1

Senior Information Security Risk Manager Jobs (NOW HIRING)

Conduct and manage enterprise information security risk assessment through recognized frameworks (including NIST 800-30) and maintain an information security risk register. * Lead third-party ...

What you'll do Docusign is looking for a Senior Security Risk Manager to join our Security ... Bachelor's degree in Computer Science, Information Security, or related field * Experience with ...

Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for ...

Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for ...

Developing an agency Information Security Risk Management Strategy in accordance with the latest released versions of NIST Special Publications (SPs) such as SP 800-37, Risk Management Framework for ...

next page

Showing results 1-20

Senior Information Security Risk Manager information

See salary details

$22.5K

$118.3K

$210K

How much do senior information security risk manager jobs pay per year?

As of Jun 5, 2026, the average yearly pay for senior information security risk manager in the United States is $118,258.00, according to ZipRecruiter salary data. Most workers in this role earn between $84,500.00 and $145,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Senior Information Security Risk Manager, and why are they important?

To thrive as a Senior Information Security Risk Manager, you need extensive knowledge of risk assessment, security frameworks (such as ISO 27001 and NIST), and experience in information security management, typically supported by a degree in cybersecurity or a related field. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), vulnerability assessment software, and certifications such as CISSP or CISM are commonly required. Strong leadership, analytical thinking, and communication skills help in influencing stakeholders and managing cross-functional teams. These competencies are critical to effectively identify, assess, and mitigate information security risks in complex enterprise environments.

How does a Senior Information Security Risk Manager typically collaborate with other departments to mitigate risks?

A Senior Information Security Risk Manager works closely with various departments, such as IT, legal, compliance, and business units, to identify and assess potential security risks. They facilitate risk assessments, help develop mitigation strategies, and ensure that controls are understood and implemented across the organization. Regular meetings, cross-functional training, and clear communication are key to aligning risk management initiatives with business goals. This collaborative approach not only strengthens the organization's security posture but also fosters a culture of shared responsibility for information security.

What does a Senior Information Security Risk Manager do?

A Senior Information Security Risk Manager is responsible for identifying, assessing, and mitigating risks that could compromise the confidentiality, integrity, and availability of an organization's information systems. They develop and implement risk management strategies, ensure compliance with security regulations, and oversee security audits. Additionally, they collaborate with other departments to develop security policies and respond to security incidents, helping to protect the organization from potential cyber threats.

What is the difference between Senior Information Security Risk Manager vs Information Security Analyst?

AspectSenior Information Security Risk ManagerInformation Security Analyst
CertificationsCISSP, CISM, CRISCCISSP, Security+, CEH
Work EnvironmentRisk management, policy development, strategic planningMonitoring security systems, incident response, vulnerability assessment
Employer & Industry UsageFinancial, healthcare, large enterprisesIT departments, cybersecurity firms, government agencies

The Senior Information Security Risk Manager focuses on identifying, assessing, and mitigating security risks at a strategic level, often managing policies and compliance. In contrast, the Information Security Analyst primarily monitors security systems, investigates incidents, and performs vulnerability assessments. Both roles require relevant certifications, but the Risk Manager's role is more strategic and managerial, while the Analyst's role is more technical and operational.

What cities are hiring for Senior Information Security Risk Manager jobs? Cities with the most Senior Information Security Risk Manager job openings:
What states have the most Senior Information Security Risk Manager jobs? States with the most job openings for Senior Information Security Risk Manager jobs include:
Infographic showing various Senior Information Security Risk Manager job openings in the United States as of May 2026, with employment types broken down into 1% As Needed, 93% Full Time, 4% Part Time, 1% Temporary, and 1% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $118,258 per year, or $56.9 per hour.
Sr. Information Security Risk Analyst

Sr. Information Security Risk Analyst

UMB Financial

Kansas City, MO • On-site, Remote

$69K - $109K/yr

Full-time

Posted 28 days ago


Job description

As part of UMB's Corporate Information Security and Privacy (CISP) team, the mission is to identify threats, vulnerabilities, and risks and to help protect the people, information, and services within the organization. CISP works closely with all lines of business. This role will work especially close with UMB enterprise technology and information security teams to ensure data protection initiatives are present, usable and, understood within the organization.

As the Sr. Information Security Risk Analyst, you will be responsible for supporting UMB's Information Security Program to ensure UMB is able to address rapidly changing threats, technologies, and business conditions. This is a subset of the overall responsibilities which involves other multiple initiatives as assigned by Corporate Risk leadership.

