Security Risk Analyst

hace 5 días


San José, Costa Rica Catalina Marketing A tiempo completo

**Why Catalina?** Catalina delivers omni-channel solutions to our customers with a long-standing history of rich data assets, but our _greatest _asset is our people. Our guiding principles set the stage for winning in the markets we serve, and our potential is powerful. When you join the Catalina team, you will be part of an inclusive environment that embraces flexibility, community involvement, work-life balance as well as opportunities to grow professionally.

**Our Team**

The Security Risk Analyst plays a pivotal role in safeguarding our organization against the potential risks posed by third-party vendors and service providers. This individual ensures that all external partnerships adhere to strict regulatory standards and internal policies, prioritizing data privacy and security controls by conducting thorough evaluations and risk assessments. Collaborating closely with internal stakeholders, the analyst facilitates a comprehensive approach to third-party risk management, enhancing the integration of services with a keen focus on security and compliance. Additionally, leading and innovating the Security Awareness Program, the analyst champions a culture of security mindfulness across the organization, educating employees on best practices and mitigating the risks of social engineering attacks.

**Responsibilities**
- Evaluate third-party vendors and service providers to identify and mitigate potential organizational risks, ensuring compliance with regulatory requirements and internal policies.
- Work collaboratively with internal stakeholders, including the privacy team, procurement, and business owners, to manage third-party risks effectively, ensuring the secure integration of services and data management.
- Facilitate the completion and evaluation of third-party risk management forms by vendors, ensuring comprehensive risk analysis before proceeding with partnerships.
- Participate and improve the Security Awareness Program, including Phishing campaigns, to educate users on security best practices, contributing to a culture of heightened security awareness and reduced risk of social engineering attacks.
- Proactively conduct risk assessments to identify potential vulnerabilities and compliance gaps with third-party vendors, focusing on data privacy, security controls, and contractual obligations to safeguard organizational assets.
- Recommend and implement risk mitigation plans for identified vulnerabilities, ensuring that all third-party services align with the company's security standards and compliance requirements.
- Monitor and enforce third-party compliance with relevant regulatory standards and internal policies, reducing legal and operational risks.
- Keep accurate and up-to-date records of risk assessments, mitigation actions, and compliance activities to support audit processes and decision-making.
- Assist in SOC2 and other relevant audits by liaising with auditors and conducting thorough IT controls testing to ensure the design and operational effectiveness of security measures.
- Develop and lead the Security Awareness Program, conducting Phishing campaigns and other initiatives to educate and test the workforce, aiming to reduce susceptibility to cyber threats.
- Compile and analyze results from security initiatives, like Phishing campaigns, to identify trends, report on program effectiveness, and adjust strategies accordingly.
- Interact with vendors to conduct assessments and ensure the completion of necessary evaluations, emphasizing the importance of security from the onset of vendor relationships.
- Provide guidance to internal stakeholders regarding the importance of third-party risk management, educating them on the processes and requirements for adding new vendors or services.
- Continually seek opportunities to improve third-party risk management practices, security awareness programs, and compliance processes to adapt to changing threats and regulatory landscapes.
- Other assigned tasks to support the security program.

**Qualifications**
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Systems, or a related field; or equivalent experience.
- Professional certifications such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), or equivalent certifications focused on risk management, audit, and compliance preferred.
- 3 to 5 years of experience in conducting risk assessments, managing third-party risks, and ensuring compliance with relevant standards and regulations.
- In-depth understanding of auditing standards, compliance requirements (e.g., SOC2, ISO 27001, NIST CSF, GDPR), and risk management frameworks.
- Expertise in evaluating and implementing risk mitigation strategies to address vulnerabilities associated with third-party vendors and service providers.
- Strong analytical, communication, and project management skills, essential for managing risk assessments, mitigation actions, and


  • Security Risk Analyst

    hace 3 semanas


    San José, Costa Rica Splunk OLD (Read Only) A tiempo completo

    Splunk is the leader in big data and machine learning analytics, with a significant presence in the cybersecurity market. Join us as we pursue our disruptive vision to make machine data accessible, usable, and valuable to everyone. We are a company filled with people who are passionate about our product and seek to deliver the best experience for our...


  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    Job DescriptionExperian Employer Services, Verifications, and Housing (EVH) is seeking a motivated professional to join its product information security team as a Security Analyst focused on managing risks and vulnerabilities for both applications and infrastructure within a cloud-first environment.The Security Analyst will play a critical role in...


  • San José, Costa Rica Splunk A tiempo completo

    **About SPLUNK**: Splunk is the leader in big data and machine learning analytics, with a significant presence in the cybersecurity market. Join us as we pursue our disruptive vision to make machine data accessible, usable, and valuable to everyone. We are a company filled with people who are passionate about our product and seek to deliver the best...


  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    Job OverviewExperian Employer Services, Verifications, and Housing (EVH) is seeking a skilled professional to join its product information security team as a Security Analyst focused on managing risks and vulnerabilities for both applications and infrastructure within a cloud-first environment.This role will play a critical part in safeguarding the...

  • Security Analyst

    hace 4 semanas


    San José, San José, Costa Rica Catalina Marketing A tiempo completo

    **Why Catalina?** Catalina delivers omni-channel solutions to our customers with a long-standing history of rich data assets, but our _greatest _asset is our people.Our guiding principles set the stage for winning in the markets we serve, and our potential is powerful.When you join the Catalina team, you will be part of an inclusive environment that embraces...

