Security Risk Analyst

hace 5 meses


San José, Costa Rica Catalina Marketing A tiempo completo

**Why Catalina?** Catalina delivers omni-channel solutions to our customers with a long-standing history of rich data assets, but our _greatest _asset is our people. Our guiding principles set the stage for winning in the markets we serve, and our potential is powerful. When you join the Catalina team, you will be part of an inclusive environment that embraces flexibility, community involvement, work-life balance as well as opportunities to grow professionally.

**Our Team**

The Security Risk Analyst plays a pivotal role in safeguarding our organization against the potential risks posed by third-party vendors and service providers. This individual ensures that all external partnerships adhere to strict regulatory standards and internal policies, prioritizing data privacy and security controls by conducting thorough evaluations and risk assessments. Collaborating closely with internal stakeholders, the analyst facilitates a comprehensive approach to third-party risk management, enhancing the integration of services with a keen focus on security and compliance. Additionally, leading and innovating the Security Awareness Program, the analyst champions a culture of security mindfulness across the organization, educating employees on best practices and mitigating the risks of social engineering attacks.

**Responsibilities**
- Evaluate third-party vendors and service providers to identify and mitigate potential organizational risks, ensuring compliance with regulatory requirements and internal policies.
- Work collaboratively with internal stakeholders, including the privacy team, procurement, and business owners, to manage third-party risks effectively, ensuring the secure integration of services and data management.
- Facilitate the completion and evaluation of third-party risk management forms by vendors, ensuring comprehensive risk analysis before proceeding with partnerships.
- Participate and improve the Security Awareness Program, including Phishing campaigns, to educate users on security best practices, contributing to a culture of heightened security awareness and reduced risk of social engineering attacks.
- Proactively conduct risk assessments to identify potential vulnerabilities and compliance gaps with third-party vendors, focusing on data privacy, security controls, and contractual obligations to safeguard organizational assets.
- Recommend and implement risk mitigation plans for identified vulnerabilities, ensuring that all third-party services align with the company's security standards and compliance requirements.
- Monitor and enforce third-party compliance with relevant regulatory standards and internal policies, reducing legal and operational risks.
- Keep accurate and up-to-date records of risk assessments, mitigation actions, and compliance activities to support audit processes and decision-making.
- Assist in SOC2 and other relevant audits by liaising with auditors and conducting thorough IT controls testing to ensure the design and operational effectiveness of security measures.
- Develop and lead the Security Awareness Program, conducting Phishing campaigns and other initiatives to educate and test the workforce, aiming to reduce susceptibility to cyber threats.
- Compile and analyze results from security initiatives, like Phishing campaigns, to identify trends, report on program effectiveness, and adjust strategies accordingly.
- Interact with vendors to conduct assessments and ensure the completion of necessary evaluations, emphasizing the importance of security from the onset of vendor relationships.
- Provide guidance to internal stakeholders regarding the importance of third-party risk management, educating them on the processes and requirements for adding new vendors or services.
- Continually seek opportunities to improve third-party risk management practices, security awareness programs, and compliance processes to adapt to changing threats and regulatory landscapes.
- Other assigned tasks to support the security program.

**Qualifications**
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Systems, or a related field; or equivalent experience.
- Professional certifications such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), or equivalent certifications focused on risk management, audit, and compliance preferred.
- 3 to 5 years of experience in conducting risk assessments, managing third-party risks, and ensuring compliance with relevant standards and regulations.
- In-depth understanding of auditing standards, compliance requirements (e.g., SOC2, ISO 27001, NIST CSF, GDPR), and risk management frameworks.
- Expertise in evaluating and implementing risk mitigation strategies to address vulnerabilities associated with third-party vendors and service providers.
- Strong analytical, communication, and project management skills, essential for managing risk assessments, mitigation actions, and



  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    About the RoleThe IT Control Testing Analyst will be responsible for performing control testing over data security and key resiliency risks across the Experian global business. This role will work closely with the Controls Testing Leads and the Data Analytics Team to support risk assessment, planning activities, and the identification and development of data...

  • Credit Risk Analyst

    hace 1 mes


    San José, San José, Costa Rica World Fuel Services A tiempo completo

    Job Title: Junior Credit AnalystAt World Fuel Services, we are seeking a highly skilled Junior Credit Analyst to join our team. As a Junior Credit Analyst, you will play a critical role in supporting our credit risk management efforts by analyzing and evaluating credit applications, monitoring customer creditworthiness, and providing recommendations to...


  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    **Job Summary**Experian is seeking a highly skilled IT Control Testing Analyst to join our team. In this role, you will be responsible for performing control testing over data security and key resiliency risks across the Experian global business.**Key Responsibilities**Develop and execute testing plans leveraging advanced analytics and manual activities to...

  • Security Risk Partner

    hace 3 semanas


    San Francisco, Heredia, Costa Rica Experian A tiempo completo

    Job Title: Security Risk PartnerOverview:We are seeking a highly skilled Security Risk Partner to join our team at Experian. As a key member of our organization, you will play a critical role in ensuring the security and integrity of our systems and data.Key Responsibilities:- Conduct and prioritize project security assessments for new enterprise development...


  • San Francisco, Heredia, Costa Rica Stryker A tiempo completo

    About the Role:The Cyber Security Senior Lead Risk Analyst will be responsible for daily administrative and risk management due diligence and related activities to execute and support Stryker's Risk Management program.Key Responsibilities:Ensure that risk assessments are completed on new and existing third-party vendors and other parties engaging...