This role is hybrid (Mon through Thu on-site / Fri remote) for candidates in the Kansas City metropolitan area.

How you will spend your time:

  • Collaborate and drive security initiatives, working with people across multiple teams and diverse functions.
  • Enable the business and other stakeholders to make risk-aware decisions by advising business units and technology leaders of the information security risks and proposing acceptable risk treatment options and alternatives.
  • Support the information security program efforts through the collection of performance indicators, metrics, and other evidence and communicating relevant, succinct, and actionable recommendations to leadership.
  • Support UMB's PCI-DSS compliance and assessment activities while supporting our internal technology and business teams across the organization.
  • Proactively maintain a current and working understanding of information security best practices, the practical application of security concepts, relevant information security and technology regulations, threats, and industry trends.
  • Assist in responding to internal/external audits, including third-party security assessments, if applicable.
  • Maintain a current and working understanding of relevant information security and technology regulations and industry trends, including UMB Information Security Policies and the practical application of the Policies.
  • Manage multiple simultaneous workstreams supporting disparate stakeholders, providing appropriate and timely communication of issues, concerns, risks, and status.

We are excited to talk if you have:

  • Bachelor's degree in Management Information Systems (MIS), Computer Science or a related discipline OR equivalent work experience.
  • At least 5 years of experience in information security, security audit, or information security risk management/compliance.
  • Working knowledge and practical application of the PCI-DSS compliance framework and how organizations meet those requirements.
  • Strong knowledge of risk and controls, including working knowledge of standards and frameworks such as COSO, COBIT, ISO, NIST, and ITIL.
  • Ability to thrive in an environment of change and manage multiple tasks and responsibilities simultaneously.
  • Understanding of and practical experience with information security risk assessments and information security audits.

Bonus Points if you have:

  • CISSP, CRISC, SEC+, PCI-DSS ISA/PCIP or applicable certifications/accreditation.
  • Strong understanding of information security regulatory requirements and best practices.
  • General understanding of banking and financial services processes, and the related risks to securing and managing data.

Applicants must have legal authority to work in the United States. Work Visa sponsorship not available for this position.


Compensation Ranges:

US Employees in California, Washington DC, New Jersey, and New York:

$83,810 - $131,550

US Employees in Colorado, Connecticut, Delaware, Illinois, Massachusetts, Maryland, Minnesota, Pennsylvania, Rhode Island, Texas, Washington, and Wisconsin:

$76,520 - $120,210

US Employees in all other states not listed above:

$69,230 - $109,120

The posted compensation range on this listing represents UMB's good faith and reasonable estimate based on its budget and what it expects to be the starting pay for this role, but the actual compensation may vary by geographic location, experience level, and other job-related factors. Please see the description of benefits included with this job posting for additional information.

UMB offers competitive and varied benefits to eligible associates, such as Paid Time Off; a 401(k) matching program; annual incentive pay; paid holidays; a comprehensive company sponsored benefit plan including medical, dental, vision, and other insurance coverage; health savings, flexible spending, and dependent care accounts; adoption assistance; an employee assistance program; fitness reimbursement; tuition reimbursement; an associate wellbeing program; an associate emergency fund; and various associate banking benefits. Benefit offerings and eligibility requirements vary.

Are you ready to be part of something more?
You're more than a means to an end-a way to help us meet the bottom line. UMB isn't comprised of workers, but of people who care about their work, one another, and their community. Expect more than the status quo. At UMB, you can expect more heart. You'll be valued for exactly who you are and encouraged to support causes you care about. Expect more trust. We want you to do the right thing, no matter what. And, expect more opportunities. UMBers are known for having multiple careers here and having their voices heard.


UMB and its affiliates are committed to inclusion and diversity and provide employment opportunities to all employees and applicants for employment without regard to race, color, religion, sex (including gender, pregnancy, sexual orientation, and gender identity), national origin, age, disability, military service, veteran status, genetic information, or any other status protected by applicable federal, state, or local law. If you need accommodation for any part of the employment process because of a disability, please send an e-mail to talentacquisition@umb.com to let us know the nature of your request.


If you are a California resident, please visit our Privacy Notice for California Job Candidates to understand how we collect and use your personal information when you apply for employment with UMB.


#LI-MD1