Logo for Outcoding

Senior Associate – Security Risk Management

Role overview

Qualifications

  • 3–5 years of experience in Security Reviews, IT Risk Assessments, IT Audits, Risk Audits, or similar activities
  • Experience reviewing and interpreting SOC, Penetration Testing, and Vulnerability Management reports
  • Strong written and verbal communication skills

Responsibilities

  • Perform Security Reviews, IT Risk Assessments, IT Audits, and related security evaluation activities
  • Evaluate security posture against established standards, policies, methodologies, and control objectives
  • Identify potential security and control gaps and evaluate their impact within the broader risk assessment
  • Document assessments, findings, risks, and recommendations clearly and accurately

Key facts

Hard skills

Other skills

  • Analytical Skills
  • Troubleshooting (Problem Solving)
  • Organizational Skills
  • Verbal Communication Skills

About the company

Outcoding logo

Outcoding

IT Services & IT Consulting

Welcome to Outcoding, an EX Squared company - your premier nearshore outsourcing solution provider! Combining technical expertise with creative execution, we serve as a subsidiary of the renowned technology services provider, EX Squared. With over two decades of experience in the software industry, we excel in delivering high-quality solutions for businesses worldwide.Our team consists of creative minds and technical experts who imagine, build, and evolve digital futures for organizations across the globe. Experience the best of technology and innovation with Outcoding.

Company details

Company typeSME
IndustryIT Services & IT Consulting
Company size501 - 1000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

At EX Squared LATAM, we partner with leading organizations across global and regional markets to connect exceptional professionals with high-impact career opportunities.

Our client is a leading global organization in the professional services and consulting industry, supporting businesses with complex technology, cybersecurity, risk, compliance, and transformation initiatives.

For this position, EX Squared LATAM is supporting our client with the recruitment and selection process. The selected professional will be hired directly by the client under their local payroll in Mexico, becoming part of their internal team.

Role Overview

We’re currently looking for a Senior Associate – Security Risk Management to perform security reviews and IT risk assessments across projects, vendors, applications, and technology environments.

This is an Individual Contributor role focused on assessing security posture, reviewing technical evidence, identifying control gaps, and determining whether projects and third parties align with established security standards, policies, methodologies, and control requirements.

The ideal candidate will bring approximately 3–5 years of experience in Security Reviews, IT Risk Assessments, IT Audits, Risk Audits, or similar activities, along with enough technical cybersecurity knowledge to interpret findings and reports produced by specialized teams such as Penetration Testing, SOC, and Vulnerability Management.

This position does not perform Penetration Testing or Ethical Hacking directly. Instead, the professional must be able to understand technical security reports and use that information as part of broader risk and control assessments.

Location

Mexico. Candidates located in Mexico City or Guadalajara are highly preferred.

  • For professionals based in Mexico City or Guadalajara, the position follows a hybrid model with onsite attendance approximately 2–3 days per week.
  • Candidates based in other cities in Mexico may be considered for a remote arrangement; however, Mexico City and Guadalajara profiles will receive priority.

Contract Duration

Permanent, direct employment with the client.

This is a 100% payroll position in Mexico.

Working Hours

Monday through Friday, 8:00 a.m. to 5:00 p.m.

Language Requirement

Advanced English.

Candidates must be comfortable conducting business and technical conversations with both technical and administrative stakeholders, including U.S.-based teams.

What you'll do

  • Perform Security Reviews, IT Risk Assessments, IT Audits, and related security evaluation activities for projects, vendors, applications, and technology environments.
  • Evaluate security posture against established standards, policies, methodologies, control objectives, and security best practices.
  • Review and interpret technical documentation and reports generated by teams such as Penetration Testing, Security Operations Centers (SOC), and Vulnerability Management.
  • Identify potential security and control gaps and evaluate their impact within the broader risk assessment.
  • Assess security considerations across areas such as application security, architecture, access control, cryptography, data protection, monitoring, vulnerabilities, and secure development practices.
  • Review projects and vendors against relevant information security and regulatory requirements.
  • Work with technical and business stakeholders to clarify findings, collect supporting evidence, and communicate security requirements.
  • Document assessments, findings, risks, and recommendations clearly and accurately.
  • Escalate issues when appropriate and maintain documentation that can withstand internal or external audit review.
  • Manage multiple concurrent assessments and priorities in a customer-focused and collaborative environment.
  • Stay current with evolving information security requirements, threats, technologies, controls, and practices.

What you'll bring

  • Approximately 3–5 years of experience performing Security Reviews, IT Risk Assessments, IT Audits, Risk Audits, or similar activities.
  • Experience reviewing and interpreting SOC, Penetration Testing, and Vulnerability Management reports.
  • Broad understanding of multiple information security domains, including:
    • Application security
    • Security architecture
    • Secure coding concepts
    • Access control
    • Data protection
    • Cryptography
    • Monitoring
    • Vulnerability management
  • Understanding of security principles, IT security controls, and related technologies and products.
  • Knowledge of the OWASP Top 10 web application security risks.
  • Familiarity with standards and regulatory frameworks such as NIST 800 series, ISO 27000, PCI-DSS, and HIPAA.
  • Familiarity with security technologies such as Active Directory, LDAP, Okta or other access management solutions, IDS, firewalls, load balancers, proxies, DLP, Qualys, Carbon Black, Symantec CCS, or comparable technologies.
  • Strong analytical, troubleshooting, organizational, and documentation skills.
  • Ability to prioritize and manage multiple projects or assessments simultaneously.
  • Strong written and verbal communication skills and the ability to collaborate effectively with stakeholders at different organizational levels.

What will make you stand out

  • Experience with GRC platforms such as Archer.
  • Certifications such as CISSP, CCSP, CISA, CCSK, or similar credentials.
  • Strong experience reviewing third-party or vendor security risks.
  • Exposure to several cybersecurity domains rather than expertise limited to only one technical area.
  • Experience working with U.S.-based or multicultural teams.
  • Ability to take highly technical security findings and translate them into understandable risk, control, and business implications.
  • Experience operating in environments where assessments and documentation may be subject to internal or external audit.

Why this opportunity?

This is an opportunity to join a large, globally recognized organization in the professional services and consulting industry, working with multidisciplinary and international teams on cybersecurity and technology risk initiatives.

The role provides exposure to a broad range of security domains, enterprise technologies, projects, and vendors while allowing the professional to develop deeper expertise in Security Risk Management, security assessments, IT controls, and cybersecurity governance.

It is particularly well suited for someone who enjoys understanding technical security issues but wants to apply that knowledge from a risk assessment and advisory perspective rather than an offensive security role.

What the Client Offers

  • Career growth opportunities.
  • Annual performance review with potential salary adjustments and internal growth.
  • Meal/grocery vouchers.
  • Savings fund.
  • Vacation premium and statutory benefits.
  • Remote-work allowance, when applicable.

Selection Process

The selection process is expected to include:

  • Initial interview with the local/direct leader.
  • Technical interviews with the U.S.-based team, typically involving two interviewers per session.
  • Final interview with the U.S. Area Director.
  • Background check.

Eligibility Note

This opportunity is available to candidates currently residing in Mexico.

Candidates located in Mexico City and Guadalajara are strongly preferred due to the hybrid working model. Candidates located elsewhere in Mexico may also be considered for remote work depending on profile and business requirements.

Ready for your next career opportunity?

Apply through EX Squared LATAM and take the next step toward joining a global organization where cybersecurity knowledge, technology risk, and security governance come together.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Risk Management Specialist Related jobs

Other jobs at Outcoding

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.