About the job
Credicorp Capital seeks a Senior Cybersecurity Audit Analyst in Bogotá to lead technical audits focused on governance, risk management, and security controls. This role evaluates the security posture of both internal systems and key external vendors, aiming to strengthen the technological resilience of Credicorp Capital Regional.
Main Responsibilities
- Review internal and external regulations affecting information security, cybersecurity, and audit practices.
- Assess network architectures, including segmentation, micro-segmentation, routing protocols, and layered security, to identify vulnerabilities in hybrid environments (on-premise and cloud).
- Validate the hardening of critical assets such as servers, databases, firewalls, and IPS/IDS, referencing standards like CIS Benchmarks and NIST CSF 2.0.
- Audit cloud architectures with a focus on identity management (IAM), storage security, and compliance with cloud security policies.
- Design and execute audit procedures, including technical walkthrough tests, to confirm controls are effective and resistant to evasion.
- Draft clear audit observations that link technical weaknesses to business risks, and recommend steps to advance regional cybersecurity maturity.
Role Overview
This position plays a key part in evaluating and challenging the effectiveness of security controls across a regional financial group. The analyst works to identify risks in both internal platforms and vendor relationships, supporting continuous improvement in cybersecurity posture.
