Job Posting Organization: CIMMYT is a cutting-edge, non-profit, international organization dedicated to solving tomorrow’s problems today. Established to enhance the quantity, quality, and dependability of production systems and basic cereals such as maize, wheat, triticale, sorghum, millets, and associated crops, CIMMYT employs applied agricultural science, particularly in the Global South. The organization builds strong partnerships to improve the livelihoods and resilience of millions of resource-poor farmers while working towards a more productive, inclusive, and resilient agrifood system within planetary boundaries. As a core CGIAR Research Center, CIMMYT is part of a global research partnership aimed at reducing poverty, enhancing nutrition" style="border-bottom: 1px dotted #007bff !important;">food and nutrition security" style="border-bottom: 1px dotted #007bff !important;">security, and improving natural resources. For more information, visit https://www.cimmyt.org/
Job Overview: The Cybersecurity Manager will be responsible for leading the protection of CIMMYT's information assets that support its global research operations. This role involves overseeing the information security function and managing the Information Security Management System (ISMS) in alignment with ISO/IEC 27001:202
The successful candidate will have operational ownership of the Center's security platforms and will lead a team dedicated to maintaining and improving these systems. The position requires a hands-on approach to cybersecurity, ensuring that all security measures are effectively implemented and continuously improved. The Cybersecurity Manager will also be responsible for preparing and presenting risk and control items, ensuring that decisions and actions are followed through effectively.
Duties and Responsibilities: The Cybersecurity Manager will lead CIMMYT's information security function, managing, coaching, and developing the cybersecurity team. Key responsibilities include: operating and continuously improving the Information Security Management System aligned with ISO/IEC 27001:2022 and NIST CSF v2.0; preparing and presenting risk and control items; performing hands-on configuration, integration, tuning, and troubleshooting across various security platforms; owning vulnerability and patch management; managing security incident response from detection to post-incident review; validating control effectiveness; supporting internal and external audits; managing security suppliers and licenses; coordinating security standards with regional IT specialists; and reporting monthly on security posture and risk performance through agreed metrics.
Required Qualifications: Candidates must possess a Bachelor’s degree in computer science, Information Technology, Information Security, or a related field. A master's degree is considered an advantage. Additionally, a security certification such as CISSP, CISM, ISO/IEC 27001 Lead Implementer or Lead Auditor, or equivalent is required. Technical platform certifications are also advantageous. Candidates should have at least 8 years of professional experience in information security, with a minimum of three years in a managerial or supervisory role overseeing a technical team.
Educational Background: The educational background required for this position includes a Bachelor’s degree in computer science, Information Technology, Information Security, or a related field. A master's degree is preferred and can enhance a candidate's profile. Furthermore, relevant security certifications are mandatory, demonstrating the candidate's expertise in the field.
Experience: The position requires a minimum of 8 years of professional experience in information security, with at least three years in a managerial or supervisory capacity. Candidates should have practical experience in implementing and operating an ISO/IEC 27001 management system, including control mapping and audit evidence production. Experience managing security vendors, contracts, licenses, and budgets is also essential. Familiarity with multi-country or distributed organizations, particularly in international research, development, or non-profit sectors, is advantageous.
Languages: While the job description does not specify mandatory languages, proficiency in English is likely essential given the international nature of CIMMYT's operations. Additional languages may be beneficial but are not explicitly required.
Additional Notes: CIMMYT offers an attractive remuneration package that includes provisions beyond the Mexican Labor Law, such as a year-end bonus equivalent to 40 days, a vacation premium of 56%, life and medical insurance, supermarket coupons, a savings fund, and social benefits under Mexican law (IMSS, SAR / Infonavit). It is important to note that only short-listed candidates will be contacted, and foreign national candidates must possess legal documentation to work in Mexico. The position will remain open until filled, and CIMMYT is committed to fostering a multicultural work environment that values gender equality, teamwork, and respect for diversity.
Info
Job Posting Disclaimer
This job posting is provided for informational purposes only. The accuracy of the job description, qualifications, and other details mentioned is the sole responsibility of the employer or the organization listing the job. We do not guarantee the validity or legitimacy of this job posting. Candidates are advised to conduct their own due diligence and verify the details directly with the employer before applying.
We are not liable for any decisions or actions taken by applicants in response to this job listing. By applying, you agree that all application processes, interviews, and potential job offers are managed exclusively by the listed employer or organization.
Beware of fraudulent job offers. Do not provide sensitive personal information or make any payments to secure a job.