1

Cyber Security Risk Management Jobs in Pennsylvania

Cybersecurity Engineer

Mechanicsburg, PA · On-site

$150K - $185K/yr

Lead RMF and Cybersecurity Risk Management Construct (CSRMC) activities, including system authorization, continuous monitoring, and maintenance of ATO/cATO packages.Manage and maintain eMASS records ...

Cybersecurity Engineer

Mechanicsburg, PA · On-site

$150K - $185K/yr

Lead RMF and Cybersecurity Risk Management Construct (CSRMC) activities, including system authorization, continuous monitoring, and maintenance of ATO/cATO packages. * Manage and maintain eMASS ...

Cybersecurity Engineer

Mechanicsburg, PA · On-site

$150K - $185K/yr

Lead RMF and Cybersecurity Risk Management Construct (CSRMC) activities, including system authorization, continuous monitoring, and maintenance of ATO/cATO packages. * Manage and maintain eMASS ...

Cybersecurity Senior GRC Analyst

Denver, PA

$96K - $123K/yr

Risk Management: * Responsible for tracking all activities (i.e., Tabletop exercises, Cybersecurity Architecture Design Reviews, TSA Cybersecurity Action Plan, the Biennial cybersecurity audit ,etc ...

Cybersecurity Senior GRC Analyst

Denver, PA · On-site

$96K - $123K/yr

Risk Management: * Responsible for tracking all activities (i.e., Tabletop exercises, Cybersecurity Architecture Design Reviews, TSA Cybersecurity Action Plan, the Biennial cybersecurity audit ,etc ...

Lead Cybersecurity Engineer

Paxtonia, PA · On-site

$150 - $200/hr

This position balances security risk management with business enablement and drives continuous ... Execute cybersecurity engineering strategies, roadmaps, and priorities aligned with business ...

next page

Showing results 1-20

Cyber Security Risk Management information

See Pennsylvania salary details

$57.1K

$133.3K

$186.4K

How much do cyber security risk management jobs pay per year?

As of Aug 22, 2026, the average yearly pay for cyber security risk management in Pennsylvania is $133,281.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,300.00 and $150,400.00 per year, depending on experience, location, and employer.

What is cyber security risk management?

Cyber security risk management is the process of identifying, assessing, and prioritizing risks to an organization's information systems and data. It involves evaluating potential threats and vulnerabilities, determining the likelihood and impact of these risks, and implementing measures to mitigate or manage them. Effective risk management helps organizations protect sensitive data, ensure regulatory compliance, and minimize the impact of cyber attacks. This process is ongoing and adapts to new threats and changes in technology.

What are the key skills and qualifications needed to thrive in cyber security risk management?

To thrive in Cyber Security Risk Management, you need a solid understanding of risk assessment methodologies, information security frameworks (such as ISO 27001 or NIST), and often a relevant degree or certification like CISSP or CISM. Familiarity with security tools, vulnerability assessment platforms, and risk management software is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying threats and conveying risk to stakeholders. These skills ensure that organizations can proactively manage and mitigate cyber threats, safeguarding critical assets and maintaining compliance.

What are some typical challenges faced in cyber security risk management, and how can they be addressed?

Professionals in Cyber Security Risk Management often encounter challenges such as staying updated with rapidly evolving threats, balancing security needs with business objectives, and ensuring compliance with various regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and the implementation of robust risk assessment frameworks. Collaboration with IT, legal, and business teams is essential to develop practical security policies that protect assets without hindering operations.

What is the difference between Cyber Security Risk Management vs Cyber Security Analyst?

AspectCyber Security Risk ManagementCyber Security Analyst
CertificationsCompTIA Security+, CISSP, CISMCompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentPolicy development, risk assessment, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageOrganizations focusing on risk mitigation and complianceOrganizations implementing and maintaining security measures

Cyber Security Risk Management professionals focus on identifying, assessing, and mitigating security risks at an organizational level, often involved in policy and strategy. Cyber Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the same industry, their core responsibilities differ: risk managers develop strategies, whereas analysts execute security measures and respond to threats.

What does a cyber security risk management do?

A cyber security risk management professional identifies, assesses, and prioritizes potential security threats to an organization’s information systems. They develop strategies and implement controls to mitigate risks, often using frameworks like NIST or ISO, and may conduct regular audits to ensure security measures are effective.

What are popular job titles related to Cyber Security Risk Management jobs in Pennsylvania?

For Cyber Security Risk Management jobs in Pennsylvania, the most frequently searched job titles are:

What job categories do people searching Cyber Security Risk Management jobs in Pennsylvania look for?

The top searched job categories for Cyber Security Risk Management jobs in Pennsylvania are:

What cities in Pennsylvania are hiring for Cyber Security Risk Management jobs?

