Sr. Information Security Risk Analyst
4 days ago
As part of UMB's Corporate Information Security and Privacy (CISP) team, the mission is to identify threats, vulnerabilities, and risks and to help protect the people, information, and services within the organization. CISP works closely with all lines of business. This role will work especially close with UMB enterprise technology and information security teams to ensure data protection initiatives are present, usable and, understood within the organization.
As a Sr. Information Security Risk Analyst, you will be responsible for supporting UMB Financial Corporation's Information Security Program to ensure UMB is able to address rapidly changing threats, technologies, and business conditions. You will support and perform a variety of program initiatives such as risk and controls assessments and governance activities at the direction of the Security Governance Director. This is a subset of the overall responsibilities which involves other multiple initiatives as assigned by Corporate Risk leadership.
This role is hybrid (Monday through Thursday on-site; Friday remote) and located in downtown Kansas City, MO.
How you'll spend your time:
- Assist in the documentation and assessment of UMB's IT governance, risk management, and compliance program (IT GRC).
- Manage the currency of UMB's NIST CSF and OCC Cybersecurity Work Program documentation to maintain a current understanding of UMB's information security and technology control posture.
- Lead efforts to coordinate and complete information security assessments, which may include identifying, compiling, and analyzing assessment inputs and the execution and documentation of the risk or controls assessment in accordance with the defined approach.
- Support the continuous maturity and evolution of the Information Security and Privacy Program by challenging current approaches and proactively identifying improvement opportunities to drive assessment, monitoring, and response effectiveness and efficiency.
- Lead efforts to validate, identify remediation actions, and monitor gaps identified through security risk/controls assessments, as well as external security scorecards (e.g., Security Scorecard, ISS, and/or Risk Recon).
- Provide input and facilitate the annual review of information security policies and procedures.
- Coordinate and respond to internal/external audits, including third-party security assessments as well as third-party client due diligence questions.
- Lead efforts to perform targeted risk and control assessments of new and existing service providers.
- Perform gap analysis against regulatory expectations or industry standards.
- Write, review, and maintain Information Security and Privacy related policies and procedures.
- Maintain a current and working understanding of relevant information security and technology regulations and industry trends, including UMB Information Security Policies and the practical application of the policies.
We're excited to talk with you if:
- You have a Bachelor's Degree in Management Information Systems (MIS), Accounting Information Systems, Computer Science or a related discipline OR equivalent work experience.
- You have at least 5 years of experience in information security, security audit, or information security risk management/compliance.
- You have strong knowledge of risk and controls.
- You have proficiency in identifying and assessing Information Security risk.
- You have working knowledge of standards and frameworks such as NIST CSF, HIPAA, ISO, etc.
Bonus Points If:
- You have industry recognized certification relevant to information security or risk assessment (i.e. CISSP, CISA, CRISC, etc.).
- You have in-depth understanding of and practical experience with information security control frameworks, risk management, and security audits.
- You have strong understanding of information security regulatory requirements and best practices.
- You have knowledge of the financial services industry.
- You are able to evaluate and execute complex data mining and analysis strategies using MS Excel, Power BI, or other analysis software in an efficient manner with a focus on data integrity.
- You have knowledgeable with the Archer GRC platform.
Applicants must have legal authority to work in the United States. Work Visa sponsorship not available for this position.
Compensation Range:
$69, $149,000.00The posted compensation range on this listing represents UMB's standard for this role, but the actual compensation may vary by geographic location, experience level, and other job-related factors. In addition, this range does not encompass the full earning potential for this role. Please see the description of benefits included with this job posting for additional information
UMB offers competitive and varied benefits to eligible associates, such as Paid Time Off; a 401(k) matching program; annual incentive pay; paid holidays; a comprehensive company sponsored benefit plan including medical, dental, vision, and other insurance coverage; health savings, flexible spending, and dependent care accounts; adoption assistance; an employee assistance program; fitness reimbursement; tuition reimbursement; an associate wellbeing program; an associate emergency fund; and various associate banking benefits. Benefit offerings and eligibility requirements vary.
Are you ready to be part of something more?
You're more than a means to an end—a way to help us meet the bottom line. UMB isn't comprised of workers, but of people who care about their work, one another, and their community. Expect more than the status quo. At UMB, you can expect more heart. You'll be valued for exactly who you are and encouraged to support causes you care about. Expect more trust. We want you to do the right thing, no matter what. And, expect more opportunities. UMBers are known for having multiple careers here and having their voices heard.
