> Markdown version of [/jobs/ext/3015960-iso-security-analyst](https://www.wearedevelopers.com/jobs/ext/3015960-iso-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ISO Security Analyst - **Company:** Popular Inc. - **Location:** San Juan County, CO, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Data Analysis, Cyber Security, Computer Engineering, Information Technology Audit, Powerpivot, Power BI, Programming Logic, Information Technology, Data Management - **Published:** September 20, 2026 - **Apply:** https://www.disabledperson.com/jobs/75335871-iso-security-analyst ## About the Role Bachelor's degree in business administration, Computer Engineering, Computer Science, Information Technology, or related fields. Experience Two (2) years of related experience in information technology audit, information security, or vendor management is preferred. Certifications / Licenses Certifications and licenses such as CISA, CISM, and CISSP are preferable. Knowledge, Skills and Abilities (KSA's) * Strong business acumen: ability to understand the needs and concerns of business stakeholders and colleagues and respond promptly and effectively to stakeholder requests. Ability to conduct analysis on work procedures, business results and recommend changes to improve the effectiveness of the business's management. * Strong technical acumen: knowledge of Information Security and Information Technology concepts. Ability to write technical instructions using programs and technology. Robust knowledge of applicable local and federal laws, regulations, and guidelines. * Communication skills: effectively interact with internal and external stakeholders. Ability to foster trusting relationships with colleagues and clients. Highly develop written and verbal communications skills, strong ability to communicate ideas (storytelling). Presents numerical data effectively. Superior communication and interpersonal skills. Excellent report-writing and presentation skills. Polished in preparing presentations, summaries, and reports for all audiences. * Analytical skills: Stays focused on main issues, prevents irrelevant issues or distractions from interfering with timely completion of assignments. Collects, research and complements data; Synthesizes complex or diverse information. Demonstrates attention to detail; Applies design principles; Generate creative solutions. Strong quantitative, research and analytical skills. Experience with data analysis, persuasive and informative writing, workload management, and process management. * Problem Solving: Identifies and resolves problems in a timely manner; Develops alternative solutions. * Project Management: Ability to prioritize and work with multiple projects and tasks with minimum supervision; self-direct and task switch between strategic and tactical initiatives regularly. Capacity to achieve results according to plan ensuring the expected quality. Excellent organization capacity to define priorities, meet deadlines, and flexible to change. Knowledge on project coordination, identification of business needs, work plan, budget control, time management, resource allocation, team management and status reports. Must demonstrate leadership, logic, and reasoning skills. * Operational/Regulations Processes: Knowledge on budget administration, resources allocation, organization's policies, and regulations. Ability to establish, conduct and track operational processes properly. * Computer and Technological Skills: Proficient in MS Office 365. Experience with data management tools such as Power Pivot, and/or Power BI, among others is preferred. Basic knowledge of artificial intelligence technology is preferred. Ability to achieve results by providing innovative ways of working with operational and technological considerations. Knowledge of computer flow charts and programming logic and codes. ## Description As an entry-level member of the Business Information Security Office (BISO) Enablement Unit, you will support the execution of information security risk management, governance, and business-aligned information security advisory activities in coordination with CISP teams, business stakeholders, and other control functions., * Serving as a liaison between assigned business or enablement areas and Corporate Information Security & Privacy teams for security requests, requirements, and risk-related matters. * Assisting business units in translating enterprise information security policies, standards, and guidelines into practical, business-aligned requirements and advisory guidance. * Support security awareness and risk culture initiatives by helping communicate information security expectations, risks, and requirements to business stakeholders in a clear and practical manner. * Perform information security risk assessments for business initiatives, applications, products, services, vendors, and emerging technologies, including artificial intelligence use cases, as applicable. * Perform third-party vendor information security due diligence activities, including ongoing vendor reviews, contract security reviews, and follow-up of identified risks or recommendations. * Perform tracking, reporting, and follow-up of information security risks and issues, remediation plans, exceptions, action items, and residual risk decisions identified as a result of the ongoing vendor information security due diligence assessments. * Prepare ongoing vendor information security due diligence reports and/or status updates to support management oversight, risk visibility, and decision-making. * Contribute to the BISO Unit's documentation governance activities, including the inventory, review, update, and lifecycle management of information security policies, standards, procedures, guidelines, and related repositories. * Assist with the alignment of documentation and control activities to relevant cybersecurity frameworks, regulatory expectations, and internal governance requirements. ## Related Videos - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Beyond Dashboards: Fixing Text-to-SQL with Semantic RAG](https://www.wearedevelopers.com/videos/2036-beyond-dashboards-fixing-text-to-sql-with-semantic-rag) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Data Science on Software Data](https://www.wearedevelopers.com/videos/162-data-science-on-software-data) - [REST, GraphQL, gRPC, and more: A comparison of modern API styles](https://www.wearedevelopers.com/videos/100247-rest-graphql-grpc-and-more-a-comparison-of-modern-api-styles) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)