1

Cyber Security Risk Management Jobs in Philadelphia, PA

The Global GRC Senior Analyst will report directly to the Global Cybersecurity Governance, Risk and Compliance Manager. This role involves collaborating with cross-functional teams to design ...

next page

Showing results 1-20

Cyber Security Risk Management information

See Philadelphia, PA salary details

$54.5K

$127.1K

$177.8K

How much do cyber security risk management jobs pay per year?

As of Jul 26, 2026, the average yearly pay for cyber security risk management in Philadelphia, PA is $127,075.00, according to ZipRecruiter salary data. Most workers in this role earn between $106,100.00 and $143,400.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Cyber Security Risk Management professional, and why are they important?

To thrive in Cyber Security Risk Management, you need a solid understanding of risk assessment methodologies, information security frameworks (such as ISO 27001 or NIST), and often a relevant degree or certification like CISSP or CISM. Familiarity with security tools, vulnerability assessment platforms, and risk management software is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying threats and conveying risk to stakeholders. These skills ensure that organizations can proactively manage and mitigate cyber threats, safeguarding critical assets and maintaining compliance.

What is cyber security risk management?

Cyber security risk management is the process of identifying, assessing, and prioritizing risks to an organization's information systems and data. It involves evaluating potential threats and vulnerabilities, determining the likelihood and impact of these risks, and implementing measures to mitigate or manage them. Effective risk management helps organizations protect sensitive data, ensure regulatory compliance, and minimize the impact of cyber attacks. This process is ongoing and adapts to new threats and changes in technology.

What is the difference between Cyber Security Risk Management vs Cyber Security Analyst?

AspectCyber Security Risk ManagementCyber Security Analyst
CertificationsCompTIA Security+, CISSP, CISMCompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentPolicy development, risk assessment, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageOrganizations focusing on risk mitigation and complianceOrganizations implementing and maintaining security measures

Cyber Security Risk Management professionals focus on identifying, assessing, and mitigating security risks at an organizational level, often involved in policy and strategy. Cyber Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the same industry, their core responsibilities differ: risk managers develop strategies, whereas analysts execute security measures and respond to threats.

What does a cyber risk manager do?

A cyber risk manager assesses and prioritizes cybersecurity threats to an organization, develops strategies to mitigate risks, and implements security policies. They often use tools like risk assessment frameworks and require certifications such as CISSP or CISM to effectively manage security risks in a dynamic environment.

What are some typical challenges faced by professionals in Cyber Security Risk Management, and how can they be addressed?

Professionals in Cyber Security Risk Management often encounter challenges such as staying updated with rapidly evolving threats, balancing security needs with business objectives, and ensuring compliance with various regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and the implementation of robust risk assessment frameworks. Collaboration with IT, legal, and business teams is essential to develop practical security policies that protect assets without hindering operations.

Can you make $500,000 a year in cyber security?

Cyber security risk management professionals can potentially earn $500,000 or more annually, especially at senior levels, in leadership roles, or with extensive experience and specialized certifications like CISSP or CISM. High salaries are often associated with executive positions, consulting, or working for large organizations with complex security needs.

Can I make $200,000 a year in cyber security?

Cyber Security Risk Management professionals can potentially earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP or CISM, and roles in high-demand sectors or leadership positions. Salaries vary based on location, company size, and individual expertise, but high-level cybersecurity roles often reach or exceed this income level.

Is security risk management a good career?

Security risk management is a valuable career in cybersecurity, focusing on identifying and mitigating potential threats to an organization’s information systems. It often requires knowledge of security frameworks, risk assessment tools, and certifications like CISSP or CISM, and offers strong job growth and demand across various industries.
What are popular job titles related to Cyber Security Risk Management jobs in Philadelphia, PA? For Cyber Security Risk Management jobs in Philadelphia, PA, the most frequently searched job titles are:
What job categories do people searching Cyber Security Risk Management jobs in Philadelphia, PA look for? The top searched job categories for Cyber Security Risk Management jobs in Philadelphia, PA are:
What cities near Philadelphia, PA are hiring for Cyber Security Risk Management jobs? Cities near Philadelphia, PA with the most Cyber Security Risk Management job openings:
Infographic showing various Cyber Security Risk Management job openings in Philadelphia, PA as of July 2026, with employment types broken down into 3% Locum Tenens, 88% Full Time, 6% Part Time, and 3% Contract. Highlights an 90% Physical, 4% Hybrid, and 6% Remote job distribution, with an average salary of $127,075 per year, or $61.1 per hour.
Senior First Line Risk Specialist - Enterprise Data

Senior First Line Risk Specialist - Enterprise Data

M&T Bank

Wilmington, DE • Hybrid

Full-time

Posted 29 days ago


M&T Bank rating

7.8

Company rating: 7.8 out of 10

Based on 185 frontline employees who took The Breakroom Quiz

88th of 170 rated banks


Job description

This role is four days onsite at our Wilmington, DE location, with the flexibility to work from home one day per week

Overview:

Leads risk analysis for complex initiatives within the Enterprise Data division, serving as the primary First-Line risk representative for this space. This role influences the overarching risk framework, drives datacentric risk governance, and provides advanced guidance to leadership to support informed decisionmaking aligned with organizational imperatives. The individual must bring strong experience in process mapping, audit practices, data governance, and the DCAM framework, with the ability to independently evaluate data processes, identify control gaps, and recommend corrective actions.

