Start Your Search Here

Job Search

Lean Solutions Group

, , Colombia / Global

CyberSecurity Manager

  • Remote

Job Description

Company Overview: Global Technology Services is a rapidly expanding organization situated in Medellín, Colombia. We pride ourselves on possessing one of the most influential networks within software development and IT services for the entertainment, financial, and logistics sectors. Our corporate projections offer a multitude of opportunities for professionals to elevate their careers and experience substantial growth. Joining our team means engaging with expansive engineering teams across Latin America, Philippines and the United States, contributing to cutting-edge developments in multiple industries.

Position Title: CyberSecurity Manager Category: Cybersecurity & Risk Management Seniority: Senior Location: LATAM (Colombia Preferred) What you will be doing: You will be the first dedicated security hire and the single owner of our security posture. Nobody else is going to do this for you, and nobody else is going to do it for you, you set the program, you run it, you maintain compliance, you’re accountable for it.

Your first-year headline objective: get the company to a clean SOC 2 Type II certification report. Everything else supports that or protects the company while you do it. Once certification is achieved, you will be fully responsible for always maintaining it.

This is a hands-on role. You will write Terraform, tune AWS security controls, build policies, run tabletops, enforce personnel compliance, chase evidence, and sit on customer security calls — often in the same week. If you want a role where you manage a team and review dashboards, this isn’t it yet. If you want to build a real security program from scratch and own the outcome, it is.

Key Responsibilities SOC 2 certification (the priority) Define scope and trust services criteria; run the readiness/gap assessment

Close control gaps across engineering, AWS Cloud, IT, HR, and operations

Select and manage the audit firm; own the relationship and timeline

Drive Type I, then manage the observation window through to Type II

Build the program so year-two renewal is routine, not a fire drill

Drata Full ownership as administrator: control mapping, monitoring coverage, and evidence automation

Policy lifecycle — author, version, publish, and enforce annual attestation

Personnel onboarding/offboarding controls, enforcing personnel compliance, access reviews, and background check tracking

Vendor and risk registers kept genuinely current, not backfilled the week before an audit

AWS cloud security IAM least privilege, role hygiene, and elimination of long-lived credentials

AWS Organizations, SCPs, and account separation between environments

GuardDuty, Security Hub, Config, CloudTrail, and centralized log retention

Encryption at rest and in transit; KMS key management and rotation

VPC design, network segmentation, security group review, WAF

Secrets management, S3 and RDS access controls, and public-exposure prevention

Backup, restore testing, and disaster recovery with defined RTO/RPO

Patch and vulnerability management with remediation SLAs that are actually met

Application security (with Engineering) Owning Aikido for repository scanning and vulnerability resolution with engineering

Bi-annual pentesting with Aikido

Embed SAST, DAST, dependency, and IaC scanning into CI/CD

Secure SDLC standards, security review of designs, and developer guardrails

Coordinate annual penetration testing and drive remediation to closure

Audit logging and monitoring of PHI access inside our products

HIPAA and healthcare-specific compliance Serve as our designated HIPAA Security Official

Maintain the HIPAA Security Rule risk analysis and risk management plan

BAA governance in both directions — customers and subprocessors

42 CFR Part 2 controls for substance use disorder records

Breach assessment and notification procedures, with defined timelines

Track applicable state privacy laws affecting our customer base

Identity, endpoints, and internal IT security SSO and enforced MFA across all business systems

MDM, disk encryption, and endpoint protection on every company device

Quarterly access reviews and least-privilege enforcement on internal tools

Physical security Office access control, visitor procedures, and badge/key management

Camera coverage, clean desk standards, and secure device and document disposal

Remote and home-office security standards for our distributed staff

Document inherited AWS data center controls for audit purposes

Incident response Write and maintain the IR plan; define severity levels and escalation paths

Run tabletop exercises at least semiannually, including a ransomware and a PHI-exposure scenario

Lead investigations and post-incident reviews

Security awareness and customer trust Annual training plus ongoing phishing simulations, with completion enforcement

Own security questionnaires, RFP responses, and customer security calls — fast turnaround here directly wins deals

Maintain our public trust page and customer-facing security documentation

Required Skills & Experience 5 – 7 years in security, with meaningful hands-on ownership rather than pure oversight

Degree in computer science or related field.

Deep, practical AWS security experience in a production environment

You have taken at least one compliance audit (SOC 2, ISO 27001, HITRUST, or similar) from gap assessment through to issued report

Working knowledge of HIPAA and handling PHI in a SaaS environment

Comfort in infrastructure as code (Terraform preferred) and scripting to automate controls

Ability to write clearly — policies, customer responses, and executive updates all land on your desk

Judgment about risk. You can tell a real threat from an audit artifact and prioritize accordingly

Nice to Have Skills CISSP, CCSP, AWS Certified Security – Specialty, CISA, or equivalent

Healthcare or behavioral health SaaS background

Familiarity with 42 CFR Part 2 or HITRUST

Prior experience as a first security hire at a growing company

Soft Skills Strong problem-solving and debugging skills

Ability to work independently and take ownership of projects

Strong communication skills with the ability to articulate, diagram and document complex engineering concepts.

Why you will love GTS: Join a powerful tech workforce and help us change the world through technology

Professional development opportunities with international customers

Collaborative work environment

Career path and mentorship programs that will lead to new levels.

Join GTS and contribute to shaping the data landscape within a dynamic and growing organization. Your skills will be honed, and your contributions will play a vital role in our continued success. GTS is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

#J-18808-Ljbffr

Aplicar Now

Similar Opportunities

View all jobs