Apply now »

Senior Risk Analyst, Information Security Risk Management

Date:  Oct 9, 2026
Location: 

CO, Colombia, Virtual, Colombia, LATAM

Shape what's next with BCD

 

Senior Risk Analyst, Information Security Risk Management

Full time, Colombia, Costa Rica and Mexico

 

The Senior Risk Analyst operates within the Information Security Risk Management Team and is a core contributor to BCD Travel’s enterprise information security risk management program. The role is responsible for identifying, assessing, documenting, monitoring, and supporting the treatment of information security risks across business services, applications, technology environments, projects, and third-party suppliers.

 

The position applies structured and standards-based risk methodologies to assess inherent and residual risk, identify control gaps, evaluate control effectiveness, recommend proportionate treatment options, and support informed risk decisions. The role works closely with business owners, technology teams, control owners, and governance functions to ensure risks are clearly understood, appropriately owned, and supported by informed, well-documented risk decisions and treatment actions.

 

The Senior Risk Analyst maintains and continuously improves the centralized information security risk register, including the relationships between risk entries, security risk assessments, findings, projects, controls, exceptions, and remediation activities.

 

The ideal candidate brings strong information security risk management experience, sound professional judgment, and a governance-first mindset, enabling them to contribute quickly with minimal oversight.

 

What You'll Do

  • Lead information security risk assessments covering applications, infrastructure, cloud services, business processes, projects, integrations, and third-party suppliers
  • Determine inherent and residual risk ratings using approved criteria, documented evidence, and clear rationale
  • Identify control gaps and evaluate the design, implementation, and effectiveness of security controls
  • Develop clear risk statements and recommend practical risk treatment options that address business and security requirements
  • Map risks and findings to internal policies, control procedures, regulatory requirements, and recognized security frameworks
  • Partner with business and risk owners to develop remediation and risk treatment plans with defined actions, ownership, target dates, and expected residual risk outcomes
  • Maintain and continuously improve the centralized information security risk register, ensuring risk ratings, ownership, treatment decisions, control mappings, and supporting evidence remain current and appropriate
  • Conduct security risk assessments for new and existing third-party suppliers, including reviews of security assurance documentation, certifications, independent assessment reports, testing evidence, contractual requirements, and identified control gaps
  • Assess risks associated with emerging technologies, including artificial intelligence, and provide guidance on governance, control considerations, and risk management requirements to support informed adoption and business decision-making
  • Collaborate with Security, Privacy, Legal, Compliance, Audit, Technology, Procurement, Business Relationship Management, and business stakeholders to support informed and consistent risk decisions
  • Prepare risk summaries, dashboards, metrics, and management reporting that communicate key exposures, treatment progress, emerging risks, overdue actions, and decisions requiring management attention
  • Monitor changes in technology, business processes, suppliers, threats, vulnerabilities, regulatory requirements, and control environments, initiating reassessment activities when appropriate

 

What You'll Bring

  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Risk Management, Business, or related field, or equivalent experience
  • Demonstrated experience conducting information security or technology risk assessments using structured risk management methodologies
  • Strong understanding of information security risk concepts, including threats, vulnerabilities, business impact, control effectiveness, and residual risk
  • Proven ability to identify control gaps, evaluate controls, and develop practical risk treatment recommendations
  • Working knowledge of information security risk management frameworks and standards, including ISO/IEC 27001, ISO/IEC 27002, ISO 31000, NIST CSF, or equivalent frameworks
  • Experience assessing risks across applications, cloud services, infrastructure, third-party suppliers, data protection, vulnerability management, and operational security
  • Experience supporting third-party risk assessments and reviewing assurance documentation such as ISO certifications, SOC reports, PCI DSS documentation, penetration test results, and supplier security questionnaires
  • Experience maintaining risk registers and producing accurate, traceable, and audit-ready documentation
  • Ability to facilitate risk discussions, influence stakeholders, and translate complex technical issues into clear business risks and actionable recommendations
  • Familiarity with emerging technology risks, including artificial intelligence, privacy, and evolving regulatory requirements
  • Relevant certifications such as CRISC, CISSP, CISM, or ISO/IEC 27001 Lead Auditor/Implementer
  • Governance first mindset with strong analytical skills, professional judgment, and the ability to operate independently in a global environment

 

Why you’ll love working here 
Join a global industry leader where curiosity drives innovation, growth is continuous, and every voice matters. At BCD, you'll have the freedom to make an impact, the support to develop your potential, and the opportunity to help shape the future of travel. 

 

Meet BCD  
BCD Travel creates connections that move people and ideas forward. Through open technology and trusted human expertise, we help companies and people navigate change, simplify complexity and make confident decisions about how and when they travel. Our intuitive digital experiences for every stakeholder power journeys that fuel success and drive progress. With 15,000+ dedicated team members serving clients in 170+ countries, BCD is shaping a more sustainable future for business travel. Industry-leading meetings and events management and a global consultancy complete our suite of solutions and services. In 2025, BCD achieved $24.4 billion in sales. For more information, visit www.bcdtravel.com.   
 

Get to know us by exploring our career site and checking out our social media:

 

What’s in it for you 

  • Flexible working hours and work-from-home or remote opportunities 

  • Opportunities to grow your skillset and career 

  • Work at the forefront of travel technology and help shape the future of business travel 

  • Generous vacation days so you can rest and recharge 

  • A compensation package that feels fair to you, including mental, physical, and financial wellbeing tools 

  • Travel industry professional perks and discounts 

  • An inclusive work environment where diversity is celebrated 

  • Work From Anywhere opportunity for 60 days per year 
     

Ready to shape what’s next? Apply now! 
 
We’re dedicated to building a diverse, inclusive and authentic workplace. If you’re excited about a role, but your experience doesn’t align perfectly, we still encourage you to apply. 
 
We are committed to providing reasonable and necessary accommodations to ensure all employees can perform their roles effectively. For accommodation requests or further information, contact our Talent Acquisition department at careers@bcdtravel.com. 

#LI-Remote

#LI-VP1

Apply now »