Skip Navigation
Job Search

Senior Security Risk Analyst

Job Number: R0002544 Posted On: 06/10/2025 Location: San José, Provincia de San José Additional Locations: San Jose, San Jose, Costa Rica
Apply Now

Why Catalina? Catalina Marketing Costa Rica is part of the Catalina Group which is headquartered in the United States. The Catalina Group delivers omni-channel solutions to its customers with a long-standing history of rich data assets, but the company also recognizes its greatest asset is its people. The company’s guiding principles set the stage for winning in the markets we serve, and our potential is powerful. When you join the Catalina team, you will be part of an inclusive environment that embraces flexibility, community involvement, work-life balance as well as opportunities to grow professionally.

The Opportunity

The Senior Security Risk Analyst is a strategic leader and critical thinker who drives the organization’s efforts to mitigate risks associated with third-party vendors and service providers, while championing a robust security culture through the Security Awareness Program. This role ensures that external partnerships comply with stringent regulatory standards and internal policies, leveraging deep expertise in Third-Party Risk Management (TPRM) to conduct advanced risk assessments and implement proactive mitigation strategies.

The Senior Analyst actively engages in industry webinars, conferences, and professional networks to stay ahead of emerging TPRM risks and cyber threats, applying cutting-edge knowledge to enhance organizational resilience. As the leader of the Security Awareness Program, the Senior Analyst innovates and adapts strategies to counter sophisticated phishing techniques and social engineering tactics employed by bad actors, fostering a security-conscious workforce.

Reporting to the VP of Security and Risk and the CISO, this role oversees the day-to-day operations of TPRM and Security Awareness initiatives, providing strategic and operational recommendations to strengthen the organization’s security posture.

  • Lead Third-Party Risk Management (TPRM): Oversee the evaluation of third-party vendors and service providers, employing critical thinking to identify, assess, and mitigate complex risks, ensuring alignment with regulatory requirements (e.g., SOC2, ISO 27001, GDPR, NIST CSF) and internal policies.

  • Drive Strategic Collaboration: Partner with senior stakeholders, including the privacy team, procurement, legal, and business leaders, to integrate secure third-party services, providing expert guidance on TPRM best practices and risk mitigation strategies.

  • Enhance TPRM Processes: Design and refine TPRM frameworks, facilitating the completion and critical evaluation of risk management forms by vendors, ensuring comprehensive analysis of data privacy, security controls, and contractual obligations.

  • Stay Current on TPRM Trends: Actively participate in industry webinars, conferences, and professional forums to maintain up-to-date knowledge of TPRM risks, incorporating insights into organizational strategies to address evolving threats.

  • Lead Security Awareness Program: Innovate and manage the Security Awareness Program, developing targeted phishing campaigns and training initiatives to educate employees on security best practices, with a focus on countering advanced phishing techniques and social engineering attacks.

  • Adapt to Phishing Trends: Monitor and analyze bad actor phishing tactics, leveraging threat intelligence to dynamically adjust the Security Awareness Program, ensuring employees remain vigilant against emerging cyber threats.

  • Conduct Advanced Risk Assessments: Proactively identify vulnerabilities and compliance gaps in third-party relationships, using sophisticated risk assessment methodologies to safeguard organizational assets and data.

  • Develop Mitigation Strategies: Recommend and implement strategic risk mitigation plans, ensuring third-party services align with the company’s security standards and regulatory requirements.

  • Ensure Compliance: Monitor and enforce third-party adherence to regulatory standards and internal policies, minimizing legal and operational risks through rigorous oversight.

  • Maintain Robust Documentation: Oversee the creation and maintenance of accurate, audit-ready records of risk assessments, mitigation actions, and compliance activities to support decision-making and regulatory audits.

  • Support Audit Processes: Lead SOC2 and other audit engagements, collaborating with auditors and conducting advanced IT controls testing to validate the design and operational effectiveness of security measures.

  • Analyze Security Initiatives: Compile and analyze data from phishing campaigns and other security awareness activities, identifying trends, reporting on program effectiveness, and recommending strategic adjustments to senior leadership.

  • Vendor Engagement: Lead interactions with vendors to ensure thorough security assessments, embedding a security-first mindset from the onset of partnerships.

  • Educate Stakeholders: Provide thought leadership and training to internal stakeholders on TPRM processes and requirements, fostering a culture of risk awareness and compliance.

  • Drive Continuous Improvement: Proactively identify opportunities to enhance TPRM practices, security awareness programs, and compliance processes, adapting to the evolving threat landscape and regulatory requirements.

