1

Senior Information Security Risk Analyst Jobs in Minooka, IL

The Information Security Specialist supports the organization's security program by helping operate ... Support periodic reviews to ensure risk records remain accurate and current Identity & Access ...

Assess security risk and communicate information about security threats and vulnerabilities to ... and protocol analysis * Basic understanding of network security, including the design ...

The AVP ensures the ongoing testing schedule is executed by analyzing capacity and assigning responsibilities aligned with departmental priorities, as directed by the SVP of Enterprise Risk. About ...

next page

Showing results 1-20

Senior Information Security Risk Analyst information

See Minooka, IL salary details

$31

$57

$73

How much do senior information security risk analyst jobs pay per hour?

As of Sep 3, 2026, the average hourly pay for senior information security risk analyst in Minooka, IL is $57.08, according to ZipRecruiter salary data. Most workers in this role earn between $44.38 and $64.09 per hour, depending on experience, location, and employer.

What does a senior information security risk analyst do?

A Senior Information Security Risk Analyst is responsible for identifying, evaluating, and mitigating risks to an organization's information systems and data. They conduct risk assessments, develop security policies, and recommend measures to protect against cyber threats and vulnerabilities. Additionally, they work closely with IT and business teams to ensure compliance with regulations and industry standards, and they often play a key role in incident response and security awareness training.

What are the key skills and qualifications needed to thrive as a senior information security risk analyst?

A Senior Information Security Risk Analyst requires a deep understanding of cybersecurity frameworks, risk assessment methodologies, and regulatory compliance, usually backed by a degree in information security or a related field. Familiarity with tools like risk management software (e.g., Archer, RSA), SIEM systems, and certifications such as CISSP, CISM, or CRISC are typically expected. Exceptional analytical thinking, attention to detail, and strong communication skills set top performers apart in this role. These competencies are crucial to effectively identify, evaluate, and mitigate security risks, ensuring the organization's information assets remain protected against evolving threats.

How does a senior information security risk analyst typically collaborate with other departments to manage organizational risk?

A Senior Information Security Risk Analyst regularly works with various departments such as IT, legal, compliance, and business units to identify and address security risks. This collaboration often includes conducting risk assessments, reviewing new projects for potential vulnerabilities, and providing guidance on security best practices. Effective communication skills are essential, as the analyst must translate technical risks into business impacts and help teams implement appropriate controls. Close teamwork ensures that security is integrated into all business processes and that the organization remains compliant with relevant regulations.

What is the difference between Senior Information Security Risk Analyst vs Information Security Analyst?

AspectSenior Information Security Risk AnalystInformation Security Analyst
CertificationsCISSP, CISA, CRISCCISSP, Security+, CEH
Work EnvironmentFocus on risk assessment, policy development, and strategic planningImplementing security measures, monitoring, and incident response
Employer & Industry UsageFinancial, healthcare, and large enterprises with complex security needsVariety of industries, including tech, retail, and government

Senior Information Security Risk Analysts typically handle advanced risk assessments and strategic security planning, often requiring certifications like CISSP or CISA. Information Security Analysts focus on implementing security controls and monitoring systems. Both roles are vital in maintaining organizational security but differ in scope and seniority.

What cities near Minooka, IL are hiring for Senior Information Security Risk Analyst jobs?

Cities near Minooka, IL with the most Senior Information Security Risk Analyst job openings:

Security Human Risk & Resilience Analyst

Kemper

Downers Grove, IL

$89K - $148K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 3 days ago

New


Job description

Location(s)

P&C-Butterfield Road-Downers Grove-IL-AAC

Details

Kemper is one of the nation's leading specialized insurers. Our success is a direct reflection of the talented and diverse people who make a positive difference in the lives of our customers every day. We believe a high-performing culture, valuable opportunities for personal development and professional challenge, and a healthy work-life balance can be highly motivating and productive. Kemper's products and services are making a real difference to our customers, who have unique and evolving needs. By joining our team, you are helping to provide an experience to our stakeholders that delivers on our promises.

