Hiring.Camp

Senior IT Risk Management Specialist

Mmc

·

Yesterday

Location
Mexico City - Paseo
Workplace
Hybrid
Type
Full-time
Department
Finance
Seniority
Senior
Source
Workday

Description

Company:

Marsh

Description:

Senior IT Risk Management Specialist

 


We are seeking a Senior IT Risk Management Specialist to join our team at Marsh. This role will be based in Mexico City. This is a hybrid role that has a requirement of working at least three days a week in the office. As the Senior IT Risk Management Specialist, you will discover and catalog existing IT controls across the enterprise, convert technical implementations and documentation into clear, testable control statements and procedures, and maintain a centralized, auditable controls library mapped to NIST frameworks, corporate policy, and applicable legal and regulatory requirements. This lead role will mentor a small team of controls specialists, partner with IT and business control owners, and ensure the controls library is structured to support audit readiness and automation opportunities.

 


We will count on you to:

  • Identify existing controls: conduct interviews, workshops, and evidence reviews across infrastructure, applications, cloud, identity, change management, and third-party services to recognize and document implemented controls.
  • Draft control statements and test procedures: convert technical design/configurations and documentation into concise control statements, acceptance criteria, and evidence requirements.
  • Design and execute enterprise Control Self‑Assessment (CSA) program: develop and run a risk‑based CSA methodology to validate implemented controls, collect owner attestations, perform evidence review and sampling, score control design effectiveness and evidence completeness, and ensure CSA instances are linked to controls library entries and managed in GRC with auditable trails.
  • Confirm and complete: review drafted controls with owners and auditors, secure ownership, and finalize control language for the repository.
  • Prioritize and remediate gaps: triage undocumented or weak controls, recommend immediate compensating controls, and track remediation or formal exceptions.
  • Coach and scale: mentor team members, as well as IT and business control owners and run control identification playbooks and templates to accelerate consistent library population.

 


What you need to have:

 

  • Knowledge of regulatory laws impacting global IT organizations (e.g., Sarbanes-Oxley, NYDFS Cybersecurity Regulation, CPS 234, China PIPL, etc.).
  • Knowledge of information systems, software and security related products and services.
  • Knowledge of Security frameworks including NIST CSF, NIST SP800-53 and ISO 27001.
  • Experience supporting audit objectives (e.g., SOC 1, SOC 2, GS007, SOX).
  • An undergraduate or graduate degree in IT Management, Computer Information Systems (CIS), or equivalent.
  • Significant experience with Microsoft Office Suite.
  • The ability to articulate business/technical requirements to IT teams and business users.
  • Great people skills and ability to establish partnerships and collaborate at various levels.
  • Demonstrated ability to meet deadlines in a fast-paced environment.
  • Excellent verbal and written communication skills (incl. Presentation development)
  • Advanced level on English is a must

 


Why join our team:

 

  • We help you be your best through professional development opportunities, interesting work and supportive leaders.
  • We foster a vibrant and inclusive culture where you can work with talented colleagues to create new solutions and have impact for colleagues, clients and communities.
  • Our scale enables us to provide a range of career opportunities, as well as benefits and rewards to enhance your well-being.

Marsh (NYSE: MRSH) is a global leader in risk, reinsurance and capital, people and investments, and management consulting, advising clients in 130 countries. With annual revenue of over $27 billion and more than 95,000 colleagues, Marsh helps build the confidence to thrive through the power of perspective. For more information, visit marsh.com, or follow us on LinkedIn and X.

Marsh is committed to creating a diverse, inclusive and flexible work environment. We aim to attract and retain the best people and embrace diversity of age, background, disability, ethnic origin, family duties, gender orientation or expression, marital status, nationality, parental status, personal or social status, political affiliation, race, religion and beliefs, sex/gender, sexual orientation or expression, skin color, or any other characteristic protected by applicable law.

Marsh is committed to hybrid work, which includes the flexibility of working remotely and the collaboration, connections and professional development benefits of working together in the office. All Marsh colleagues are expected to be in their local office or working onsite with clients at least three days per week. Office-based teams will identify at least one “anchor day” per week on which their full team will be together in person.

