Vuelve a tus resultados:InfoSec Manager / Santo Domingo

At
GBS International,
we are a global full-service company in the vacation ownership industry. Our commitment is to deliver world-class service, building strong relationships with our clients and creating unforgettable experiences.

About the Job:

At
GBS International
, we're looking for an
Information Security Manager
to lead our global information security efforts — blending hands-on technical expertise with strategic leadership. You'll play a critical role in protecting our infrastructure, cloud environments, and data while ensuring compliance with frameworks like
SOC 1/2
,
ISO 27001
, and
PCI DSS
.

This is an on-site position in Santo Domingo.

Key Responsibilities:

Governance & Risk Management:

  • Develop and maintain a robust Information Security Governance Framework aligned with business goals and compliance standards.
  • Define and enforce security policies, procedures, and controls.
  • Conduct security risk assessments, manage risk registers, and lead third-party/vendor security reviews.
  • Collaborate with GRC, Legal, Audit, and Compliance on enterprise risk initiatives.

Program Management & Technical Oversight:

  • Build and own a comprehensive
    Information Security Management Program (ISMP)
    .
  • Oversee and continuously improve:

-Network & Perimeter Security
: Firewalls, WAF, IDS/IPS, NAC, VPNs, ZTNA.

-Endpoint & Cloud Security
: EDR/XDR, DLP, encryption, patching, IAM, CASB, key management.

-Identity & Access Management
: RBAC, PAM, SSO, MFA, Zero Trust enforcement.

-Monitoring & Detection
: SIEM, logging, alerts, vulnerability scanning, threat hunting.

-SDLC Security
: SAST, DAST, IaC checks, DevSecOps practices, CI/CD pipeline security.

-Data & Application Security
: Secure APIs, encryption, classification, secure backups.

-Communication Security
: Secure integrations for omnichannel systems (voice, chat, email, bots).

  • Manage compliance and evidence collection for
    SOC 2, PCI DSS, ISO 27001
    .

Incident Response & Business Continuity

  • Lead the Incident Response program: detection, containment, remediation, and recovery.
  • Coordinate with SOC, MSPs, and forensic teams during incidents.
  • Maintain and test BC/DR plans and post-incident playbooks.

Physical Security

  • Oversee physical security for data centers, offices, and call centers.
  • Ensure best practices for access control, surveillance, and environmental risk mitigation.

Leadership & Collaboration

  • Lead and mentor a team of security analysts and engineers.
  • Work cross-functionally with Infrastructure, Development, GRC, and Executive teams.
  • Promote a security-first culture through awareness, training, and continuous improvement.

What We're Looking For:

Education & Certifications:

  • Bachelor's in Computer Science, Information Security, or related field (Master's preferred).
  • Preferred certifications:
    CISM, CISSP, CCSP, CEH, DevSecOps
    .
  • Bonus: Vendor-specific certifications (Fortinet, AWS, Azure).

Experience:

  • 7+ years
    in InfoSec roles, including
    3+ in leadership
    .
  • Strong expertise in
    firewalls
    ,
    cloud security
    ,
    IAM/PAM
    ,
    SIEM
    ,
    EDR/XDR
    , and vulnerability management.
  • Proven experience embedding security in
    SDLC/DevSecOps pipelines
    .
  • Background in
    BPO or SaaS environments
    , including
    call centers
    and
    Cloud PBX
    .
  • Regulatory experience with
    SOC 2, PCI DSS, ISO 27001
    compliance.

Skills:

  • Network protocols (TCP/IP, DNS, HTTPS, SMTP, SNMP)
  • Scripting/automation with
    Python
    ,
    PowerShell
  • Deep understanding of
    log analysis
    ,
    threat detection
    , and
    compliance mapping
  • Bilingual:
    Spanish and English
    required

Soft Skills:

  • Strategic mindset with a hands-on approach
  • Strong problem-solving and analytical capabilities
  • Leadership and executive communication skills

What We Offer:

  • Career growth in a global leader within the vacation ownership and BPO industry
  • Exposure to
    cutting-edge technologies,
    security automation, and AI integration projects
  • Collaborative, supportive, and security-aware work environment
  • Opportunity to build and scale a modern, enterprise-grade security program


Apply now
or
share with someone in your network
who might be a great fit