  • Strategic Recommendations: Provide actionable operational and strategic recommendations to the VP of Security and Risk and the CISO, aligning TPRM and security awareness initiatives with organizational goals.

  • Other Duties: Undertake additional tasks to support the security program, demonstrating flexibility and leadership in addressing emerging needs.

Qualifications

  • Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Systems, or a related field; or equivalent experience. Advanced degrees (e.g., Master’s in Cybersecurity or MBA) are a plus.

  • Professional certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), or equivalent credentials focused on risk management, audit, and compliance are highly preferred.

  • 5–7 years of progressive experience in cybersecurity, with at least 3 years focused on conducting advanced risk assessments, leading TPRM programs, and managing compliance with industry standards and regulations.

  • TPRM Expertise: Demonstrated expertise in Third-Party Risk Management, with a proven track record of designing and implementing TPRM frameworks and mitigating complex vendor-related risks. Familiarity with TPRM assessment tools such as OneTrust is desired.

  • Active participation in webinars, conferences, and professional networks to stay current on TPRM risks and cybersecurity trends, with the ability to translate insights into actionable strategies.

  • Extensive experience leading Security Awareness Programs, including designing and executing sophisticated phishing campaigns and adapting strategies to address evolving social engineering tactics.

  • In-depth understanding of auditing standards, compliance frameworks (e.g., SOC2, ISO 27001, NIST CSF, GDPR, CCPA), and risk management methodologies, with expertise in evaluating and implementing advanced risk mitigation strategies.

  • Exceptional analytical and problem-solving skills, with the ability to assess complex risks, anticipate emerging threats, and develop innovative solutions.

  • Proven ability to lead cross-functional teams, influence senior stakeholders, and drive strategic initiatives in TPRM and security awareness.

  • Outstanding verbal and written communication skills in English, with the ability to articulate complex security concepts to diverse audiences, including vendors, executives, and global teams, while fostering collaboration across cultural backgrounds.

  • Strong project management skills, with experience leading TPRM and security awareness initiatives, managing timelines, and delivering measurable outcomes.

  • Flexibility to accommodate U.S. and UK business hours, ensuring effective leadership and collaboration with internal and external stakeholders across global regions.

  • Ability to thrive in a dynamic environment, staying ahead of evolving cyber threats and regulatory changes while driving continuous improvement.

The intent of this job description is to describe the major duties and responsibilities performed by incumbents of this job. Incumbents may be required to perform other job-related tasks other than those specifically included in this description.

All duties and responsibilities are essential job functions and requirements and are subjected to possible modification to reasonably accommodate individuals with disabilities.

This position may be performed as a hybrid position.

About Catalina

Catalina is a leader in shopper intelligence and precisely targeted in-store, TV and digital media that personalizes the shopper journey. Powered by an unrivaled real-time shopper database and AI-optimized data science, Catalina helps retailers, CPG brands and agencies optimize every stage of media planning, execution and measurement to deliver more than $6 billion in consumer value annually. Catalina has no higher priority than ensuring the privacy and security of the data entrusted to the company and maintaining consumer trust. Catalina has operations in the United States, Costa Rica and Europe. To learn more, please visit www.catalina.com or follow us on LinkedIn.

We are committed to investing in, empowering, and retaining a more inclusive community within our company.   We are dedicated to hiring the best and brightest from all backgrounds, experiences, and perspectives. We believe that true innovation happens when everyone has a seat at the table and a voice to be heardOur goal is to ensure that all our talented professionals are equipped with support, resources, and the opportunity to excel.

Catalina values your privacy and is committed to protecting your personal information. Please review our privacy policy, which provides details on how we process the data you provided for job applications.

We are committed to providing equal employment opportunities to all individuals and maintaining a safe, drug-free workplace in compliance with Costa Rican labor laws.

#LI – BP1

Apply Now

Saved Jobs

There are no saved jobs.

Work in San José

Check out where you could be working if you apply.

View this location

Recent Jobs

You currently have no Saved Jobs

Featured Jobs

View All Jobs

Job Alerts

Join our talent network and receive company news and job alerts to your inbox.

Interested InSelect a job category from the list of options. Search for a location and select one from the list of suggestions. Finally, click “Add” to create your job alert.

  • Global Technology Operations, San José, Provincia de San José, Costa RicaRemove
  • Technology, San José, Provincia de San José, Costa RicaRemove

By submitting your information, you acknowledge that you have read our privacy policy and consent to receive email communication from Catalina.

sign up