  • San José, San José, Costa Rica Equifax A tiempo completo

    **Security Risk Management Role**At Equifax, we are seeking a skilled Security Risk Management Specialist to join our team. In this role, you will be responsible for reviewing and tracking new security issues, as well as reviewing artifacts provided as evidence to close current issues. You will also be cross-trained in our Deviations process to support when...


  • San José, Costa Rica Equifax A tiempo completo

    As a Security Analyst, you will have the opportunity to collaborate to monitor, detect and respond to security threats along the global organization. While interacting with other teams across Cyber Security you will conduct security investigations and be able to learn and get experience with each incident. The level 1 Security Operations Center (SOC)...

  • Governance Risk

    hace 5 meses


    San José, Costa Rica Mondelēz International A tiempo completo

    **Are You Ready to Make It Happen at Mondelēz International?** **Join our Mission to Lead the Future of Snacking. Make It Uniquely Yours.** You work with the information security team as a competent and experienced information security and compliance specialist. **How you will contribute** **What you will bring** A desire to drive your future and...


  • San José, Costa Rica Equifax A tiempo completo

    Equifax is where you can power your possible. If you want to achieve your true potential, chart new paths, develop new skills, collaborate with bright minds, and make a meaningful impact, we want to hear from you. As a Security Analyst, you will have the opportunity to collaborate to monitor, detect, and respond to security threats along the global...


  • San José, Costa Rica GSB A tiempo completo

    We are seeking a motivated professional to join its information security operations team as a **Security Analyst **focused on managing risks and vulnerabilities of a modern technology cloud first environment. The Security Analyst will play a critical role in safeguarding the integrity and resilience of Experian’s modern cloud-based infrastructure. **Key...


  • San Francisco, Heredia, Costa Rica GFT Technologies SE A tiempo completo

    About the Role:We are seeking a skilled Security Risk Specialist to join our team at GFT Technologies SE. As a Security Risk Specialist, you will be responsible for ensuring that vulnerability disclosure program requirements are followed and adhered to on client applications and system topologies.A Day in this Role:Prioritize newly identified vulnerabilities...


  • San José, San José, Costa Rica Mondelez International A tiempo completo

    About the RoleAs a Governance, Risk & Compliance Senior Analyst at Mondelez International, you will play a pivotal role in ensuring alignment of vendor activities with internal security policies. This position requires a deep understanding of security frameworks, risk management, and compliance standards, coupled with excellent communication skills to...


  • San Francisco, Heredia, Costa Rica Stryker A tiempo completo

    About the RoleStryker, a leading medical technology company, is seeking an experienced Cyber Security Risk Consultant to join its team. This role will play a key part in helping us deliver safe and robust solutions to our customers.Job SummaryWe are looking for a skilled professional with strong analysis and problem-solving skills, as well as excellent...


  • San José, Costa Rica Equifax A tiempo completo

    As a **Cyber Security Vulnerability Analyst **, you are responsible for the security of Equifax’s corporate infrastructure as well as the infrastructure hosting Equifax’s SaaS offerings. **What you’ll do** - Responsible for supporting a global program to identify, analyze, and communicate vulnerabilities including mitigation or remediation...


  • San Francisco, Heredia, Costa Rica Stryker A tiempo completo

    We are seeking a skilled Cyber Security Risk Specialist to join our team at Stryker. This role is responsible for identifying, assessing, and mitigating cyber risks that impact our critical assets, operations, and reputation.About the Role:This position involves conducting thorough risk assessments, managing vendors, creating detailed reports, and performing...


  • San José, San José, Costa Rica Gsb A tiempo completo

    We are seeking a highly skilled professional to fill the role of Cloud Security Risk Manager at Gsb. This position plays a critical role in safeguarding the integrity and resilience of our modern cloud-based infrastructure.Key Responsibilities:Collaborate with cross-functional teams to prioritize and categorize vulnerabilities based on severity, potential...


  • San José, Costa Rica Equifax A tiempo completo

    Reporting to the Security Compliance Manager, the Security Compliance Analyst is a key member of the Security, Governance and Compliance team. This position is focused on PCI and SOC1/SOC2 compliance, working across multiple business units and markets globally to ensure and deliver upon our annual compliance assessments and improve our security compliance...


  • San José, San José, Costa Rica Equifax A tiempo completo

    About the RoleWe are seeking a highly skilled Cyber Security Vulnerability Assessment Analyst to join our team at Equifax. As a key member of our security team, you will be responsible for identifying, analyzing, and communicating vulnerabilities in our corporate infrastructure and SaaS offerings.Key ResponsibilitiesSupport a global program to identify,...


  • San José, San José, Costa Rica Mondelez International A tiempo completo

    **Secure the Future of Snacking**At Mondelez International, we're committed to leading the future of snacking. As a Governance, Risk & Compliance Senior Analyst, you'll play a pivotal role in ensuring the alignment of vendor activities with internal security policies.**Key Responsibilities**Conduct thorough reviews of security organization contracts with...


  • San José, San José, Costa Rica Amazon Support Services Costa Rica SRL A tiempo completo

    Job DescriptionAre you an experienced Risk Manager/Analyst seeking a new challenge? Amazon Support Services Costa Rica SRL is looking for a skilled Risk Intelligence Analyst to join our Buyer Risk Prevention (BRP) Organization.As a Risk Intelligence Analyst, you will be responsible for conducting risk intelligence assessments for existing lines of business,...