1

Cyber Security Risk Analyst Jobs in Pennsylvania

System Cybersecurity Architect

Pittsburgh, PA ยท On-site

$225K/yr

Experience performing vulnerability assessments and cybersecurity risk assessments. * Knowledge of ... Analytical thinking and problem-solving skills to identify and mitigate cybersecurity risks.

Cybersecurity Analyst II Category: Cyber Security Main location: United States, Pennsylvania ... Exposure to Risk Management Framework (RMF) Step 3-6 activities, including POA&M management and ...

Cyber Security Senior Risk Advisor

Philadelphia, PA ยท On-site

$100K - $130K/yr

Workwith clients both internally and externally to help them understand cybersecurity risks and how ... Driveinnovation as a differentiator by leveraging of digital technologies anddata analytics * Multi ...

Senior Cybersecurity Engineer

Philadelphia, PA ยท On-site +1

$115K - $158K/yr

Assess cybersecurity risk across software, cloud, infrastructure, vulnerability management, and ... and risk reduction. * Analyze security telemetry, scan results, and large data sets to identify ...

Senior Cybersecurity Engineer

Philadelphia, PA ยท On-site

$115K - $158K/yr

Assess cybersecurity risk across software, cloud, infrastructure, vulnerability management, and ... and risk reduction. * Analyze security telemetry, scan results, and large data sets to identify ...

Senior Cybersecurity Engineer

Philadelphia, PA ยท On-site +1

$115K - $158K/yr

Assess cybersecurity risk across software, cloud, infrastructure, vulnerability management, and ... and risk reduction. * Analyze security telemetry, scan results, and large data sets to identify ...

Showing results 21-40

Cyber Security Risk Analyst information

See Pennsylvania salary details

$43.1K

$99.6K

$150.4K

How much do cyber security risk analyst jobs pay per year?

As of Aug 21, 2026, the average yearly pay for cyber security risk analyst in Pennsylvania is $99,639.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,700.00 and $115,800.00 per year, depending on experience, location, and employer.

What is a cyber security risk analyst?

A Cyber Security Risk Analyst is responsible for identifying, assessing, and mitigating cybersecurity risks within an organization. They analyze potential threats, evaluate security controls, and recommend improvements to protect sensitive data and systems. Their role often involves conducting risk assessments, ensuring compliance with industry regulations, and collaborating with IT and security teams to enhance defenses. They also monitor emerging threats and provide strategic insights to minimize vulnerabilities. Ultimately, they help organizations maintain a strong security posture against cyber threats.

What are some typical challenges faced by cyber security risk analysts on the job?

Cyber Security Risk Analysts commonly face the challenge of keeping up with constantly evolving threats and technology landscapes. They must balance the need for robust security with business objectives, often requiring nuanced decision-making and collaboration across departments. Analysts may also encounter difficulties in communicating complex technical risks to non-technical stakeholders. Successfully navigating these challenges is key to maintaining organizational security and fostering a culture of risk awareness.

What are the key skills and qualifications needed to thrive in the cyber security risk analyst position, and why are they important?

A Cyber Security Risk Analyst requires a solid understanding of information security principles, risk assessment methodologies, and a relevant degree such as computer science or cybersecurity. Familiarity with tools like risk management frameworks (NIST, ISO 27001), vulnerability scanners, and certifications such as CISSP, CISM, or CRISC is common in this role. Strong analytical thinking, attention to detail, effective communication, and problem-solving skills are vital soft skills. These competencies enable analysts to accurately identify, assess, and communicate cyber risks, protecting organizations from evolving threats.

How much does a cyber security risk analyst make?

The average salary for a cyber security risk analyst in the United States ranges from $70,000 to $120,000 annually, depending on experience, certifications, and location. Entry-level positions typically start around $60,000, while experienced analysts with certifications like CISSP or CISA can earn over $130,000. The role often requires knowledge of risk assessment tools and security frameworks.

What are the most commonly searched types of Cyber Security Risk Analyst jobs in Pennsylvania?

The most popular types of Cyber Security Risk Analyst jobs in Pennsylvania are:

What are popular job titles related to Cyber Security Risk Analyst jobs in Pennsylvania?

For Cyber Security Risk Analyst jobs in Pennsylvania, the most frequently searched job titles are:

What job categories do people searching Cyber Security Risk Analyst jobs in Pennsylvania look for?

The top searched job categories for Cyber Security Risk Analyst jobs in Pennsylvania are:

What cities in Pennsylvania are hiring for Cyber Security Risk Analyst jobs?

Cities in Pennsylvania with the most Cyber Security Risk Analyst job openings:

Infographic showing various Cyber Security Risk Analyst job openings in Pennsylvania as of August 2026, with employment types broken down into 81% Full Time, 17% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $99,639 per year, or $47.9 per hour.

AWS Cybersecurity Engineer

GBTI Solutions Inc

Mechanicsburg, PA โ€ข On-site

Full-time

Posted 2 days ago

New


Job description

Position Summary
The Cybersecurity Expert serves as the lead technical authority for information systems security engineering, automation, and architecture. This individual designs, implements, and operationalizes automated GRC frameworks, Compliance-as-Code (CaC), Policy-as-Code (PaC), and Infrastructure-as-Code (IaC) solutions aligned with Zero Trust and DoD Cybersecurity Risk Management Construct.
Key Responsibilities
  • Serve as lead technical resource for designing, developing, implementing, and operationalizing the automated GRC framework (PWS Section 5.7).
  • Design and implement a four-layer automation architecture:
    • Infrastructure Provisioning Layer (secure IaC templates) 
    • Configuration Management Layer
    • Compliance Validation Layer (PaC / CaC)
    • Orchestration and Workflow Layer
  • Translate complex regulatory requirements (RMF, NIST SP 800-53, DISA STIGs) and architectural diagrams into functional, automated, and operational code.
  • Integrate and configure AWS-native security services (Audit Manager, Security Hub, Config, CloudTrail, CloudWatch) for continuous monitoring and automated evidence collection.
  • Support development of real-time Compliance Scoring Dashboards and RESTful APIs.
  • Participate in solution analysis and architectural reviews to ensure compliance with DoD regulations, Zero Trust principles, and DSCA policies.
  • Provide technical guidance to ISSMs, ISSOs, and other stakeholders on the security posture and operational function of automated systems.
Required Qualifications
  • Active SECRET clearance.
  • Bachelor’s degree from an accredited institution in Information Technology, Computer Science, Engineering, or related technical discipline.
  • Must possess one of the following certifications:
    • AWS Certified DevOps Engineer – Professional or AWS Certified Solutions Architect – Professional
    • AWS Certified Security – Specialty 
    • ISC² CISSP (preferably with ISSEP or ISSAP concentration)
  • Twelve (12) years of demonstrated experience in systems engineering and cybersecurity, with at least seven (7) years focused on security automation, cloud engineering, and architecture.
  • Five (5) years of experience serving as a lead technical authority on enterprise-level projects responsible for designing and implementing security solutions (not just assessing them).
  • Five (5) years of experience translating complex regulatory requirements (RMF, NIST, DISA STIGs) and architectural diagrams into functional, automated, and operational code.

Flexible work from home options available.