Security Master Plan Specialist
This job was originally posted in Spanish and automatically translated to English. You'll most likely need Spanish to apply.
Job Description
- Leadership of one or more blocks of the Cybersecurity Master Plan (maturity diagnosis, definition of strategic lines, roadmap, and prioritized initiatives), being responsible for the end-to-end deliverable to the client.
- Definition of the maturity analysis methodology according to reference frameworks (NIST CSF, ISO/IEC 27001, ENS, CIS Controls) and conducting interviews with the managers of each domain to identify gaps relative to the target state.
- Definition of the cybersecurity dashboard (KPI/KRI) aligned with the client's business objectives and, based on this, formulation of prioritized recommendations with their business impact and risk justification.
- Autonomous conduction of work sessions with the CISO and middle management, and co-presentation of results and recommendations to Senior Management, adapting the message to the executive or technical profile of the interlocutor and sustaining the argument against objections.
- Preparation of periodic security posture reports that serve as a basis for strategic decision-making, ensuring the quality (QA) of the workflow deliverables before delivery.
- Support in aligning the cyber strategy with corporate governance frameworks (ISO 38500, COBIT, NIST AI RMF for AI projects), with the ability to perform cross-mapping between frameworks autonomously.
- Design of the cybersecurity governance model (roles, responsibilities, committees, and reporting flows) and facilitation of workshops with the involved areas for validation.
- Coordination of the work of 1-2 junior profiles on the team: distribution of tasks, quality review of their deliverables, and mentoring in methodology.
- Day-to-day management of the workflow: planning of their part of the schedule, progress control, and management of the relationship with the interlocutors in their area at the client.
- Experience: +5 years in cybersecurity or GRC consulting, with at least 2 years in the development of Master Plans or maturity analysis.
- English level: C1 (or high B2 with demonstrated fluency in executive meetings).
- Valuable certifications: CRISC, CISM or equivalent;
About Accenture
Accenture is a leading global professional services company that helps the world's leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services-creating tangible value at speed and scale. We are a talent- and innovation-led company with approximately 791,000 people serving clients in more than 120 countries. Technology is at the core of change today, and we are one of the world's leaders in helping drive that change, with strong ecosystem relationships. We combine our strength in technology and leadership in cloud, data and AI with unmatched industry experience, functional expertise and global delivery capability. Our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Song, together with our culture of shared success and commitment to creating 360° value, enable us to help our clients reinvent and build trusted, lasting relationships. We measure our success by the 360° value we create for our clients, each other, our shareholders, partners and communities.Visit us atwww.accenture.com
Equal Employment Opportunity Statement
We believe that no one should be discriminated against for their differences. All employment decisions will be made regardless of age, race, creed, color, religion, sex, national origin, ancestry, disability, military veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship, or any other criteria protected by applicable law. Our rich diversity makes us more innovative, competitive, and creative, which helps us better serve our clients and communities.
View original advert (Spanish)
- Liderazgo de uno o varios bloques del Plan Director de Ciberseguridad (diagnóstico de madurez, definición de líneas estratégicas, hoja de ruta e iniciativas priorizadas), siendo responsable del entregable end-to-end ante el cliente.
- Definición de la metodología de análisis de madurez conforme a marcos de referencia (NIST CSF, ISO/IEC 27001, ENS, CIS Controls) y conducción de las entrevistas con los responsables de cada dominio para la identificación de gaps respecto al estado objetivo.
- Definición del cuadro de mando de ciberseguridad (KPI/KRI) alineado con los objetivos de negocio del cliente y, a partir de él, formulación de recomendaciones priorizadas con su justificación de impacto en negocio y riesgo.
- Conducción autónoma de sesiones de trabajo con el CISO y mandos intermedios, y co-presentación de resultados y recomendaciones ante la Alta Dirección, adaptando el mensaje al perfil ejecutivo o técnico del interlocutor y sosteniendo la argumentación ante objeciones.
- Elaboración de informes de postura de seguridad periódicos que sirvan de base para la toma de decisiones estratégicas, garantizando la calidad (QA) de los entregables del flujo de trabajo antes de su entrega.
- Soporte en la alineación de la estrategia cyber con los marcos de gobierno corporativo (ISO 38500, COBIT, NIST AI RMF para proyectos con IA), con capacidad de mapeo cruzado entre marcos de forma autónoma.
- Diseño del modelo de gobierno de ciberseguridad (roles, responsabilidades, comités y flujos de reporte) y facilitación de los talleres con las áreas implicadas para su validación.
- Coordinación del trabajo de 1-2 perfiles junior del equipo: reparto de tareas, revisión de calidad de sus entregables y mentoring en metodología.
- Gestión del día a día del flujo de trabajo: planificación de su parte del cronograma, control de avance y gestión de la relación con los interlocutores de su ámbito en el cliente.
- Experiencia: +5 años en consultoría de ciberseguridad o GRC, con al menos 2 años en elaboración de Planes Directores o análisis de madurez.
- Nivel inglés: C1 (o B2 alto con soltura demostrada en reuniones ejecutivas).
- Certificaciones valorables: CRISC, CISM o equivalente;
About Accenture
Accenture is a leading global professional services company that helps the world's leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services-creating tangible value at speed and scale. We are a talent- and innovation-led company with approximately 791,000 people serving clients in more than 120 countries. Technology is at the core of change today, and we are one of the world's leaders in helping drive that change, with strong ecosystem relationships. We combine our strength in technology and leadership in cloud, data and AI with unmatched industry experience, functional expertise and global delivery capability. Our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Song, together with our culture of shared success and commitment to creating 360° value, enable us to help our clients reinvent and build trusted, lasting relationships. We measure our success by the 360° value we create for our clients, each other, our shareholders, partners and communities.Visit us atwww.accenture.com
Declaración de igualdad de oportunidades en el empleo
Creemos que nadie debe ser discriminado por sus diferencias. Todas las decisiones de empleo se tomarán sin importar la edad, raza, credo, color, religión, sexo, origen nacional, ascendencia, discapacidad, condición de veterano militar, orientación sexual, identidad o expresión de género, información genética, estado civil, ciudadanía ni ningún otro criterio protegido por la legislación aplicable. Nuestra rica diversidad nos hace más innovadores, competitivos y creativos, lo que nos ayuda a servir mejor a nuestros clientes y comunidades.