1

Insider Risk Manager Jobs in Pennsylvania (NOW HIRING)

... risk management/insurance. You'll be a member of the Legal team and collaborate with ... Insider Trading Policy * Advise on corporate governance, related policies and approvals, board ...

... risk management/insurance. You'll be a member of the Legal team and collaborate with cross ... Insider Trading Policy * Advise on corporate governance, related policies and approvals, board ...

This role demands the ability to drive measurable risk reduction, security maturity, and cyber ... insider threat management. * Exceptional communication, presentation, and storytelling skills.

... insider threats, and advanced persistent threats * Lead and coordinate incident response ... Collaborate and lead within the Cyber & Tech Risk practice, partnering across threat management ...

... ransomware groups, insider threats, and emerging AI-enabled attack techniques. Translate ... Drive innovation while ensuring exercises remain aligned with business objectives and risk ...

Serve as primary or backup HR representative on the Insider Threat Working Group, supporting risk assessment, mitigation strategies, and case management. * Act as primary or backup member of the ...

Showing results 21-40

Insider Risk Manager information

What does an insider risk manager do?

An Insider Risk Manager is responsible for identifying, assessing, and mitigating risks posed by individuals within an organization, such as employees, contractors, or business partners. Their work focuses on preventing data breaches, intellectual property theft, and other security incidents caused by trusted insiders. They develop policies, conduct investigations, monitor employee activity for suspicious behavior, and collaborate with other departments to strengthen security measures. Ultimately, their goal is to protect the organization's assets and reputation from internal threats.

What are some common challenges faced by an insider risk manager, and how can they be addressed?

Insider Risk Managers often face challenges such as detecting subtle behavioral changes that may signal insider threats, balancing employee privacy with effective monitoring, and fostering a culture of security awareness. Addressing these challenges typically involves working closely with IT, HR, and legal teams to implement risk assessment tools, develop clear communication strategies, and provide regular training. Additionally, staying updated on the latest threat trends and maintaining transparent incident response protocols help Insider Risk Managers mitigate potential risks effectively.

What is the difference between Insider Risk Manager vs Data Loss Prevention Specialist?

AspectInsider Risk ManagerData Loss Prevention Specialist
CredentialsSecurity certifications (CISSP, CISM), risk management experienceSecurity certifications, technical knowledge of DLP tools
Work EnvironmentCorporate security teams, risk assessment settingsIT security teams, technical implementation roles
Industry UsageFinancial, healthcare, government sectorsTech, finance, enterprise sectors
Primary FocusIdentifying and mitigating insider threatsPreventing data exfiltration and leaks

The Insider Risk Manager focuses on detecting and managing risks posed by internal employees, while the Data Loss Prevention Specialist concentrates on technical measures to prevent data leaks. Both roles require security certifications and are vital in protecting organizational assets, but they differ in scope and daily responsibilities.

What are the key skills and qualifications needed to thrive as an insider risk manager, and why are they important?

To thrive as an Insider Risk Manager, you need expertise in cybersecurity, risk assessment, and incident response, often supported by a degree in information security or a related field. Familiarity with SIEM tools, DLP systems, and certifications like CISSP or CISM are typically required. Strong analytical thinking, discretion, and communication skills help in identifying threats and collaborating with stakeholders. These skills ensure effective mitigation of insider threats, protecting organizational assets and sensitive information.

What are popular job titles related to Insider Risk Manager jobs in Pennsylvania?

For Insider Risk Manager jobs in Pennsylvania, the most frequently searched job titles are:

What job categories do people searching Insider Risk Manager jobs in Pennsylvania look for?

The top searched job categories for Insider Risk Manager jobs in Pennsylvania are:

What cities in Pennsylvania are hiring for Insider Risk Manager jobs?

Cities in Pennsylvania with the most Insider Risk Manager job openings:

Senior Cybersecurity Engineer Specialist

Concurrent Technologies Corporation

Johnstown, PA โ€ข On-site

$105K - $142K/yr

Full-time

Posted 25 days ago


Job description

SENIOR CYBERSECURITY ENGINEER SPECIALIST

Concurrent Technologies Corporation

Johnstown, PA

Minimum Clearance Required: N/A

Clearance Level Must Be Able to Obtain: Secret

Employee Background Check Required

Concurrent Technologies Corporation (CTC), an independent, nonprofit applied scientific research and development organization, is seeking a Senior Cybersecurity Engineer to join its internal Information Technology team. This senior-level role is responsible for strengthening and advancing the organization's cybersecurity posture by providing technical leadership across enterprise security initiatives, cloud technologies, identity and access management, endpoint protection, vulnerability management, and data security. You will work closely with cross-functional teams to develop innovative security solutions that protect critical business systems while enabling CTC's mission to deliver advanced technology solutions for government and industry.

