1

Cyber Security Risk Management Jobs in Pittsburgh, PA

Cybersecurity Infrastructure availability Cloud services Identity and Access Management Data protection Artificial Intelligence Third-Party Technology Risk Executive Risk Reporting Produces executive ...

Cybersecurity Infrastructure availability Cloud services Identity and Access Management Data protection Artificial Intelligence Third-Party Technology Risk Develops methodologies, models, and ...

Risk Scenario Development · Leads development of enterprise technology risk scenarios across: · Cybersecurity · Infrastructure availability · Cloud services · Identity and Access Management · ...

New

Technology Risk Specialist Sr

Pittsburgh, PA · On-site

$95K/yr

Risk Scenario Development • Leads development of enterprise technology risk scenarios across: • Cybersecurity • Infrastructure availability • Cloud services • Identity and Access Management ...

New

next page

Showing results 1-20

Cyber Security Risk Management information

See Pittsburgh, PA salary details

$55.3K

$129.1K

$180.6K

How much do cyber security risk management jobs pay per year?

As of Sep 4, 2026, the average yearly pay for cyber security risk management in Pittsburgh, PA is $129,078.00, according to ZipRecruiter salary data. Most workers in this role earn between $107,800.00 and $145,600.00 per year, depending on experience, location, and employer.

What is cyber security risk management?

Cyber security risk management is the process of identifying, assessing, and prioritizing risks to an organization's information systems and data. It involves evaluating potential threats and vulnerabilities, determining the likelihood and impact of these risks, and implementing measures to mitigate or manage them. Effective risk management helps organizations protect sensitive data, ensure regulatory compliance, and minimize the impact of cyber attacks. This process is ongoing and adapts to new threats and changes in technology.

What are the key skills and qualifications needed to thrive in cyber security risk management?

To thrive in Cyber Security Risk Management, you need a solid understanding of risk assessment methodologies, information security frameworks (such as ISO 27001 or NIST), and often a relevant degree or certification like CISSP or CISM. Familiarity with security tools, vulnerability assessment platforms, and risk management software is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying threats and conveying risk to stakeholders. These skills ensure that organizations can proactively manage and mitigate cyber threats, safeguarding critical assets and maintaining compliance.

What are some typical challenges faced in cyber security risk management, and how can they be addressed?

Professionals in Cyber Security Risk Management often encounter challenges such as staying updated with rapidly evolving threats, balancing security needs with business objectives, and ensuring compliance with various regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and the implementation of robust risk assessment frameworks. Collaboration with IT, legal, and business teams is essential to develop practical security policies that protect assets without hindering operations.

What is the difference between Cyber Security Risk Management vs Cyber Security Analyst?

AspectCyber Security Risk ManagementCyber Security Analyst
CertificationsCompTIA Security+, CISSP, CISMCompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentPolicy development, risk assessment, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageOrganizations focusing on risk mitigation and complianceOrganizations implementing and maintaining security measures

Cyber Security Risk Management professionals focus on identifying, assessing, and mitigating security risks at an organizational level, often involved in policy and strategy. Cyber Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the same industry, their core responsibilities differ: risk managers develop strategies, whereas analysts execute security measures and respond to threats.

What does a cyber security risk management do?

A cyber security risk management professional identifies, assesses, and prioritizes potential security threats to an organization’s information systems. They develop strategies and implement controls to mitigate risks, often using frameworks like NIST or ISO, and may conduct regular audits to ensure security measures are effective.

What are popular job titles related to Cyber Security Risk Management jobs in Pittsburgh, PA?

For Cyber Security Risk Management jobs in Pittsburgh, PA, the most frequently searched job titles are:

What job categories do people searching Cyber Security Risk Management jobs in Pittsburgh, PA look for?

The top searched job categories for Cyber Security Risk Management jobs in Pittsburgh, PA are:

What cities near Pittsburgh, PA are hiring for Cyber Security Risk Management jobs?

Cities near Pittsburgh, PA with the most Cyber Security Risk Management job openings:

Infographic showing various Cyber Security Risk Management job openings in Pittsburgh, PA as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 15% Part Time, and 2% Contract. Highlights an 90% Physical, 2% Hybrid, and 8% Remote job distribution, with an average salary of $129,078 per year, or $62.1 per hour.

Cybersecurity Analyst (1344)

GEM Technologies, Inc.

West Mifflin, PA • On-site

$90 - $130/hr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 8 days ago


Job description

ABOUT THE ROLE

We are seeking a Cybersecurity Analyst to join our team supporting the Naval Nuclear Laboratory (NNL) at their Bettis Atomic Power Laboratory site! This position is full-time and will be based out of West Mifflin, PA or Niskayuna, NY.

Responsibilities

  • Support cybersecurity activities for Naval Nuclear Laboratory (NNL) information systems and the Naval Nuclear Propulsion Program (NNPP).

  • Execute cybersecurity activities in accordance with National Institute of Standards and Technology (NIST) directives and requirements.

  • Support implementation and execution of the Risk Management Framework (RMF) throughout the information system authorization process.

  • Assist Information System Owners (ISOs) with the development, review, and maintenance of System Security Plans (SSPs).

  • Develop and support Security Assessment Reports (SARs) required for system authorization.

  • Utilize the existing RSA Archer application on the Naval Nuclear Propulsion Network (NNPP Net) to document and manage cybersecurity and authorization activities.

