1

Cyber Security Risk Analyst Jobs in Lancaster, PA

Cybersecurity Senior GRC Analyst

Denver, PA

$96K - $123K/yr

Job Summary The Governance Risk & Compliance (GRC) Cybersecurity Senior Analyst plays a critical role in ensuring that UGI Utilities Inc. operates within its regulatory, legal, and compliance ...

Cybersecurity Senior GRC Analyst

Denver, PA · On-site

$96K - $123K/yr

Job Summary The Governance Risk & Compliance (GRC) Cybersecurity Senior Analyst plays a critical role in ensuring that UGI Utilities Inc. operates within its regulatory, legal, and compliance ...

The Global Cybersecurity Senior GRC Analyst plays a critical role in ensuring that the organization ... Track key risk indicators and security metrics Risk Management: Assist with conducting gap ...

... analysis • Vulnerability and Risk Management • Web proxy filtering • Good documentation and presentation skills are also necessary for this position • Familiarity with disaster recovery ...

... analysis Vulnerability and Risk Management Web proxy filtering Good documentation and presentation skills are also necessary for this position Familiarity with disaster recovery planning and test ...

... analysis Vulnerability and Risk Management Web proxy filtering Good documentation and presentation skills are also necessary for this position Familiarity with disaster recovery planning and test ...

next page

Showing results 1-20

Cyber Security Risk Analyst information

See Lancaster, PA salary details

$41.8K

$96.6K

$145.8K

How much do cyber security risk analyst jobs pay per year?

As of Jul 31, 2026, the average yearly pay for cyber security risk analyst in Lancaster, PA is $96,601.00, according to ZipRecruiter salary data. Most workers in this role earn between $77,300.00 and $112,200.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the Cyber Security Risk Analyst position, and why are they important?

A Cyber Security Risk Analyst requires a solid understanding of information security principles, risk assessment methodologies, and a relevant degree such as computer science or cybersecurity. Familiarity with tools like risk management frameworks (NIST, ISO 27001), vulnerability scanners, and certifications such as CISSP, CISM, or CRISC is common in this role. Strong analytical thinking, attention to detail, effective communication, and problem-solving skills are vital soft skills. These competencies enable analysts to accurately identify, assess, and communicate cyber risks, protecting organizations from evolving threats.

Can you make $200,000 in cyber security?

Cyber Security Risk Analysts with extensive experience, advanced certifications, and specialized skills can potentially earn $200,000 or more annually, especially in high-demand industries or senior roles. Achieving this salary often requires a combination of technical expertise, certifications like CISSP or CISA, and a strong understanding of risk management and security frameworks.

What does a cyber security risk analyst do?

A cyber security risk analyst evaluates an organization’s security posture by identifying vulnerabilities, assessing potential threats, and recommending measures to mitigate risks. They analyze security data, develop risk management strategies, and often use tools like vulnerability scanners and risk assessment frameworks to protect information systems.

What is a Cyber Security Risk Analyst job?

A Cyber Security Risk Analyst is responsible for identifying, assessing, and mitigating cybersecurity risks within an organization. They analyze potential threats, evaluate security controls, and recommend improvements to protect sensitive data and systems. Their role often involves conducting risk assessments, ensuring compliance with industry regulations, and collaborating with IT and security teams to enhance defenses. They also monitor emerging threats and provide strategic insights to minimize vulnerabilities. Ultimately, they help organizations maintain a strong security posture against cyber threats.

What are some typical challenges faced by Cyber Security Risk Analysts on the job?

Cyber Security Risk Analysts commonly face the challenge of keeping up with constantly evolving threats and technology landscapes. They must balance the need for robust security with business objectives, often requiring nuanced decision-making and collaboration across departments. Analysts may also encounter difficulties in communicating complex technical risks to non-technical stakeholders. Successfully navigating these challenges is key to maintaining organizational security and fostering a culture of risk awareness.

How much does a cybersecurity risk analyst make?

A cybersecurity risk analyst's average salary in the United States ranges from $70,000 to $120,000 annually, depending on experience, certifications, and location. Entry-level positions typically start around $60,000, while experienced analysts with certifications like CISSP or CISA can earn over $130,000. The role often requires knowledge of risk assessment tools and security frameworks.

Can you make $500,000 a year in cyber security?

Cyber Security Risk Analysts typically earn between $70,000 and $130,000 annually, depending on experience, certifications, and location. Reaching a $500,000 salary usually requires senior roles such as Chief Information Security Officer (CISO) or executive positions, which involve strategic leadership and extensive industry experience. High salaries in cybersecurity are often associated with leadership, specialized skills, and working in high-demand sectors or organizations.
What are the most commonly searched types of Cyber Security Risk Analyst jobs in Lancaster, PA? The most popular types of Cyber Security Risk Analyst jobs in Lancaster, PA are:
What are popular job titles related to Cyber Security Risk Analyst jobs in Lancaster, PA? For Cyber Security Risk Analyst jobs in Lancaster, PA, the most frequently searched job titles are:
What cities near Lancaster, PA are hiring for Cyber Security Risk Analyst jobs? Cities near Lancaster, PA with the most Cyber Security Risk Analyst job openings:
Infographic showing various Cyber Security Risk Analyst job openings in Lancaster, PA as of July 2026, with employment types broken down into 100% Full Time. Highlights an 67% In-person, and 33% Remote job distribution, with an average salary of $96,601 per year, or $46.4 per hour.