The ideal candidate is an experienced cybersecurity professional with a strong background in Microsoft security technologies, Azure Government, Microsoft 365, and enterprise security operations. This individual will serve as a trusted technical expert, driving security improvements, evaluating emerging threats and technologies, and helping shape cybersecurity strategy through automation, secure architecture, and modern security best practices. Success in this role requires strong analytical and problem-solving skills, a collaborative mindset, and the ability to communicate complex technical concepts to both technical and non-technical stakeholders while supporting compliance with government and industry cybersecurity standards.

Key Responsibilities:

  • General Security Operations - Participate in incident response activities, continuous monitoring, and the development of security standards and procedures in collaboration with internal cyber, IT, development, and data security teams.
  • Vulnerability & Threat Management - Perform threat hunting by analyzing threat feeds from various government and commercial sources and leveraging Rapid7 Insight VM and Microsoft Cloud tools to scan, prioritize, and remediate vulnerabilities across on-premises and cloud assets.
  • Endpoint & Device Security - Administer endpoint security systems (Microsoft Defender for Endpoint, SentinelOne, Intune, EntraID, Azure) for threat detection, investigation, and automated response across enterprise devices with a focus on compliance policies, configuration profiles, and conditional access enforcement.
  • Identity Security - Support and harden Microsoft Entra ID configurations, including conditional access, multi-factor authentication, privileged identity management, and identity governance.
  • Cloud Security - Apply, monitor, and enforce security best practices across AzureGov cloud services and Microsoft 365, ensuring alignment with government compliance frameworks (e.g., FedRAMP, NIST 800-171, CMMC as applicable).
  • Data Protection - Configure and manage Microsoft Purview data loss prevention (DLP), insider risk management and support compliance and eDiscovery initiatives, ensuring data governance policies are enforced across the M365 environment.
  • Secure Software Development & Automation - Collaborate with development and DevOps teams to embed security into the software development lifecycle (SDLC), including secure coding practices, code review, and dependency scanning.
  • AI-Related Security - Evaluate security considerations associated with the adoption of AI and generative AI tools, including data leakage, prompt injection, model misuse, and shadow AI risks while contributing to the development of AI usage guardrails and monitoring practices aligned with emerging federal AI security guidance.

Basic Qualifications:

  • Education: Bachelor's or Master's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
  • Experience: 4-6 years of hands-on experience in a Cyber Security analyst or related IT or cyber engineer role.
  • Ability to obtain and maintain Secret government security clearance.
  • Demonstrated experience with Microsoft M365, Azure, or AWS cloud security components (e.g. Defender for Identy and Endpoint, Purview, Intune, Azure, EntraID)
  • Demonstrated ability to script and use command line interfaces with PowerShell, Python, or similar language.
  • Solid grasp of networking, operating system security (Windows-centric), and cloud security fundamentals.
  • Excellent verbal and written communication skills with the ability to explain and document technical information for a non-technical audience.
  • Proven ability to approach complex problems with a structured, analytical, and inquisitive mindset.
  • Relevant certifications such as CISSP, CISM, Security+, Microsoft SC-200/SC-300/AZ-500, or CEH.
  • Experience operating in AzureGov or other government/regulated cloud environments.
  • Familiarity with DevSecOps practices and secure CI/CD pipeline tooling (SAST/DAST/SCA).
  • Experience with Linux, macOS, and Windows in a heterogeneous network environment.
  • Understanding of security frameworks such as NIST 800-171 or 800-53, NIST Cybersecurity Framework, and CIS Controls.
  • Knowledge of CMMC, FedRAMP, or NIST compliance requirements.
  • Experience assessing security risks associated with AI/generative AI technologies.
  • Background in incident response and threat hunting.

Why CTC?

  • Our teams at CTC are passionate and thrive on collaboration in a team environment.
  • When we encounter a difficult problem, we have a variety of talented and diverse employees that work together to solve the toughest challenges.
  • Competitive salary and benefits package.
  • Although our work at CTC is extremely important, we also recognize the need for our employees to maintain a proper mix of work and personal life.
  • Visit www.ctc.com to learn more!

Join us! CTC offers exceptional career growth, cutting edge technology, educational opportunities, and recognition for quality work.

https://concurrent-technologies-corporation.breezy.hr/

Staffing Requisition: SR#2026-0093

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability status, protected veteran status, or any other characteristic protected by law.