Bachelor's degree in cybersecurity, information technology, information systems, computer science, risk management, business, mathematics, decision sciences, or a related field, or an equivalent ...
Bachelor's degree in cybersecurity, information technology, information systems, computer science, risk management, business, mathematics, decision sciences, or a related field, or an equivalent ...
Bachelor's degree in cybersecurity, information technology, information systems, computer science, risk management, business, mathematics, decision sciences, or a related field, or an equivalent ...
Bachelor's degree in cybersecurity, information technology, information systems, computer science, risk management, business, mathematics, decision sciences, or a related field, or an equivalent ...
... cybersecurity risk management program, including efforts that strengthen employee security ... awareness and risk-informed decision-making. The Intermediate level performs routine to moderately ...
... cybersecurity risk management program, including efforts that strengthen employee security ... awareness and risk-informed decision-making. The Intermediate level performs routine to moderately ...
... cybersecurity risk management program, including efforts that strengthen employee security ... awareness and risk-informed decision-making. The Intermediate level performs routine to moderately ...
... cybersecurity risk management program, including efforts that strengthen employee security ... awareness and risk-informed decision-making. The Intermediate level performs routine to moderately ...
Cybersecurity Specialist
Pittsburgh, PA · On-site
Ensure cybersecurity activities comply with applicable DOE/NNSA requirements, Federal requirements, and local Cyber Security Risk Management Program guidance. * Develop, maintain, and implement ...
Quick apply
Cybersecurity Specialist
Pittsburgh, PA · On-site
Ensure cybersecurity activities comply with applicable DOE/NNSA requirements, Federal requirements, and local Cyber Security Risk Management Program guidance. * Develop, maintain, and implement ...
Digital Risk Advisory & Cybersecurity Associate Attorney
Philadelphia, PA · On-site
$245K - $345K/yr
Counsel clients on privacy, cybersecurity, regulatory compliance, and enterprise risk management matters. * Conduct cybersecurity risk assessments and assist clients in strengthening cybersecurity ...
Quick apply
Digital Risk Advisory & Cybersecurity Associate Attorney
Philadelphia, PA · On-site
$245K - $345K/yr
Counsel clients on privacy, cybersecurity, regulatory compliance, and enterprise risk management matters. * Conduct cybersecurity risk assessments and assist clients in strengthening cybersecurity ...
$106K - $143K/yr
Establish and maintain an enterprise cyber risk management program, including risk assessments, mitigation strategies, and reporting on cybersecurity risks and trends. * Ensure compliance with ...
$106K - $143K/yr
Establish and maintain an enterprise cyber risk management program, including risk assessments, mitigation strategies, and reporting on cybersecurity risks and trends. * Ensure compliance with ...
Cybersecurity & Risk Services (CRS) Director - For Energy Sector
Dallas, PA · On-site
$200K - $280K/yr
Manage Presales Consulting, Architect Solutions according to the customer demands * Responsible for revenue management for the allocated region / accounts * Create Business Development Plans for ...
Cybersecurity & Risk Services (CRS) Director - For Energy Sector
Dallas, PA · On-site
$200K - $280K/yr
Manage Presales Consulting, Architect Solutions according to the customer demands * Responsible for revenue management for the allocated region / accounts * Create Business Development Plans for ...
Senior Cybersecurity GRC Analyst
King Of Prussia, PA · On-site
$80K - $105K/yr
This individual will partner with Information Technology, Legal, Enterprise Risk Management, Human Resources, and business stakeholders to drive compliance, governance, and cybersecurity risk ...
Senior Cybersecurity GRC Analyst
King Of Prussia, PA · On-site
$80K - $105K/yr
This individual will partner with Information Technology, Legal, Enterprise Risk Management, Human Resources, and business stakeholders to drive compliance, governance, and cybersecurity risk ...
Lead Cybersecurity Engineer
Paxtonia, PA · On-site
This position balances security risk management with business enablement and drives continuous ... Execute cybersecurity engineering strategies, roadmaps, and priorities aligned with business ...
