1

Cyber Security Risk Management Jobs in Philadelphia, PA

Cyber Compliance Manager (Financial Services)

Blue Bell, PA · On-site

$106K - $143K/yr

Cybersecurity risk management * Third party vendor management * Interactions with consumers / individuals (data subject requests) * Incident management and breach notifications * Bachelor's degree in ...

next page

Showing results 1-20

Cyber Security Risk Management information

See Philadelphia, PA salary details

$57.5K

$134.2K

$187.7K

How much do cyber security risk management jobs pay per year?

As of Sep 4, 2026, the average yearly pay for cyber security risk management in Philadelphia, PA is $134,170.00, according to ZipRecruiter salary data. Most workers in this role earn between $112,000.00 and $151,400.00 per year, depending on experience, location, and employer.

What is cyber security risk management?

Cyber security risk management is the process of identifying, assessing, and prioritizing risks to an organization's information systems and data. It involves evaluating potential threats and vulnerabilities, determining the likelihood and impact of these risks, and implementing measures to mitigate or manage them. Effective risk management helps organizations protect sensitive data, ensure regulatory compliance, and minimize the impact of cyber attacks. This process is ongoing and adapts to new threats and changes in technology.

What are the key skills and qualifications needed to thrive in cyber security risk management?

To thrive in Cyber Security Risk Management, you need a solid understanding of risk assessment methodologies, information security frameworks (such as ISO 27001 or NIST), and often a relevant degree or certification like CISSP or CISM. Familiarity with security tools, vulnerability assessment platforms, and risk management software is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying threats and conveying risk to stakeholders. These skills ensure that organizations can proactively manage and mitigate cyber threats, safeguarding critical assets and maintaining compliance.

What are some typical challenges faced in cyber security risk management, and how can they be addressed?

Professionals in Cyber Security Risk Management often encounter challenges such as staying updated with rapidly evolving threats, balancing security needs with business objectives, and ensuring compliance with various regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and the implementation of robust risk assessment frameworks. Collaboration with IT, legal, and business teams is essential to develop practical security policies that protect assets without hindering operations.

What is the difference between Cyber Security Risk Management vs Cyber Security Analyst?

AspectCyber Security Risk ManagementCyber Security Analyst
CertificationsCompTIA Security+, CISSP, CISMCompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentPolicy development, risk assessment, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageOrganizations focusing on risk mitigation and complianceOrganizations implementing and maintaining security measures

Cyber Security Risk Management professionals focus on identifying, assessing, and mitigating security risks at an organizational level, often involved in policy and strategy. Cyber Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the same industry, their core responsibilities differ: risk managers develop strategies, whereas analysts execute security measures and respond to threats.

What does a cyber security risk management do?

A cyber security risk management professional identifies, assesses, and prioritizes potential security threats to an organization’s information systems. They develop strategies and implement controls to mitigate risks, often using frameworks like NIST or ISO, and may conduct regular audits to ensure security measures are effective.

What are popular job titles related to Cyber Security Risk Management jobs in Philadelphia, PA?

For Cyber Security Risk Management jobs in Philadelphia, PA, the most frequently searched job titles are:

What job categories do people searching Cyber Security Risk Management jobs in Philadelphia, PA look for?

The top searched job categories for Cyber Security Risk Management jobs in Philadelphia, PA are:

What cities near Philadelphia, PA are hiring for Cyber Security Risk Management jobs?

Cities near Philadelphia, PA with the most Cyber Security Risk Management job openings:

Infographic showing various Cyber Security Risk Management job openings in Philadelphia, PA as of August 2026, with employment types broken down into 90% Full Time, 5% Part Time, and 5% Contract. Highlights an 90% In-person, and 10% Remote job distribution, with an average salary of $134,170 per year, or $64.5 per hour.

Governance, Risk and Compliance Analyst

Crownholdings

Yardley, PA • On-site

Full-time

Posted 10 days ago


Key responsibilities

  • Manage the end-to-end third-party security risk assessment process.

  • Assess vendor security controls and assurance documentation using ISO 27001, NIST frameworks, and SOC 2 reports.

  • Support cybersecurity risk assessments, maintain risk registers, and track remediation activities.


Job description

About Crown

Crown Holdings, Inc. through it's subsidiaries, is a world leader in the metal packaging production process. We design and manufacture a wide range of innovative and sustainable metal packaging solutions and products. Our clients are some of the largest and most respected companies in the world.


Crown is dedicated to building a team of highly talented, dedicated, and driven individuals. It's an exciting time to join our business because Crown offers you the opportunity to grow and develop your skills in an expanding industry.

