Jobs · Finance · Texas

Bilingual Cybersecurity Policy & Regulatory Analyst

GM Financial · Arlington, TX · 2 wk ago
HybridFinanceFull-time

About the role

The Bilingual Cybersecurity Policy and Regulatory Analyst is responsible for monitoring, analyzing, and supporting cybersecurity regulatory requirements across multiple international jurisdictions. This position ensures alignment with applicable laws, regulations, industry standards, organizational governance objectives, and policies. This role requires fluency in English and Spanish to support global compliance initiatives, communicate regulatory impacts, manage cross-functional projects, and collaborate with stakeholders across regions. The position combines regulatory analysis, cybersecurity knowledge, policy governance, technical acumen, and project management expertise to assess the impact of evolving requirements on security controls, technologies, and operational processes.

Responsibilities

  • Research, monitor, analyze, and interpret cybersecurity regulations, regulatory guidance, compliance requirements, and industry standards, translating requirements into actionable policies, standards, procedures, controls, and implementation recommendations.
  • Manage and coordinate regulatory impact assessments, gap analyses, and remediation activities to evaluate compliance obligations and implementation requirements across multiple jurisdictions.
  • Lead and support regulatory compliance initiatives by coordinating implementation activities, stakeholder engagement, deliverables, and evidence collection.
  • Interpret and communicate business, operational, and compliance impacts of new, proposed, and evolving cybersecurity regulations.
  • Track regulatory implementation risks, issues, dependencies, and corrective actions to support successful execution of compliance initiatives.
  • Prepare regulatory readiness reports, executive briefings, implementation updates, and compliance metrics for leadership and key stakeholders.
  • Collaborate with Legal, Compliance, Risk Management, Privacy, Technology, and business stakeholders to support the interpretation and implementation of regulatory requirements.
  • Identify opportunities to improve regulatory compliance processes and implementation efficiencies through standardization, automation, and continuous improvement.
  • Lead and coordinate cybersecurity policy governance initiatives to ensure alignment with regulatory requirements, legal obligations, organizational objectives, and industry frameworks.
  • Manage the cybersecurity policy lifecycle, including policy development, review, approval, publication, communication, implementation, and periodic recertification.
  • Coordinate policy reviews and governance activities with cybersecurity, legal, compliance, privacy, risk management, technology, and business stakeholders.
  • Develop and maintain governance documentation, implementation plans, milestones, and action items supporting policy lifecycle management.
  • Facilitate governance meetings, stakeholder reviews, and policy working sessions; document decisions, action items, and implementation outcomes.
  • Monitor policy governance activities and remediation efforts to support timely resolution of policy-related gaps and issues.
  • Prepare policy governance metrics, compliance findings, executive summaries, and management reports to support decision-making.
  • Maintain policy records, documentation, and evidence repositories to support regulatory compliance, audit readiness, and examination activities.
  • Provide policy interpretation and implementation guidance to promote consistent adoption and adherence across the organization.
  • Support internal and external audits, regulatory examinations, and assessments by coordinating policy-related documentation and evidence.
  • Identify opportunities to strengthen policy governance processes, stakeholder engagement, and operational effectiveness through continuous improvement initiatives.

Requirements

  • Minimum of 1-5 years of experience in a large and complex business environment with a successful track record working directly with senior-level management.
  • At least 1 year of experience in one or more of the following domains: Access Control, Telecom and Network Security, Cybersecurity Governance, Risk Management, Software Development Security, Cryptography, Security Architecture and Design, Operational Security, Business Continuity & Disaster Recovery, Legal Regulations, Investigations and Compliance, Physical (Environmental) Security, IT or Security Audit, IT or Security Compliance.
  • Experience with UML Design Tools preferred.
  • Experience with alternate management methods using SSH, serial connections, and the command-line interface (TMSH preferred).
  • Experience in documentation tools such as Visio and Microsoft Office products.
  • Experience with Network and VLAN segmentation preferred.
  • Experience with technical writing preferred.
  • High School Diploma required; Associate degree, Bachelor’s Degree in a related field, or equivalent work experience strongly preferred.

Qualifications

  • Experience working with one or more of the following Regulatory or Frameworks: NIST Cybersecurity Framework (CSF), NIST SP 800-53, NIST SP 800-171, ISO 27001/27002, CIS Critical Security Controls, NYDFS Cybersecurity Regulation, SEC Cybersecurity Disclosure Rules, GDPR, Brazil LGPD, Chile Privacy Requirements, Colombia Cybersecurity and Data Protection Regulations, Mexico Cybersecurity and Privacy Requirements.
  • Regulatory analysis experience.
  • Cybersecurity governance experience.
  • Policy development and administration experience.
  • Risk assessment experience.
  • Project coordination experience.
  • Strong written and verbal communication skills.
  • Cross-functional collaboration experience.
  • Process improvement experience.
  • Attention to detail.
  • Bilingual communication (English/Spanish).
  • Professional certifications such as CISSP, CISM, CRISC, CISA, CGRC (formerly CAP) are a plus but not required.

Benefits

  • 401K matching.
  • Bonding leave for new parents (12 weeks, 100% paid).
  • Tuition assistance.
  • Training opportunities.
  • GM employee auto discount.
  • Community service pay.
  • Nine company holidays.

Pay

Competitive pay and bonus eligibility.

Schedule

Hybrid work environment, 4 days a week in office in Arlington, Texas.

Similar jobs