Lead Cybersecurity Engineer
Paxtonia, PA · On-site
This position balances security risk management with business enablement and drives continuous ... Execute cybersecurity engineering strategies, roadmaps, and priorities aligned with business ...
... Risk Management Program guidelines. • Develop and maintain cybersecurity policies, procedures, security plans, and long-range strategies. • Conduct and lead cybersecurity audits, compliance ...
... Risk Management Program guidelines. • Develop and maintain cybersecurity policies, procedures, security plans, and long-range strategies. • Conduct and lead cybersecurity audits, compliance ...
Sr. Cybersecurity Regulatory Compliance Analyst (OT/SCADA)
Denver, PA · On-site
$96K - $123K/yr
Risk Management: * Responsible for tracking all activities (i.e., Tabletop exercises, Cybersecurity Architecture Design Reviews, TSA Cybersecurity Action Plan, the Biennial cybersecurity audit ,etc ...
Sr. Cybersecurity Regulatory Compliance Analyst (OT/SCADA)
Denver, PA · On-site
$96K - $123K/yr
Risk Management: * Responsible for tracking all activities (i.e., Tabletop exercises, Cybersecurity Architecture Design Reviews, TSA Cybersecurity Action Plan, the Biennial cybersecurity audit ,etc ...
Risk Management: * Responsible for tracking all activities (i.e., Tabletop exercises, Cybersecurity Architecture Design Reviews, TSA Cybersecurity Action Plan, the Biennial cybersecurity audit ,etc ...
Risk Management: * Responsible for tracking all activities (i.e., Tabletop exercises, Cybersecurity Architecture Design Reviews, TSA Cybersecurity Action Plan, the Biennial cybersecurity audit ,etc ...
Cyber Compliance Manager (Financial Services)
Blue Bell, PA · On-site
$106K - $143K/yr
Cybersecurity risk management * Third party vendor management * Interactions with consumers / individuals (data subject requests) * Incident management and breach notifications * Bachelor's degree in ...
Cyber Compliance Manager (Financial Services)
Blue Bell, PA · On-site
$106K - $143K/yr
Cybersecurity risk management * Third party vendor management * Interactions with consumers / individuals (data subject requests) * Incident management and breach notifications * Bachelor's degree in ...
Cyber Compliance Manager (Financial Services)
Philadelphia, PA · On-site
$112K - $151K/yr
Cybersecurity risk management * Third party vendor management * Interactions with consumers / individuals (data subject requests) * Incident management and breach notifications * Bachelor's degree in ...
Cyber Compliance Manager (Financial Services)
Philadelphia, PA · On-site
$112K - $151K/yr
Cybersecurity risk management * Third party vendor management * Interactions with consumers / individuals (data subject requests) * Incident management and breach notifications * Bachelor's degree in ...
This is a highly collaborative, advisory-focused role that combines cybersecurity architecture, risk management, governance, and stakeholder engagement across both Information Technology (IT) and ...
This is a highly collaborative, advisory-focused role that combines cybersecurity architecture, risk management, governance, and stakeholder engagement across both Information Technology (IT) and ...
Senior DevSecOps Cybersecurity Engineer Belong. Connect. Grow. with KBR! KBR's National Security ... Support Risk Management Framework (RMF) activities across development, test, staging, and ...
Senior DevSecOps Cybersecurity Engineer Belong. Connect. Grow. with KBR! KBR's National Security ... Support Risk Management Framework (RMF) activities across development, test, staging, and ...
Senior Manager Product Cybersecurity COE
Pittsburgh, PA · On-site
$122K - $162K/yr
This role provides strategic and people leadership to embed cybersecurity requirements, risk management, and governance throughout the product lifecycle. The Senior Manager partners with various ...
Senior Manager Product Cybersecurity COE
Pittsburgh, PA · On-site
$122K - $162K/yr
This role provides strategic and people leadership to embed cybersecurity requirements, risk management, and governance throughout the product lifecycle. The Senior Manager partners with various ...
Work closely with client executives and management teams to understand their businesses and assist ... risk across a wide range of areas, including cybersecurity, IT strategy and governance, IT ...
