> Markdown version of [/jobs/ext/575807-information-security-risk-analyst](https://www.wearedevelopers.com/jobs/ext/575807-information-security-risk-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Risk Analyst - **Company:** Ecco - **Location:** Kansas City, MO, United States (Remote available) - **Experience:** Expert - **Salary:** $105,000.0 - $120,000.0 - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Security Management, PCI Data Security Standards, Information Technology Security Auditing, Information Technology - **Published:** June 21, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ba13ead3b3b35034 ## About the Role Do you have experience in Security risk assessment investigation?, Do you have a Bachelor's degree?, * Bachelor's degree in Management Information Systems, Computer Science, or a related field, or an equivalent combination of education and experience. * A minimum of 5 years of progressively responsible experience in information security, security audit, or information security risk management/compliance. * Strong working knowledge and hands-on experience with PCI-DSS compliance frameworks and associated organizational requirements. * In-depth understanding of risk and controls, with practical experience applying relevant security standards and frameworks such as COSO, COBIT, ISO, NIST, and ITIL. * Experience conducting information security risk assessments and facilitating or responding to information security audits. * Adaptability and ability to manage multiple parallel tasks in a dynamic environment, while clearly communicating status, concerns, and solutions. * Proactive approach to ongoing professional development in information security concepts, industry trends, and regulatory changes., * Professional certifications such as CISSP, CRISC, SEC+, PCI-DSS ISA/PCIP or similar accreditation are highly desirable. * Demonstrated understanding of information security regulatory requirements and industry best practices. * General familiarity with banking and financial services processes and knowledge of related data protection and risk management considerations is a plus. ## Description As a Sr. Information Security Risk Analyst, you will play a key role in supporting the organization's Information Security Program and its ability to address rapidly changing security threats, technologies, and evolving business needs. This position works closely with enterprise technology and information security teams, as well as business units across the organization, to promote and ensure strong data protection initiatives. Your core responsibilities will include: * Collaborating across diverse teams and business units to drive key security initiatives forward. * Enabling the business and stakeholders to make informed, risk-aware decisions by advising on information security risks and proposing feasible and acceptable risk treatment options. * Supporting the collection and analysis of security performance indicators, metrics, and other evidence as part of information security program efforts, and communicating actionable recommendations to leadership. * Contributing to the organization's PCI-DSS compliance and assessment activities while supporting internal technology and business teams throughout the organization. * Maintaining up-to-date knowledge of information security best practices, evolving threats, technology regulations, and industry trends, and applying this expertise to daily operations and decision-making. * Assisting in responses to internal and external audits, including third-party security assessments where appropriate. * Managing multiple, simultaneous workstreams for different stakeholders, communicating issues, risks, and statuses with clarity and timeliness. * Ensuring practical application and understanding of information security policies and standards across business and technology teams. ## Related Videos - [GitOps keeps focus on apps, not on infrastructure](https://www.wearedevelopers.com/videos/182-gitops-keeps-focus-on-apps-not-on-infrastructure) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [It's not easy being green](https://www.wearedevelopers.com/videos/558-it-s-not-easy-being-green) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)