Manager -Regional Information Security Officer NAFTA

Mercedes-Benz Financial Services USA•Fort Worth, TX

About The Position

The Regional Information Security Officer (RISO) line function is responsible for leading the Information Security Team within the Mercedes Benz Financial Services Americas organization. This role works closely with the global Cybersecurity team to support business units in identifying and mitigating information security risks and contributes to corporate information security initiatives. The RISO is accountable for the implementation and continuous improvement of information security within their respective business unit or area. Additionally, the role is responsible for securing and governing cloud and AI platforms, ensuring resilient architecture, compliant data usage, and trusted deployment of AI capabilities across the organization. The RISO provides strategic direction for cybersecurity initiatives, ensuring alignment with Mercedes-Benz’s global security standards, regulatory frameworks (e.g., A22.1, RISE 2.0), and the organization’s risk appetite. The role acts as a trusted advisor to senior leadership, offering insights on emerging threats, security-related business impacts, and required investments for resilience. Fostering a culture of security awareness across all business units is a key part of this role, involving close partnership with BISOs, ISAs, IT, Compliance, Legal, and broader corporate security functions to embed secure-by-design practices. By enabling transparency, continuity, and cross-functional collaboration, the RISO ensures Mercedes-Benz operations remain secure, compliant, and prepared for evolving cyber risks.

Requirements

  • Applicants must be legally authorized to work in the U.S. at the time of application.
  • This position requires a minimum of 5 years of overall work experience.
  • Strong background in cybersecurity including large-scale IT product rollouts
  • Experience with Networking, Cloud-based applications, Server hardening/security baseline standards, patch management, and remediations.
  • High School Diploma/(GED) is required
  • CISSP (Certified Information Systems Security Professional).
  • Knowledge of IT guidelines and corporate IT policies, IT standards, knowledge of IT organization (e.g., for escalation paths for non-standard requests)
  • Ability to assess risk and implement effective security controls during and after the development process.
  • Deep understanding of IT application architecture, integration, and lifecycle management.
  • Understanding of Zero Trust Architecture (ZTA), AI security governance, and cloud security frameworks
  • Proficiency in DevOps tools and practices, coupled with deep knowledge in cybersecurity.
  • Strong communication skills to translate complex technical concepts into business terms.
  • Strong proficiency with common management frameworks, regulatory requirements, and industry-leading practices
  • Excellent leadership and communication skills to drive security initiatives and foster collaboration
  • Proven leadership in cross-functional environments, including mentoring and team development
  • Contribute to overall strategy development related to IT security and IT more broadly and the business

Nice To Haves

  • Bachelor's Degree is preferred.
  • Recommended majors include: Computer/Information Science or Information Technology
  • CCSP (Certified Cloud Security Professional) or AZ500 Azure Security Engineer are highly recommended.

