Senior Security Risk Analyst
Job in
Houston, Harris County, Texas, 77246, USA
Listed on 2026-08-29
Listing for:
Crane Worldwide Logistics
Full Time
position Listed on 2026-08-29
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
Job Description & How to Apply Below
The Sr. Security Risk Analyst provides assessments, gap analysis, and recommendations around technical security control implementations across multiple software products, supporting infrastructure technologies, and business processes in alignment with Crane security policies and standards. As part of the Information Security team, the successful candidate will have the opportunity to become our cloud environment security subject matter expert (SME) and work closely with Crane teams to improve the maturity of our security control environment.
ESSENTIAL JOB FUNCTIONS
- Support security team projects such as threat modeling, vulnerability scanning and audits.
- Lead security framework certification efforts.
- Design, develop, and implement IT security controls for cloud-based enterprise business systems that are aligned with policy and compliance requirements.
- Assist with vulnerability, risk, and security assessments of networks, hardware, and software.
- Develops, implements, and maintain security risk management processes that enable security risks to be identified, aggregated, tracked, and managed.
- Execute risk and threat analyst activities that include track, measure, validate, and report on risk identification, acceptances, and remediation efforts.
- Lead discussions, assessments, tracking, and overall reporting of technology security risks to support organizational cyber security objectives.
- Advises on acceptable mitigating controls related to Policy and Standard Exceptions.
- Assists in the development, dissemination, and management of security metrics to be used in monitoring and improving the company’s security posture and decision‑making.
- Provides ongoing maintenance of the security risk register.
- Manage the effectiveness of tooling, rationalizing tools as needed, and identifying new tool requirements as necessary.
- Define metrics and key performance indicators to determine the effectiveness of the Security automation program.
- Demonstrate technical leadership to manage and provide multiple technical solutions, establish, and enforce coding guidelines and best practices.
- Serve as an internal security consultant to teams looking to make IT investments; ensure systems are designed in accordance with and are aligned to Crane's security policies and standards.
- Influence the continuous improvement of the security program.
OTHER
SKILLS AND ABILITIES
- Knowledge of risk management frameworks and applying risk methodologies.
- Understanding of conducting risk and/or self‑assessment activities to identify key risk areas in the business.
- Experience associated with 3rd party risk assessments and understanding security in‑depth principles to measure risk.
- Knowledge of security auditing procedures.
- Enthusiasm for scalable, reproducible security management.
- Experience working on applications deployed within Azure is desirable.
- Understanding of Dev Ops and CI/CD practices and tools.
- Experience with security compliance monitoring tool including SIEM tools, vulnerability scanning tools, DLP (Data Loss Prevention) PAM (Privileged Access Management), and other infrastructure security tools.
- Knowledge of GRC and risk assessment tools (Archer or One Trust preferred).
- Industry certification preferred in one of the following areas: (e.g., CISSP, CISM, CRISC, or CISA).
- Familiarity with standards such as ISO 27001/27002 or the NIST Cybersecurity Framework is desirable.
- Knowledge of current data privacy laws (CCPA, GDPR).
EDUCATION AND EXPERIENCE
- Bachelor’s Degree in Computer Science, Information Technology, Cybersecurity, or related field required.
- Minimum 7 years of experience working with security frameworks and implementing cyber security controls across a heterogenous environment.
- Experience with public cloud architecture, cloud strategy, networking, security, and compliance workload types.
PHYSICAL REQUIREMENTS
- Job may require extended sitting or standing, use of standard office equipment.
- Job requires the ability to use vision, adjust focus and work on a standard computer screen.
- Use of audio-visual equipment is required.
- Job may require presence on‑site at the assigned work location.
WHY SHOULD YOU WORK FOR CRANE?
At Crane, we believe in providing our…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×