FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Risk Analyst, Information Security Risk Management
BCD Travel. Lead information security risk assessments across applications, infrastructure, cloud services, business processes, projects, integrations, and third-party suppliers .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in conducting information security risk assessments, evaluating control effectiveness, and developing risk treatment recommendations. Proficient in maintaining risk registers and producing audit-ready documentation while collaborating with various stakeholders to address emerging technology risks and regulatory requirements.
Highest-signal resume keywords
Information Security Risk AssessmentsISO/IEC 27001 KnowledgeThird-Party Risk AssessmentsRisk Management MethodologiesControl Gap Identification
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Risk AssessmentControl EvaluationRisk Treatment RecommendationsRisk Register MaintenanceThreat AnalysisVulnerability ManagementData ProtectionOperational SecurityRegulatory ComplianceEmerging Technology Risk Assessment
Soft Skills
Analytical SkillsStakeholder InfluenceProfessional JudgmentCommunication SkillsCollaboration
Certifications & Qualifications
CRISCCISSPCISMISO/IEC 27001 Lead AuditorISO/IEC 27001 Implementer
Industry Keywords
NIST CSFISO/IEC 27002ISO 31000SOC ReportsPCI DSSPenetration TestingSecurity FrameworksAudit-Ready DocumentationBusiness Impact AnalysisControl Effectiveness
Tech Stack
Tools & technologiesCloudCyber Security
About the role
Key responsibilities & impact- Lead information security risk assessments across applications, infrastructure, cloud services, business processes, projects, integrations, and third-party suppliers
- Determine inherent and residual risk ratings using approved criteria, documented evidence, and clear rationale
- Identify control gaps and evaluate security control design, implementation, and effectiveness
- Develop risk statements and recommend practical risk treatment options
- Map risks and findings to internal policies, control procedures, regulatory requirements, and security frameworks
- Partner with business and risk owners on remediation and risk treatment plans
- Maintain and continuously improve the centralized information security risk register
- Conduct third-party supplier security risk assessments and review assurance documentation, certifications, reports, testing evidence, contractual requirements, and control gaps
- Assess emerging technology risks, including artificial intelligence, and advise on governance and controls
- Collaborate with Security, Privacy, Legal, Compliance, Audit, Technology, Procurement, Business Relationship Management, and business stakeholders
- Prepare risk summaries, dashboards, metrics, and management reporting
- Monitor changes in technology, business processes, suppliers, threats, vulnerabilities, regulations, and control environments, initiating reassessments when appropriate
Requirements
What you’ll need- Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Risk Management, Business, or related field, or equivalent experience
- Demonstrated experience conducting information security or technology risk assessments using structured risk management methodologies
- Strong understanding of information security risk concepts, including threats, vulnerabilities, business impact, control effectiveness, and residual risk
- Proven ability to identify control gaps, evaluate controls, and develop practical risk treatment recommendations
- Working knowledge of ISO/IEC 27001, ISO/IEC 27002, ISO 31000, NIST CSF, or equivalent frameworks
- Experience assessing risks across applications, cloud services, infrastructure, third-party suppliers, data protection, vulnerability management, and operational security
- Experience supporting third-party risk assessments and reviewing ISO certifications, SOC reports, PCI DSS documentation, penetration test results, and supplier security questionnaires
- Experience maintaining risk registers and producing accurate, traceable, and audit-ready documentation
- Ability to facilitate risk discussions, influence stakeholders, and translate complex technical issues into clear business risks and actionable recommendations
- Familiarity with emerging technology risks, including artificial intelligence, privacy, and evolving regulatory requirements
- Relevant certifications such as CRISC, CISSP, CISM, or ISO/IEC 27001 Lead Auditor/Implementer
- Governance-first mindset, strong analytical skills, professional judgment, and ability to operate independently in a global environment
Benefits
Comp & perks- Flexible working hours and work-from-home or remote opportunities
- Opportunities to grow your skillset and career
- Work at the forefront of travel technology and help shape the future of business travel
- Generous vacation days
- Compensation package including mental, physical, and financial wellbeing tools
- Travel industry professional perks and discounts
- Inclusive work environment where diversity is celebrated
- Work From Anywhere opportunity for 60 days per year