Smashcr logo

Cyber Governance and Risk Manager

smashcr

On-site
San José, Costa Rica
Full-time
Manager
Salary not listedPosted 2w ago

Real job — pulled straight from smashcr’s careers page · Verified August 1, 2026 · No reposts.

Job description

smashcr is hiring a Cyber Governance and Risk Manager — a full-time, based in San José, Costa Rica role. Apply directly on smashcr's careers page below.

Cyber Governance & Risk Manager (C-564)

Location: San José, Costa Rica

SMASH, Who we are?
We are agents for tech professionals in Costa Rica and Colombia that help them build careers in the United States.

We believe in long-lasting relationships with our talent. We invest time getting to know them and understanding what they seek as their professional next step.

We aim to find the perfect match. As agents, we pair our talent with our US clients, not only by their technical skills but as a cultural fit. Our core competency is to find the right talent fast.

We purposefully move away from the “contractor” or “outsourcing” type of relationship. Our clients don’t want contractors or “just a service.” Neither does our talent.

Our Benefits

  • Wellness Coverage

  • Remote Work

  • Birthday day off

  • Recognition and rewards system

  • Referrals Program

  • Business skill coaching

  • English classes for Smashers and relatives

  • Learning opportunities

This position is Remote to work with a US Company; you will require to have Citizenship or a work permit from Costa Rica to apply for this role.

Role summary

You will lead cybersecurity governance and risk initiatives by strengthening enterprise control frameworks, evaluating IT and cyber risks, and ensuring compliance with regulatory standards. This hands-on role partners with operational and technology teams to improve governance practices, enhance risk visibility, and support secure, compliant business operations.

Responsibilities

  • Define and maintain ownership of cybersecurity controls across operational and technology teams.
  • Perform hands-on cyber risk and control evaluations to assess control effectiveness and identify improvement opportunities.
  • Conduct regulatory analysis and align cybersecurity controls with frameworks such as NCUA, FFIEC, and internal governance requirements.
  • Develop and maintain governance frameworks, including control libraries, RACI matrices, policies, standards, and procedures.
  • Drive governance practices across Enterprise Secure Software Development Lifecycle (ESDLC) and IT Operations.
  • Perform cyber risk assessments and map identified risks to appropriate technical and operational controls.
  • Develop and maintain enterprise Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), and executive reporting dashboards.
  • Produce enterprise IT governance reports that communicate risk posture, control effectiveness, compliance status, and operational performance.
  • Translate enterprise security policies into actionable operational standards and ensure consistent implementation across IT teams.
  • Partner with technology, security, audit, and compliance teams to strengthen governance processes and support regulatory readiness.
  • Monitor governance metrics and recommend continuous improvements to cybersecurity and operational risk programs.

Requirements – Must-haves

  • Proven experience in Cyber Governance, IT Risk Management, or Information Security Governance.
  • Hands-on experience performing risk and control evaluations within enterprise IT environments.
  • Experience conducting regulatory analysis and implementing cybersecurity governance practices.
  • Strong knowledge of cybersecurity control frameworks and regulatory standards such as NCUA, FFIEC, NIST, ISO 27001, or similar.
  • Experience implementing governance practices within Enterprise Secure Software Development Lifecycle (ESDLC) and IT Operational environments.
  • Experience designing and maintaining governance frameworks, including policies, standards, procedures, control libraries, and RACI models.
  • Experience developing enterprise-level KRIs, KPIs, dashboards, and IT governance reporting.
  • Strong understanding of enterprise IT controls, operational risk management, and control ownership.
  • Excellent analytical, documentation, and stakeholder communication skills.
  • Experience collaborating with technology, security, audit, compliance, and business teams.

Nice-to-haves (optional)

  • Experience supporting financial institutions or highly regulated industries.
  • Professional certifications such as CISSP, CISM, CRISC, CGEIT, or similar.
  • Experience with Governance, Risk, and Compliance (GRC) platforms.
  • Knowledge of enterprise reporting and business intelligence tools.

Languages

  • English C1
  • Spanish C1

Get Cyber Governance and Risk Manager jobs like this

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Sequoia Connect logo

Compliance and Product Security Engineer

Mexico
✓ From careers page· 1h ago
Accenture logo

Secure AI Engineer Manager

$80k–$294kAtlanta, GA
✓ From careers page· 1h ago
Accenture logo

Secure AI Architect

$113k–$339kAtlanta, GA
✓ From careers page· 1h ago
Accenture logo

Cybersecurity Manager

$80k–$294kChicago, IL
✓ From careers page· 1h ago

Frequently asked questions

What skills are required for Cyber Governance and Risk Manager at smashcr?

The required skills for Cyber Governance and Risk Manager at smashcr include: Cybersecurity, NIST, ISO 27001, CISSP, CISM.

What is the seniority level for Cyber Governance and Risk Manager at smashcr?

Cyber Governance and Risk Manager at smashcr is a Manager level position.

How do I apply for Cyber Governance and Risk Manager at smashcr?

You can view the full description and apply for Cyber Governance and Risk Manager at smashcr on EchoJobs: https://echojobs.io/job/smashcr-cyber-governance-amp-risk-manager-c-564-fzvog.