Cities in Pennsylvania with the most Cyber Security Risk Management job openings:

Infographic showing various Cyber Security Risk Management job openings in Pennsylvania as of August 2026, with employment types broken down into 1% As Needed, 79% Full Time, 18% Part Time, and 2% Contract. Highlights an 84% Physical, 3% Hybrid, and 13% Remote job distribution, with an average salary of $133,281 per year, or $64.1 per hour.

Cybersecurity Engineer

ThinkTek

Mechanicsburg, PA • On-site

$150K - $185K/yr

Full-time

Medical, Dental, Vision, PTO

Posted 26 days ago


Job description

Cybersecurity Engineer (Secret Clearance)Who We Are:ThinkTek LLC is a fast-growing Certified SBA 8(a) and Service-Disabled Veteran-Owned Small Business (SDVOSB) company. We specialize in providing management and technology consulting services to support the business and technology modernization efforts of the Federal Government. ThinkTek was formed with the specific purpose of providing its clients a tailored solution around Program & Project Management, Strategic Planning, and IT Operations.Position OverviewWe are seeking an experienced Cybersecurity Engineer to support a Federal Government customer by providing advanced cybersecurity engineering, assessment, and compliance support. This position serves as a senior cybersecurity practitioner responsible for implementing and assessing security controls, maintaining system authorization packages, conducting security assessments, and supporting risk-based authorization decisions across a portfolio of mission-critical systems.The Cybersecurity Engineer will work across traditional, cloud-native, and SaaS environments, supporting the Risk Management Framework (RMF), Cybersecurity Risk Management Construct (CSRMC), Continuous Authorization to Operate (cATO), and Zero Trust initiatives. The role requires deep expertise in cybersecurity engineering, security compliance automation, cloud security, vulnerability analysis, risk assessment, and governance, risk, and compliance (GRC) processes.This position requires a highly skilled cybersecurity professional with strong technical expertise, project management experience, and an active Secret security clearance.ResponsibilitiesServe as the lead cybersecurity engineer and Information System Security Officer (ISSO) supporting a portfolio of DSCA mission systems across on-premises, cloud, and SaaS environments.Lead RMF and Cybersecurity Risk Management Construct (CSRMC) activities, including system authorization, continuous monitoring, and maintenance of ATO/cATO packages.Manage and maintain eMASS records, authorization artifacts, control implementation evidence, and Plans of Action & Milestones (POA&Ms).Assess and validate NIST 800-53, DoD RMF, DISA STIG, FedRAMP, and DoD Cloud Computing Security Requirements Guide (CC SRG) security controls.Conduct security control assessments and independent validations to evaluate control effectiveness and support risk-informed authorization decisions.Develop Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), and authorization recommendation memorandums.Analyze vulnerabilities, security findings, automated scan results, and threat data to assess mission impact and prioritize remediation activities.Review and validate Compliance-as-Code (CaC), Policy-as-Code (PaC), and automated security assessment outputs to ensure accuracy and compliance.Collaborate with system owners, developers, engineers, and program stakeholders to implement security controls, address findings, and reduce enterprise risk.Support DevSecOps and cloud security initiatives by integrating security throughout the system development lifecycle and continuous delivery processes.Monitor security posture across AWS cloud, traditional infrastructure, and SaaS platforms, ensuring compliance with federal and DoD cybersecurity requirements.Brief government leadership and Authorizing Officials on system risk posture, assessment results, remediation strategies, and authorization recommendations.Required QualificationsActive Secret Security Clearance.Bachelor's degree in Information Technology, Computer Science, Engineering or a related technical field from an accredited college or university.Minimum 5 years of dedicated Information Assurance, Cybersecurity, or Information Security experience.At least 3 consecutive years of recent experience supporting DoD cybersecurity programs.Experience with Risk Management Framework (RMF) authorization processes.Experience administering and maintaining eMASS authorization packages.Experience conducting security control assessments, validations, and risk assessments.Experience supporting ATO, cATO, and continuous monitoring programs.Experience analyzing vulnerabilities, security findings, and organizational risk posture.Experience supporting cloud security initiatives in AWS, Azure, or other FedRAMP-authorized environments.Strong understanding of NIST 800-53 security controls and DISA STIG requirements.Required CertificationsCandidates must possess:One DoD 8570/8140 IAM Level II or IAT Level ll baseline requirements, such as:CISSPSecurity+ CECISMCASP+ CEPay RangeThe anticipated annual salary range for this position is $150,030 – $185,020. This range is a good-faith estimate and not a guarantee of compensation. Final compensation will be based on factors including experience, education, skills, geographic location, internal equity, market data, and applicable contract requirements, and may fall outside the posted range.**THIS POSITION IS CONTINGENT UPON CONTRACT AWARD**ThinkTek LLC is proud to be an Equal Opportunity Employer (EOE), making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. ThinkTek offers medical, dental, and vision insurance to all full-time employees; PTO and a variety of other paid leave options are also available. You can read more about ThinkTek benefits at https://www.thinktekllc.com/careers/.