> Markdown version of [/jobs/ext/2654161-sr-security-risk-analyst](https://www.wearedevelopers.com/jobs/ext/2654161-sr-security-risk-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Security Risk Analyst - **Company:** Crane Worldwide Logistics - **Location:** Houston, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Business Systems, Cyber Security, Information Leak Prevention, DevOps, Security Information and Event Management, Cloud Optimization, Security Orchestration, Automation & Response, Vulnerability Analysis - **Published:** August 3, 2026 - **Apply:** https://dejobs.org/x/x/4D83CA052A25407394ACFDF9811F53B9/job/ ## About the Role * Knowledge of risk management frameworks and applying risk methodologies. * Understanding of conducting risk and/or self-assessment activities to identify key risk areas in the business. * Experience associated with 3rd party risk assessments and understanding security in-depth principles to measure risk. * Knowledge of security auditing procedures. * Enthusiasm for scalable, reproducible security management. * Experience working on applications deployed within Azure is desirable. * Understanding of DevOps and CI/CD practices and tools. * Experience with security compliance monitoring tool including SIEM tools, vulnerability scanning tools, DLP (Data Loss Prevention) PAM (Privileged Access Management), and other infrastructure security tools. * Knowledge of GRC and risk assessment tools (Archer or OneTrust preferred). * Industry certification preferred in one of the following areas: (e.g., CISSP, CISM, CRISC, or CISA). * Familiarity with standards such as ISO 27001/27002 or the NIST Cybersecurity Framework is desirable. * Knowledge of current data privacy laws (CCPA, GDPR) * Excellent verbal and written communication skills and excellent time management abilities. * Strong customer orientation and excellent interpersonal and communication skills., * Bachelor's Degree preferred * Minimum 7 years of experience working with security frameworks and implementing cyber security controls across a heterogenous environment. * Experience with public cloud architecture, cloud strategy, networking, security, and compliance workload types PHYSICAL REQUIREMENTS * Job may require extended sitting or standing, use of standard office equipment * Job requires the ability to use vision, adjust focus and work on a standard computer screen * Use of audio-visual equipment is required * Job may require presence on-site at the assigned work location ## Description * Support security team projects such as threat modeling, vulnerability scanning and audits. * Lead security framework certification efforts. * Design, develop, and implement IT security controls for cloud-based enterprise business systems that are aligned with policy and compliance requirements. * Assist with vulnerability, risk, and security assessments of networks, hardware, and software. * Develops, implements, and maintain security risk management processes that enable security risks to be identified, aggregated, tracked, and managed. * Execute risk and threat analyst activities that include track, measure, validate, and report on risk identification, acceptances, and remediation efforts. * Lead discussions, assessments, tracking, and overall reporting of technology security risks to support organizational cyber security objectives. * Advises on acceptable mitigating controls related to Policy and Standard Exceptions. * Assists in the development, dissemination, and management of security metrics to be used in monitoring and improving the company's security posture and decision-making. * Provides ongoing maintenance of the security risk register. * Manage the effectiveness of tooling, rationalizing tools as needed, and identifying new tool requirements as necessary. * Define metrics and key performance indicators to determine the effectiveness of the Security automation program. * Demonstrate technical leadership to manage and provide multiple technical solutions, establish, and enforce coding guidelines and best practices. * Serve as an internal security consultant to teams looking to make IT investments; ensure systems are designed in accordance with, and are aligned to Crane's security policies and standards * Influence the continuous improvement of the security program. * Other duties as assigned ## Related Videos - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)