UMB and its affiliates are committed to inclusion and diversity and provide employment opportunities to all employees and applicants for employment without regard to race, color, religion, sex (including gender, pregnancy, sexual orientation, and gender identity), national origin, age, disability, military service, veteran status, genetic information, or any other status protected by applicable federal, state, or local law. If you need accommodation for any part of the employment process because of a disability, please send an e-mail to to let us know the nature of your request.
If you are a California resident, please visit our Privacy Notice for California Job Candidates to understand how we collect and use your personal information when you apply for employment with UMB.
-
Risk Analyst
5 days ago
Kansas City, Missouri, United States Aston Carter Full time $60,000 - $120,000 per yearWe are seeking a Third-Party Risk Analyst for a great client ours on a six-month contract, with the potential for permanent hire. This role involves executing the Third-Party Risk Management program by conducting vendor risk assessments, due diligence, and security reviews, while monitoring performance and managing remediation to ensure compliance with...
-
Cyber Security Analyst
4 days ago
Kansas City, Missouri, United States Kansas City Public Library Full time $60,000 - $68,000 per year:The Information Systems Cyber Security Analyst reports to the Information Systems Manager and has primary responsibility for the digital security of the library. The Information Systems Cyber Security Analyst will assist in advising the Information Systems Manager on the security posture of the library. This includes developing, configuring, documenting,...
-
Sr Project Analyst
1 day ago
Kansas City, Missouri, United States Kansas City National Security Campus Full time $80,000 - $120,000 per year**Join the industry leader to design the next generation of breakthroughs.Innovate to solve the world's most important challenges.**Honeywell is a Fortune 100 company that invents and manufactures technologies to address critical challenges linked to global macrotrends such as safety, security, productivity, global urbanization and energy. With approximately...
-
Information Security Engineer
5 days ago
Kansas City, Missouri, United States Shook, Hardy & Bacon LLP Full time $80,000 - $120,000 per yearProvides advanced technical level information security support to ensure the firm's overall information assets are adequately protected. This position is responsible for the technical engineering aspect of all information security hardware and software, with the skills to interpret data, configure and tune equipment and applications from both security and...
-
Associate Researcher, Research
5 days ago
Kansas City, Missouri, United States Spotlight Analyst Relations Full time $60,000 - $90,000 per yearSpotlight's Research & Intelligence team provides unparalleled insights, analysis, and perspective to Spotlight's clients and client teams. The Associate Researcher role is critical in supporting the creation and maintenance of deliverables focused on industry analysts, analyst firms, technology market trends, and B2B technology buyer reviews.The ultimate...
-
FLEX Security Officer
1 day ago
Kansas City, Missouri, United States Marksman Security LLC Full time $40,000 - $60,000 per yearMarksman Security is built on serving our clients and building careers – just like yours. We are trusted by some of the most well-known companies and properties in the country while remaining dedicated to building personalized security solutions that solve the needs of every customer we support. Named as a nationally recognized Top Workplace in 2024 and...
-
Security Officer
1 day ago
Kansas City, Missouri, United States Securitas Security Services Full time $18 - $21Security Officer – Full Time – Kansas City, MOFormer Military / Law Enforcement Encouraged To ApplyWage: $18.00-$21.00/HRThinking about a job in the security field?Securitas employees come from all walks of life, bringing with them a variety of distinctive skills and perspectives. United through our core values of integrity, vigilance, and helpfulness,...
-
Information Systems Inventory Analyst
6 days ago
Kansas City, Missouri, United States Children's Mercy KC Full timeThanks for your interest in Children's MercyDo you envision finding a meaningful role with an inclusive and compassionate team? At Children's Mercy, we believe in making a difference in the lives of all children and shining a light of hope to the patients and families we serve. Our employees make the difference, which is why we have been recognized by U.S....
-
Senior Security/Technical Risk Asssessor
3 days ago
Jefferson City, Missouri, United States Chameleon Integrated Services Full time $120,000 - $180,000 per yearWe are a growing information technology company that offers its employees a culture of success, the chance to work on revolutionary federal IT infrastructure, and the opportunity to grow alongside cutting-edge technology that is reshaping the industry. We are seeking forward thinking candidates that have strong experience in operational support and can help...
-
Program Manager, Research
5 days ago
Kansas City, Missouri, United States Spotlight Analyst Relations Full time $60,000 - $120,000 per yearSpotlight's Research & Intelligence team provides unparalleled insights, analysis, and perspective to Spotlight's clients and client teams. The role of Program Manager is ideal for a highly organized, proactive, and client-focused individual looking to grow into a strategic intelligence leader, blending program management, client communication, and light...