Primary Responsibilities:
  • Develop and implement strategic approaches for indepth risk assessments across Enterprise Data, ensuring comprehensive coverage of all datarelated capabilities, processes, and governance functions.

  • Create, maintain, and analyze detailed process maps to identify points of failure, operational inefficiencies, control gaps, and potential risks; translate findings into actionable remediation plans and new or enhanced controls.

  • Apply auditdriven methodologies to evaluate Enterprise Data processes, ensuring alignment with regulatory expectations, internal standards, and industry best practices.

  • Leverage the DCAM framework to assess data management maturity, identify capability gaps, and guide the Enterprise Data organization toward stronger governance and compliance.

  • Develop and execute sophisticated risk management frameworks and programs that align Enterprise Data practices with business objectives and regulatory requirements, including leading risk and control selfassessments and summarizing complex findings for leadership.

  • Drive enforcement of risk and governance frameworks, providing expert guidance and continually assessing regulations, standards, and emerging risks to achieve industryleading compliance across data operations.

  • Act proactively as the firstline risk owner, independently identifying emerging risks, control weaknesses, and areas requiring improvement across Enterprise Data-without waiting for issues to be escalated or discovered by second or thirdline functions.

  • Spearhead collaboration among crossfunctional teams and senior/executive leadership, ensuring Enterprise Data practices align with broader business goals, regulatory requirements, and enterprise risk expectations.

  • Coordinate preparation and response to regulatory engagements, including reviewing responses for accuracy, organizing documentation, and leading exam management activities (e.g., firstday letters, followup requests).

  • Encourage innovation in risk management strategies by identifying advanced methodologies to address evolving datarelated risks and recommending implementation paths to Technology and Enterprise Data leadership.

  • Provide advanced mentorship to midlevel analysts, fostering professional growth and ensuring a high standard of risk analysis and data governance expertise across the team.

  • Contribute to the design and delivery of training programs to strengthen organizational knowledge of data risk management, data governance, and associated regulatory expectations.

  • Understand and adhere to the Company's risk and regulatory standards, policies, and controls in accordance with the Company's Risk Appetite. Identify riskrelated issues requiring escalation.

  • Promote an environment that supports belonging and reflects the M&T Bank brand.

  • Maintain internal control standards, including timely remediation of audit points and regulatory issues.

  • Complete other related duties as assigned.

Scope of Responsibilities:
  • This role primarily interacts with senior people leaders within the Technology and Cybersecurity teams, senior people leaders of Technology and Cybersecurity Risk, and internal partners such as the Risk Division, Internal Audit, and Regulatory Affairs.

  • Work is accomplished with periodic direction. The position exercises judgement in selecting methods, techniques, and evaluation criteria in obtaining results. It exerts significant latitude in determining objective of assignment and takes calculated risks with consultation from expert.

  • This role may present to Regulators under direction of senior Technology and Cybersecurity Risk leaders.

Education and Experience Required:
  • Bachelor's degree and a minimum of 7 years' relevant work experience, or in lieu of a degree, a combined minimum of 11 years' higher education and/or work experience

  • Demonstrated expert knowledge of Technology and/or Cybersecurity risk principles

  • Minimum of 6 years' relevant work experience in or with the specific Technology, Cybersecurity risk area and/or business unit

Education and Experience Preferred:
  • Master's degree in Information Technology, Computer Science, Cybersecurity, Law, Business Administration, or related field

  • Applicable certification align to function or domain such as Certified in Risk and Information Systems Control (CRISC), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP)

  • Ability to lead critical analysis of work and problem solve

  • Excellent communication and interpersonal skills

  • Experience partnering with leadership to design solutions aligned with business needs

  • Excellent ability to strategically seek critical information, and apply across a broad array of processes

  • Prior experience prioritizing across competing priorities and quickly changing landscape, and execute outcomes aligned with priorities

  • Experience effectively influencing peers and leaders

  • Ability to train and mentor peers

#LI-JB3#Hybrid

M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $136,000.00 - $226,600.00 (USD). The successful candidate's particular combination of knowledge, skills, and experience will inform their specific compensation.LocationWilmington, Delaware, United States of America

What M&T Bank employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom