Job Closed
This listing is no longer active.
Travel smart. Achieve more.
Analista Senior de Seguridad de la Información
Location
Colombia
Posted
4 days ago
Salary
0
Seniority
Senior
Job Description
Analista Senior de Seguridad de la Información
BCD Travel
• Será responsable de contribuir a la protección de los activos de información. • Garantizar el cumplimiento de estándares de seguridad y apoyar la operación segura de la infraestructura tecnológica de la organización. • Implementar y monitorear políticas, procedimientos y controles de Seguridad de la Información. • Garantizar el cumplimiento de estándares y marcos normativos como ISO 27001, NIST y PCI DSS. • Identificar, evaluar y gestionar riesgos de seguridad de la información. • Administrar y dar soporte a soluciones de seguridad perimetral, incluyendo FortiGate. • Realizar monitoreo y análisis de eventos e incidentes de seguridad. • Ejecutar actividades de fortalecimiento y mejora continua de los controles de ciberseguridad. • Gestionar revisiones de configuraciones de seguridad en infraestructura tecnológica. • Apoyar auditorías internas y externas relacionadas con seguridad de la información. • Generar informes, indicadores y recomendaciones para la mitigación de riesgos. • Brindar acompañamiento técnico a las diferentes áreas en temas de seguridad y cumplimiento.
Job Requirements
- Profesional o Tecnólogo en Ingeniería de Sistemas, Ingeniería Electrónica o carreras afines.
- Conocimiento y manejo en políticas y procesos de seguridad de la información.
- Conocimiento y manejo de la normativa (familias ISO 27000 – 26000).
- Conocimiento y manejo de la normativa NIST.
- Conocimiento y manejo de la normativa PCI para comercios y pagos con tarjetas.
- Conocimiento y manejo de Network Appliances FORTIGATE.
- Conocimientos en red (Switching, Routing y Firewall).
- Conocimiento Sistemas operativo Windows server.
- Experiencia verificable de 1 año o más desempeñando funciones relacionadas con seguridad de la información y ciberseguridad.
- Inglés nivel B1 técnico conversacional (Deseable).
Benefits
- N/A
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Title: Quantitative Intelligence Analyst Job Description: Location San Francisco Employment Type Full time Location Type Hybrid Department Intelligence & Investigations Compensation - $198K – $320K • Offers Equity The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance-related bonus(es) for eligible employees, and the following benefits. - Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts - Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit) - 401(k) retirement plan with employer match - Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks) - Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees - 13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick or safe time (1 hour per 30 hours worked, or more, as required by applicable state or local law) - Mental health and wellness support - Employer-paid basic life and disability coverage - Annual learning and development stipend to fuel your professional growth - Daily meals in our offices, and meal delivery credits as eligible - Relocation support for eligible employees - Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided. More details about our benefits are available to candidates during the hiring process. This role is at-will and OpenAI reserves the right to modify base pay and other compensation components at any time based on individual performance, team or company results, or market conditions. OverviewApplication About the Team The Intelligence and Investigations team seeks to rapidly identify and mitigate abuse and strategic risks to ensure a safe online ecosystem. We are dedicated to identifying emerging abuse trends, analyzing risks, and working with our internal and external partners to implement effective mitigation strategies to protect against misuse. Our efforts contribute to OpenAI's overarching goal of developing AI that benefits humanity. The Strategic Intelligence & Analysis (SIA) team provides safety intelligence for OpenAI’s products by monitoring, analyzing, and forecasting real-world abuse, geopolitical risks, and strategic threats. Our work informs safety mitigations, product decisions, and partnerships, ensuring OpenAI’s tools are deployed securely and responsibly across critical sectors. About the Role As a Quantitative Intelligence Analyst, you will focus on discovering novel and emerging risks in complex human–AI systems before they are well-defined, measurable, or widely understood. You will use deep subject matter expertise and quantitative tooling to surface weak, early, and unconventional risk signals. You will build analytic models that explain how harms could emerge and translate ambiguous patterns into structured, data-driven insight. Your work will help identify potential gaps in policy or coverage and operationalize previously