Credicorp Capital logo

DevSecOps Security Architect

On-site Full-time

Clicking Apply Now takes you to AutoApply where you can tailor your resume and apply.


Experience Level

Experience

Qualifications

Qualifications:Bachelor's degree in Computer Science, Information Technology, or a related field. Proven experience in security architecture design, preferably within a DevSecOps context. Strong knowledge of information security frameworks and standards including ISO 27001, ISO 27017/27018, and DORA compliance. Experience with cloud services and data platforms. Ability to work collaboratively with cross-functional teams and promote security best practices. Excellent analytical and problem-solving skills.

About the job

Join Credicorp Capital, where we transform challenges into opportunities! We invite you to become our next DevSecOps Security Architect on the Technology team in Lima, Peru.


Mission:

To design, evaluate, and support the implementation of secure technological architectures that enable the business, ensuring that IT solutions, including those incorporating cloud, data, artificial intelligence, and DevOps practices, meet corporate information security standards, the Information Security Management System (ISMS), applicable regulatory frameworks (including DORA), and the organization's risk appetite.


Key Responsibilities:

  • Design and review secure architectures for solutions: On-premises, cloud, and hybrid environments; Applications, APIs, and microservices; Data platforms.

  • Integrate security controls from the early stages of projects (security by design).

  • Ensure compliance with corporate guidelines, regulatory standards, and operational resilience.

  • Support development teams in adopting DevSecOps practices, ensuring security controls in CI/CD pipelines: SAST, DAST, SCA; Secure secrets management; Identity and access control.

  • Define security guidelines for: Secure development, Deployment automation, Infrastructure as Code (IaC).

  • Promote a culture of shift-left security.

  • Engage in the analysis and consolidation of cybersecurity risks in technology projects, evaluating risks associated with: Infrastructure and cloud, Applications, APIs and data, DevOps chain, and third-party technology providers.

  • Consider principles of digital operational resilience, aligned with DORA, such as: Critical service continuity and management of technology dependencies.

  • Implement and translate ISMS policies, standards, and controls into technical designs.

  • Support the second line of defense in: Technical analysis of findings, Exception management, Regulatory audits, and Action plans addressing compliance gaps.

About Credicorp Capital

Credicorp Capital is a leading financial services firm dedicated to delivering innovative solutions that empower businesses. With a strong commitment to security and operational resilience, we are at the forefront of transforming financial services in Peru.

Similar jobs

Browse all companies, explore by city & role, or SEO search pages. View directory listings: all jobs, search results, location & role pages.

Tailoring 0 resumes

We'll move completed jobs to Ready to Apply automatically.