For Employers

BCD

Senior Risk Analyst, Information Security Risk Management

Posted 9 hours ago
5-10 years experience
Apply Now

Please mention DailyRemote when applying

?
Resume Match Score

See how much of this job your resume covers, and what’s missing.

Want a recruiter to go through it line by line?

Get professional review

Create a cover letter for this job

Upload your resume and we draft a letter for this exact role, tailored to what it asks for.

  • Tailored to this role
  • Based on your resume
  • Fully editable
AI Summary

The Senior Risk Analyst identifies, assesses, and documents information security risks across business services, applications, and third-party suppliers. They partner with stakeholders to develop remediation plans and maintain the centralized information security risk register.

Shape what's next with BCD

 

Senior Risk Analyst, Information Security Risk Management

Full time, Colombia, Costa Rica and Mexico

 

The Senior Risk Analyst operates within the Information Security Risk Management Team and is a core contributor to BCD Travel’s enterprise information security risk management program. The role is responsible for identifying, assessing, documenting, monitoring, and supporting the treatment of information security risks across business services, applications, technology environments, projects, and third-party suppliers.

 

The position applies structured and standards-based risk methodologies to assess inherent and residual risk, identify control gaps, evaluate control effectiveness, recommend proportionate treatment options, and support informed risk decisions. The role works closely with business owners, technology teams, control owners, and governance functions to ensure risks are clearly understood, appropriately owned, and supported by informed, well-documented risk decisions and treatment actions.

 

The Senior Risk Analyst maintains and continuously improves the centralized information security risk register, including the relationships between risk entries, security risk assessments, findings, projects, controls, exceptions, and remediation activities.

 

The ideal candidate brings strong information security risk management experience, sound professional judgment, and a governance-first mindset, enabling them to contribute quickly with minimal oversight.

 

What You'll Do

  • Lead information security risk assessments covering applications, infrastructure, cloud services, business processes, projects, integrations, and third-party suppliers
  • Determine inherent and residual risk ratings using approved criteria, documented evidence, and clear rationale
  • Identify control gaps and evaluate the design, implementation, and effectiveness of security controls
  • Develop clear risk statements and recommend practical risk treatment options that address business and security requirements
  • Map risks and findings to internal policies, control procedures, regulatory requirements, and recognized security frameworks
  • Partner with business and risk owners to develop remediation and risk treatment plans with defined actions, ownership, target dates, and expected residual risk outcomes
  • Maintain and continuously improve the centralized information security risk register, ensuring risk ratings, ownership, treatment decisions, control mappings, and supporting evidence remain current and appropriate
  • Conduct security risk assessments for new and existing third-party suppliers, including reviews of security assurance documentation, certifications, independent assessment reports, testing evidence, contractual requirements, and identified control gaps
  • Assess risks associated with emerging technologies, including artificial intelligence, and provide guidance on governance, control considerations, and risk management requirements to support informed adoption and business decision-making
  • Collaborate with Security, Privacy, Legal, Compliance, Audit, Technology, Procurement, Business Relationship Management, and business stakeholders to support informed and consistent risk decisions
  • Prepare risk summaries, dashboards, metrics, and management reporting that communicate key exposures, treatment progress, emerging risks, overdue actions, and decisions requiring management attention
  • Monitor changes in technology, business processes, suppliers, threats, vulnerabilities, regulatory requirements, and control environments, initiating reassessment activities when appropriate

 

What You'll Bring

  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Risk Management, Business, or related field, or equivalent experience
  • Demonstrated experience conducting information security or technology risk assessments using structured risk management methodologies
  • Strong understanding of information security risk concepts, including threats, vulnerabilities, business impact, control effectiveness, and residual risk
  • Proven ability to identify control gaps, evaluate controls, and develop practical risk treatment recommendations
  • Working knowledge of information security risk management frameworks and standards, including ISO/IEC 27001, ISO/IEC 27002, ISO 31000, NIST CSF, or equivalent frameworks
  • Experience assessing risks across applications, cloud services, infrastructure, third-party suppliers, data protection, vulnerability management, and operational security
  • Experience supporting third-party risk assessments and reviewing assurance documentation such as ISO certifications, SOC reports, PCI DSS documentation, penetration test results, and supplier security questionnaires
  • Experience maintaining risk registers and producing accurate, traceable, and audit-ready documentation
  • Ability to facilitate risk discussions, influence stakeholders, and translate complex technical issues into clear business risks and actionable recommendations
  • Familiarity with emerging technology risks, including artificial intelligence, privacy, and evolving regulatory requirements
  • Relevant certifications such as CRISC, CISSP, CISM, or ISO/IEC 27001 Lead Auditor/Implementer
  • Governance first mindset with strong analytical skills, professional judgment, and the ability to operate independently in a global environment

 

Why you’ll love working here 
Join a global industry leader where curiosity drives innovation, growth is continuous, and every voice matters. At BCD, you'll have the freedom to make an impact, the support to develop your potential, and the opportunity to help shape the future of travel. 

 

Meet BCD  
BCD Travel creates connections that move people and ideas forward. Through open technology and trusted human expertise, we help companies and people navigate change, simplify complexity and make confident decisions about how and when they travel. Our intuitive digital experiences for every stakeholder power journeys that fuel success and drive progress. With 15,000+ dedicated team members serving clients in 170+ countries, BCD is shaping a more sustainable future for business travel. Industry-leading meetings and events management and a global consultancy complete our suite of solutions and services. In 2025, BCD achieved $24.4 billion in sales. For more information, visit www.bcdtravel.com.   
 

Get to know us by exploring our career site and checking out our social media:

 

What’s in it for you 

  • Flexible working hours and work-from-home or remote opportunities 

  • Opportunities to grow your skillset and career 

  • Work at the forefront of travel technology and help shape the future of business travel 

  • Generous vacation days so you can rest and recharge 

  • A compensation package that feels fair to you, including mental, physical, and financial wellbeing tools 

  • Travel industry professional perks and discounts 

  • An inclusive work environment where diversity is celebrated 

  • Work From Anywhere opportunity for 60 days per year 
     

Ready to shape what’s next? Apply now! 
 
We’re dedicated to building a diverse, inclusive and authentic workplace. If you’re excited about a role, but your experience doesn’t align perfectly, we still encourage you to apply. 
 
We are committed to providing reasonable and necessary accommodations to ensure all employees can perform their roles effectively. For accommodation requests or further information, contact our Talent Acquisition department at careers@bcdtravel.com. 

#LI-Remote

#LI-VP1

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Software Development jobs →

Senior Backend (PHP/Golang) Software Engineer

Full Time Software Development

Senior Partner Solutions Architect - Cloud Platform

Full Time $149K - $235K per year Software Development

AI Content Specialist

Full Time $600 - $800 per month Software Development

Ingeniero/a Software Java/ Kotlin | 100% Remoto

Full Time Software Development

AI Pod- Java Senior Lead

Full Time Software Development

Graduate Software Engineer, Open Source and Linux, Canonical Ubuntu

Full Time Software Development
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Featuring 222,920+ Jobs in Software Development

Answer easy questions

Answer easy questions

222,920+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified