Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
BCD Travel

Senior Risk Analyst, Information Security Risk Management

BCD Travel

. Lead information security risk assessments across applications, infrastructure, cloud services, business processes, projects, integrations, and third-party suppliers .

Posted 10/9/2026full-timeRemote • Colombia, Costa Rica, MexicoSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in conducting information security risk assessments, evaluating control effectiveness, and developing risk treatment recommendations. Proficient in maintaining risk registers and producing audit-ready documentation while collaborating with various stakeholders to address emerging technology risks and regulatory requirements.

Highest-signal resume keywords
Information Security Risk AssessmentsISO/IEC 27001 KnowledgeThird-Party Risk AssessmentsRisk Management MethodologiesControl Gap Identification

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Risk AssessmentControl EvaluationRisk Treatment RecommendationsRisk Register MaintenanceThreat AnalysisVulnerability ManagementData ProtectionOperational SecurityRegulatory ComplianceEmerging Technology Risk Assessment
Soft Skills
Analytical SkillsStakeholder InfluenceProfessional JudgmentCommunication SkillsCollaboration
Certifications & Qualifications
CRISCCISSPCISMISO/IEC 27001 Lead AuditorISO/IEC 27001 Implementer
Industry Keywords
NIST CSFISO/IEC 27002ISO 31000SOC ReportsPCI DSSPenetration TestingSecurity FrameworksAudit-Ready DocumentationBusiness Impact AnalysisControl Effectiveness

Tech Stack

Tools & technologies
CloudCyber Security

About the role

Key responsibilities & impact
  • Lead information security risk assessments across applications, infrastructure, cloud services, business processes, projects, integrations, and third-party suppliers
  • Determine inherent and residual risk ratings using approved criteria, documented evidence, and clear rationale
  • Identify control gaps and evaluate security control design, implementation, and effectiveness
  • Develop risk statements and recommend practical risk treatment options
  • Map risks and findings to internal policies, control procedures, regulatory requirements, and security frameworks
  • Partner with business and risk owners on remediation and risk treatment plans
  • Maintain and continuously improve the centralized information security risk register
  • Conduct third-party supplier security risk assessments and review assurance documentation, certifications, reports, testing evidence, contractual requirements, and control gaps
  • Assess emerging technology risks, including artificial intelligence, and advise on governance and controls
  • Collaborate with Security, Privacy, Legal, Compliance, Audit, Technology, Procurement, Business Relationship Management, and business stakeholders
  • Prepare risk summaries, dashboards, metrics, and management reporting
  • Monitor changes in technology, business processes, suppliers, threats, vulnerabilities, regulations, and control environments, initiating reassessments when appropriate

Requirements

What you’ll need
  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Risk Management, Business, or related field, or equivalent experience
  • Demonstrated experience conducting information security or technology risk assessments using structured risk management methodologies
  • Strong understanding of information security risk concepts, including threats, vulnerabilities, business impact, control effectiveness, and residual risk
  • Proven ability to identify control gaps, evaluate controls, and develop practical risk treatment recommendations
  • Working knowledge of ISO/IEC 27001, ISO/IEC 27002, ISO 31000, NIST CSF, or equivalent frameworks
  • Experience assessing risks across applications, cloud services, infrastructure, third-party suppliers, data protection, vulnerability management, and operational security
  • Experience supporting third-party risk assessments and reviewing ISO certifications, SOC reports, PCI DSS documentation, penetration test results, and supplier security questionnaires
  • Experience maintaining risk registers and producing accurate, traceable, and audit-ready documentation
  • Ability to facilitate risk discussions, influence stakeholders, and translate complex technical issues into clear business risks and actionable recommendations
  • Familiarity with emerging technology risks, including artificial intelligence, privacy, and evolving regulatory requirements
  • Relevant certifications such as CRISC, CISSP, CISM, or ISO/IEC 27001 Lead Auditor/Implementer
  • Governance-first mindset, strong analytical skills, professional judgment, and ability to operate independently in a global environment

Benefits

Comp & perks
  • Flexible working hours and work-from-home or remote opportunities
  • Opportunities to grow your skillset and career
  • Work at the forefront of travel technology and help shape the future of business travel
  • Generous vacation days
  • Compensation package including mental, physical, and financial wellbeing tools
  • Travel industry professional perks and discounts
  • Inclusive work environment where diversity is celebrated
  • Work From Anywhere opportunity for 60 days per year