Kemper is seeking a Security Risk & Resilience Analyst to work at our Kemper office. This position combines substantive security GRC execution with security-culture and human-risk program design. The role uses risk, control, incident, phishing, training, and workforce data to identify behavioral and governance risk, influence business leaders, and drive measurable improvements rather than functioning as an administrative compliance or training-coordination role.

Position Responsibilities
  • Execute security risk assessments, control and policy support, issue tracking, governance reporting, and assurance coordination with sufficient technical understanding to challenge weak evidence or control design.
  • Design targeted security-culture and human-risk interventions based on role, behavior, business context, incident patterns, and measurable risk indicators.
  • Develop role-based education, leader toolkits, campaigns, and behavior-change initiatives that extend beyond annual awareness requirements.
  • Analyze GRC, control, incident, phishing, training, and workforce data to identify risk patterns and measure program effectiveness.
  • Develop dashboards, KRIs/KPIs, cohort analyses, executive insights, and action plans tied to actual risk outcomes.
  • Partner with business leaders, HR, Communications, technology teams, and security specialists to implement sustainable changes in behavior and control execution.
  • Own assigned GRC/culture processes end to end; standardize, automate, document, and improve recurring workflows.
Position Qualifications
  • 5+ years of cybersecurity GRC, risk, compliance, security awareness/human risk, change management, or related experience, with demonstrated ownership of both risk/control work and measurable stakeholder or behavior-change outcomes.
  • Bachelor's degree in Cybersecurity, Information Systems, Risk Management, Business, Communications, Behavioral Science, Education, or a related discipline, or equivalent relevant professional experience.
  • Practical experience with security GRC processes including risk assessments, controls, policies, issues, governance, and assurance support.
  • Strong analytics capability using spreadsheets, BI/reporting tools, GRC platforms, or equivalent data sources.
  • Experience designing and measuring security-awareness, human-risk, or behavior-change interventions
  • Ability to understand technical security evidence and identify when a control or response does not address the underlying risk.
  • Working knowledge of cybersecurity risks and controls across common domains and ability to connect security culture to incidents and control outcomes.
  • Ability to build clear metrics, dashboards, and risk narratives for leaders
  • Understanding of security governance, policy, risk treatment, assurance, and issue-management concepts.
  • Ability to distinguish compliance activity from meaningful risk reduction.
  • Excellent written and verbal communication.
  • Behavior-change and stakeholder-influence capability.
  • Analytical curiosity and evidence-based decision-making.
  • Ability to tailor messages to executives, leaders, technical teams, and general workforce populations.
  • Independent process ownership and continuous-improvement mindset.
Preferred Qualifications
  • CISSP, CISM, CRISC, Security+, or comparable security/risk credential.
  • Formal training or certification in change management, adult learning, communications, or behavioral science.
  • Experience with GRC platforms, BI/analytics tools, phishing/human-risk platforms, and security metrics.
  • Experience in a regulated enterprise supporting audit, compliance, or governance forums.

This position is a hybrid role that sits in either our Downers Grove, IL or Chicago, IL office locations

The base range for this position is $89,000 to $148,100. When determining candidate offers, we consider experience, skills, education, certifications, and geographic location among other factors. This job is eligible for an annual discretionary bonus, equity, and Kemper benefits (Medical, Dental, Vision, PTO, 401k, etc.)

Kemper is proud to be an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran, disability status or any other status protected by the laws or regulations in the locations where we operate. We are committed to supporting diversity and equality across our organization and we work diligently to maintain a workplace free from discrimination.

Kemper does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Kemper and Kemper will not be obligated to pay a placement fee.

Kemper will never request personal information, such as your social security number or banking information, via text or email. Additionally, Kemper does not use external messaging applications like WireApp or Skype to communicate with candidates. If you receive such a message, delete it.

#LI-AK