1

Grc Risk Analyst Jobs in Pennsylvania (NOW HIRING)

Job Overview The Security GRC Analyst role is to ensure the secure operation of the Credit Union ... Assess technology risk across IT and the organization, collaborate to develop remediation plans ...

An excellent career opportunity is currently available for an entry level Risk & Compliance Analyst ... GRC's privacy and compliance initiatives Required Qualifications: * High School diploma/GED ...

The GRC function provides governance, risk evaluation, and compliance oversight to support informed ... The Security Awareness and Compliance Analyst administers the organization''''s Security Awareness ...

New

... Analyst within the client, supporting the client's Governance, Risk, and Compliance (GRC ... The GRC function provides governance, risk evaluation, and compliance oversight to support informed ...

An excellent career opportunity is currently available for an entry level Risk & Compliance Analyst ... GRC's privacy and compliance initiatives Required Qualifications: * High School diploma/GED ...

Experience selling into or supporting GRC, security compliance, cyber risk, or security reporting/analytics use cases and comfortable engaging with both practitioners and executives. * Practical data ...

Support Governance, Risk, and Compliance (GRC) initiatives * Participate in continuous improvement ... Experience analyzing metrics, creating reports, and identifying trends * Strong written and verbal ...

Showing results 41-60

Grc Risk Analyst information

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What cities in Pennsylvania are hiring for Grc Risk Analyst jobs?

Cities in Pennsylvania with the most Grc Risk Analyst job openings:

Infographic showing various Grc Risk Analyst job openings in Pennsylvania as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 14% Part Time, 2% Contract, and 1% Nights. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution.

Security GRC Analyst

Citadel

Exton, PA • On-site

Full-time

Re-posted 6 days ago


Job description

Job Overview
The Security GRC Analyst role is to ensure the secure operation of the Credit Union's computer systems, servers, and network connections. The role will primarily be responsible for the assessment of technology risk, including third party risk, developing remediation plans, and tracking to completion, enforcement of the network security policy, and compliance with requirements and recommendations of security audits and assessments. The incumbent will also be expected to make suggestions for hardware, software and policy changes that will improve the security posture of the organization.
Responsibilities
  • Assess technology risk across IT and the organization, collaborate to develop remediation plans, and track initiatives to completion. Perform control gap assessments, communicate and track findings, and initiate plans for remediation.
  • Assess third party risk, work with the business unit and vendor to communicate risk and determine action plans, and track initiatives to completion.
  • Act as a security resource for projects in support of the business throughout the year. Communicate with IT Security team to clearly identify all required technical tasks and time requirements for each project to assist with determining a realistic estimated completion date. Ensure that technology risk is identified for new products and that systems are implemented in the most secure manner possible.
  • Participate in all internal and external audits, guaranteeing that all security related documentation and materials are accurate, current and readily available. Ensure prompt and thorough response to and remediation of all findings and recommendations.
  • Participate in all internal and external security assessments, guaranteeing that all security related documentation and materials are accurate, current and readily available and that the proactive testing is non-intrusive to maintain daily business operations. Manage prompt and thorough response to and remediation of all findings and recommendations.
  • Support and contribute to the organization's security programs and help ensure that the team appropriately follows all incident response procedures when needed.
  • Participate in regular vulnerability assessments of the infrastructure and follow up on and respond to or implement the remediation actions for all findings and recommendations.
  • Evaluate the security of the infrastructure and identify areas for improvement. Suggest action plans that will increase the security posture of the organization without limiting or hindering required functionality.
  • Develop or review and regularly enhance system hardening procedures for all infrastructure equipment based on industry standards.
  • Take an active role in managing vendor relationships and analyzing internal processes to reduce expenses and/or increase efficiencies in support of continuous improvement. Assist with research of expenses and preparation of annual budgets and ensure accuracy when processing any assigned invoices.
  • Look for opportunities to work more proactively and less reactively with a goal of continuous improvement. Identify ways in which to better monitor and/or improve the security of all systems and applications in order to increase system and application stability and up-time.
  • Create and maintain Information Security Policies as directed. Ensure that written procedures are documented for all assigned functions and remain current.
  • Participate effectively and efficiently when assigned tasks in support of disaster recovery exercises.
  • Continually work on developing a full understanding of the LAN/WAN and Infrastructure.
  • Must keep professional skills up to date and consistent with current technology.
  • Must be a high energy individual who can multi-task and work well in stressful situations.
  • Must be technically oriented and have excellent analytical, organizational and communication skills.
  • Perform additional duties as assigned.

Qualifications and Education Requirements
  • Minimum of three years of IT Security or technology risk experience required; Banking experience preferred.
  • Bachelor's Degree in related field required. Three years demonstrated technical experience may be substituted in lieu of degree.
  • One or more industry certifications preferred, such as: CompTIA Security+, GIAC (Information Security Fundamentals), CISSP (Certified Information Systems Security Professional), CISA (Certified Information Security Auditor), CISM (Certified Information Security Manager), CCNA Security (Cisco Certified Network Associate Security), SSCP (Systems Security Certified Practitioner), MCSA (Microsoft Certified Systems Administrator) with specialization in Security. Certifications in security specialties may fulfill this requirement.
  • Working knowledge of cyber security frameworks.
  • Working knowledge of security protocols.
  • Knowledge of IT systems, security measures and best practices required to protect corporate networks.
  • Knowledge of system and network exploitation as well as common attack vectors and various types of malware.
  • Knowledge of mobile device security strategies.
  • Broad range of network, infrastructure and telecommunications knowledge.
  • Knowledge of servers, software, networking equipment, and infrastructure elements.

Additional Skills/Notes:
  • Excellent oral and written communication skills required.
  • Analytical skills, such as process flow analysis and systems analysis required.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.