Join Credicorp Capital and transform challenges into opportunities as our next Architect of Security for Gen AI within the Gen AI & Innovation team, located in Lima, Peru.Mission:To design and oversee secure architectures for solutions within the GenAI ecosystem (cloud, data, integrations, and AI components), ensuring compliance with corporate standards, ISMS, regulations, and Credicorp Capital's risk appetite. You will translate requirements and risks into applicable technical controls, incorporating security by design while adjusting controls proportionally based on the maturity of the solution (sandbox vs. production), enabling innovation and industrialization without compromising security or compliance.Responsibilities:Design and review security architectures for on-premise, cloud, and hybrid solutions; applications, APIs, and microservices; data platforms, ensuring “security by design” from early stages.Define specific patterns/controls for GenAI archetypes (e.g., RAG, agents, and tool usage): access controls, data protection in inputs/outputs, safeguards for integration with tools, and minimum criteria for security logging/monitoring.Collaborate with QA and AI Risk Specialists to define abuse scenarios and security validation criteria for GenAI solutions, ensuring that mitigations are reflected in architecture and technical controls.Prioritize and implement technical security controls based on identified risks and solution maturity, clearly differentiating between experimentation/sandbox and production environments without sacrificing agility or increasing risks.Assess risks and vulnerabilities related to infrastructure, applications, data, third-party services, and AI usage; contribute technical perspectives to risk analysis and translate findings into actionable requirements and controls.Validate compliance with corporate guidelines, ISMS, and regulatory requirements; translate policies/standards into technical designs; support addressing findings (audits, action plans, exceptions) with technical inputs.Prepare, structure, and present technical inputs for technology risk committees/forums, offering clear analysis (risks, controls, trade-offs) that facilitate informed decision-making.Evaluate security aspects of technological solutions and vendors (requirements, controls, third-party risks) and recommend conditions/mitigations for adoption.Requirements:University degree in relevant fields...
Apr 30, 2026