Sr. Security Risk Analyst

. Crane Worldwide Logistics .Houston, TX
Onsite

About The Position

The Security Risk Analyst will support security team projects such as threat modeling, vulnerability scanning, and audits. This role will lead security framework certification efforts, design, develop, and implement IT security controls for cloud-based enterprise business systems aligned with policy and compliance requirements. The analyst will assist with vulnerability, risk, and security assessments of networks, hardware, and software, and develop, implement, and maintain security risk management processes. Responsibilities include executing risk and threat analyst activities, leading discussions and reporting on technology security risks, advising on acceptable mitigating controls for policy and standard exceptions, and assisting in the development and management of security metrics. The role also involves managing the effectiveness of tooling, defining metrics for the Security automation program, providing technical leadership, and serving as an internal security consultant for IT investments. The analyst will influence the continuous improvement of the security program and perform other duties as assigned.

Requirements

  • Knowledge of risk management frameworks and applying risk methodologies.
  • Understanding of conducting risk and/or self-assessment activities to identify key risk areas in the business.
  • Experience associated with 3rd party risk assessments and understanding security in-depth principles to measure risk.
  • Knowledge of security auditing procedures.
  • Enthusiasm for scalable, reproducible security management.
  • Experience with security compliance monitoring tool including SIEM tools, vulnerability scanning tools, DLP (Data Loss Prevention) PAM (Privileged Access Management), and other infrastructure security tools.
  • Knowledge of GRC and risk assessment tools (Archer or OneTrust preferred).
  • Knowledge of current data privacy laws (CCPA, GDPR).
  • Excellent verbal and written communication skills and excellent time management abilities.
  • Strong customer orientation and excellent interpersonal and communication skills.
  • Bachelor’s Degree preferred.
  • Minimum 7 years of experience working with security frameworks and implementing cyber security controls across a heterogenous environment.
  • Experience with public cloud architecture, cloud strategy, networking, security, and compliance workload types.

Nice To Haves

  • Experience working on applications deployed within Azure is desirable.
  • Understanding of DevOps and CI/CD practices and tools.
  • Industry certification preferred in one of the following areas: (e.g., CISSP, CISM, CRISC, or CISA).
  • Familiarity with standards such as ISO 27001/27002 or the NIST Cybersecurity Framework is desirable.

Responsibilities

  • Support security team projects such as threat modeling, vulnerability scanning and audits.
  • Lead security framework certification efforts.
  • Design, develop, and implement IT security controls for cloud-based enterprise business systems that are aligned with policy and compliance requirements.
  • Assist with vulnerability, risk, and security assessments of networks, hardware, and software.
  • Develops, implements, and maintain security risk management processes that enable security risks to be identified, aggregated, tracked, and managed.
  • Execute risk and threat analyst activities that include track, measure, validate, and report on risk identification, acceptances, and remediation efforts.
  • Lead discussions, assessments, tracking, and overall reporting of technology security risks to support organizational cyber security objectives.
  • Advises on acceptable mitigating controls related to Policy and Standard Exceptions.
  • Assists in the development, dissemination, and management of security metrics to be used in monitoring and improving the company’s security posture and decision-making.
  • Provides ongoing maintenance of the security risk register.
  • Manage the effectiveness of tooling, rationalizing tools as needed, and identifying new tool requirements as necessary.
  • Define metrics and key performance indicators to determine the effectiveness of the Security automation program.
  • Demonstrate technical leadership to manage and provide multiple technical solutions, establish, and enforce coding guidelines and best practices.
  • Serve as an internal security consultant to teams looking to make IT investments; ensure systems are designed in accordance with, and are aligned to Crane's security policies and standards.
  • Influence the continuous improvement of the security program.
  • Other duties as assigned.

Benefits

  • Quarterly Incentive Plan
  • 136 hours of Paid Time Off which equals 17 days for the year, that can be used for Sick Time or for Personal Use
  • Excellent Medical, Dental and Vision benefits
  • Tuition Reimbursement for education related to your job
  • Employee Referral Bonuses
  • Employee Recognition and Rewards Program
  • Paid Volunteer Time to support a cause that is close to your heart and contributes to our communities
  • Employee Discounts
  • Wellness Incentives that can go up to $100 per year for completing challenges, in addition to a discount on contribution rates
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service