1

It Risk Analyst Jobs in Philadelphia, PA (NOW HIRING)

Director, Technology Risk Management

West Point, PA · On-site

$173 - $273/hr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

The Director, Business Information Risk Officer (BIRO) is a critical leadership role responsible ... This role provides risk governance for all IT systems managed by the EIT organization, whether they ...

Third Party Risk Analyst About the role As a Third-Party Risk Analyst on Vanguard's Third-Party ... Contribute to regular reviews of third-party risk technologies and recommend enhancements to ...

Contribute to shaping team strategy, vision, and operating model Required Qualifications * 5+ years of experience in technology risk, IT audit, cybersecurity risk, operational risk, or a related ...

Third Party Risk Analyst About the role As a Third-Party Risk Analyst on Vanguard's Third-Party ... Contribute to regular reviews of third-party risk technologies and recommend enhancements to ...

Quantitative Risk Analyst

Philadelphia, PA · On-site

$64K - $105K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... technologies, prepare analysis and reports to support discussions on key analytics and model ... Ability to create visualizations of data and/or quantitative information for management decision ...

Quantitative Risk Analyst

Philadelphia, PA · On-site

$64K - $105K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... technologies, prepare analysis and reports to support discussions on key analytics and model ... Ability to create visualizations of data and/or quantitative information for management decision ...

Quantitative Risk Analyst

Philadelphia, PA

$64K - $105K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... technologies, prepare analysis and reports to support discussions on key analytics and model ... Ability to create visualizations of data and/or quantitative information for management decision ...

Manager, IT Audit

Wilmington, DE

$105K - $167K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

The role designs IT risk assessments and audit programs, oversees engagement execution and quality ... Proficiency with IT audit tools, data analytics, and system querying techniques. Full time ...

In this role, you will lead risk-based audits to evaluate internal controls and influence senior ... Experience leveraging data analytics to enhance audit insights and conclusions. Special Factors ...

Minimum of three years of IT Security or technology risk experience required; Banking experience ... Analytical skills, such as process flow analysis and systems analysis required.

Minimum of three years of IT Security or technology risk experience required; Banking experience ... Analytical skills, such as process flow analysis and systems analysis required. Equal Opportunity ...

Showing results 21-40

It Risk Analyst information

See Philadelphia, PA salary details

$15

$40

$66

How much do it risk analyst jobs pay per hour?

As of Aug 17, 2026, the average hourly pay for it risk analyst in Philadelphia, PA is $40.85, according to ZipRecruiter salary data. Most workers in this role earn between $30.10 and $49.71 per hour, depending on experience, location, and employer.

What does an IT Risk Analyst do?

An IT Risk Analyst is responsible for identifying, assessing, and mitigating risks that could impact an organization's information technology systems and data. They analyze potential threats, such as cyberattacks or data breaches, and develop strategies to minimize these risks. Their role involves working closely with other IT professionals to ensure compliance with security policies and regulatory requirements, as well as preparing risk reports and recommending improvements. Ultimately, IT Risk Analysts help organizations protect sensitive information and maintain secure, reliable IT operations.

What are some common challenges IT Risk Analysts face when collaborating with other departments?

IT Risk Analysts often work closely with various departments such as IT, compliance, and operations to identify and mitigate risks. One common challenge is translating technical risk information into terms that non-technical stakeholders can understand. Additionally, balancing the need for rigorous security measures with business objectives can sometimes lead to conflicting priorities. Effective communication and building strong relationships across teams are key to overcoming these challenges and ensuring that risk controls are both practical and effective.

What are the key skills and qualifications needed to thrive as an IT Risk Analyst, and why are they important?

To thrive as an IT Risk Analyst, you need a strong understanding of risk management frameworks, cybersecurity principles, and regulatory compliance—often supported by a degree in information technology or a related field. Familiarity with tools such as risk assessment software, vulnerability scanners, and certifications like CISSP or CISA is typically required. Analytical thinking, attention to detail, and effective communication are vital soft skills that distinguish top performers in this role. These competencies are crucial for accurately identifying risks, ensuring regulatory compliance, and effectively communicating findings to stakeholders.

What is the difference between It Risk Analyst vs Cybersecurity Analyst?

