GetGlobalJob

Senior Risk Analyst, Information Security Risk Management (CO, Colombia, Virtual

BCD Travel · Remote — Colombia

عن بُعد
التقديم من الموقع الأصلي ↗سجّل الدخول للحفظ

سجّل الدخول وارفع سيرتك لترى توافقك مع هذه الوظيفة.

تسجيل الدخول

ملخص الوظيفة

المكان
Remote — Colombia
نمط العمل
عن بُعد
نوع العمل
دوام كامل
مستوى الخبرة
خبير
تاريخ النشر
11 أكتوبر 2026
آخر تحقق من المصدر
11 أكتوبر 2026
مصدر الوظيفة
عبر Himalayas

المهام

• Lead information security risk assessments covering applications, infrastructure, cloud services, business processes, projects, integrations, and third-party suppliers • Determine inherent and residual risk ratings using approved criteria, documented evidence, and clear rationale • Identify control gaps and evaluate the design, implementation, and effectiveness of security controls • Develop clear risk statements and recommend practical risk treatment options that address business and security requirements • Map risks and findings to internal policies, control procedures, regulatory requirements, and recognized security frameworks • Partner with business and risk owners to develop remediation and risk treatment plans with defined actions, ownership, target dates, and expected residual risk outcomes • Maintain and continuously improve the centralized information security risk register, ensuring risk ratings, ownership, treatment decisions, control mappings, and supporting evidence remain current and appropriate • Conduct security risk assessments for new and existing third-party suppliers, including reviews of security assurance documentation, certifications, independent assessment reports, testing evidence, contractual requirements, and identified control gaps • Assess risks associated with emerging technologies, including artificial intelligence, and provide guidance on governance, control considerations, and risk management requirements to support informed adoption and business decision-making • Collaborate with Security, Privacy, Legal, Compliance, Audit, Technology, Procurement, Business Relationship Management, and business stakeholders to support informed and consistent risk decisions • Prepare risk summaries, dashboards, metrics, and management reporting that communicate key exposures, treatment progress, emerging risks, overdue actions, and decisions requiring management attention • Monitor changes in technology, business processes, suppliers, threats, vulnerabilities, regulatory requirements, and control environments, initiating reassessment activities when appropriate

المتطلبات

• Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Risk Management, Business, or related field, or equivalent experience • Demonstrated experience conducting information security or technology risk assessments using structured risk management methodologies • Strong understanding of information security risk concepts, including threats, vulnerabilities, business impact, control effectiveness, and residual risk • Proven ability to identify control gaps, evaluate controls, and develop practical risk treatment recommendations • Working knowledge of information security risk management frameworks and standards, including ISO/IEC 27001, ISO/IEC 27002, ISO 31000, NIST CSF, or equivalent frameworks • Experience assessing risks across applications, cloud services, infrastructure, third-party suppliers, data protection, vulnerability management, and operational security • Experience supporting third-party risk assessments and reviewing assurance documentation such as ISO certifications, SOC reports, PCI DSS documentation, penetration test results, and supplier security questionnaires • Experience maintaining risk registers and producing accurate, traceable, and audit-ready documentation • Ability to facilitate risk discussions, influence stakeholders, and translate complex technical issues into clear business risks and actionable recommendations • Familiarity with emerging technology risks, including artificial intelligence, privacy, and evolving regulatory requirements • Relevant certifications such as CRISC, CISSP, CISM, or ISO/IEC 27001 Lead Auditor/Implementer • Governance first mindset with strong analytical skills, professional judgment, and the ability to operate independently in a global environment

المهارات

التأشيرة والانتقال

الإعلان لا يذكر كفالة التأشيرة. تحقّق من الإعلان الأصلي أو اسأل الشركة.

الإعلان لا يذكر دعم الانتقال.

