Rodeo
Get started

Baker McKenzie

Senior IT Audit, Risk & Security Governance Analyst

Buenos Aires
Posted 1 day ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Information Security Governance, Risk and Assurance Analyst

The Information Security Governance, Risk and Assurance Analyst will work closely with stakeholders across Technology, Information Security, Risk and Procurement teams to support the Firm's information security governance, risk, compliance and assurance objectives.

The role holder will be responsible for conducting risk-based IT audits, security assessments, third-party risk reviews and governance activities, ensuring alignment with the Firm's security framework, policies and applicable standards. They will also support the ongoing development of the third-party risk programme, helping to strengthen supplier assurance, onboarding processes and integration governance.

Main responsibilities:

  • Plan and execute risk-based IT and information security audits, control assessments and compliance reviews across internal functions, technology platforms, business processes and third parties.
  • Assess control design and operating effectiveness across governance, access management, change management, IT operations, cloud, network and endpoint security, data protection, secure development, incident management, resilience, supplier management and compliance.
  • Define scope, objectives, test procedures, evidence requirements and sampling approaches with relevant stakeholders.
  • Produce clear, defensible workpapers and reports documenting evidence, control gaps, root causes, risk implications and practical recommendations.
  • Maintain findings and corrective-action records, validate remediation, track actions to closure and escalate overdue or material issues.
  • Support internal and external audits, client security assessments, regulatory reviews and assurance requests by coordinating evidence and providing accurate, consistent responses.
  • Respond to RFPs, RFIs, due diligence questionnaires and contractual security enquiries supporting business development and client onboarding.
  • Perform security due diligence and manage risk activities across the third-party lifecycle, including intake, classification, assessment, contracting support, onboarding, monitoring, periodic review, issue management and offboarding.
  • Improve vendor assessment and onboarding cycle times through risk-based scoping, clear evidence requirements, stakeholder coordination and timely escalation of blockers.
  • Coordinate annual and periodic reviews of critical and high-risk vendors and maintain a forward review schedule.
  • Monitor critical suppliers, investigate material alerts and track vendor remediation to closure.
  • Maintain complete, accurate and audit-ready inventories, risk records, evidence, review dates, findings, exceptions and remediation status.
  • Work with Procurement, Legal, Privacy, Compliance, Technology, business owners and suppliers to identify and manage third-party risk.
  • Support governance of third-party integrations, connected applications, APIs and data exchanges, including ownership, inventory, security, privacy, authentication, authorization, logging, monitoring, resilience and lifecycle controls.
  • Identify unmanaged or insufficiently governed integrations and APIs, assess risk and coordinate remediation or formal risk acceptance.
  • Monitor compliance with information security policies, standards and procedures and contribute to continual improvement of the ISMS and risk framework.
  • Develop metrics, KPIs, KRIs, dashboards and risk-based recommendations covering audits, assessments, vendor onboarding, review cycle times, monitoring, findings and remediation.
  • Improve policies, standards, procedures, control descriptions, assessment methods, templates and guidance, and identify opportunities to streamline or automate GRC processes without reducing control quality.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Skills and experience:

  • Strong understanding of information security, technology risk, governance, compliance, audit and control principles.
  • Demonstrable experience planning or performing IT or information security audits, risk assessments, control testing or compliance reviews.
  • Authoritative knowledge of audit principles across governance, asset management, identity and access management, change management, IT operations, cloud and network security, secure development, incident management, resilience, supplier management and compliance.
  • Experience conducting third-party security due diligence and supporting vendor risk management across onboarding, periodic review, continuous monitoring, issue management and offboarding.
  • Experience improving assessment workflows, coordinating stakeholders and delivering work to defined service levels or target dates.
  • Working knowledge of third-party integration and API risks, including ownership, inventory, authentication, authorization, data exchange, logging, monitoring and lifecycle governance.
  • Experience with GRC, third-party risk or external security-rating platforms; familiarity with SecurityScorecard or an equivalent service is advantageous.
  • Working knowledge of ISO/IEC 27001, NIST Cybersecurity Framework, NIST SP 800-53, COBIT, SOC 2 or equivalent control and assurance frameworks.
  • Working knowledge of Active Directory, cloud services, networking, endpoint management, SaaS platforms and security monitoring capabilities.
  • Ability to evaluate evidence, analyse facts, identify control gaps, assess risk and recommend practical improvements.
  • Ability to produce clear, concise and defensible audit workpapers, findings, risk statements, management reports and client-facing responses.
  • Strong business acumen and stakeholder-management skills, with professional written and spoken English.
  • Proficiency in Microsoft Word and Excel, with the ability to use data and reporting tools to monitor workflow, risks, findings and remediation.
  • Ability to work independently and collaboratively, manage competing priorities, maintain attention to detail and respond constructively to feedback.
  • Bachelor's degree in Computer Science, Information Security, Information Systems, Audit, Risk Management or a related discipline, or substantial equivalent experience.
  • Relevant experience in IT audit, information security assurance, third-party risk management, client audit response, security metrics or remediation tracking.
  • CISA, CRISC, CISM, CISSP, ISO 27001 Lead Auditor or equivalent certification is preferred.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Reports to: Associate Director, Information Security

Position Type: Centre Services

Development Framework: Specialist

About Us

Baker McKenzie empowers clients to compete in the global economy. We provide comprehensive and practical legal advice that cuts through complexity with clear, actionable guidance. Our people represent diverse cultures and jurisdictions, combining local know-how with international expertise to ensure your business thrives across borders.

Additional Information

Baker McKenzie is an Equal Opportunity Employer. We are committed to promoting diversity and inclusion for all. Our unique international culture is reflected in the drawing together of a worldwide family of individuals from diverse cultures and backgrounds in all of our offices. We encourage the best people - regardless of race, religion or belief if any, gender, gender identity, disability, sexual orientation or age - to fulfill their professional aspirations with us. We are committed to ensuring an inclusive and accessible experience for all candidates.

Job Information

  • Posting Date: 09-Oct-2026
  • Requisition ID: 3605
  • States/Provinces/Cities: Belfast, Buenos Aires, Manila
  • Location Type: Hybrid
  • Business Unit: Business Professionals
  • Function: Technology
  • Full Time or Part Time: Full Time
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

Buenos Aires, Argentina

Sign up to applySee more jobs like this