Kemper

Security Human Risk & Resilience Analyst

Downers Grove ILFull timePosted about 15 hours ago
Apply on Kemper →

Sign in to see who you know at Kemper.

Location(s)

P&C-Butterfield Road-Downers Grove-IL-AAC

Details

Kemper is one of the nation’s leading specialized insurers. Our success is a direct reflection of the talented and diverse people who make a positive difference in the lives of our customers every day. We believe a high-performing culture, valuable opportunities for personal development and professional challenge, and a healthy work-life balance can be highly motivating and productive. Kemper’s products and services are making a real difference to our customers, who have unique and evolving needs. By joining our team, you are helping to provide an experience to our stakeholders that delivers on our promises.

Kemper is seeking a Security Risk & Resilience Analyst to work at our Kemper office. This position combines substantive security GRC execution with security-culture and human-risk program design. The role uses risk, control, incident, phishing, training, and workforce data to identify behavioral and governance risk, influence business leaders, and drive measurable improvements rather than functioning as an administrative compliance or training-coordination role.

Position Responsibilities

  • Execute security risk assessments, control and policy support, issue tracking, governance reporting, and assurance coordination with sufficient technical understanding to challenge weak evidence or control design.
  • Design targeted security-culture and human-risk interventions based on role, behavior, business context, incident patterns, and measurable risk indicators.
  • Develop role-based education, leader toolkits, campaigns, and behavior-change initiatives that extend beyond annual awareness requirements.
  • Analyze GRC, control, incident, phishing, training, and workforce data to identify risk patterns and measure program effectiveness.
  • Develop dashboards, KRIs/KPIs, cohort analyses, executive insights, and action plans tied to actual risk outcomes.
  • Partner with business leaders, HR, Communications, technology teams, and security specialists to implement sustainable changes in behavior and control execution.
  • Own assigned GRC/culture processes end to end; standardize, automate, document, and improve recurring workflows.

Position Qualifications

  • 5+ years of cybersecurity GRC, risk, compliance, security awareness/human risk, change management, or related experience, with demonstrated ownership of both risk/control work and measurable stakeholder or behavior-change outcomes.
  • Bachelor's degree in Cybersecurity, Information Systems, Risk Management, Business, Communications, Behavioral Science, Education, or a related discipline, or equivalent relevant professional experience.
  • Practical experience with security GRC processes including risk assessments, controls, policies, issues, governance, and assurance support.
  • Strong analytics capability using spreadsheets, BI/reporting tools, GRC platforms, or equivalent data sources.
  • Experience designing and measuring...