Crown was founded with the goal of valuing and promoting sustainability and this vision continues to be essential to our long-term future.

Job Description:

Global Information Security GRC Analyst - Third-Party Risk

The Company:

CROWN Cork & Seal USA, Inc., a wholly owned company of Crown Holdings, Inc. is a global leader in the design, manufacture and sale of packaging products for consumer goods. At Crown, we are passionate about helping our customers build their brands and connect with consumers around the world. We do this by delivering innovative packaging that offers significant value for brand owners, retailers, and consumers alike. With operations in 39 countries employing over 23,000 people and net sales of nearly $12 billion, we are uniquely positioned to bring best practices in quality and manufacturing to our customers to drive their businesses locally and globally. Sustaining a leadership position requires us to build a team of highly talented, dedicated, and driven individuals.

The Team:

The mission of the Global Information Security team is to protect Crown's global information systems, data and employees from cyber-based security threats while ensuring the confidentiality, integrity and availability of information used by the Crown business units to produce world class sustainable packaging solutions to our customers.

You will join a cohesive and collaborative team who love what they do and are committed to creating a safe and secure environment for the Crown family. We are nimble with dynamic backgrounds that foster an environment of continuous learning and growth.

The Job:

We are seeking a Global Information Security GRC Analyst - Third Party Risk to support the execution and continuous improvement of Crown's cybersecurity governance program. This role is part of Crown's Global Cybersecurity team and will help expand and mature the company's global GRC capabilities, with primary responsibility for supporting third-party security risk management. The role will also support related cyber risk and governance activities, including cybersecurity risk assessments, risk register maintenance, remediation tracking, risk reporting, AI governance, policy governance, compliance, and audit readiness.

The ideal candidate is analytical, collaborative, and passionate about helping the organization manage risk while enabling business objectives.

Key Responsibilities

Third-Party Security Risk Management

  • Manage the end-to-end third-party security risk assessment process.
  • Assess vendor security controls and assurance documentation using ISO 27001, NIST frameworks, and SOC 2 reports.
  • Review vendor security documentation, identify risks, and track remediation activities.
  • Maintain third-party risk registers and support ongoing vendor monitoring and reporting.

Governance, Risk & Compliance

  • Conduct cybersecurity risk assessments and maintain risk registers.
  • Support AI governance activities, including risk assessments and inventory management.
  • Coordinate cybersecurity policy development, review, approval, and lifecycle activities.
  • Support compliance and audit readiness through control testing, evidence collection, and remediation tracking.
  • Develop cybersecurity metrics, dashboards, and leadership reporting.
  • Identify opportunities to improve and automate GRC processes.

Location

This is a full-time, on-site position based in Yardley, Pennsylvania. Employees are expected to work from the office five days per week, with flexibility in daily start and end times.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, or a related field or equivalent professional experience.
  • 3-5 years of experience in cybersecurity, GRC, cyber risk, or third-party risk management.
  • Experience conducting security assessments and reviewing vendor security documentation.
  • Knowledge of cybersecurity frameworks such as ISO 27001, NIST CSF, and SOC 2.
  • Strong analytical, communication, and stakeholder management skills.

Preferred Qualifications

  • Certifications such as CISSP, CISM, CISA, CRISC, Security+, or ISO 27001 Lead Implementer/Auditor.
  • Experience with GRC platforms such as LogicGate, ServiceNow GRC, Archer, OneTrust, or AuditBoard.
  • Familiarity with AI governance frameworks including NIST AI RMF and ISO/IEC 42001.
  • Experience supporting cloud security and regulatory compliance initiatives.
  • Experience supporting GRC and TPRM activities across multiple countries and cultures.

Additional Job Considerations

This role requires collaboration, teamwork, and regular interaction with business stakeholders, technology teams, and external partners.

What Crown Offers You

  • Strong commitment to employee safety and well-being
  • Opportunity to build a meaningful career
  • Professional development through training and work experiences
  • Exposure to global cybersecurity and risk management initiatives

Join us and become part of a team helping to protect Crown's business through effective cybersecurity governance, risk management, and compliance.

What Crown Offers You
  • Strong engagement and commitment to the safety of our employees

  • The opportunity to build a meaningful career

  • Professional and personal development through training and work experiences

Join us and become part of a team of professionals who are passionate about sustainable packaging!

Working TogetherWorking Together is one of the five pillars that make up our Twentyby30 program. We aim to value and respect each individual and foster an environment of inclusivity.