  • Assist with the development and maintenance of Plans of Action and Milestones (POA&Ms) for cybersecurity deficiencies identified during the authorization process.

  • Support the development and documentation of Risk-Based Decisions (RBDs) associated with identified security deficiencies and risks.

  • Identify, document, track, and support remediation of cybersecurity findings and deficiencies.

  • Work with Information System Owners and other stakeholders to collect and maintain required security documentation and evidence.

  • Support ongoing information system authorization and compliance activities to ensure adherence to applicable NIST, RMF, and organizational cybersecurity requirements.

  • Maintain accurate cybersecurity documentation and records throughout the system authorization lifecycle.

  • Support cybersecurity activities at the Bettis Atomic Power Laboratory or Knolls Atomic Power Laboratory location.

Requirements

  • Education & Years of Experience – Bachelor’s Degree in Engineering or related discipline and 5+ years of relevant experience.

  • Citizenship – To be considered, you must be a United States (U.S.) citizen due to the federal nature of the work.

  • Clearance – To be considered, you MUST be able to obtain and maintain a government issued clearance before you can start.

    • Candidates with an active DOE "L" Clearance or DOD "Secret" clearance are HIGHLY DESIRED.

  • Minimum of four years of combined cybersecurity experience in one or more of the following roles:

    • Security Control Validator
    • Security Control Assessor (SCA)
    • Information System Security Officer (ISSO)
    • Information System Security Manager (ISSM)
  • Minimum of two years of experience supporting the development of information system security authorization packages in accordance with the NIST Risk Management Framework (RMF).

  • Working knowledge and experience applying NIST SP 800-37, NIST SP 800-53, and NIST SP 800-53A requirements.

  • Minimum of two years of experience working with the Federal Risk and Authorization Management Program (FedRAMP).

  • Current CompTIA Security+ certification.

Desired Skills

  • Experience using the RSA Archer application for cybersecurity, risk management, compliance, or system authorization activities.

  • Minimum of two years of experience working as part of IT security or cybersecurity project teams.

  • At least one year of experience managing IT or cybersecurity projects.

  • Knowledge of IT infrastructure and services, including:

    • Data centers
    • Physical and virtual servers
    • Local Area Networks (LAN) and Wide Area Networks (WAN)
    • Cloud Infrastructure as a Service (IaaS)
    • Platform as a Service (PaaS)
    • Software as a Service (SaaS)
  • Knowledge of cybersecurity policies, standards, and guidance, including NIST Special Publications and Security Technical Implementation Guides (STIGs).

  • Familiarity with the DoD Cloud Computing Security Requirements Guide (SRG).

  • Knowledge of infrastructure security, endpoint protection, and vulnerability management tools and practices.

  • Previous experience supporting the authorization of information systems within classified Department of Energy (DOE) or Department of Defense (DoD) environments.

  • Familiarity with NIST SP 800-171 and requirements for protecting Controlled Unclassified Information (CUI).

  • Certified Information Systems Security Professional (CISSP) certification.

  • Certificate of Cloud Security Knowledge (CCSK) certification.

About the Site

The Naval Nuclear Laboratory is comprised of the Bettis Atomic Power Laboratory, located in West Mifflin, Pennsylvania, the Knolls Atomic Power Laboratory located in Niskayuna, New York, the Kesselring Site, located in West Milton, New York, and the Naval Reactor Facility located in Idaho Falls, Idaho. Together, they develop advanced technology for the United States Naval Nuclear Propulsion Program, ensure the safety and reliability of naval nuclear reactors, and train Sailors who operate reactors in submarines and aircraft carrier fleets (energy.gov).

ABOUT GEM

GEM Technologies, Inc. (GEM) is an award-winning federal contractor with more than 30 years of experience providing environmental, construction, facility management, and technical services to federal agencies, state and local governments, and commercial organizations. Founded in 1994 as a nuclear engineering firm to support federal operations in East Tennessee, GEM has since expanded into a nationwide, multi-disciplinary provider with over 270 employees and a diverse portfolio of contracts in the environmental, nuclear, and defense sectors. Some reasons to join GEM are:

  • Our philosophy – We believe in the power of effective collaboration and recognize that good partnerships are the building blocks to success.

  • Our relationships – Partnering with federal clients, we solve complex problems, exceed expectations, and advance critical missions.

  • Our team – We are committed to managing a cohesive workforce and cultivating a supportive workplace for our employees on contracts and in-office.

  • Our community involvement – Supporting our communities, we invest time and money in local schools and non-profit organizations.

COMPENSATION AND BENEFITS

GEM’s offered compensation is dependent on candidates’ education, qualifications, and relevant years of experience. To recruit and retain our exceptional staff, we offer the opportunity to elect benefit packages that best suit our employee’s needs; this includes, but is not limited to, a competitive Salary, Medical, Dental and Vision Insurance (including HSA & PPO options), Paid Time Off (PTO), Paid Holidays, Life Insurance, and a matching 401(k) Retirement Plan.

Please Note: With the exception of mandated state requirements, GEM does not publish salary information on external job boards; as such, most ranges listed are estimates made by vendors and not actual salary ranges.

EQUAL OPPORTUNITY EMPLOYER

GEM Technologies, Inc. is an Equal Opportunity/Affirmative Action Employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.

#J-18808-Ljbffr