Senior Risk Analyst, Information Security Risk Management

🔥 20 hours ago

🌐 Colombia, Costa Rica, +1 more countries – Remote

infoinfo

⏰ Full Time

🟠 Senior

🔐 Security Analyst

👻 Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of BCD Travel

BCD Travel

10,000+ employees

Founded 2006

💼 Consulting

📦 Logistics

🏨 Hospitality

Consulting • Logistics • Hospitality

BCD Travel is a leading business travel management company that simplifies the conversation around corporate travel by offering integrated solutions and services to meet various program goals. With a global network spanning over 100 countries, BCD Travel provides tailored travel management services, risk management solutions, and innovative tools to enhance the travel experience for organizations and their employees. Their expertise in the travel industry has earned them multiple recognitions, and they are committed to sustainability and optimizing business travel programs.

📋 Description

• Lead information security risk assessments across applications, infrastructure, cloud services, business processes, projects, integrations, and third-party suppliers • Determine inherent and residual risk ratings using approved criteria, documented evidence, and clear rationale • Identify control gaps and evaluate security control design, implementation, and effectiveness • Develop risk statements and recommend practical risk treatment options • Map risks and findings to internal policies, control procedures, regulatory requirements, and security frameworks • Partner with business and risk owners on remediation and risk treatment plans • Maintain and continuously improve the centralized information security risk register • Conduct third-party supplier security risk assessments and review assurance documentation, certifications, reports, testing evidence, contractual requirements, and control gaps • Assess emerging technology risks, including artificial intelligence, and advise on governance and controls • Collaborate with Security, Privacy, Legal, Compliance, Audit, Technology, Procurement, Business Relationship Management, and business stakeholders • Prepare risk summaries, dashboards, metrics, and management reporting • Monitor changes in technology, business processes, suppliers, threats, vulnerabilities, regulations, and control environments, initiating reassessments when appropriate

🎯 Requirements

• Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Risk Management, Business, or related field, or equivalent experience • Demonstrated experience conducting information security or technology risk assessments using structured risk management methodologies • Strong understanding of information security risk concepts, including threats, vulnerabilities, business impact, control effectiveness, and residual risk • Proven ability to identify control gaps, evaluate controls, and develop practical risk treatment recommendations • Working knowledge of ISO/IEC 27001, ISO/IEC 27002, ISO 31000, NIST CSF, or equivalent frameworks • Experience assessing risks across applications, cloud services, infrastructure, third-party suppliers, data protection, vulnerability management, and operational security • Experience supporting third-party risk assessments and reviewing ISO certifications, SOC reports, PCI DSS documentation, penetration test results, and supplier security questionnaires • Experience maintaining risk registers and producing accurate, traceable, and audit-ready documentation • Ability to facilitate risk discussions, influence stakeholders, and translate complex technical issues into clear business risks and actionable recommendations • Familiarity with emerging technology risks, including artificial intelligence, privacy, and evolving regulatory requirements • Relevant certifications such as CRISC, CISSP, CISM, or ISO/IEC 27001 Lead Auditor/Implementer • Governance-first mindset, strong analytical skills, professional judgment, and ability to operate independently in a global environment

🏖️ Benefits

• Flexible working hours and work-from-home or remote opportunities • Opportunities to grow your skillset and career • Work at the forefront of travel technology and help shape the future of business travel • Generous vacation days • Compensation package including mental, physical, and financial wellbeing tools • Travel industry professional perks and discounts • Inclusive work environment where diversity is celebrated • Work From Anywhere opportunity for 60 days per year

Apply Now

Similar Jobs

🕒 4 days ago

Hyland

1001 - 5000

🤝 B2B

☁️ SaaS

🏢 Enterprise

Senior Cyber Security Analyst protecting Hyland's enterprise content intelligence platform. Designing security solutions, responding to incidents, and strengthening cloud and organizational security controls.

🇨🇴 Colombia – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

🔐 Security Analyst

🕒 September 28

Masabi

201 - 500

💼 Consulting

✈️ Travel

📦 Logistics

Security Compliance Analyst managing controls, third-party risk and audits for Masabi’s global public-transit fare-payment platform. Supporting customer security requests and improving compliance workflows.

🇨🇴 Colombia – Remote

💰 Venture Round on 2022-03

⏰ Full Time

🟡 Mid-level

🟠 Senior

🔐 Security Analyst

🕒 September 26

Stefanini LATAM

10,000+ employees

💼 Consulting

📦 Logistics

📣 Marketing

Analista DLP investigando alertas y validando flujos legĂ­timos para SURA Colombia. Coordinando ajustes de reglas con Seguridad de la InformaciĂłn y proveedores.

🇨🇴 Colombia – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

🔐 Security Analyst

🗣️🇪🇸 Spanish Required