ISO Security Analyst
Listed on 2026-09-23
-
IT/Tech
Information Security & Data Protection, Cybersecurity, IT Consultant, IT Business Analyst
Position Title: ISO Security Analyst
Date: Sep 18, 2026
Location: San Juan, CO
Company: Popular Bank
Job Title:
ISO Security Analyst
As an entry-level member of the Business Information Security Office (BISO) Enablement Unit, you will support the execution of information security risk management, governance, and business-aligned information security advisory activities in coordination with CISP teams, business stakeholders, and other control functions.
Essential Duties and Responsibilities- Serving as a liaison between assigned business or enablement areas and Corporate Information Security & Privacy teams for security requests, requirements, and risk-related matters.
- Assisting business units in translating enterprise information security policies, standards, and guidelines into practical, business-aligned requirements and advisory guidance.
- Support security awareness and risk culture initiatives by helping communicate information security expectations, risks, and requirements to business stakeholders in a clear and practical manner.
- Perform information security risk assessments for business initiatives, applications, products, services, vendors, and emerging technologies, including artificial intelligence use cases, as applicable.
- Perform third-party vendor information security due diligence activities, including ongoing vendor reviews, contract security reviews, and follow-up of identified risks or recommendations.
- Perform tracking, reporting, and follow-up of information security risks and issues, remediation plans, exceptions, action items, and residual risk decisions identified as a result of the ongoing vendor information security due diligence assessments.
- Prepare ongoing vendor information security due diligence reports and/or status updates to support management oversight, risk visibility, and decision-making.
- Contribute to the BISO Unit's documentation governance activities, including the inventory, review, update, and lifecycle management of information security policies, standards, procedures, guidelines, and related repositories.
- Assist with the alignment of documentation and control activities to relevant cybersecurity frameworks, regulatory expectations, and internal governance requirements.
Bachelor's degree in business administration, Computer Engineering, Computer Science, Information Technology, or related fields.
ExperienceTwo (2) years of related experience in information technology audit, information security, or vendor management is preferred.
Certifications / LicensesCertifications and licenses such as CISA, CISM, and CISSP are preferable.
Knowledge,Skills and Abilities
(KSA's)
- Strong business acumen: ability to understand the needs and concerns of business stakeholders and colleagues and respond promptly and effectively to stakeholder requests. Ability to conduct analysis on work procedures,business results and recommend changes to improve the effectiveness of the business's management.
- Strong technical acumen: knowledge of Information Security and Information Technology concepts. Ability to write technical instructions using programs and technology. Robust knowledge of applicable local and federal laws, regulations, and guidelines.
- Communication skills: effectively interact with internal and external stakeholders. Ability to foster trusting relationships with colleagues and clients. Highly develop written and verbal communications skills, strong abilityto communicate ideas (storytelling). Presents numerical data effectively. Superior communication and interpersonal skills. Excellent report-writing and presentation skills. Polished in preparing presentations,summaries, and reports for all audiences.
- Analytical skills:
Stays focused on main issues,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).