1

Cyber Risk Assessment Jobs in Pennsylvania (NOW HIRING)

next page

Showing results 1-20

Cyber Risk Assessment information

What is a cyber risk assessment?

A cyber risk assessment is a process used to identify, evaluate, and prioritize potential threats and vulnerabilities in an organization's information systems. It helps organizations understand the potential impact of cyber threats and determine the likelihood of such events occurring. By conducting a cyber risk assessment, businesses can implement appropriate security controls and strategies to mitigate risks, comply with regulatory requirements, and protect sensitive data from cyberattacks. Regular assessments are essential to adapt to evolving threats and maintain a strong cybersecurity posture.

What are the key skills and qualifications needed to thrive as a cyber risk assessor?

To thrive as a Cyber Risk Assessor, you need a strong understanding of cybersecurity principles, risk management frameworks, and relevant regulations, often backed by a degree in information security or related certifications like CISSP or CISA. Familiarity with security assessment tools, vulnerability scanners, and risk analysis platforms is typically required. Analytical thinking, attention to detail, and effective communication are vital soft skills for accurately identifying threats and conveying risks to stakeholders. These skills and qualities are crucial for protecting organizational assets and ensuring compliance in an evolving threat landscape.

What are some common challenges faced by professionals in cyber risk assessment, and how can they be addressed?

Professionals in Cyber Risk Assessment often encounter challenges such as rapidly evolving threat landscapes, keeping up with regulatory changes, and ensuring clear communication of technical risks to non-technical stakeholders. To address these, staying current with industry trends through continuous learning, leveraging robust risk assessment frameworks, and developing strong communication skills are essential. Additionally, collaborating closely with IT, compliance, and business units helps ensure comprehensive and effective risk management.

What is the difference between Cyber Risk Assessment vs Cyber Security Analyst?

AspectCyber Risk AssessmentCyber Security Analyst
Primary FocusIdentifying and evaluating cybersecurity risks and vulnerabilitiesMonitoring, detecting, and responding to security threats
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentRisk management teams, consulting firms, security departmentsSecurity operations centers, IT departments, incident response teams
ResponsibilitiesRisk analysis, vulnerability assessments, complianceThreat detection, incident response, security monitoring

While both roles involve cybersecurity, Cyber Risk Assessments focus on evaluating potential risks and vulnerabilities to inform security strategies, whereas Cyber Security Analysts actively monitor and respond to ongoing security threats. Understanding these differences helps organizations assign the right roles for comprehensive cybersecurity management.

What are popular job titles related to Cyber Risk Assessment jobs in Pennsylvania?

For Cyber Risk Assessment jobs in Pennsylvania, the most frequently searched job titles are:

What job categories do people searching Cyber Risk Assessment jobs in Pennsylvania look for?

The top searched job categories for Cyber Risk Assessment jobs in Pennsylvania are:

What cities in Pennsylvania are hiring for Cyber Risk Assessment jobs?

Cities in Pennsylvania with the most Cyber Risk Assessment job openings:

Infographic showing various Cyber Risk Assessment job openings in Pennsylvania as of August 2026, with employment types broken down into 1% As Needed, 85% Full Time, 11% Part Time, 2% Contract, and 1% Nights. Highlights an 86% Physical, 5% Hybrid, and 9% Remote job distribution.

Technical Manager - Cyber Risk Management

Pittsburgh, PA โ€ข On-site

Cmu
Offices of Mental Health Practitionersย โ€ขย 201 - 500 employees

Full-time

This job post hasย expired 4 days ago.ย Applications are no longer accepted.


Job description

The SEI CERT Cyber Risk and Resilience Directorate, enables organizations to achieve operational resilience by performing research in emerging areas of operational risk, producing measurement and assessment tools that help organizations better understand their current risk and resilience posture, and developing and validating models, frameworks, and tools to drive quantifiable risk reduction. Our Cyber Risk Management team focuses on designing, prototyping, transitioning risk management novel methods. We support partners in government and industry in achieving cyber-dependent missions. .


Job Description Summary

The individual in this position will work as a technical manager of the Cyber Risk Management (CRM) Team within CERT's Cyber Risk & Resilience Directorate. This candidate will be responsible for the creation, development and management of a sustained applied research and technical agenda for Risk & Resilience CRM Team consistent with and directly supporting the US Department of War's strategic challenges and emerging threats. The technical manager is responsible for developing and communicating technical vision, developing tasking, creating project work statements, developing and managing project plans, managing initiative finances and accounting, generating new work and customers, working with business development staff, executing work with high degree of customer satisfaction, and supervising staff.

The successful candidate must have proven experience conducting and leading technical efforts in support of the US Federal Government (USG) and Department of War (DOW); managing technical teams; be self-directed, have a track record of creating interdisciplinary approaches to problem solving, and demonstrate exceptionally strong presentation and writing skills. The candidate must also be able to interact with clients and staff of all levels in a highly professional and competent manner.

Minimum Qualifications and Requirements

Education/Training:

BS in risk management, cybersecurity, information systems, economics, mathematics or a related technical field; advanced degree strongly preferred.

Other educational backgrounds of a technical nature with significant relevant experience as described may be considered.


Experience:
Total of ten (10) years of experience as an enterprise risk executive, enterprise risk manager, primary investigator engaged in risk management research or similarly technical occupation.

Experience and expert knowledge of:
risk quantification tools and techniques
risk management frameworks/model/standards of practice
risk governance

Experience with and substantial knowledge of:

network architectures, and telecommunications

cybersecurity and operational resilience

information security models, frameworks, and metrics

foundational artificial intelligence concepts and techniques

project planning and financial management

strategic planning and product development

USG and DoW risk tools, techniques, and methods

USG and DoW risk management strategies, policies, and directives


Skills/Abilities:
mastery of risk management concepts, cyber security best practices and standards, information security and risk evaluation methods, development

excellent analytical, organizational, reasoning and problem-solving skills

outstanding written and oral communication skills

demonstrated ability and experience in employee performance management

outstanding financial and resource management skills

demonstrated ability to prepare papers and deliver presentations for technical and non-technical audiences

demonstrated experience in developing a strategic plan and associated technical agenda

demonstrated experience in developing products and transition (go-to-market)

ability to interact effectively with diverse constituencies internally and externally, including senior executives and managers in government and industry

ability to recognize and deal appropriately with confidential and sensitive information, and where appropriate, ability to obtain and hold a security clearance

active involvement in professional societies

Preferred Qualifications:

RIMS-Certified Risk Management Professional (preferred)

Certified Enterprise Risk Manager (preferred)

Certified Information Systems Security Professional (preferred)

Certified Information Security Manager (preferred)

Certified Information Systems Auditor (preferred)

Other: You will be subject to a background investigation, and you must have the ability to obtain and maintain a Department of War security clearance.

Location

Pittsburgh, PA

Job Function

Software/Applications Development/Engineering

Position Type

Staff - Regular

Full time/Part time

Full time

Pay Basis

SalaryMore Information:
  • Please visit "Why Carnegie Mellon" to learn more about becoming part of an institution inspiring innovations that change the world.

  • Click here to view a listing of employee benefits

  • Carnegie Mellon University is an Equal Opportunity Employer/Disability/Veteran.

  • Statement of Assurance


CMU logo

About CMU

Sourced by ZipRecruiter

Industry

Offices of mental health practitioners

Company size

201 - 500 Employees

Headquarters location

Harrisburg, PA, US