Work closely with client executives and management teams to understand their businesses and assist ... risk across a wide range of areas, including cybersecurity, IT strategy and governance, IT ...
Information System Security Manager (ISSM) - Contingent Upon Contract Award
Philadelphia, PA · On-site
$123K - $187K/yr
Cybersecurity Program & Risk Management * Support information security goals and initiatives that reduce organizational cybersecurity risk. * Coordinate cybersecurity activities and communicate ...
Quick apply
Information System Security Manager (ISSM) - Contingent Upon Contract Award
Philadelphia, PA · On-site
$123K - $187K/yr
Cybersecurity Program & Risk Management * Support information security goals and initiatives that reduce organizational cybersecurity risk. * Coordinate cybersecurity activities and communicate ...
Cyber Security Risk Management information
See Pennsylvania salary details
$57.1K - $68.9K
1% of jobs
$68.9K - $80.6K
4% of jobs
$80.6K - $92.4K
5% of jobs
$92.4K - $104.2K
9% of jobs
$110.6K is the 25th percentile. Wages below this are outliers.
$104.2K - $115.9K
11% of jobs
$115.9K - $127.7K
10% of jobs
The median wage is $132.2K / yr.
$127.7K - $139.4K
28% of jobs
$146.2K is the 75th percentile. Wages above this are outliers.
$139.4K - $151.2K
14% of jobs
$151.2K - $162.9K
11% of jobs
$162.9K - $174.7K
4% of jobs
$174.7K - $186.4K
4% of jobs
$57.1K
$133.3K
$186.4K
How much do cyber security risk management jobs pay per year?
What is cyber security risk management?
What are the key skills and qualifications needed to thrive in cyber security risk management?
What are some typical challenges faced in cyber security risk management, and how can they be addressed?
What is the difference between Cyber Security Risk Management vs Cyber Security Analyst?
| Aspect | Cyber Security Risk Management | Cyber Security Analyst |
|---|---|---|
| Certifications | CompTIA Security+, CISSP, CISM | CompTIA Security+, CEH, CISSP (preferred) |
| Work Environment | Policy development, risk assessment, strategic planning | Monitoring security systems, incident response, vulnerability analysis |
| Employer & Industry Usage | Organizations focusing on risk mitigation and compliance | Organizations implementing and maintaining security measures |
Cyber Security Risk Management professionals focus on identifying, assessing, and mitigating security risks at an organizational level, often involved in policy and strategy. Cyber Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the same industry, their core responsibilities differ: risk managers develop strategies, whereas analysts execute security measures and respond to threats.
What does a cyber security risk management do?
What are popular job titles related to Cyber Security Risk Management jobs in Pennsylvania?
For Cyber Security Risk Management jobs in Pennsylvania, the most frequently searched job titles are:
What job categories do people searching Cyber Security Risk Management jobs in Pennsylvania look for?
The top searched job categories for Cyber Security Risk Management jobs in Pennsylvania are:
What cities in Pennsylvania are hiring for Cyber Security Risk Management jobs?
Cities in Pennsylvania with the most Cyber Security Risk Management job openings:

Cybersecurity Risk Management Consultant
Philadelphia, PA • On-site
Full-time
Posted 5 days ago
Deloitte rating
8.2
Based on 93 frontline employees who took The Breakroom Quiz
Job description
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.
