Job Overview
Job description
- Location:
- Argentina
- Work arrangement:
- Remote
Role Summary
About Retorna
We are a fintech specialized in remittances and cross-border payments, 100% remote, with presence in LATAM and Europe. We are currently a talented team working to make moving money across borders simple, fast and humane.
We are looking for a Cyber GRC Analyst to join our Cybersecurity team to ensure that we manage our risks in a structured way and comply with the regulatory frameworks that apply to a fintech. You will design and implement governance, risk and compliance policies, controls and processes, coordinate internal and external audits, and manage third-party risk.
If you are someone with analytical and structured thinking, capable of translating regulatory requirements into controls that really work in the day-to-day operation, and with the ability to communicate risk to both technical and non-technical areas, this is your opportunity.
Responsibilities
- Design, implement and maintain the Governance, Risk & Compliance (GRC) program in cybersecurity.
- Develop and update information security policies, standards and procedures.
- Identify, evaluate and monitor security risks in processes, systems and suppliers, keeping the risk register updated.
- Coordinate internal and external audits, and manage compliance with frameworks such as ISO 27001, PCI-DSS, SOC 2 and NIST.
- Carry out risk assessments on third parties and critical suppliers (vendor risk management).
- Follow up on security findings and coordinate their closure with the corresponding technical areas.
- Monitor regulatory changes in the countries where Retorna operates and update policies and controls as appropriate.
- Design and execute security awareness programs for collaborators.
- Collaborate with Engineering, Legal and Operations to ensure effective implementation of controls.
Requirements
- Professional in Systems Engineering, Computer Science, Cybersecurity or related fields.
- At least 3 years of experience in GRC, compliance or cybersecurity risk management roles.
- We value previous experience in fintech, banking or other regulated companies.
- Knowledge of frameworks such as ISO 27001, PCI-DSS, SOC 2 or NIST CSF.
- Experience developing information security policies and procedures, and conducting risk assessments for third parties.
- Knowledge of data protection and security regulations applicable to the financial sector in LatAm.
- Desirable: use of GRC tools (Vanta, Drata, OneTrust or similar).
- Valuable: familiarity with technical cybersecurity concepts (pentesting, vulnerability management, cloud architecture).
- Strong written and verbal communication, and ability to influence without direct authority.
- Autonomy to work 100% remotely and coordinate with multiple areas of the company.
Benefits
100% remote
- Key role in building a strong security culture in a rapidly growing fintech.
- Direct impact on the way we manage the risk of a platform that moves money across borders for millions of people.
- People-first culture, with a focus on results and flexibility.
- Local holidays
Unlimited days off
Can you imagine transforming regulatory compliance into a competitive advantage for a fintech that never stops growing?
- Role:
- Cyber GRC
- Job Type:
- Full Time