
Senior Risk Analyst, Information Security Risk Management
Posted 17 hours ago

Posted 17 hours ago
This is a fully remote position, open to applicants in Colombia, +2 more countries.
• Lead assessments of information security risks across applications, infrastructure, cloud services, business processes, projects, integrations, and third-party vendors.
• Assess inherent and residual risk ratings utilizing approved criteria, documented evidence, and a clear rationale.
• Identify control deficiencies and analyze the design, implementation, and effectiveness of security controls.
• Create risk statements and propose actionable risk treatment options.
• Align risks and findings with internal policies, control procedures, regulatory standards, and security frameworks.
• Collaborate with business and risk owners on remediation strategies and risk treatment plans.
• Sustain and enhance the centralized information security risk register.
• Perform security risk assessments of third-party suppliers and review assurance documentation, certifications, reports, testing evidence, contractual obligations, and control deficiencies.
• Evaluate risks associated with emerging technologies, including artificial intelligence, and provide guidance on governance and controls.
• Work together with Security, Privacy, Legal, Compliance, Audit, Technology, Procurement, Business Relationship Management, and business stakeholders.
• Generate risk summaries, dashboards, metrics, and management reports.
• Track changes in technology, business processes, suppliers, threats, vulnerabilities, regulations, and control environments, prompting reassessments as necessary.
• Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Risk Management, Business, or a related field, or equivalent experience.
• Proven experience conducting information security or technology risk assessments utilizing structured risk management methodologies.
• Strong grasp of information security risk concepts, including threats, vulnerabilities, business impact, control effectiveness, and residual risk.
• Demonstrated ability to identify control deficiencies, assess controls, and formulate practical risk treatment recommendations.
• Familiarity with ISO/IEC 27001, ISO/IEC 27002, ISO 31000, NIST CSF, or comparable frameworks.
• Experience in assessing risks across applications, cloud services, infrastructure, third-party suppliers, data protection, vulnerability management, and operational security.
• Background in supporting third-party risk assessments and reviewing ISO certifications, SOC reports, PCI DSS documentation, penetration test results, and supplier security questionnaires.
• Experience in maintaining risk registers and producing precise, traceable, and audit-ready documentation.
• Ability to facilitate risk discussions, influence stakeholders, and translate complex technical issues into clear business risks and actionable recommendations.
• Understanding of emerging technology risks, including artificial intelligence, privacy, and evolving regulatory requirements.
• Relevant certifications such as CRISC, CISSP, CISM, or ISO/IEC 27001 Lead Auditor/Implementer.
• Governance-focused mindset, strong analytical abilities, sound professional judgment, and the capability to operate independently in a global setting.
• Flexible working hours and options for remote work or working from home.
• Opportunities for skill development and career advancement.
• Engage at the cutting edge of travel technology and contribute to shaping the future of business travel.
• Generous vacation policy.
• Compensation package that includes resources for mental, physical, and financial well-being.
• Perks and discounts associated with the travel industry.
• An inclusive work environment that celebrates diversity.
• Work From Anywhere opportunity for up to 60 days each year.
Guthrie
Great Gray Trust Company
Sony Interactive Entertainment
Re:Build Manufacturing
Get handpicked remote jobs straight to your inbox weekly.