Title: Information Security Analyst Advisory- Scotiatech
Requisition ID: 267799
Thanks for your interest in ScotiaTech, Scotiabank's new and innovative Technology hub in Bogota.
Join a purpose driven winning team that promotes creativity and innovation in a fast-paced environment, where we’re always committed to results, in an inclusive, diverse, and high-performing culture.
Purpose
The Enterprise Vulnerability Management (EVM) Program is responsible for identifying, assessing, prioritizing, tracking, and reporting on cybersecurity vulnerabilities across the Bank's technology environment. The program provides centralized governance, operational oversight, vulnerability reporting, remediation tracking, and risk management capabilities to reduce cyber risk and support regulatory, audit, and operational requirements.
The Information Security Analyst Advisory serves as a Subject Matter Expert (SME) within the EVM Program, providing operational leadership across key vulnerability management initiatives and processes. The role is responsible for coordinating day-to-day operations, driving process improvements, supporting audit and regulatory activities, maintaining documentation and governance artifacts, producing operational metrics, and ensuring the successful execution of business-as-usual (BAU) activities.
This position works closely with technology teams, remediation teams, risk partners, audit stakeholders, and cybersecurity functions to ensure vulnerabilities are managed effectively and in accordance with enterprise standards and regulatory expectations.
Accountabilities
• Act as a Subject Matter Expert (SME) for EVM operational processes, standards, procedures, and vulnerability management activities.
• Lead operational initiatives such as Zero Tolerance, remediation governance, ticketing improvements, and process maturity efforts.
• Coordinate and monitor vulnerability remediation activities across multiple technology and business teams.
• Manage the end-to-end vulnerability ticket lifecycle, including ticket creation, assignment validation, tracking, escalation, and closure review.
• Support the execution and ongoing management of the Zero Tolerance program, including tracking, reporting, stakeholder engagement, and escalation activities.
• Ensure timely completion of BAU operational activities and adherence to established service level objectives.
• Produce weekly, monthly, and ad-hoc operational metrics, dashboards, and executive reporting packages.
• Analyze vulnerability trends and performance indicators to identify opportunities for process improvement and risk reduction.
• Assist with internal audits, regulatory reviews, management responses, evidence collection, and closure package preparation.
• Develop, maintain, and enhance operational documentation, process flows, procedures, standards mappings, and governance materials.
• Facilitate meetings, working sessions, and stakeholder engagements to drive remediation activities and resolve issues.
• Provide guidance and support to remediation teams regarding vulnerability management requirements and expectations.
• Respond to stakeholder inquiries and provide timely updates on operational activities, remediation status, and escalations.
• Contribute to strategic EVM initiatives, technology enhancements, automation opportunities, and continuous improvement efforts.
• Support governance forums through accurate reporting, presentation materials, and operational insights.
• Maintain inventories of operational processes, controls, procedures, and supporting documentation.
• Make presentations to leadership and stakeholders regarding program performance, operational effectiveness, and emerging risks.
Education / Experience / Other Information (include only those that are specific to the role)
• Bachelor's degree in engineering or related.
• 3-5 years of experience in Vulnerability Management principles and lifecycle processes.
• Strong understanding of Vulnerability Management principles and lifecycle processes.
• Knowledge of vulnerability scanning technologies and security assessment methodologies.
• Understanding of CVSS scoring, vulnerability prioritization, exploitability, remediation workflows, and risk treatment concepts.
• Experience with vulnerability management platforms such as Tenable, application security tools, or similar technologies.
• Experience using ServiceNow, JIRA, or comparable ticket management solutions.
• Experience with reporting, analytics, and dashboarding tools including Excel, Power BI, or similar platforms.
• Knowledge of cybersecurity risk management, governance, and control frameworks.
Professional Skills
• Excellent analytical, problem-solving, and organizational skills.
• Strong stakeholder management and relationship-building capabilities.
• Excellent verbal and written communication skills.
• Ability to interpret operational data and present findings to management and executive audiences.
• Strong documentation and process management skills.
• Ability to manage multiple priorities and deliverables in a fast-paced environment.
• Highly motivated, collaborative, and results-oriented mindset.
• Strong attention to detail and commitment to operational excellence.
• Ability to adapt quickly to changing priorities and business requirements.
Preferred Experience
• Experience supporting cybersecurity, risk management, audit, or regulatory programs.
• Experience supporting evidence collection and audit readiness activities.
• Experience preparing executive reports, governance packages, and operational dashboards.
• Experience leading operational initiatives and process improvement activities.
• Familiarity with financial services environments and regulatory expectations.
• Experience with automation, data analysis, or reporting enhancements is considered an asset.
Working Conditions
• Work in a standard office-based environment; non-standard hours are a common occurrence. No travel needs.
Location(s): Colombia : Bogota : Bogota
ScotiaTech is a business unit within ScotiaGBS, a Scotiabank Group company located in Bogota, Colombia. The ScotiaTech hub was created to support different technology systems and processes of the Bank. We offer an inclusive, positive work environment, and competitive benefits.
At ScotiaTech, we value the unique skills and experiences each individual brings and are committed to creating and maintaining an inclusive and accessible environment for everyone. Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at ScotiaTech; however, only those candidates who are selected for an interview will be contacted.
Job Segment:
Information Security, Cyber Security, Business Process, Engineer, Technology, Security, Management, Engineering