SMASH, Who we are?
We are agents for tech professionals in Costa Rica and Colombia that help them build careers in the United States.
We believe in long-lasting relationships with our talent. We invest time getting to know them and understanding what they seek as their professional next step.
We aim to find the perfect match. As agents, we pair our talent with our US clients, not only by their technical skills but as a cultural fit. Our core competency is to find the right talent fast.
We purposefully move away from the “contractor” or “outsourcing” type of relationship. Our clients don’t want contractors or “just a service.” Neither does our talent.
Our Benefits
This position is Remote to work with a US Company; you will require to have Citizenship or a work permit from Costa Rica to apply for this role.
Role summary
You will lead cybersecurity governance and risk initiatives by strengthening enterprise control frameworks, evaluating IT and cyber risks, and ensuring compliance with regulatory standards. This hands-on role partners with operational and technology teams to improve governance practices, enhance risk visibility, and support secure, compliant business operations.
Responsibilities
- Define and maintain ownership of cybersecurity controls across operational and technology teams.
- Perform hands-on cyber risk and control evaluations to assess control effectiveness and identify improvement opportunities.
- Conduct regulatory analysis and align cybersecurity controls with frameworks such as NCUA, FFIEC, and internal governance requirements.
- Develop and maintain governance frameworks, including control libraries, RACI matrices, policies, standards, and procedures.
- Drive governance practices across Enterprise Secure Software Development Lifecycle (ESDLC) and IT Operations.
- Perform cyber risk assessments and map identified risks to appropriate technical and operational controls.
- Develop and maintain enterprise Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), and executive reporting dashboards.
- Produce enterprise IT governance reports that communicate risk posture, control effectiveness, compliance status, and operational performance.
- Translate enterprise security policies into actionable operational standards and ensure consistent implementation across IT teams.
- Partner with technology, security, audit, and compliance teams to strengthen governance processes and support regulatory readiness.
- Monitor governance metrics and recommend continuous improvements to cybersecurity and operational risk programs.
Requirements – Must-haves
- Proven experience in Cyber Governance, IT Risk Management, or Information Security Governance.
- Hands-on experience performing risk and control evaluations within enterprise IT environments.
- Experience conducting regulatory analysis and implementing cybersecurity governance practices.
- Strong knowledge of cybersecurity control frameworks and regulatory standards such as NCUA, FFIEC, NIST, ISO 27001, or similar.
- Experience implementing governance practices within Enterprise Secure Software Development Lifecycle (ESDLC) and IT Operational environments.
- Experience designing and maintaining governance frameworks, including policies, standards, procedures, control libraries, and RACI models.
- Experience developing enterprise-level KRIs, KPIs, dashboards, and IT governance reporting.
- Strong understanding of enterprise IT controls, operational risk management, and control ownership.
- Excellent analytical, documentation, and stakeholder communication skills.
- Experience collaborating with technology, security, audit, compliance, and business teams.
Nice-to-haves (optional)
- Experience supporting financial institutions or highly regulated industries.
- Professional certifications such as CISSP, CISM, CRISC, CGEIT, or similar.
- Experience with Governance, Risk, and Compliance (GRC) platforms.
- Knowledge of enterprise reporting and business intelligence tools.
Languages