> Markdown version of [/jobs/ext/1291488-sr-information-security-risk-analyst](https://www.wearedevelopers.com/jobs/ext/1291488-sr-information-security-risk-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Information Security Risk Analyst - **Company:** UMB Bank - **Location:** Kansas City, MO, United States - **Experience:** Expert - **Salary:** $100,000.0 - $120,000.0 - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Security Management, PCI Data Security Standards, Information Technology Security Auditing, Information Technology - **Published:** July 16, 2026 - **Apply:** https://www.juju.com/job/00000000ggwfjb ## About the Role + Bachelor's degree in Management Information Systems (MIS), Computer Science or a related discipline OR equivalent work experience. + At least 5 years of experience in information security, security audit, or information security risk management/compliance. + Working knowledge and practical application of the PCI-DSS compliance framework and how organizations meet those requirements. + Strong knowledge of risk and controls, including working knowledge of standards and frameworks such as COSO, COBIT, ISO, NIST, and ITIL. + Ability to thrive in an environment of change and manage multiple tasks and responsibilities simultaneously. + Understanding of and practical experience with information security risk assessments and information security audits. _Bonus Points if you have:_ + CISSP, CRISC, SEC+, PCI-DSS ISA/PCIP or applicable certifications/accreditation. + Strong understanding of information security regulatory requirements and best practices. + General understanding of banking and financial services processes, and the related risks to securing and managing data. Applicants must have legal authority to work in the United States. Work Visa sponsorship is not available for this position. ## Description As part of UMB's **Corporate Information Security and Privacy (CISP)** team, the mission is to identify threats, vulnerabilities, and risks and to help protect the people, information, and services within the organization. CISP works closely with all lines of business. This role will work especially close with UMB enterprise technology and information security teams to ensure data protection initiatives are present, usable and, understood within the organization. As the **Sr. Information Security Risk Analyst,** you will be responsible for supporting UMB's Information Security Program to ensure UMB is able to address rapidly changing threats, technologies, and business conditions. This is a subset of the overall responsibilities which involves other multiple initiatives as assigned by Corporate Risk leadership. This role is hybrid (Mon through Thu on-site / Fri remote) located in our downtown Kansas City, MO headquarters. _How you will spend your time:_ + Collaborate and drive security initiatives, working with people across multiple teams and diverse functions. + Enable the business and other stakeholders to make risk-aware decisions by advising business units and technology leaders of the information security risks and proposing acceptable risk treatment options and alternatives. + Support the information security program efforts through the collection of performance indicators, metrics, and other evidence and communicating relevant, succinct, and actionable recommendations to leadership. + Support UMB's PCI-DSS compliance and assessment activities while supporting our internal technology and business teams across the organization. + Proactively maintain a current and working understanding of information security best practices, the practical application of security concepts, relevant information security and technology regulations, threats, and industry trends. + Assist in responding to internal/external audits, including third-party security assessments, if applicable. + Maintain a current and working understanding of relevant information security and technology regulations and industry trends, including UMB Information Security Policies and the practical application of the Policies. + Manage multiple simultaneous workstreams supporting disparate stakeholders, providing appropriate and timely communication of issues, concerns, risks, and status. ## Related Videos - [GitOps keeps focus on apps, not on infrastructure](https://www.wearedevelopers.com/videos/182-gitops-keeps-focus-on-apps-not-on-infrastructure) - [It's not easy being green](https://www.wearedevelopers.com/videos/558-it-s-not-easy-being-green) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Opening Keynote: Civic Coding, A Framework for Democratic Tech](https://www.wearedevelopers.com/videos/963-opening-keynote-civic-coding-a-framework-for-democratic-tech) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)