وصف الوظيفة

Shape what's next with BCD Senior Risk Analyst, Information Security Risk Management Full time, Colombia, Costa Rica and Mexico The Senior Risk Analyst operates within the Information Security Risk Management Team and is a core contributor to BCD Travel’s enterprise information security risk management program. The role is responsible for identifying, assessing, documenting, monitoring, and supporting the treatment of information security risks across business services, applications, technology environments, projects, and third-party suppliers. The position applies structured and standards-based risk methodologies to assess inherent and residual risk, identify control gaps, evaluate control effectiveness, recommend proportionate treatment options, and support informed risk decisions. The role works closely with business owners, technology teams, control owners, and governance functions to ensure risks are clearly understood, appropriately owned, and supported by informed, well-documented risk decisions and treatment actions. The Senior Risk Analyst maintains and continuously improves the centralized information security risk register, including the relationships between risk entries, security risk assessments, findings, projects, controls, exceptions, and remediation activities. The ideal candidate brings strong information security risk management experience, sound professional judgment, and a governance-first mindset, enabling them to contribute quickly with minimal oversight. What You'll Do • Lead information security risk assessments covering applications, infrastructure, cloud services, business processes, projects, integrations, and third-party suppliers • Determine inherent and residual risk ratings using approved criteria, documented evidence, and clear rationale • Identify control gaps and evaluate the design, implementation, and effectiveness of security controls • Develop clear risk statements and recommend practical risk treatment options that address business and security requirements • Map risks and findings to internal policies, control procedures, regulatory requirements, and recognized security frameworks • Partner with business and risk owners to develop remediation and risk treatment plans with defined actions, ownership, target dates, and expected residual risk outcomes • Maintain and continuously improve the centralized information security risk register, ensuring risk ratings, ownership, treatment decisions, control mappings, and supporting evidence remain current and appropriate • Conduct security risk assessments for new and existing third-party suppliers, including reviews of security assurance documentation, certifications, independent assessment reports, testing evidence, contractual requirements, and identified control gaps • Assess risks associated with emerging technologies, including artificial intelligence, and provide guidance on governance, control considerations, and risk management requirements to support informed adoption and business decision-making • Collaborate with Security, Privacy, Legal, Compliance, Audit, Technology, Procurement, Business Relationship Management, and business stakeholders to support informed and consistent risk decisions • Prepare risk summaries, dashboards, metrics, and management reporting that communicate key exposures, treatment progress, emerging risks, overdue actions, and decisions requiring management attention • Monitor changes in technology, business processes, suppliers, threats, vulnerabilities, regulatory requirements, and control environments, initiating reassessment activities when appropriate What You'll Bring • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Risk Management, Business, or related field, or equivalent experience • Demonstrated experience conducting information security or technology risk assessments using structured risk management methodologies • Strong understanding of information security risk concepts, including threats, vulnerabilities, business impact, control effectiveness, and residual risk • Proven ability to identify control gaps, evaluate controls, and develop practical risk treatment recommendations • Working knowledge of information security risk management frameworks and standards, including ISO/IEC 27001, ISO/IEC 27002, ISO 31000, NIST CSF, or equivalent frameworks • Experience assessing risks across applications, cloud services, infrastructure, third-party suppliers, data protection, vulnerability management, and operational security • Experience supporting third-party risk assessments and reviewing assurance documentation such as ISO certifications, SOC reports, PCI DSS documentation, penetration test results, and supplier security questionnaires • Experience maintaining risk registers and producing accurate, traceable, and audit-ready documentation • Ability to facilitate risk discussions, influence stakeholders, and translate complex technical issues into clear business risks and actionable recommendations • Familiarity with emerging technology risks, including artificial intelligence, privacy, and evolving regulatory requirements • Relevant certifications such as CRISC, CISSP, CISM, or ISO/IEC 27001 Lead Auditor/Implementer • Governance first mindset with strong analytical skills, professional judgment, and the ability to operate independently in a global environment Why you’ll love working here Join a global industry leader where curiosity drives innovation, growth is continuous, and every voice matters. At BCD, you'll have the freedom to make an impact, the support to develop your potential, and the opportunity to help shape the future of travel. Meet BCD BCD Travel creates connections that move people and ideas forward. Through open technology and trusted human expertise, we help companies and people navigate change, simplify complexity and make confident decisions about how and when they tr
التقديم من الموقع الأصلي ↗مصدر الوظيفة: عبر Himalayas

GetGlobalJob ليست صاحبة العمل ولا وسيطاً في التوظيف. يتم التقديم على موقع الناشر الأصلي، فتحقّق دائماً من الإعلان قبل إرسال بياناتك، ولا تدفع أي مبلغ مقابل وظيفة.

قيّم توافقك لهذه الوظيفة

أنشئ حسابك مجاناً وارفع سيرتك الذاتية لترى نسبة توافقك مع هذه الوظيفة والمهارات التي تنقصك.

قيّم توافقي