Argentina
1 month ago

Job Overview

Job Type
Full Time
Pay
Not disclosed

Job description

Location:
Argentina
Work arrangement:
Remote

Role Summary

About Retorna

We are a fintech specialized in remittances and cross-border payments, 100% remote, with presence in LATAM and Europe. We are currently a talented team working to make moving money across borders simple, fast and humane.

We are looking for a Cyber GRC Analyst to join our Cybersecurity team to ensure that we manage our risks in a structured way and comply with the regulatory frameworks that apply to a fintech. You will design and implement governance, risk and compliance policies, controls and processes, coordinate internal and external audits, and manage third-party risk.

If you are someone with analytical and structured thinking, capable of translating regulatory requirements into controls that really work in the day-to-day operation, and with the ability to communicate risk to both technical and non-technical areas, this is your opportunity.

Responsibilities

  • Design, implement and maintain the Governance, Risk & Compliance (GRC) program in cybersecurity.
  • Develop and update information security policies, standards and procedures.
  • Identify, evaluate and monitor security risks in processes, systems and suppliers, keeping the risk register updated.
  • Coordinate internal and external audits, and manage compliance with frameworks such as ISO 27001, PCI-DSS, SOC 2 and NIST.
  • Carry out risk assessments on third parties and critical suppliers (vendor risk management).
  • Follow up on security findings and coordinate their closure with the corresponding technical areas.
  • Monitor regulatory changes in the countries where Retorna operates and update policies and controls as appropriate.
  • Design and execute security awareness programs for collaborators.
  • Collaborate with Engineering, Legal and Operations to ensure effective implementation of controls.

Requirements

  • Professional in Systems Engineering, Computer Science, Cybersecurity or related fields.
  • At least 3 years of experience in GRC, compliance or cybersecurity risk management roles.
  • We value previous experience in fintech, banking or other regulated companies.
  • Knowledge of frameworks such as ISO 27001, PCI-DSS, SOC 2 or NIST CSF.
  • Experience developing information security policies and procedures, and conducting risk assessments for third parties.
  • Knowledge of data protection and security regulations applicable to the financial sector in LatAm.
  • Desirable: use of GRC tools (Vanta, Drata, OneTrust or similar).
  • Valuable: familiarity with technical cybersecurity concepts (pentesting, vulnerability management, cloud architecture).
  • Strong written and verbal communication, and ability to influence without direct authority.
  • Autonomy to work 100% remotely and coordinate with multiple areas of the company.

Benefits

100% remote

  • Key role in building a strong security culture in a rapidly growing fintech.
  • Direct impact on the way we manage the risk of a platform that moves money across borders for millions of people.
  • People-first culture, with a focus on results and flexibility.
  • Local holidays

Unlimited days off

Can you imagine transforming regulatory compliance into a competitive advantage for a fintech that never stops growing?

Role:
Cyber GRC
Job Type:
Full Time