1

Cyber Security Risk Analyst Jobs in Philadelphia, PA

The Global GRC Senior Analyst will report directly to the Global Cybersecurity Governance, Risk and Compliance Manager. This role involves collaborating with cross-functional teams to design ...

Cybersecurity Analyst II Category: Cyber Security Main location: United States, Pennsylvania ... Exposure to Risk Management Framework (RMF) Step 3-6 activities, including POA&M management and ...

Cyber Security Senior Risk Advisor

Philadelphia, PA · On-site

$100K - $130K/yr

Workwith clients both internally and externally to help them understand cybersecurity risks and how ... Driveinnovation as a differentiator by leveraging of digital technologies anddata analytics * Multi ...

Senior Cybersecurity Engineer

Philadelphia, PA · On-site +1

$115K - $158K/yr

Assess cybersecurity risk across software, cloud, infrastructure, vulnerability management, and ... and risk reduction. * Analyze security telemetry, scan results, and large data sets to identify ...

Senior Cybersecurity Engineer

Philadelphia, PA · On-site +1

$115K - $158K/yr

Assess cybersecurity risk across software, cloud, infrastructure, vulnerability management, and ... and risk reduction. * Analyze security telemetry, scan results, and large data sets to identify ...

Workwith clients both internally and externally to help them understand cybersecurity risks and how ... Effective written and verbal communication skills andorganizational and analytical skills ...

next page

Showing results 1-20

Cyber Security Risk Analyst information

See Philadelphia, PA salary details

$43.4K

$100.3K

$151.4K

How much do cyber security risk analyst jobs pay per year?

As of Aug 8, 2026, the average yearly pay for cyber security risk analyst in Philadelphia, PA is $100,303.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,200.00 and $116,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the cyber security risk analyst position, and why are they important?

A Cyber Security Risk Analyst requires a solid understanding of information security principles, risk assessment methodologies, and a relevant degree such as computer science or cybersecurity. Familiarity with tools like risk management frameworks (NIST, ISO 27001), vulnerability scanners, and certifications such as CISSP, CISM, or CRISC is common in this role. Strong analytical thinking, attention to detail, effective communication, and problem-solving skills are vital soft skills. These competencies enable analysts to accurately identify, assess, and communicate cyber risks, protecting organizations from evolving threats.

What is a cyber security risk analyst?

A Cyber Security Risk Analyst is responsible for identifying, assessing, and mitigating cybersecurity risks within an organization. They analyze potential threats, evaluate security controls, and recommend improvements to protect sensitive data and systems. Their role often involves conducting risk assessments, ensuring compliance with industry regulations, and collaborating with IT and security teams to enhance defenses. They also monitor emerging threats and provide strategic insights to minimize vulnerabilities. Ultimately, they help organizations maintain a strong security posture against cyber threats.

What are some typical challenges faced by cyber security risk analysts on the job?

Cyber Security Risk Analysts commonly face the challenge of keeping up with constantly evolving threats and technology landscapes. They must balance the need for robust security with business objectives, often requiring nuanced decision-making and collaboration across departments. Analysts may also encounter difficulties in communicating complex technical risks to non-technical stakeholders. Successfully navigating these challenges is key to maintaining organizational security and fostering a culture of risk awareness.

What does a cybersecurity risk analyst do?

A cybersecurity risk analyst evaluates an organization’s security posture by identifying vulnerabilities, assessing potential threats, and analyzing risks to information systems. They develop strategies to mitigate risks, often using tools like risk assessment frameworks and security audits, and may hold certifications such as CISSP or CISA. Their work helps organizations protect sensitive data and ensure compliance with security standards.

How much does a cyber security risk analyst make?

The average salary for a cyber security risk analyst is around $80,000 to $110,000 per year, depending on experience, certifications, and location. Entry-level positions typically start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries. The role often requires knowledge of risk assessment tools and security frameworks.
What are the most commonly searched types of Cyber Security Risk Analyst jobs in Philadelphia, PA? The most popular types of Cyber Security Risk Analyst jobs in Philadelphia, PA are:
What job categories do people searching Cyber Security Risk Analyst jobs in Philadelphia, PA look for? The top searched job categories for Cyber Security Risk Analyst jobs in Philadelphia, PA are:
What cities near Philadelphia, PA are hiring for Cyber Security Risk Analyst jobs? Cities near Philadelphia, PA with the most Cyber Security Risk Analyst job openings:
Infographic showing various Cyber Security Risk Analyst job openings in Philadelphia, PA as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $100,303 per year, or $48.2 per hour.

