Senior IT Audit, Risk & Security Governance Analyst

Baker McKenzieBuenos Aires, Buenos Aires F.D.On-siteFull-timeSenior, 5–8 yearsListed 1 hour ago

Apply now

About this role

The Information Security Governance, Risk and Assurance Analyst will work closely with stakeholders across Technology, Information Security, Risk and Procurement teams to support the Firm's information security governance, risk, compliance and assurance objectives.

The role holder will be responsible for conducting risk-based IT audits, security assessments, third-party risk reviews and governance activities, ensuring alignment with the Firm's security framework, policies and applicable standards. They will also support the ongoing development of the third-party risk programme, helping to strengthen supplier assurance, onboarding processes and integration governance.

Main responsibilities:

- Plan and execute risk-based IT and information security audits, control assessments and compliance reviews across internal functions, technology platforms, business processes and third parties.
- Assess control design and operating effectiveness across governance, access management, change management, IT operations, cloud, network and endpoint security, data protection, secure development, incident management, resilience, supplier management and compliance.
- Define scope, objectives, test procedures, evidence requirements and sampling approaches with relevant stakeholders.
- Produce clear, defensible workpapers and reports documenting evidence, control gaps, root causes, risk implications and practical recommendations.
- Maintain findings and corrective-action records, validate remediation, track actions to closure and escalate overdue or material issues.
- Support internal and external audits, client security assessments, regulatory reviews and assurance requests by coordinating evidence and providing accurate, consistent responses.
- Respond to RFPs, RFIs, due diligence questionnaires and contractual security enquiries supporting business development and client onboarding.
- Perform security due diligence and manage risk activities across the third-party lifecycle, including intake, classification, assessment, contracting support, onboarding, monitoring, periodic review, issue management and offboarding.
- Improve vendor assessment and onboarding cycle times through risk-based scoping, clear evidence requirements, stakeholder coordination and timely escalation of blockers.
- Coordinate annual and periodic reviews of critical and high-risk vendors and maintain a forward review schedule.
- Monitor critical suppliers, investigate material alerts and track vendor remediation to closure.
- Maintain complete, accurate and audit-ready inventories, risk records, evidence, review dates, findings, exceptions and remediation status.
- Work with Procurement, Legal, Privacy, Compliance, Technology, business owners and suppliers to identify and manage third-party risk.
- Support governance of third-party integrations, connected applications, APIs and data exchanges, including ownership, inventory, security, privacy, authentication, authorization, logging, monitoring, resilience and lifecycle controls.
- Identify unmanaged or insufficiently governed integrations and APIs, assess risk and coordinate remediation or formal risk acceptance.
- Monitor compliance with information security policies, standards and procedures and contribute to continual improvement of the ISMS and risk framework.
- Develop metrics, KPIs, KRIs, dashboards and risk-based recommendations covering audits, assessments, vendor onboarding, review cycle times, monitoring, findings and remediation.
- Improve policies, standards, procedures, control descriptions, assessment methods, templates and guidance, and identify opportunities to streamline or automate GRC processes without reducing control quality.

Skills and experience:

- Strong understanding of information security, technology risk, governance, compliance, audit and control principles.
- Demonstrable experience planning or performing IT or information security audits, risk assessments, control testing or compliance reviews.
- Authoritative knowledge of audit principles across governance, asset management, identity and access management, change management, IT operations, cloud and network security, secure development, incident management, resilience, supplier management and compliance.
- Experience conducting third-party security due diligence and supporting vendor risk management across onboarding, periodic review, continuous monitoring, issue management and offboarding.
- Experience improving assessment workflows, coordinating stakeholders and delivering work to defined service levels or target dates.
- Working knowledge of third-party integration and API risks, including ownership, inventory, authentication, authorization, data exchange, logging, monitoring and lifecycle governance.
- Experience with GRC, third-party risk or external security-rating platforms; familiarity with SecurityScorecard or an equivalent service is advantageous.
- Working knowledge of ISO/IEC 27001, NIST Cybersecurity Framework, NIST SP 800-53, COBIT, SOC 2 or equivalent control and assurance frameworks.
- Working knowledge of Active Directory, cloud services, networking, endpoint management, SaaS platforms and security monitoring capabilities.
- Ability to evaluate evidence, analyse facts, identify control gaps, assess risk and recommend practical improvements.
- Ability to produce clear, concise and defensible audit workpapers, findings, risk statements, management reports and client-facing responses.
- Strong business acumen and stakeholder-management skills, with professional written and spoken English.
- Proficiency in Microsoft Word and Excel, with the ability to use data and reporting tools to monitor workflow, risks, findings and remediation.
- Ability to work independently and collaboratively, manage competing priorities, maintain attention to detail and respond constructively to feedback.
- Bachelor's degree in Computer Science, Information Security, Information Systems, Audit, Risk Management or a related discipline, or substantial equivalent experience.
- Relevant experience in IT audit, information security assurance, third-party risk management, client audit response, security metrics or remediation tracking.
- CISA, CRISC, CISM, CISSP, ISO 27001 Lead Auditor or equivalent certification is preferred.

Reports to: Associate Director, Information Security

Position Type: Centre Services

Development Framework: Specialist

Baker McKenzie empowers clients to compete in the global economy. We provide comprehensive and practical legal advice that cuts through complexity with clear, actionable guidance. Our people represent diverse cultures and jurisdictions, combining local know-how with international expertise to ensure your business thrives across borders .

Baker McKenzie is an Equal Opportunity Employer. We are committed to promoting diversity and inclusion for all. Our unique international culture is reflected in the drawing together of a worldwide family of individuals from diverse cultures and backgrounds in all of our offices. We encourage the best people - regardless of race, religion or belief if any, gender, gender identity, disability, sexual orientation or age - to fulfill their professional aspirations with us. We are committed to ensuring an inclusive and accessible experience for all candidates.