  • Security Analyst

    hace 3 días


    San José, Costa Rica Catalina Marketing A tiempo completo

    **Why Catalina?** Catalina delivers omni-channel solutions to our customers with a long-standing history of rich data assets, but our _greatest _asset is our people. Our guiding principles set the stage for winning in the markets we serve, and our potential is powerful. When you join the Catalina team, you will be part of an inclusive environment that...


  • San José, San José, Costa Rica Equifax A tiempo completo

    At Equifax, you will have the opportunity to make a meaningful impact by collaborating with other teams across Cyber Security to monitor and respond to security threats. As a key member of our Security Operations Center (SOC), you will be responsible for monitoring for security risks and acting upon information according to predefined procedures and...


  • San José, San José, Costa Rica Ex2 Outcoding A tiempo completo

    Ex2 Outcoding is seeking an experienced Enterprise Security Risk Manager to join our Governance, Risk, and Compliance team. As a Cybersecurity Compliance Lead, you will be responsible for developing and implementing our security compliance program, ensuring that we meet all relevant regulatory requirements and industry standards.We are looking for a highly...


  • San José, San José, Costa Rica Catalina Marketing A tiempo completo

    About Our Team:We are a diverse and inclusive team at Catalina Marketing, committed to investing in, empowering, and retaining a more inclusive community within our company. We believe that true innovation happens when everyone has a seat at the table and a voice to be heard.Job Description:We are seeking a highly skilled Security Operations Center Analyst...


  • San José, San José, Costa Rica Equifax A tiempo completo

    The Security Operations Center Analyst role at Equifax offers an exciting opportunity to work at the forefront of cybersecurity. As a key member of our team, you will be responsible for monitoring and responding to security threats in real-time, utilizing your analytical and problem-solving skills to protect our systems and data.Responsibilities:Monitor and...


  • San José, Costa Rica Equifax A tiempo completo

    Equifax is where you can power your possible. If you want to achieve your true potential, chart new paths, develop new skills, collaborate with bright minds, and make a meaningful impact, we want to hear from you. In this role you will be responsible for performing security risk assessment reviews of Equifax third parties, reviewing documentation related to...


  • San José, San José, Costa Rica Amzn Support Srvcs Costa Rica A tiempo completo

    About the RoleWe are seeking a highly skilled Commercial Risk Analyst to join our team at Amzn Support Srvcs Costa Rica. As a key member of our merchant risk evaluation team, you will be responsible for evaluating merchant accounts and safeguarding Amazon's global marketplaces.Key Responsibilities:Evaluate suspicious merchant activity and behavior that could...


  • San José, San José, Costa Rica Equifax A tiempo completo

    Equifax is where you can power your possible.If you want to achieve your true potential, chart new paths, develop new skills, collaborate with bright minds, and make a meaningful impact, we want to hear from you.In this role you will be responsible for performing security risk assessment reviews of Equifax third parties, reviewing documentation related to...


  • San Francisco, Heredia, Costa Rica Experian A tiempo completo

    About the RoleWe are seeking a highly skilled Security Analyst to join our product information security team. As a Security Analyst, you will be responsible for managing risks and vulnerabilities for both applications and infrastructure within a cloud-first environment.This role will play a critical part in safeguarding the integrity, resilience, and...


  • San José, San José, Costa Rica Gsb A tiempo completo

    We are seeking a motivated professional to join its information security operations team as a **Security Analyst **focused on managing risks and vulnerabilities of a modern technology cloud first environment.The Security Analyst will play a critical role in safeguarding the integrity and resilience of Experian's modern cloud-based infrastructure.**Key...


  • San José, San José, Costa Rica Emerson A tiempo completo

    We are looking for an experienced SAP Security Risk Management Expert to join our team at Emerson. This individual will be responsible for identifying and mitigating risks associated with the company's SAP systems, as well as developing and implementing security policies and procedures to ensure compliance with regulatory requirements.Key...

  • Governance Risk

    hace 3 días


    San José, Costa Rica Mondelēz International A tiempo completo

    **Are You Ready to Make It Happen at Mondelēz International?** **Join our Mission to Lead the Future of Snacking. Make It Uniquely Yours.** You work with the information security team as a competent and experienced information security and compliance specialist. **How you will contribute** **What you will bring** A desire to drive your future and...


  • San José, Costa Rica Equifax A tiempo completo

    Equifax is where you can power your possible. If you want to achieve your true potential, chart new paths, develop new skills, collaborate with bright minds, and make a meaningful impact, we want to hear from you. As a Security Analyst, you will have the opportunity to collaborate to monitor, detect and respond to security threats along the global...

  • Risk Management Expert

    hace 19 horas


    San José, San José, Costa Rica Mondelez International A tiempo completo

    **Mondelez International: A Leader in the Snack Food Industry**We are seeking a highly skilled Governance, Risk & Compliance Senior Analyst to join our team. This role will play a pivotal part in ensuring the alignment of vendor activities with internal security policies.This position requires a deep understanding of security frameworks, risk management, and...


  • San José, Costa Rica DXC Technology A tiempo completo

    **Job specifics/responsibilities**: - Receive input from various event sources, investigate it for unusual and potentially malicious behavior that may indicate security incidents, and escalate any suspicious activity or anomalies to the Tier 2 SIRCC Analyst team; - During security incidents, liaise with the Tier 2 SIRCC Analyst and Tier 3 Incident...