GFT logo

Technical Security Expert

Hiring from
Costa Rica
Work type
Remote
Posted
Is this job info correct?
Show job description
Campo personalizado 1: Architecture
Campo personalizado 3: Architecture
País/región: CR
Fecha: 5 oct 2026
Ubicación:
Lugar de trabajo: Remoto

Job description_

About the Role_

We are seeking a talented individual to execute Project Security Assessments (PSAs) and related security reviews for applications, infrastructure, and associated components undergoing cloud migration initiatives. The contractor operates under the direction of the designated Security Partner, applying established security procedures and requirements to each assessment rather than setting business unit security strategy or making independent risk decisions. This is an execution-focused role, distinct from the Security Partner position. The contractor is not expected to advise business leadership, represent the business unit to security governance organizations, or make risk acceptance or policy exception decisions. Such decisions are escalated to and retained by the Security Partner.

A day in this role_

  • Manage a portfolio of Project Security Assessments (PSAs) in line with service level agreements, completing assessments for each workstream and migration path according to established security requirements.
  • Facilitate the submission, review, and tracking of issues and exceptions to security controls identified during assessments, escalating business-critical issues and exception decisions to the Security Partner.
  • Assist in the completion of thematic and risk-driven security assessments for cloud migration initiatives, including security validations against AWS-native controls, such as:

o IAM

o Security Groups / NACLs

o KMS / Encryption

o WAF

o CloudTrail / CloudWatch logging and monitoring

o GuardDuty / Config

o Vulnerability scanning

· Coordinate penetration testing activities where required.

o Maintain a working understanding of information security risks related to cloud migration projects, identifying situations where risk assessments, reviews, or risk-rating changes require Security Partner involvement.

o Keep assessment status current and visible by maintaining clear progress notes and outstanding items in the organization's GRC platform, and by providing regular status updates to application, project, and security stakeholders.

o Interpret and apply security policies, standards, and procedures consistently across the assessment portfolio

The expertise requested_

  • Bachelor's degree in a relevant field or equivalent experience in information security, risk management, audit, or compliance.
  • Demonstrable experience in cybersecurity, with a technical background and/or experience conducting security risk assessments or audits.
  • Hands-on experience working in or assessing AWS environments, including the ability to review architecture diagrams and cloud configurations.
  • Strong presentation, data analysis, and problem-solving skills.
  • Experience interpreting and applying security policies, standards, and procedures.
  • Self-motivated and solutions-oriented, with the ability to research and apply appropriate guidance independently.
  • AWS core services and security controls, including:

o IAM

o VPC and Security Groups

o KMS

o WAF

o CloudTrail / CloudWatch

o GuardDuty

o AWS Config

· Common cloud migration patterns and associated security considerations.

· Information security frameworks such as:

o ISO 27001

o NIST

o COBIT

· Risk analysis, assessment, treatment, and management methodologies.

· Knowledge of healthcare-related regulatory frameworks (e.g., HIPAA) is a plus.

· Familiarity with Agile software development methodologies.

· Ability to work independently with minimal supervision.

· Ability to collaborate effectively with stakeholders across multiple business functions.

· Process-driven mindset with strong attention to detail, consistency, and efficiency across a high-volume assessment workload.

· Escalates ambiguous, high-risk, or judgment-based decisions to the Security Partner as appropriate.

Desired or nice to have expertise_

  • CompTIA Security+
  • AWS Certified Cloud Practitioner
  • AWS Certified Security – Specialty
  • AWS Certified Solutions Architect – Associate
  • CISSP or equivalent certifications are advantageous but not required.
  • Experience with Archer GRC or similar governance, risk, and compliance tools is beneficial but not required.

Our Core values are focus to inclusion and diversity, all qualified applicants will be considered for employment and will go thru a fair recruitment process regardless of their race, religion, gender identity, sexual orientation, national origin or disability status.

Your journey with us begins here!!

Als Partner für IT-Beratung und Software-Entwicklung sind wir auf die digitale Transformation unserer Kunden aus den Bereichen Finanzen, Versicherungen und Industrie spezialisiert. Unsere rund 700 Talente in Deutschland entwickeln mit modernsten Technologien nachhaltige Lösungen.

Cinco motivos para ser parte del #TeamGFT

  • Flexibilidad: ¡Aquí el equilibrio lo es todo! Ofrecemos un entorno que respalda el balance de la vida personal y laboral y trabajo remoto.
  • Colaboración: La colaboración es fundamental. Trabajamos en equipos multidisciplinarios, donde cada persona aporta sus habilidades únicas.
  • Multiculturalidad: Contamos con un equipo global diverso que fomenta una atmósfera de aprendizaje y crecimiento personal.
  • Desarrollo: Ofrecemos un plan de carrera personalizado, así como programas de formación para desbloquear tu potencial.
  • Relevancia: Colaboramos con clientes líderes en la industria en proyectos de alto impacto que definen el futuro tecnológico.

¿No estás listo (a) para aplicar?

Únete a nuestra TALENT COMMUNITY para oportunidades de trabajo que coincidan con tus intereses.

Similar jobs

Apply for this job