AspectIt Risk AnalystCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CEH, CompTIA Security+
Work EnvironmentFinancial, healthcare, corporate sectors focusing on risk managementIT security teams, cybersecurity firms, tech companies
Employer & Industry UsageFinancial institutions, large corporations, consulting firmsTech companies, government agencies, security firms

While both roles focus on protecting information, the It Risk Analyst primarily assesses and manages overall IT risks within organizations, emphasizing compliance and risk mitigation strategies. In contrast, the Cybersecurity Analyst concentrates on defending systems from cyber threats and attacks. Both roles often collaborate but serve distinct functions in an organization's security framework.

How much do IT risk analysts get paid?

IT risk analysts typically earn a median annual salary of around $80,000 to $100,000, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries. Salaries also vary based on industry and company size.

Is an IT risk analyst a hard job?

An IT risk analyst's job involves assessing and managing cybersecurity threats, which requires strong analytical skills, attention to detail, and knowledge of security tools and frameworks. The role can be challenging due to the evolving nature of cyber threats and the need for continuous learning and certification, such as CISSP or CISA. Overall, it can be demanding but is manageable with proper training and experience.

What are popular job titles related to It Risk Analyst jobs in Philadelphia, PA?

For It Risk Analyst jobs in Philadelphia, PA, the most frequently searched job titles are:

Infographic showing various It Risk Analyst job openings in Philadelphia, PA as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $84,975 per year, or $40.9 per hour.

Director, Technology Risk Management

Merck & Co.

West Point, PA • On-site

$173 - $273/hr

Other

Medical, Dental, Vision, Retirement, PTO

This job post has expired today. Applications are no longer accepted.


Merck rating

8.0

Company rating: 8.0 out of 10

Based on 51 frontline employees who took The Breakroom Quiz

43rd of 86 rated pharmaceutical


Job description

Job Description

The Director, Business Information Risk Officer (BIRO) is a critical leadership role responsible for aligning cybersecurity, risk management, and compliance strategies with business objectives. This individual will act as a trusted advisor to the business leaders in the Enterprise IT (EIT) that supports our company's Global Support Functions (GSF), such as Finance, HR, Legal, and Procurement, among others, ensuring that information security and compliance risks are proactively identified, assessed, and managed while enabling business innovation and growth. This role provides risk governance for all IT systems managed by the EIT organization, whether they are hosted internally or in the cloud, fostering a secure, compliant, and risk-aware culture. Additionally, the BIRO maintains a continuous feedback loop with the Information Technology Risk Management & Security (ITRMS) team to enhance and align the risk management processes to the business goals. The ideal candidate will possess deep technical expertise and working knowledge of industry standard platforms such as SAP S/4, Workday, etc., a strong understanding of business operations (particularly Finance, HR, Legal, and Procurement), and excellent leadership and stakeholder management skills. S/he must be able to translate complex Cybersecurity concepts into business language and influence stakeholders to drive a risk-aware culture across the EIT organization and any newly acquired businesses.