Responsibilities

  • Develop and lead the enterprise-wide cybersecurity strategy aligned with business objectives and evolving threat landscapes.
  • Drive continuous improvement of cybersecurity maturity by assessing posture, identifying gaps, and leading remediation initiatives.
  • Advise senior leadership on cyber risks, emerging threats, regulatory impacts, and required investments.
  • Define, maintain, and enforce cybersecurity policies, standards, procedures, and architectural principles.
  • Ensure compliance with A22, Regulations for Information Security (RISE), ISO/IEC 27000, GDPR, CCPA, and other applicable regulations.
  • Oversee risk management programs, including risk identification, assessment, prioritization, and mitigation.
  • Govern the secure and ethical adoption of AI and emerging technologies across the enterprise.
  • Manage exceptions, deviations, and escalations related to non-compliance with security or privacy requirements.
  • Manage the implementation and continuous improvement of the enterprise information-security program.
  • Evaluate organizational security maturity and deliver structured improvement plans.
  • Embed a security-first culture through awareness, education, and shift-left practices.
  • Integrate Security-by-Design and DevSecOps principles across the SDLC for secure code development.
  • Identify, track, and remediate vulnerabilities, audit findings, and operational security gaps.
  • Ensure alignment with RISE requirements and contribute feedback for global improvements.
  • Support incident-response activities including triage, containment, remediation, and lessons learned.
  • Conduct Cyber Security Assessments and support internal/external audits.
  • Collaborate with Global Cyber Security (GCS) to ensure alignment with global security strategies and frameworks.
  • Partner with Local Compliance and the DPO/LCO to integrate data-protection requirements into cybersecurity practices.
  • Work with Business Information Security Officers (BISOs) to align security controls with business needs and risk profiles.
  • Maintain strong communication channels across security governance bodies, ensuring transparent, consistent reporting.
  • Contribute to global awareness programs, ISO forums, and multi-stakeholder security initiatives.
  • Establish and enforce data-privacy controls and secure-handling requirements aligned with regulatory and industry standards.
  • Implement data classification, protection, and lifecycle governance to safeguard sensitive information.
  • Support privacy-by-design and secure data-provisioning practices (e.g., masking, minimization).
  • Lead the vendor risk-management program, evaluating and monitoring third-party cybersecurity posture.
  • Ensure supplier compliance with contractual, security, and regulatory expectations.
  • Monitor IT infrastructure, cloud, and applications for security threats, anomalies, and vulnerabilities.
  • Define and track KPIs and KRIs to measure program effectiveness.
  • Deliver regular executive-level reporting on risks, incidents, compliance, and security posture.
  • Oversee development, testing, and enhancement of BC/DR capabilities.
  • Support crisis-management processes and ensure resilience against cyber incidents, outages, and operational disruptions.
  • Drive enterprise-wide security-awareness programs and targeted training initiatives.
  • Promote a culture of shared responsibility and proactive risk mitigation across all teams.
  • Implement AI-specific cybersecurity controls, ensuring safe, ethical, and compliant adoption of AI systems.
  • Develop governance frameworks for AI risk management, including model-security reviews, monitoring, and red-teaming of AI systems.
  • Identify and mitigate risks associated with AI misuse, prompt injection, model poisoning, data leakage, and adversarial attacks.
  • Guide cross-functional teams on secure integration of AI/ML pipelines, including data governance, training-data protections, and secure deployment.
  • Evaluate security implications of emerging technologies (AI, IoT, blockchain, edge computing, autonomous systems) and ensure secure adoption.
  • Oversee cloud-security controls across multi-cloud environments, ensuring alignment with enterprise standards and Zero-Trust principles.
  • Ensure secure cloud architecture, including IAM, encryption, network segmentation, and workload protection.
  • Collaborate with platform, DevOps, and application teams to embed security-by-design into cloud deployments and migrations.
  • Manage cloud risks through continuous monitoring, configuration governance, and regular security assessments.
  • Ensure SaaS, PaaS, and IaaS services follow the shared-responsibility model and meet security and compliance requirements.
  • Inspire, motivate, and guide diverse technical and non-technical teams while fostering strong cross-functional collaboration.
  • Lead day-to-day team operations, providing coaching, guidance, and support to ensure high performance and professional growth.
  • Cultivate a team culture centered on innovation, knowledge sharing, accountability, and operational excellence.
  • Ensure the team has the necessary skills, capabilities, and talent to deliver on cybersecurity and business objectives.
  • Provide clarity and direction in ambiguous or complex situations, enabling teams to execute with confidence.
  • Drive team performance with a focus on speed, agility, stability, and continuous improvement.
  • Offer constructive feedback and empower team members to take ownership of their responsibilities and outcomes.

Benefits

  • Competitive salary plus an annual bonus based on company performance and/or personal yearly performance
  • Fifteen (15) additional corporate holidays
  • Mercedes-Benz Employee Lease Program
  • Outstanding medical, dental, and vision insurance
  • Employer-paid short and long term disability
  • On-site exercise facilities
  • Generous paid Family Leave Programs - Six Weeks for New Parents
  • Adoption Expense Reimbursement Programs - up to $6k per child
  • Tuition Assistance Scholar Program - receive up to $8k in vouchers to complete business-related coursework ($6k for undergraduate, $8k for graduate)
  • 401(K) with match
  • Generous vacation and personal time
  • Flexible work arrangements
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service