Description
Position Summary:
Axity is seeking a Senior Cybersecurity Engineer to ensure regulatory compliance, assess controls, manage vulnerabilities, and provide strategic security advisory services for organizational security.
Key Highlights:
1. Extensive experience in regulatory compliance and control assessment.
2. Specialist in ISO 27001, NIST CSF, and NIST 800-53.
3. Expert in advanced vulnerability management and mitigation.
CYBERSECURITY
SENIOR ADVANCED ENGINEER
3 hours ago
Description
Axity is a company with over 35 years of experience; our service portfolio is one of the largest in the industry: Digital Strategy, Software Development, Business Intelligence, Big Data, Advanced Analytics, Security, and IoT.
A Senior Cybersecurity Engineer with extensive experience in regulatory compliance, control assessment, and advanced vulnerability management. Specialist in implementing, verifying, and continuously improving controls aligned with ISO 27001, NIST Cybersecurity Framework (CSF), NIST SP 800-53, and complementary frameworks. Expert in risk assessment of new technology initiatives, technical vulnerability analysis, and strategic advisory services for mitigating risks and strengthening organizational security posture.
Requirements
**1. Compliance and Control Verification (ISO 27001 / NIST)**
* Assessment and validation of security controls aligned with:
* ISO/IEC 27001:2022 (Annex A)
* NIST Cybersecurity Framework (CSF)
* NIST SP 800-53
* Design, review, and updating of control matrices.
* Execution of gap analyses and remediation plans.
* Participation in internal and external audits.
* Definition and tracking of security KPIs/KRIs.
* Evidence management for certification processes.
**2. Control Assessment for New Initiatives**
* Risk analysis for new projects (infrastructure, applications, cloud, SaaS, DevOps).
* Architecture reviews from a "Security by Design" perspective.
* Compliance evaluation prior to production deployment.
* Preparation of technical reports including:
* Identified risks
* Criticality level
* Potential impact
* Mitigation recommendations
* Coordination with IT, development, and business units.
**3. Vulnerability Management and Analysis**
* Coordination of scans:
* Weekly (critical infrastructure)
* Monthly (general environments)
* On-demand (new assets or urgent requests)
* Use of tools such as:
* Nessus / Qualys / Rapid7
* OpenVAS
* SAST/DAST scanners
* Technical analysis of findings (CVSS, exploitability, business context).
* Risk-based prioritization (Risk-Based Vulnerability Management).
* Remediation tracking with technical teams.
**4. Advisory Services for Mitigation**
* Definition of corrective action plans.
* Technical recommendations:
* Server hardening
* Network segmentation
* Patch management
* Secure cloud configuration (AWS, Azure, GCP)
* MFA, Zero Trust, access control
* Post-remediation validation.
* Technical training for operational teams.
**Technical Competencies**
* Regulatory frameworks: ISO 27001, NIST CSF, NIST 800-53, CIS Controls.
* Risk management (ISO 27005, proprietary methodology, or FAIR).
* Cloud Security (AWS Security Hub, Azure Defender).
* Vulnerability management and patch management.
* Network, endpoint, and application security.
* SIEM and event monitoring.
* Knowledge of DevSecOps.
**Key Skills**
* Strategic, risk-oriented thinking.
* Advanced analytical capability.
* Effective communication with technical and executive stakeholders.
* Leadership in security projects.
* Decision-making based on impact and criticality.
We Offer
Indefinite-term contract – On-site modality
Corporate Benefits
At Axity, we foster an inclusive environment where differences are celebrated and everyone has the opportunity to grow and excel. Our commitment is clear: "to create a workplace where every talent finds the support and respect necessary to fully develop and contribute their best self".
Profile
**SENIOR ADVANCED ENGINEER**
Location
**Lima, Lima, Peru**Experience
**5 Years of Experience**