Skills

CybersecuritySOCSOXRisk ManagementChange ManagementSOC 2ISO 27001

Similar Jobs

30

IT Risk Senior

Freddiemac·Headquarters 1, US

2mo ago

R1054567 Senior Analyst, IT Compliance & Risk - Data Protection

CVS Health·Woonsocket-1 CVS Drive, US +1·Remote

2d ago

R1054609 Senior Analyst, IT Compliance & Risk - Identity and Access Management (IAM)

CVS Health·Woonsocket-1 CVS Drive, US +1·Remote

2d ago

Senior IT Risk and Compliance Analyst

Copeland·Pune, India·Hybrid

2d ago

IT Audit, Cybersecurity & Risk Senior Consultant

bakertilly·USA UT Lehi, US +5·Remote

2d ago

IT Embedded Risk Senior Associate

Depository Trust Company·Hyderabad, India

3d ago

Risk IT Audit, Senior Associate - Torino [OTS]

Pwc·Torino - Via Santa Maria 11, Italy

4d ago

Senior Technology Risk Analyst (IT Audit) - remote

Stryker is one of the·Texas, Dallas Virtual Address +3·Remote, Hybrid, Onsite

4d ago

Governance, Risk, and Compliance Senior Associate or Supervisor (IT)

Weaver·DALLAS, TX +3

1w ago

Senior IT Risk & Governance Manager

Coopers Group AG·Schweiz·Remote

1w ago

(Senior) Systems Analyst - OTC Clearing & Risk - IT (12-month contract)

HKEX Career·HK-TKO 5, F

1w ago

Risk Advisory - IT Risk Senior Associate

Riveron·Atlanta, GA +8·Remote

1w ago

Senior Software Engineer – IT Risk & Pricing (m/f/d)

auxmoney GmbH·Düsseldorf, Nordrhein-Westfalen

2w ago

Sr. Business Analyst, IE Risk Management, IT

Citicclsa·Hong Kong - One Island East

2w ago

IT Audit, Cybersecurity & Risk Senior Consultant (SOC focus)

bakertilly·USA WI Milwaukee, US +6

2w ago

Consultant Senior Tech Risk & IT M&A 26-27 (H/F)

MAZARS·Levallois-Perret, IDF·Hybrid

3w ago

Senior IT Governance, Risk & Compliance Manager

BEW Berliner Energie und Wärme GmbH·Berlin, BE

3w ago

Risk & Regulatory - IT Audit Senior Associate

Pwc·Argentina AC Olivos +1

3w ago

IT Senior, Technology Risk Assurance

BDO Seidman·New York, NY

4w ago

IT Credit Risk Senior Business Analyst | IT CIB

Natixis in Portugal·Porto, Portugal·Hybrid

4w ago

Sr Manager - IT Governance, Risk, and Compliance

Plexus·Oradea, BH

1mo ago

Sr Manager - IT Governance, Risk, and Compliance

Plexus·Livingston, GB

1mo ago

Senior LOB Risk Specialist - IT General Controls

PNC Bank·One PNC Plaza, US·Onsite

1mo ago

IT Risk Senior Associate (SOX & Internal Audit)

Grant Thornton·Chicago, IL·Hybrid

1mo ago

IT Sr Director, Compliance and Risk Governance

Intuitive Surgical·Sunnyvale, CA

1mo ago

Senior IT Risk Officer

Eurofins Scientific·Barcelona, CT·Hybrid

1mo ago

Sr. Research IT Security Risk and Compliance Analyst - Computing Services

Careers @ Carnegie Mellon·Pittsburgh, US

1mo ago

IT Audit, Cybersecurity & Risk Advisory Senior Consultant (PCI Focus)

bakertilly·USA UT Lehi, US +1·Remote

1mo ago

Governance, Risk, and Compliance Senior Associate, IT Controls & Assurance

Weaver·New York, NY

1mo ago

Senior IT Auditor, Technology Risk

Amazon

1mo ago