Information Security Specialist
On-siteLima, Lima Province, Peru
Job Summary
Ensure compliance with Cybersecurity and Information Security standards and guidelines across the company while maintaining a strategic view of business needs. Promote Information Security awareness throughout the organization and manage ISMS implementation, including security policies, controls, risk assessments, and audit support. Conduct cybersecurity risk assessments to identify threats, define risk treatment measures, and recommend technical, organizational, and administrative security controls. Track corrective actions and drive continuous improvement initiatives aligned with ISO/IEC 27001 and NIST frameworks. Requires five years of IT experience, three years in cybersecurity/GRC, mandatory ISO/IEC 27001 or CISSP certification, and fluency in Spanish and English.
Required Qualifications
- Five (5) years of experience in information technology
- strong technical foundation in infrastructure, networking and/or systems
- network and systems architecture
- TCP/IP
- network segmentation
- access control
- security architecture
- experience in complex or global organizations
- Three (3) years of proven experience in cybersecurity and/or information security roles
- experience focused on Governance, Risk and Compliance (GRC)
- experience focused on security architecture
- Mandatory certification in ISO/IEC 27001
- Mandatory certification in ISO/IEC 27005
- Mandatory certification in CISM
- Mandatory certification in CISSP
- Proven experience in ISMS implementation and maintenance
- experience with security policies
- experience with controls
- experience with risk assessments
- experience with compliance management
- experience with internal and external audit support
- experience with corrective action tracking
- experience with continuous improvement initiatives
- Proven experience conducting information security and cybersecurity risk assessments
- identification of threats
- identification of vulnerabilities
- identification of impacts
- definition of risk treatment measures
- recommendation of technical security controls
- recommendation of organizational security controls
- recommendation of administrative security controls
- recommendation of contractual requirements
- Knowledge of recognized cybersecurity frameworks and standards
- Knowledge of NIST
- Knowledge of ISA/IEC 62443
- University degree in Engineering
- University degree in Computer Science
- University degree in Information Technology
- University degree in Telecommunications
- University degree in related fields
- Fluent in Spanish
- Fluent in English
- written Spanish
- spoken Spanish
- written English
- spoken English
Desired Qualifications
- Knowledge or experience in OT/ICS
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.