1

Cybersecurity Governance Risk Compliance Jobs in Philadelphia, PA

The Global GRC Senior Analyst will report directly to the Global Cybersecurity Governance, Risk and Compliance Manager. This role involves collaborating with cross-functional teams to design ...

The Global GRC Senior Analyst will report directly to the Global Cybersecurity Governance, Risk and Compliance Manager. This role involves collaborating with cross-functional teams to design ...

next page

Showing results 1-20

Cybersecurity Governance Risk Compliance information

See Philadelphia, PA salary details

$23.2K

$114.7K

$151.9K

How much do cybersecurity governance risk compliance jobs pay per year?

As of May 28, 2026, the average yearly pay for cybersecurity governance risk compliance in Philadelphia, PA is $114,737.00, according to ZipRecruiter salary data. Most workers in this role earn between $100,900.00 and $130,200.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Cybersecurity Governance, Risk, and Compliance (GRC) professional, and why are they important?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in Cybersecurity Governance, Risk, and Compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

What is Cybersecurity Governance, Risk, and Compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What are popular job titles related to Cybersecurity Governance Risk Compliance jobs in Philadelphia, PA? For Cybersecurity Governance Risk Compliance jobs in Philadelphia, PA, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Governance Risk Compliance jobs in Philadelphia, PA look for? The top searched job categories for Cybersecurity Governance Risk Compliance jobs in Philadelphia, PA are:
What cities near Philadelphia, PA are hiring for Cybersecurity Governance Risk Compliance jobs? Cities near Philadelphia, PA with the most Cybersecurity Governance Risk Compliance job openings:
Governance, Risk & Compliance Analyst, Specialist

Governance, Risk & Compliance Analyst, Specialist

Vangard, Inc.

Malvern, PA • On-site

Full-time

Posted 16 days ago


Job description

About The Job

In this role, you will help deliver on our investment in GRC modernization. You will lead risk assessments, design and scale forward-looking governance, risk, and compliance programs, and serve as a trusted advisor who helps teams move faster and smarter while staying audit-ready and compliant.

The Governance, Risk & Compliance Analyst, Specialist is a key member of Vanguard's Global Enterprise Security's Governance, Risk, Compliance (GRC) and Strategic Operations team. This position recommends, develops, implements, and monitors enterprise-wide information security policies, standards, and operational guidelines. It assesses the end-to-end integrated GRC framework of information security policies, standards, and operational control linkages to manage cyber security risks within tolerances, satisfy regulatory obligations, and address expanding requirements, with exceptional stakeholder experience. Data-driven approaches will be used to predict risk issues, develop solutions, and partner with key owners and stakeholders. Automation will be used to accelerate delivery and improve effectiveness.

Responsibilities

  • Works with Enterprise Security and Fraud subdivisions and business units as the technical authority regarding security of application and systems software, equipment, and related capabilities and performance characteristics to evaluate their effectiveness at meeting defined requirements, determining integration requirements and identifying ramifications on operations of their implementation.
  • Conducts security and fraud assessments, risk analyses and assesses contingency plans for to verify existence and effectiveness of safeguards.
  • Supports the development and maintenance of a portfolio of global security and fraud policies and standards. Monitors and maintains the lifecycle of the portfolio. Responsible for oversight of management and decisions related to methodology and policy for all Security and fraud functions.
  • Advises key stakeholders and security policy owners during policy and standards discussions. Interfaces with clients on all inquiries related to Information and IT Security and fraud capabilities.
  • Works with Compliance and Regional Security and Fraud teams to understand global regulatory requirements, develop global and regional policies and standards, and oversee implementation. Interfaces with external regulators for Information and IT Security and Fraud.
  • Reviews and analyzes current and proposed policy and standards directives and IT technical issues which may affect the implementation of Information Security and Fraud across the enterprise.
  • Recommends, develops, implements and coordinates new security policies, standards, controls and operating doctrine at all levels across the company. Interprets policy relating to Vanguard information security and frau functions and provides guidance, as required.
  • Defines and implements automations to accelerate delivery and improve effectiveness.
  • Defines and implements data-driven approaches and dashboards to predict risk issues, develop solutions, and partner with key owners and stakeholders.
  • Designs, implements and supports modernized GRC process and tool capabilities.
  • Participates in special projects and performs other duties as assigned.

Qualifications

  • Seven years related work experience, Information Security or fraud experience required.
  • Undergraduate degree or equivalent combination of training and experience. Computer Science degree preferred.
  • In-depth knowledge of relevant frameworks and standards (i.e., NIST CSF, NIST 800-53, CIS Controls, ISO 27002) and financial services industry cyber regulations and guidelines, and considered an expert in the domain.
  • Demonstrated experience with GRC solutions platform and automation capabilities.
  • Excellent communication and influencing skills.
  • Influence key stakeholders and security policy and control owners.
  • Professional certification (CISSP, CISM, CompTIA, SANS, ISC2) preferred.

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a mission-we're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.