Work You'll Do
As a US Delivery Center Delivery Senior Consultant, Software Engineering Solutions on the team, you will:
- Advise Government & Public Services clients in executing the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) lifecycle to mitigate cyber risk and threats
- Advise federal agency clients on cyber risk posture and RMF compliance strategies aligned to FISMA, NIST, and agency-specific requirements
- Lead the development and/or review of Authority to Operate (ATO) packages (e.g., System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action & Milestones (POA&Ms))
- Assess or develop an organization's cyber risk strategy as it relates to data risk, cyber risk management, risk frameworks and policies, and risk measures and reporting
- Strategically drive the development and execution of risk assessments and mitigation plans to enhance the client's ability to identify, evaluate, prioritize, and mitigate risks
- Implement risk management solutions aligned to the client's vision and strategic priorities
- Drive development and implementation of cyber strategies grounded in leading practices, industry frameworks, and targeted to the client's risk and business needs
- Synthesize technical findings and risk data into actionable reports and executive-level briefings
- Develop impactful presentations that support engagement goals, communicate technical findings clearly to both technical and executive audiences
- Deliver key messages with clarity and confidence; tailor communication style to the audience
- Understand how business functions operate and how industry trends impact a client's cyber posture and risk profile
- Identify and evaluate complex business and technology risks, and connect findings to business impact
- Provide guidance and quality review to junior team members on RMF documentation, assessment artifacts, and deliverable development
- Participate in team problem-solving efforts and offer ideas to address client challenges
- Identify opportunities for efficiencies in work processes and innovative approaches to completing scope of work
- Own assigned work products through final review, client submission, and resolution of quality-review comments
- Assist in proposal development, as requested
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The Team
Deloitte's Government & Public Services (GPS) practice - our people, ideas, technology and outcomes - is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.
Our Cyber Strategy & Transformation offering develops and transforms cyber programs in line with a client's strategic objectives, regulatory requirements, and risk appetite. It keeps the enterprise a step ahead of the evolving threat landscape and gives stakeholders confidence in the organization's cyber posture. Includes design of the cyber organization, governance, and risk assessments.
This opportunity sits within our Deloitte US Delivery Center model, which is dedicated to driving impactful business services. It leverages Deloitte's scale and talent, as well as a center delivery model to provide high-quality, cost-effective service with standardized processes and procedures to service businesses across Deloitte.
The Deloitte US Delivery Center has a small-business feel with a big-business impact. With the resources of Deloitte and a community feel, the delivery center model provides high-quality services to our clients. USDC professionals work out of one of our specific delivery center locations, and each location presents dynamic career opportunities for professionals to focus on their work with nominal travel requirements.
Qualifications
Required:
- Bachelor's degree in cybersecurity, information technology, information systems, computer science, risk management, business, mathematics, decision sciences, or a related field, or an equivalent combination of education, professional training, and relevant cybersecurity experience in accordance with applicable talent policies.
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future
- 4+ years of professional experience in cybersecurity, information assurance, governance, risk and compliance, cybersecurity risk management, or federal security compliance, including at least 2 years supporting NIST RMF or an equivalent authorization process including participation in at least one end-to-end authorization cycle or multiple lifecycle phases across two or more systems.
- 2+ years of experience applying NIST RMF concepts and NIST SP 800-37 to information-system authorization, security assessment, or continuous-monitoring activities, including 1+ year applying NIST SP 800-53 controls. Experience with the NIST CSF, FedRAMP, or agency-specific security requirements is preferred.
- 2+ years of experience implementing, documenting, assessing, or managing NIST SP 800-53 security controls, including at least 1 year preparing control narratives, reviewing implementation evidence, documenting assessment results, or tracking remediation activities.
- 2+ years of experience developing, updating, or quality-reviewing cybersecurity policies, procedures, standards, or implementation guidance mapped to NIST SP 800-53 controls or an equivalent federal security baseline, including experience supporting at least one moderate-impact information system.
- At least 2 years of experience in RMF documentation and control implementation, plus at least 1 year in three of the following: system categorization, boundary definition, control tailoring, continuous monitoring, risk assessment, vulnerability management, or GRC tool administration.
- Ability to obtain and maintain the level of federal security clearance or Public Trust designation required for client engagements
- Delivery Center Location & Travel Requirements:
- Hybrid Work Model: Operate under a hybrid system requiring residence within a commutable distance to one of the US Delivery Center locations (Gilbert, Lake Mary, or Mechanicsburg) or Geo-Hub locations (Atlanta, Charlotte, Dallas, Houston, and Philadelphia)
- Co-location Expectation: Spend up to 30% of working time co-located at an assigned office for orchestrated opportunities, including projects, practice sessions, training, and Moments That Matter at a Deloitte Delivery Center location, Geo-Hub location, approved site, or project location
- Travel Requirement: Maximum of 10% overnight travel for client or project purposes
- Relocation Requirement: If relocation is necessary, complete the move within 12 weeks from the start date to reside within a commutable distance
Preferred:
- Previous federal or government consulting experience
- 1+ year applying NIST SP 800-171, CMMC, or equivalent controlled-unclassified-information security requirements.
