Jobs and Careers
UM

Sr. Information Security Risk Analyst

UMB Bank
Kansas City, United Statesfull_timeVerifiedPosted 18 Aug 2025
💰 $149,000/yr($69,230/yr$149,000/yr)

About the role

As part of UMB’s Corporate Information Security and Privacy (CISP) team, the mission is to identify threats, vulnerabilities, and risks and to help protect the people, information, and services within the organization. CISP works closely with all lines of business. This role will work especially close with UMB enterprise technology and information security teams to ensure data protection initiatives are present, usable and, understood within the organization.

As a Sr. Information Security Risk Analyst, you will be responsible for supporting UMB Financial Corporation’s Information Security Program to ensure UMB is able to address rapidly changing threats, technologies, and business conditions.  We currently have 2 openings with one position focusing specifically on Incident Response.  The Incident Response opening includes assisting with the coordination, response, and investigation of Information Security Incidents throughout the lifecycle of a cyber event, including incident response planning, root cause analysis and investigation, remediation actions, post-mortem discussions, and process improvement activities.  This is a subset of the overall responsibilities which involves other multiple initiatives as assigned by Corporate Risk leadership. 

These roles are Monday through Thursday on-site / Friday remote and located in downtown Kansas City, MO.

How you’ll spend your time as a Sr. Information Security Risk Analyst:

  • Collaborate and drive security initiatives, working with people across multiple teams and diverse functions.
  • Enable the business and other stakeholders to make risk-aware decisions by advising business units and technology leaders of the information security risks and proposing acceptable risk treatment options and alternatives.
  • Support the information security program efforts through the collection of performance indicators, metrics, and other evidence and communicating relevant, succinct, and actionable recommendations to leadership.
  • Support UMB’s PCI-DSS compliance and assessment activities while supporting our internal technology and business teams across the organization.
  • Proactively maintain a current and working understanding of information security best practices, the practical application of security concepts, relevant information security and technology regulations, threats, and industry trends.
  • Assist in responding to internal/external audits, including third-party security assessments, if applicable.
  • Maintain a current and working understanding of relevant information security and technology regulations and industry trends, including UMB Information Security Policies and the practical application of the Policies.
  • Manage multiple simultaneous workstreams supporting disparate stakeholders, providing appropriate and timely communication of issues, concerns, risks, and status.

How you’ll spend your time as a Sr. Information Security Risk Analyst – Incident Response:

  • Assist with the on-going maturity of the Information Security Incident Response Program, including investigative and analysis processes, organizational policies and Incident Response Plan maintenance, playbook development and maintenance, facilitate tabletop exercises, and incident root cause analysis.
  • Partner with Legal, Human Resources, Privacy, Information Technology, Corporate Security, Insider Risk, and Fraud teams to align and manage Information Security Incident Response activities including the investigations of cyber incidents, information security forensics, and cyber fraud-related activities.
  • Collaborate and drive security initiatives, working with people across multiple teams and diverse functions.
  • Enable the business and other stakeholders to make risk-aware decisions by advising business units and technology leaders of the information security risks and proposing acceptable risk treatment options and alternatives.
  • Support the information security program efforts through the collection of performance indicators, metrics, and other evidence and communicating relevant, succinct, and actionable recommendations to leadership.
  • Assist in the documentation and assessment of UMB’s governance, risk management, and compliance programs.
  • Validate, identify remediation actions, and monitor gaps identified through security risk and controls assessments.
  • Support the continuous maturity and evolution of UMB’s information security and privacy programs by challenging current approaches and proactively identifying and communicating improvement opportunities.
  • Assist in responding to internal/external audits, findings, risk assessments and gap analysis activities.
  • Perform gaps analysis against regulatory expectatio

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

UMB Bank

View company profile →