unmeasured problems into signals that can support detection, mitigation, and planning downstream. You will develop analytical frameworks that map how new risks form, evolve, and propagate as products change, policies shift, and external events unfold. Your analyses will directly inform strategic risk prioritization and planning across the company, with regular visibility through strategic risk products. This role is based in office (hybrid, 3 days/week). Relocation support is available In this role, you will: - Discover and define new quantitative risk signals where no established metrics exist, using subject matter expertise to surface early, weak, or unconventional indicators - Translate complex trust and safety challenges into measurable signals that can be tracked and stress-tested over time - Develop upstream early-warning and signal frameworks that inform downstream detection and mitigation efforts - Analyze risk trends to assess the underlying drivers and causal factors behind those changes - Conduct data mining and statistical modeling to understand how risks originate, evolve, and propagate across systems - Design adversarial scenarios, and quantitative stress tests to assess exposure, coverage gaps, and vulnerabilities - Produce clear data-driven briefs to support risk prioritization, contingency planning, and strategic risk products across teams You might thrive in this role if you: - Have 3+ years of experience in quantitative intelligence analysis, trust & safety, security analysis, or risk-focused research - Are comfortable working on complex trust and safety domains such as child safety, violent activities, self-harm, or similar high-stakes risk areas - Familiarity with data mining, statistical modeling, and supervised learning methods - Understand how to monitor signals or models for data drift, behavioral adaptation, or performance degradation over time, and can diagnose likely causes - Experience in operationalizing adversarial or strategic risk behaviors, including through red-team exercises, agent-based modeling, or structured scenario analyses - Comfortable working with Python and SQL - Nice to have: Experience with quantitative stress testing or Monte Carlo simulations to assess uncertainty and tail risk About OpenAI OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity. We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic. For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement. Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations. To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance. We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link. OpenAI Global Applicant Privacy Policy At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.
• Approvals: Act as a gatekeeper for sensitive access and firewall rule approvals, ensuring compliance with security policies and business needs. • Reviews: Conduct regular reviews of access permissions, firewall configurations, and IT infrastructure settings (e.g., AD, Intune, Office 365, Azure) to ensure adherence to security best practices and expectations. • Architectural Review and Change Management: Review and approve all proposed changes to the IT infrastructure, ensuring changes do not compromise security integrity. • Testing: Conduct vulnerability scans at both regional and laboratory levels, overseeing remediation efforts. Collaborate with Group Security to facilitate penetration testing as required. • Incident Response: Assist in the investigation of security breaches and provide support for security intelligence reported by the Group Security Operations Center (SOC). • Advisory Role: Work closely with newly acquired laboratories to enhance their security posture, leveraging internal security standards and the expertise of a Senior Security Analyst. Evaluate the security of both in-house and externally developed applications, providing recommendations for security enhancements. • Reporting: Contribute to the development of operational security Key Performance Indicators (KPIs) and offer recommendations for improvement based on data analysis and industry best practices. • Vulnerability Management: Oversee the vulnerability management process for our entire infrastructure, ensuring timely identification, prioritization, and mitigation of vulnerabilities.
IT Security Analyst
Envision Pharma GroupAt Envision, we believe in creating life-changing outcomes through the work we do with our clients, giving back to our communities, while creating a company culture where our people thrive. We believe success starts with a workplace where everyone feels valued, supported, and empowered to grow. Our Vision: To unleash the power of combined intelligence to accelerate patient access to life-changing treatments. Our Mission: Delivering smarter and faster solutions to create, communicate, and commercialize value for our clients. Our Values: Excellence, People, Growth.
