Senior Risk Analyst @BCD
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted YDay

[Hiring] Senior Risk Analyst @BCD

YDay - BCD is hiring a remote Senior Risk Analyst. πŸ’Έ Salary: unspecified πŸ“Location: Latin America (LATAM)

Role Description

The Senior Risk Analyst operates within the Information Security Risk Management Team and is a core contributor to BCD Travel’s enterprise information security risk management program. The role is responsible for identifying, assessing, documenting, monitoring, and supporting the treatment of information security risks across business services, applications, technology environments, projects, and third-party suppliers.

The position applies structured and standards-based risk methodologies to:

  • Assess inherent and residual risk
  • Identify control gaps
  • Evaluate control effectiveness
  • Recommend proportionate treatment options
  • Support informed risk decisions

The role works closely with:

  • Business owners
  • Technology teams
  • Control owners
  • Governance functions

The Senior Risk Analyst maintains and continuously improves the centralized information security risk register, including the relationships between:

  • Risk entries
  • Security risk assessments
  • Findings
  • Projects
  • Controls
  • Exceptions
  • Remediation activities

The ideal candidate brings strong information security risk management experience, sound professional judgment, and a governance-first mindset, enabling them to contribute quickly with minimal oversight.

Qualifications

  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Risk Management, Business, or related field, or equivalent experience
  • Demonstrated experience conducting information security or technology risk assessments using structured risk management methodologies
  • Strong understanding of information security risk concepts, including threats, vulnerabilities, business impact, control effectiveness, and residual risk
  • Proven ability to identify control gaps, evaluate controls, and develop practical risk treatment recommendations
  • Working knowledge of information security risk management frameworks and standards, including ISO/IEC 27001, ISO/IEC 27002, ISO 31000, NIST CSF, or equivalent frameworks
  • Experience assessing risks across applications, cloud services, infrastructure, third-party suppliers, data protection, vulnerability management, and operational security
  • Experience supporting third-party risk assessments and reviewing assurance documentation such as ISO certifications, SOC reports, PCI DSS documentation, penetration test results, and supplier security questionnaires
  • Experience maintaining risk registers and producing accurate, traceable, and audit-ready documentation
  • Ability to facilitate risk discussions, influence stakeholders, and translate complex technical issues into clear business risks and actionable recommendations
  • Familiarity with emerging technology risks, including artificial intelligence, privacy, and evolving regulatory requirements
  • Relevant certifications such as CRISC, CISSP, CISM, or ISO/IEC 27001 Lead Auditor/Implementer
  • Governance first mindset with strong analytical skills, professional judgment, and the ability to operate independently in a global environment

Requirements

  • Lead information security risk assessments covering applications, infrastructure, cloud services, business processes, projects, integrations, and third-party suppliers
  • Determine inherent and residual risk ratings using approved criteria, documented evidence, and clear rationale
  • Identify control gaps and evaluate the design, implementation, and effectiveness of security controls
  • Develop clear risk statements and recommend practical risk treatment options that address business and security requirements
  • Map risks and findings to internal policies, control procedures, regulatory requirements, and recognized security frameworks
  • Partner with business and risk owners to develop remediation and risk treatment plans with defined actions, ownership, target dates, and expected residual risk outcomes
  • Maintain and continuously improve the centralized information security risk register, ensuring risk ratings, ownership, treatment decisions, control mappings, and supporting evidence remain current and appropriate
  • Conduct security risk assessments for new and existing third-party suppliers, including reviews of security assurance documentation, certifications, independent assessment reports, testing evidence, contractual requirements, and identified control gaps
  • Assess risks associated with emerging technologies, including artificial intelligence, and provide guidance on governance, control considerations, and risk management requirements to support informed adoption and business decision-making
  • Collaborate with Security, Privacy, Legal, Compliance, Audit, Technology, Procurement, Business Relationship Management, and business stakeholders to support informed and consistent risk decisions
  • Prepare risk summaries, dashboards, metrics, and management reporting that communicate key exposures, treatment progress, emerging risks, overdue actions, and decisions requiring management attention
  • Monitor changes in technology, business processes, suppliers, threats, vulnerabilities, regulatory requirements, and control environments, initiating reassessment activities when appropriate

Benefits

  • Flexible working hours and work-from-home or remote opportunities
  • Opportunities to grow your skillset and career
  • Work at the forefront of travel technology and help shape the future of business travel
  • Generous vacation days so you can rest and recharge
  • A compensation package that feels fair to you, including mental, physical, and financial wellbeing tools
  • Travel industry professional perks and discounts
  • An inclusive work environment where diversity is celebrated
  • Work From Anywhere opportunity for 60 days per year
Before You Apply
️
remote Be aware of the location restriction for this remote position: Latin America (LATAM)
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Risk Analyst @BCD
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted YDay
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 130,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Latin America (LATAM)
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 130,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 130,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 130,828+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later