Cybersecurity Risk Management Analyst

Chubb

Philadelphia, PA • On-site

Full-time

Posted 2 days ago

New


Chubb rating

8.2

Company rating: 8.2 out of 10

Based on 66 frontline employees who took The Breakroom Quiz

141st of 303 rated insurance


Job description

As a Cybersecurity Risk Analyst on our Cyber GRC Engineering team, you will apply engineering, automation, and data analytics principles to strengthen governance, risk, and compliance across Chubb's cybersecurity environment. You will serve as a hands-on platform specialist for ServiceNow IRM, helping optimize and enhance the GRC ecosystem so it continues to meet Chubb's evolving cybersecurity analytics, compliance, and risk management needs. In this role, you will connect data, controls, and risk signals to drive deeper risk analysis, proactively identify potential issues before risk is realized, and support executive reporting on application security exposure and broader cybersecurity risk. You will also play a key role in managing the platform, including how data is reviewed, how workflows are executed, and how AI capabilities are leveraged within the platform to improve automation, insight generation, and operational efficiency.

In this role, you will:

  • Design and implement automated control testing workflows in partnership with the Cyber Risk & Assurance Manager, including detailed automation playbooks for compliance and control testing
  • Own and enhance ServiceNow IRM workflows, including issue and exception management, automated ticketing, and compliance tracking
  • Implement and maintain automated risk scoring and InfoSec criticality rating calculations based on methodology defined by the Cyber Risk Assessment team, while ensuring the logic remains aligned as the methodology evolves
  • Build and maintain custom workflows, connectors, and integrations within ServiceNow IRM to support expanding GRC Engineering use cases
  • Analyze control, risk, and exception data to identify trends, validate potential gaps, and surface issues that require remediation before they become realized risk
  • Support executive reporting by translating technical findings into clear, actionable insight on application security risk and broader cybersecurity exposure
  • Help optimize the GRC platform through automation, AI-enabled capabilities, and workflow improvements that strengthen Chubb's cybersecurity analytics and risk management posture
  • Partner cross-functionally to ensure the platform ecosystem continues to support Chubb's broader technical environment and evolving security requirements
Chubb is a world leader in insurance. With operations in 54 countries, Chubb provides commercial and personal property and casualty insurance, personal accident and supplemental health insurance, reinsurance, and life insurance to a diverse group of clients. The company is distinguished by its extensive product and service offerings, broad distribution capabilities, exceptional financial strength, underwriting excellence, superior claims handling expertise and local operations globally.

At Chubb, we are committed to equal employment opportunity and compliance with all laws and regulations pertaining to it. Our policy is to provide employment, training, compensation, promotion, and other conditions or opportunities of employment, without regard to race, color, religious creed, sex, gender, gender identity, gender expression, sexual orientation, marital status, national origin, ancestry, mental and physical disability, medical condition, genetic information, military and veteran status, age, and pregnancy or any other characteristic protected by law. Performance and qualifications are the only basis upon which we hire, assign, promote, compensate, develop and retain employees. Chubb prohibits all unlawful discrimination, harassment and retaliation against any individual who reports discrimination or harassment.
  • A minimum of 5 years of experience in GRC technology, IT automation, or security platform engineering
  • Hands-on ServiceNow development experience, with strong preference for the IRM module; experience with other GRC modules and/or platforms is also acceptable
  • Demonstrated Python scripting experience in a production or automation environment
  • Experience supporting cyber risk, compliance, or audit functions
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent practical experience
  • ServiceNow certification, such as CIS-IRM or equivalent, is a plus
  • Experience with API and integration development for platform connectors is a plus
  • Familiarity with insurance or financial services risk and compliance environments is a plus

What Chubb employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Chubb logo

About Chubb

Sourced by ZipRecruiter

Chubb is the world's largest publicly traded property and casualty insurer. With operations in 54 countries, Chubb provides commercial and personal property and casualty insurance, personal accident and supplemental health insurance, reinsurance and life insurance to a diverse group of clients. We are a unique global organization with a culture of individuals passionately committed to our respective crafts. With underwriting at our core, each of us contributes to providing the best insurance coverage and service to our clients. Our highly collaborative, inclusive nature helps us drive better business outcomes through diversity of background, experiences, insights and values.

Industry

Insurance services

Company size

10,000+ Employees

Headquarters location

Warren, NJ, US