate controlsAbility to write clearly — policies, customer responses, and executive updates all land on your deskJudgment about risk.
You can tell a real threat from an audit artifact and prioritize accordinglyNice to Have SkillsCISSP, CCSP, AWS Certified Security – Specialty, CISA, or equivalentHealthcare or behavioral health SaaS backgroundFamiliarity with 42 CFR Part 2 or HITRUSTPrior experience as a first security hire at a growing companySoft SkillsStrong problem‐solving and debugging skillsAbility to work independently and take ownership of projectsStrong communication skills with the ability to articulate, diagram and document complex engineering concepts.Why you will love GTS:Join a powerful tech workforce and help us change the world through technologyProfessional development opportunities with international customersCollaborative work environmentCareer path and mentorship programs that will lead to new levels.Join GTS and contribute to shaping the data landscape within a dynamic and growing organization.
Your skills will be honed, and your contributions will play a vital role in our continued success.
GTS is an equal opportunity employer.
We celebrate diversity and are committed to creating an inclusive environment for all employees.
#J-*****-Ljbffr

📌 Cybersecurity Manager (Huila)
🏢 Lean Tech
📍 Huila

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: cybersecurity manager (huila) / huila

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: cybersecurity manager (huila) / huila