Role Description We're looking for an IT Security Analyst to join our team and help protect Envision Pharma Group's digital assets through proactive monitoring, incident response, and operational security excellence. In this role, you will work closely with internal IT teams and external security partners to detect, investigate, and respond to security events while strengthening the organization's overall security posture. This is an excellent opportunity for an experienced IT professional who enjoys solving complex problems, improving security operations, and collaborating across teams to reduce risk in a fast-moving, global technology environment. This role is remote in Portugal. Role responsibilities - Provide day-to-day operational ownership of Envision's security platforms, collaborating closely with external SOC providers and internal IT teams. - Lead and manage security incidents through the full lifecycle, including investigation, containment, remediation, and post-incident review. - Execute and continuously improve vulnerability management processes, coordinating remediation with infrastructure, application, and operations teams. - Design, implement, and maintain technical security controls across cloud and on-premises environments. - Monitor, analyze, and tune security telemetry (SIEM, EDR, identity, network, and cloud signals) to improve detection quality and response time. - Support compliance and audit activities (ISO 27001, SOC 2, customer security reviews) through evidence generation and control validation. - Develop and maintain security operations metrics, KPIs, and KRIs to communicate risk posture and operational effectiveness. - Create and maintain security runbooks, procedures, and operational documentation. - Participate in incident response exercises, tabletop simulations, and continuous readiness activities. - Provide guidance and mentorship to operational IT teams on secure practices and incident handling. Qualifications - Typically 5+ years of progressive experience in security operations, IT operations, or systems administration, with a focus on hands-on Microsoft Security stack experience (Defender, Sentinel, Purview). - Strong operational security experience, including incident response, vulnerability management, and alert monitoring, with the ability to lead incidents end-to-end. - Experience with cloud security in Microsoft Azure and AWS, including onboarding, monitoring, and implementing controls within a SOC environment. - Proven experience in project-based security work, including the selection, onboarding, configuration, and rollout of new security tools and capabilities. - Comfortable working alongside managed SOC teams, IT teams, and business stakeholders to escalate incidents, improve workflows, and strengthen security posture. - Solid understanding of enterprise IT environments, including networking, identity systems, endpoints, and cloud infrastructure. - Hands-on experience with security tooling, such as SIEM, EDR/XDR, vulnerability scanners, identity security tools, and cloud security controls, including tuning and telemetry correlation. - Knowledge of security frameworks and compliance standards (ISO 27001, SOC 2, NIST) and applying them in operational security contexts. - Holds at least one recognized cybersecurity certification (e.g., Security+, Microsoft Security, AWS Security); CISSP is a plus. - Ability to analyze complex technical data, correlate signals across systems, and make sound risk-based decisions under pressure. - Strong verbal and written English communication skills. Company Description At Envision, we believe in creating life-changing outcomes through the work we do with our clients, giving back to our communities, while creating a company culture where our people thrive. We believe success starts with a workplace where everyone feels valued, supported, and empowered to grow. - Our Vision: To unleash the power of combined intelligence to accelerate patient access to life-changing treatments. - Our Mission: Delivering smarter and faster solutions to create, communicate, and commercialize value for our clients. - Our Values: Excellence, People, Growth.
Role Description Our customers don't just need a platform that tracks their GRC program. They need a trusted voice who can help them think through it. As a Senior GRC Analyst, you'll be the person customers turn to when a risk assessment gets complicated, an audit raises an unexpected question, or a policy needs to be adapted to their specific environment. This role goes beyond process execution and platform support. You'll bring real GRC judgment to every customer interaction, recognizing when a question is more complex than it looks, and guiding customers through it with the confidence of someone who has actually done this work before. What You'll Do - Serve as a hands-on GRC advisor for a portfolio of customers, guiding them through risk assessments, risk registers, audit preparation, and control rollouts. - Help customers prepare for and navigate audits (SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST, and similar frameworks), translating requirements into practical next steps. - Advise on policy development and control design tailored to each customer's risk profile and maturity level — not just “what the framework says,” but what actually makes sense for them. - Spot GRC complexity early — recognizing when a customer's question touches on risk, compliance, or audit nuance that needs more than a standard playbook answer. - Partner closely with Support and Customer Success to own the escalations that require real GRC expertise, not just product knowledge. - Turn recurring customer questions into scalable guidance — playbooks, internal knowledge base content, and best-practice frameworks the whole team can use. - Act as the voice of the customer internally, flagging where our platform could better support real-world GRC workflows. Qualifications - 5+ years of experience as a GRC analyst, consultant, or coordinator — in-house, at a consulting firm, or in a similar capacity. - Direct, hands-on experience with audits, risk assessments and risk registers, and policy rollouts — you've been in the room, not just read about it. - Working familiarity with common frameworks (SOC 2, ISO 27001, HIPAA, PCI-DSS, NIST, or similar) — deep specialization isn't required, but you should be able to orient quickly in any of them. - An instinct for GRC complexity: you can tell when something is more nuanced than it first appears, and you know how to break it down for someone who's stuck. - Strong consultative communication skills — you can explain a compliance concept to a nontechnical stakeholder without losing the substance. - A genuine interest in helping customers solve problems, not just closing tickets. Requirements - Certifications such as CISA, CRISC, CGRC, or ISO 27001 Lead Implementer/Auditor. - Experience working directly with a GRC software platform (as a practitioner, implementer, or vendor-side consultant). - Exposure to multiple industries or company sizes, giving you a broader sense of how GRC programs vary in practice. Benefits - Competitive salary and meaningful equity participation at a Series A inflection point. - Comprehensive paid benefits, including health insurance, 401(k), and generous leave policies.



