Information Security Risk Analyst

Ecco
Kansas City, MO, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$105,000.0 - $120,000.0
Working hours
Regular working hours
Job source

Tech stack

Control Objectives for Information and Related Technology (COBIT) Cyber Security Information Security Management PCI Data Security Standards Information Technology Security Auditing Information Technology

Job description

As a Sr. Information Security Risk Analyst, you will play a key role in supporting the organization’s Information Security Program and its ability to address rapidly changing security threats, technologies, and evolving business needs. This position works closely with enterprise technology and information security teams, as well as business units across the organization, to promote and ensure strong data protection initiatives. Your core responsibilities will include:

  • Collaborating across diverse teams and business units to drive key security initiatives forward.
  • Enabling the business and stakeholders to make informed, risk-aware decisions by advising on information security risks and proposing feasible and acceptable risk treatment options.
  • Supporting the collection and analysis of security performance indicators, metrics, and other evidence as part of information security program efforts, and communicating actionable recommendations to leadership.
  • Contributing to the organization’s PCI-DSS compliance and assessment activities while supporting internal technology and business teams throughout the organization.
  • Maintaining up-to-date knowledge of information security best practices, evolving threats, technology regulations, and industry trends, and applying this expertise to daily operations and decision-making.
  • Assisting in responses to internal and external audits, including third-party security assessments where appropriate.
  • Managing multiple, simultaneous workstreams for different stakeholders, communicating issues, risks, and statuses with clarity and timeliness.
  • Ensuring practical application and understanding of information security policies and standards across business and technology teams.

Requirements

Do you have experience in Security risk assessment investigation?, Do you have a Bachelor’s degree?, * Bachelor’s degree in Management Information Systems, Computer Science, or a related field, or an equivalent combination of education and experience.

  • A minimum of 5 years of progressively responsible experience in information security, security audit, or information security risk management/compliance.
  • Strong working knowledge and hands-on experience with PCI-DSS compliance frameworks and associated organizational requirements.
  • In-depth understanding of risk and controls, with practical experience applying relevant security standards and frameworks such as COSO, COBIT, ISO, NIST, and ITIL.
  • Experience conducting information security risk assessments and facilitating or responding to information security audits.
  • Adaptability and ability to manage multiple parallel tasks in a dynamic environment, while clearly communicating status, concerns, and solutions.
  • Proactive approach to ongoing professional development in information security concepts, industry trends, and regulatory changes., * Professional certifications such as CISSP, CRISC, SEC+, PCI-DSS ISA/PCIP or similar accreditation are highly desirable.
  • Demonstrated understanding of information security regulatory requirements and industry best practices.
  • General familiarity with banking and financial services processes and knowledge of related data protection and risk management considerations is a plus.

Benefits & conditions

Pulled from the full job description

  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Career development plan, * 401(k) matching
  • Health insurance
  • Paid time off
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:03 min

Platform compliance and security certifications for sensitive data

Chad Carlson · WWC 2021

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:46 min

Missing equipment retrieval processes for departing employees

Jasmin Azemović Jasmin Azemović · WWC Europe 2026

Videos

See all

Related articles

See all