Primary Responsibilities: Strategic Leadership & Business Partnership
  • Serve as the primary cybersecurity and risk advisor to EIT, aligning security strategies with the business priorities.
  • Provide executive-level risk insights and recommendations to EIT leadership.
  • Ensure security and risk management practices are embedded in business processes, digital transformation initiatives, and operational decision-making.
  • Act as a bridge between ITRMS and EIT, translating technical risks into business impact.
Risk Management & Governance
  • Drive compliance with applicable global regulations and internal security policies by tailoring the requirements to EIT's operational and regulatory context.
  • Identify, design, and help implement risk-based security solutions that are practical, effective, and aligned with EIT business priorities.
  • Provide security and risk leadership for strategic IT programs, such as SAP S/4HANA implementation, ensuring integration of security and compliance throughout the program lifecycle.
  • Stay updated on new and emerging technologies (e.g., AI and Quantum) and new laws and regulations, and understand their impacts on the business.
Technical Expertise & Cyber Resilience
  • Work in unison with EIT IT Value Teams to establish secure design, implementation, and monitoring of IT systems, applications, and cloud environments.
  • Proactively identify opportunities to improve the cyber resilience capabilities of EIT systems.
  • Support the Cyber Fusion Center in handling Cyber incidents related to EIT
  • Understand emerging cyber threats, vulnerabilities, and attack vectors, and establish proactive risk mitigation strategies.
Leadership, Influence & Culture Building
  • Influence EIT stakeholders to foster a security-conscious culture without impeding business agility.
  • Drive security awareness programs that resonate with business functions.
  • Lead, mentor, and develop a high-performing risk and security team
  • Demonstrates high emotional intelligence (EQ) and executive presence (EP), effectively engaging with senior executives and key stakeholders.
Education and Experience Requirements:
  • Bachelor's Degree in one or more of the following fields: information technology, cyber security, computer science, business administration, communications, or related field.
  • Knowledge of industry standard platforms such as SAP S/4, Workday, etc.
  • 10+ years' experience working in one or more of the following fields: cybersecurity, IT risk management, IT compliance, Information Technology, or a related field.
  • 5+ years' experience leading global teams in a management or leadership role, particularly in a fast-paced, service-oriented environment preferred.
  • Prior experience in the healthcare industry, with an understanding of the unique challenges in securing systems that support Finance, HR, and Legal areas prferred.
  • Risk or security certification credentials (CISSP, GSEC, CISA, CISM, etc.) preferred.
Key Competencies
  • Technical Depth & Business Acumen - Ability to blend security knowledge with business understanding.
  • Problem-Solving Mindset - Proactive, strategic, and solutions-oriented approach.
  • Change Management - Experience driving security transformation across the supported organization.
  • Influence & Executive Presence (EP) - Strong stakeholder management and leadership skills.High Emotional Intelligence (EQ) - Ability to navigate complex organizational dynamics.
Required Skills:

Business Acumen, Cybersecurity, Data Management, Digital Transformation, Emotional Intelligence, Executive Presence, Information Security, Information Technology (IT) Risk Management, IT Compliance Management, IT Governance, IT Risk Assessments, IT Risk Governance, IT Risk Response and Reporting, Knowledge of regulations and frameworks, Risk Management, Risk Management and Mitigation, Security Solutions, Stakeholder Management, Technical Advice

US and Puerto Rico Residents Only:

Our company is committed to inclusion, ensuring that candidates can engage in a hiring process that exhibits their true capabilities. Please click here if you need an accommodation during the application or hiring process.

As an Equal Employment Opportunity Employer, we provide equal opportunities to all employees and applicants for employment and prohibit discrimination on the basis of race, color, age, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability status, or other applicable legally protected characteristics.--As a federal contractor, we comply with all affirmative action requirements for protected veterans and individuals with disabilities.- For more information about personal rights under the U.S. Equal Opportunity Employment laws, visit:

EEOC Know Your Rights

EEOC GINA Supplement•

We are proud to be a company that embraces the value of bringing together, talented, and committed people with diverse experiences, perspectives, skills and backgrounds. The fastest way to breakthrough innovation is when people with diverse ideas, broad experiences, backgrounds, and skills come together in an inclusive environment. We encourage our colleagues to respectfully challenge one another's thinking and approach problems collectively.

Learn more about your rights, including under California, Colorado and other US State Acts

The salary range for this role is

$173,200.00 - $272,600.00

This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An employee's position within the salary range will be based on several factors including, but not limited to relevant education, qualifications, certifications, experience, skills, geographic location, government requirements, and business or organizational needs.

The successful candidate will be eligible for annual bonus and long-term incentive, if applicable.

We offer a comprehensive package of benefits.- Available benefits include medical, dental, vision healthcare and other insurance benefits (for employee and family), retirement benefits, including 401(k), paid holidays, vacation, and compassionate and sick days. More information about benefits is available at https://jobs.merck.com/us/en/compensation-and-benefits .

San Francisco Residents Only:

We will consider qualified applicants with arrest and conviction records for employment in compliance with the San Francisco Fair Chance Ordinance

Los Angeles Residents Only:

We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance

Employee Status:

Regular

Relocation:

Domestic

VISA Sponsorship:

No

Travel Requirements:

10%

Flexible Work Arrangements:

Hybrid

Shift:

1st - Day

Valid Driving License:

No

Hazardous Material(s):

N/A

Job Posting End Date:

08/13/2026

*A job posting is effective until 11:59:59PM on the day BEFORE -the listed job posting end date. Please ensure you apply to a job posting no later than the day BEFORE the job posting end date.

Requisition ID:

R400992

#J-18808-Ljbffr

What Merck employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom