BCD Travel
BCD Travel
BCD Travel helps organizations manage business travel through corporate travel management services, risk management support, and integrated tools for travel programs. Its operations span more than 100 countries, enabling tailored solutions for companies and their employees across the business travel, logistics, hospitality, and consulting sectors. The company also focuses on improving travel program performance and advancing more sustainable approaches to business travel.

Senior Information Security Risk Analyst

Assess security risks, controls, suppliers, and emerging technologies while supporting BCD Travel’s global governance program. Help teams manage risk across business travel technology and operations.

Description

  • Assess information security risks across applications, infrastructure, cloud services, business processes, projects, integrations, and suppliers.
  • Rate inherent and residual risk using approved criteria, supporting evidence, and documented rationale.
  • Identify control gaps and assess the design, implementation, and effectiveness of security controls.
  • Document risk statements and recommend practical ways to address risk.
  • Align risks and findings with internal policies, control procedures, regulatory obligations, and security frameworks.
  • Work with business and risk owners to plan remediation and risk treatment.
  • Maintain and improve the centralized information security risk register.
  • Assess supplier security risks and review assurance documents, certifications, reports, testing evidence, contract requirements, and control gaps.
  • Evaluate risks from emerging technologies, including artificial intelligence, and advise on governance and controls.
  • Coordinate with Security, Privacy, Legal, Compliance, Audit, Technology, Procurement, Business Relationship Management, and business teams.
  • Produce risk summaries, dashboards, metrics, and management reports.
  • Track changes in technology, processes, suppliers, threats, vulnerabilities, regulations, and controls, and initiate reassessments as needed.

Requirements

  • Bachelor’s degree in information security, cybersecurity, computer science, information systems, risk management, business, or a related field, or equivalent experience.
  • Experience conducting information security or technology risk assessments using structured risk management methods.
  • Strong knowledge of security risk concepts, including threats, vulnerabilities, business impact, control effectiveness, and residual risk.
  • Ability to identify control gaps, assess controls, and recommend practical risk treatments.
  • Working knowledge of ISO/IEC 27001, ISO/IEC 27002, ISO 31000, NIST CSF, or comparable frameworks.
  • Experience assessing risk across applications, cloud services, infrastructure, suppliers, data protection, vulnerability management, and operational security.
  • Experience supporting supplier risk assessments and reviewing ISO certifications, SOC reports, PCI DSS documentation, penetration test results, and supplier security questionnaires.
  • Experience maintaining risk registers and producing accurate, traceable, audit-ready documentation.
  • Ability to lead risk discussions, influence stakeholders, and explain complex technical issues as clear business risks and actionable recommendations.
  • Familiarity with emerging technology risks, including artificial intelligence, privacy, and changing regulatory requirements.
  • Relevant certifications such as CRISC, CISSP, CISM, or ISO/IEC 27001 Lead Auditor or Implementer.
  • Governance-focused approach, strong analytical skills, sound professional judgment, and ability to work independently in a global environment.

Benefits

  • Flexible hours and remote or work-from-home opportunities.
  • Opportunities to develop skills and advance your career.
  • Work with travel technology and contribute to the future of business travel.
  • Generous vacation allowance.
  • Compensation package with mental, physical, and financial wellbeing resources.
  • Travel industry professional perks and discounts.
  • Inclusive workplace that celebrates diversity.
  • Option to work from anywhere for 60 days per year.

Related Jobs