Cybersecurity Senior GRC Analyst

UGI

Denver, PA

$96K - $123K/yr

Other

Re-posted 26 days ago


Job description

Requisition Number: 28916 

At UGI Utilities, Inc. we believe in providing a superior range of energy products and services to our customers in a safe, affordable manner. As our energy needs evolve, UGI will be there providing safe and reliable service that brings warmth and comfort to our 750,000 customers in 45 counties in Pennsylvania and 1 county in Maryland.

We strive to reflect the communities we serve by attracting and retaining top talent, while maintaining a diverse workforce that embraces our culture of safety, service, and integrity. As an employee of UGI Utilities, you can expect a competitive total compensation plan and comprehensive benefits. Employees work in a collaborative environment, have upward mobility opportunities, and the ability to enjoy a true work life balance.

To learn more about UGI's workplace culture, sustainability efforts, and commitment to inclusivity, we invite you to visit our UGI Corporate sustainability page. 

Apply to UGI Utilities today to share in our mission and support countless neighbors, friends, and families in providing best-in-class products and services!

Job Summary

The Governance Risk & Compliance (GRC) Cybersecurity Senior Analyst  plays a critical role in ensuring that UGI Utilities Inc. operates within its regulatory, legal, and compliance obligations while managing risk effectively. The GRC Cybersecurity Senior Analyst  will report directly to the Global Cybersecurity Risk Manager. This role involves collaborating with cross-functional teams to design, implement, and maintain governance, risk, and compliance processes for UGI Utilities Inc. cybersecurity regulatory requirements. The ideal candidate is detail-oriented, analytical, and experienced in compliance, risk management frameworks, and governance best practices.

Key Responsibilities:

Governance:

  • Track UGI Utilities, Inc. compliance to the cybersecurity regulatory requirements (i.e., TSA, PUC, etc.)  
  • Through collaboration assist with tracking the maintenance of processes and procedure documentation that supports the compliance to regulatory requirements.
  • Assist with the review of policies and standards through collaborating with stakeholders.
  • Collaborate with stakeholders to establish and track metrics for UGI Utilities, Inc. cybersecurity regulatory governance programs.
  • Collaborate with stakeholders who monitor regulatory requirements and monitor industry developments to ensure compliance with changes.

Risk Management:

  • Responsible for tracking all activities (i.e., Tabletop exercises, Cybersecurity Architecture Design Reviews, TSA Cybersecurity Action Plan, the Biennial cybersecurity audit ,etc.) to measure regulatory compliance for required internal and external assessments related to UGI Utilities, Inc.
  • Track all gaps from internal and external assessments to completion.    

Compliance:

  • Create awareness of compliance to company policies and standards and regulatory requirements through monitoring and reporting.
  • Collaborate with IT stakeholders to monitor UGI Utilities, Inc. cybersecurity exceptions and other IT operational activities that may have gaps. 

Collaboration and Reporting:

  • Partner with IT, Legal, HR, Enterprise Risk Management and other departments to ensure alignment on risk and compliance efforts.
  • Collaborate with stakeholders to ensure they have operational metrics to monitor their compliance.
  • Collaborate with the Cybersecurity GRC team to deliver regular risk and compliance metrics for the IT senior leadership.

Qualifications:

  • Bachelor's degree in Information Security, Risk Management, Computer Science, or related field, required.
  • 4+ years of experience in GRC, risk management, or compliance roles.

Skills and Competencies:

  • Strong understanding of GRC tools and platforms (e.g., RSA Archer, ServiceNow GRC, Fusion).
  • Familiarity with risk management frameworks (e.g., NIST 800, COBIT, FAIR) and compliance standards.
  • Exceptional analytical, problem-solving, and organizational skills.
  • Strong written and verbal communication skills, with the ability to interact effectively with stakeholders at all levels.
  • Certifications such as CISA, CRISC, CISSP, CMMC, or PCI  preferred.

Key Attributes:

  • Attention to detail and ability to manage multiple priorities.
  • Proactive mindset with a focus on continuous improvement.
  • Collaborative team player who can influence without authority.

 UGI Utilities, Inc is an Equal Opportunity Employer. The Company does not discriminate on the basis of race, color, sex, national origin, disability, age, gender identity, sexual orientation, veteran status, or any other legally protected class in its practices.

Successful applicants shall be required to pass a pre-employment drug screen as a condition of employment, and if hired, shall be subject to substance abuse testing in accordance with UGI policies.

As a federal contractor that engages in safety-sensitive work, UGI cannot permit employees in certain positions to use medical marijuana, even if prescribed by an authorized physician. Similarly, applicants for such positions who are actively using medical marijuana may be denied hire on that basis.


UGI logo

About UGI

Sourced by ZipRecruiter

UGI Corporation, headquartered in King of Prussia, PA, US, is a diversified utility service company engaged in the distribution and marketing of energy products and services on an international scale. Founded in 1882, the corporation operates through its various subsidiaries in the domestic and international markets. Its repertoire of products and services includes natural gas, liquid fuels, and electricity. The company has fundamentally positioned itself as a leader in the energy industry with a commitment to safety, reliability, and exceptional service. UGI's mission revolves around leading the way in delivering reliable, safe, and efficient energy solutions for customers.

Industry

Utilities

Company size

10,000+ Employees

Headquarters location

King of Prussia, PA, US

Year founded

1882

Social media