Senior Information Security Analyst

Bonterra TechColumbia, DC

About The Position

The Bonterra Information Security Risk and Compliance department is looking to hire a Senior Information Security Risk Analyst to our team. If you enjoy problem solving, are enthusiastic working in a team format and want to thrive in the ever-changing risk & compliance field while learning new concepts and principles as part of your continuing education, look no further!

Requirements

  • 6+ years’ experience performing risk and compliance activities or open to less years with addition of relevant course work/degrees
  • Experience managing multiple priorities independently and in a team environment to achieve goals.
  • Excellent organizational, planning and time management skills.
  • Excellent research and analytical skills.
  • Excellent verbal and written communication skills.
  • Ability to exercise good judgement and tact in dealing with Bonterra senior management.
  • Proficient with technology and ability to learn our software systems, including GRC, ticketing and project management software and workflows.
  • Proven track record of proactively identifying needs and implementing solutions.

Nice To Haves

  • May hold one or more information systems security professional certifications (CRISC, CISA, CISSP, CISM, GSEC, GCFA, GCTI, CCSP, or other relevant Information Security certifications).

Responsibilities

  • Prepares for and facilitates examinations by qualified security assessors for frameworks such as SOC, ISO 27001, and PCI-DSS.
  • Works closely with other members of the Information Security, Risk, & Compliance team.
  • Gathers and synthesizes data; presents conclusions; and offers risk mitigation, remediation and process improvement solutions to management.
  • Works closely with control owners across the company and internal and external auditors to ensure requests are completed in a timely manner.
  • Identifies potential business risks, operational and regulatory process deficiencies and improvement opportunities.
  • Communicates risk findings and recommendations that are clear and actionable to all stakeholders.
  • Performs technical risk assessments of third party suppliers' security and privacy controls.
  • Maintains register of relevant suppliers/vendors, controls, and risks for ongoing vendor risk management activities.
  • Assists in the initial triage of compliance, risk and security requests in the ticket management system to ensure efficiency and prioritization.
  • Assists in maintaining our overall security awareness, role-based security trainings and phishing simulation programs across the enterprise.
  • Assists in conducting user activity audits where required.

Benefits

  • comprehensive benefits package that supports your health, well-being and growth
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service