- 1+ year of experience analyzing or documenting enterprise, mission-critical, cloud, or multi-system technology environments, including business processes, system dependencies, data flows, security vulnerabilities, or operational risks.
- 1+ year of experience supporting a FedRAMP authorization, cloud security assessment, or RMF activity for AWS GovCloud, Azure Government, or an equivalent federal cloud environment.
- 1+ year of experience delivering cybersecurity or RMF work in an Agile, hybrid-Agile, or iterative federal program environment, including sprint planning, backlog management, or incremental deliverable reviews.
- 2+ years of experience in at least one technical domain relevant to RMF, such as security architecture, network security, cloud infrastructure, identity and access management, endpoint security, or vulnerability management.
- CISSP, CISM, CISA, or CEH certification
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.
Work You'll Do
As a US Delivery Center Delivery Senior Consultant, Software Engineering Solutions on the team, you will:
- Advise Government & Public Services clients in executing the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) lifecycle to mitigate cyber risk and threats
- Advise federal agency clients on cyber risk posture and RMF compliance strategies aligned to FISMA, NIST, and agency-specific requirements
- Lead the development and/or review of Authority to Operate (ATO) packages (e.g., System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action & Milestones (POA&Ms))
- Assess or develop an organization's cyber risk strategy as it relates to data risk, cyber risk management, risk frameworks and policies, and risk measures and reporting
- Strategically drive the development and execution of risk assessments and mitigation plans to enhance the client's ability to identify, evaluate, prioritize, and mitigate risks
- Implement risk management solutions aligned to the client's vision and strategic priorities
- Drive development and implementation of cyber strategies grounded in leading practices, industry frameworks, and targeted to the client's risk and business needs
- Synthesize technical findings and risk data into actionable reports and executive-level briefings
- Develop impactful presentations that support engagement goals, communicate technical findings clearly to both technical and executive audiences
- Deliver key messages with clarity and confidence; tailor communication style to the audience
- Understand how business functions operate and how industry trends impact a client's cyber posture and risk profile
- Identify and evaluate complex business and technology risks, and connect findings to business impact
- Provide guidance and quality review to junior team members on RMF documentation, assessment artifacts, and deliverable development
- Participate in team problem-solving efforts and offer ideas to address client challenges
- Identify opportunities for efficiencies in work processes and innovative approaches to completing scope of work
- Own assigned work products through final review, client submission, and resolution of quality-review comments
- Assist in proposal development, as requested
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The Team
Deloitte's Government & Public Services (GPS) practice - our people, ideas, technology and outcomes - is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.
Our Cyber Strategy & Transformation offering develops and transforms cyber programs in line with a client's strategic objectives, regulatory requirements, and risk appetite. It keeps the enterprise a step ahead of the evolving threat landscape and gives stakeholders confidence in the organization's cyber posture. Includes design of the cyber organization, governance, and risk assessments.
This opportunity sits within our Deloitte US Delivery Center model, which is dedicated to driving impactful business services. It leverages Deloitte's scale and talent, as well as a center delivery model to provide high-quality, cost-effective service with standardized processes and procedures to service businesses across Deloitte.
The Deloitte US Delivery Center has a small-business feel with a big-business impact. With the resources of Deloitte and a community feel, the delivery center model provides high-quality services to our clients. USDC professionals work out of one of our specific delivery center locations, and each location presents dynamic career opportunities for professionals to focus on their work with nominal travel requirements.
Qualifications
Required:
- Bachelor's degree in cybersecurity, information technology, information systems, computer science, risk management, business, mathematics, decision sciences, or a related field, or an equivalent combination of education, professional training, and relevant cybersecurity experience in accordance with applicable talent policies.
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the futu...
About Deloitte
Sourced by ZipRecruiter
Industry
Finance and insurance and business management consulting
Company size
10,000+ Employees
Headquarters location
Orlando, FL, US