1

Security Risk Analyst Jobs in Pennsylvania (NOW HIRING)

The Credit Risk Analyst role will primarily focus on expanding coverage of securities lending and banking relationships for the Personal Wealth(PW)Division, supporting key enterprise priorities. This ...

New

The Credit Risk Analyst role will primarily focus on expanding coverage of securities lending and banking relationships for the Personal Wealth (PW) Division, supporting key enterprise priorities.

The Credit Risk Analyst role will primarily focus on expanding coverage of securities lending and banking relationships for the Personal Wealth (P W) Division, supporting key enterprise priorities.

Senior Security Analyst

Exton, PA · On-site

$92K - $121K/yr

  • Medical

  • Retirement

  • PTO

Governance, Risk & Compliance (GRC) * Execute and coordinate external security audits and assurance ... Analyze vulnerability intelligence and emerging threats. * Prioritize remediation efforts based on ...

New

LOB Risk Lead

Pittsburgh, PA

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... analyses to support risk measurement activities. Partners with Technology and Information Security teams to identify key risk indicators, control performance metrics, risk concentration measures, and ...

LOB Risk Lead

Pittsburgh, PA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... effectiveness analyses to support risk measurement activities. • Partners with Technology and Information Security teams to identify key risk indicators, control performance metrics, risk ...

Showing results 21-40

Security Risk Analyst information

See Pennsylvania salary details

$10

$50

$70

How much do security risk analyst jobs pay per hour?

As of Aug 15, 2026, the average hourly pay for security risk analyst in Pennsylvania is $50.53, according to ZipRecruiter salary data. Most workers in this role earn between $40.96 and $60.24 per hour, depending on experience, location, and employer.

What does a security risk analyst do?

A Security Risk Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security measures, conduct vulnerability assessments, and recommend strategies to protect against threats such as cyberattacks, data breaches, and unauthorized access. Their work helps ensure that a company's digital assets remain safe and compliant with industry regulations. Security Risk Analysts collaborate with IT teams and management to implement effective security policies and respond to incidents as needed.

What are the key skills and qualifications needed to thrive as a security risk analyst?

To thrive as a Security Risk Analyst, you need a strong background in risk assessment, information security principles, and analytical thinking, often supported by a degree in cybersecurity, IT, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security assessment tools, and certifications like CISSP or CISM is highly valuable. Excellent communication, attention to detail, and problem-solving abilities help you translate complex risks for varied stakeholders and drive mitigation strategies. These skills and qualities are crucial for identifying vulnerabilities, minimizing threats, and maintaining organizational security and compliance.

What are some common challenges security risk analysts face when collaborating with other departments?

Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks. A common challenge is bridging the gap between technical security requirements and business objectives, as not all stakeholders may have a cybersecurity background. Effective communication and education are key to ensuring that risk recommendations are understood and adopted. Additionally, prioritizing risks with limited resources and balancing security with operational needs can be complex, requiring strong collaboration and negotiation skills.

What is the difference between Security Risk Analyst vs Security Analyst?

AspectSecurity Risk AnalystSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, vulnerability analysis, policy developmentMonitoring security systems, incident response, security audits
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk mitigationIT departments across various industries focusing on security operations

While both roles focus on cybersecurity, Security Risk Analysts primarily assess and manage potential security threats and vulnerabilities, emphasizing risk mitigation strategies. Security Analysts tend to monitor security systems, respond to incidents, and ensure ongoing security measures. Both roles often require similar certifications and work environments but differ in their core responsibilities within cybersecurity teams.

What is a security risk analyst?

A security risk analyst is a professional who identifies, assesses, and mitigates security threats to an organization’s information systems. They analyze vulnerabilities, develop security strategies, and often use tools like risk assessment frameworks and security software to protect data and infrastructure.

What are popular job titles related to Security Risk Analyst jobs in Pennsylvania?

For Security Risk Analyst jobs in Pennsylvania, the most frequently searched job titles are:

What job categories do people searching Security Risk Analyst jobs in Pennsylvania look for?

The top searched job categories for Security Risk Analyst jobs in Pennsylvania are:

What cities in Pennsylvania are hiring for Security Risk Analyst jobs?

Cities in Pennsylvania with the most Security Risk Analyst job openings:

Infographic showing various Security Risk Analyst job openings in Pennsylvania as of August 2026, with employment types broken down into 79% Full Time, 18% Part Time, 2% Contract, and 1% Nights. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $105,100 per year, or $50.5 per hour.

Governance, Risk & Compliance Analyst, Specialist

Vangard, Inc.

Malvern, PA

Full-time

Re-posted 19 hours ago


Job description

  • Works with Enterprise Security and Fraud subdivisions and business units as the technical authority regarding security of application and systems software, equipment, and related capabilities and performance characteristics to evaluate their effectiveness at meeting defined requirements, determining integration requirements and identifying ramifications on operations of their implementation.
  • Supports the development and maintenance of a portfolio of global security and fraud policies and standards. Monitors and maintains the lifecycle of the portfolio. Responsible for oversight of management and decisions related to methodology and policy for all Security and fraud functions.
  • Advises key stakeholders and security policy owners during policy and standards discussions. Interfaces with clients on all inquiries related to Information and IT Security and fraud capabilities.
  • Works with Compliance and Regional Security and Fraud teams to understand global regulatory requirements, develop global and regional policies and standards, and oversee implementation. Interfaces with external regulators for Information and IT Security and Fraud.
  • Reviews and analyzes current and proposed policy and standards directives and IT technical issues which may affect the implementation of Information Security and Fraud across the enterprise.
  • Recommends, develops, implements and coordinates new security policies, standards, controls and operating doctrine at all levels across the company. Interprets policy relating to Vanguard information security and frau functions and provides guidance, as required.
  • Defines and implements automations to accelerate delivery and improve effectiveness.
  • Defines and implements data-driven approaches and dashboards to predict risk issues, develop solutions, and partner with key owners and stakeholders.
  • Designs, implements and supports modernized GRC process and tool capabilities.
  • Participates in special projects and performs other duties as assigned.

Qualifications

  • Seven years related work experience, Information Security or fraud experience required.
  • Undergraduate degree or equivalent combination of training and experience.
  • In-depth knowledge of relevant frameworks and standards (i.e., NIST CSF, NIST 800-53, CIS Controls, ISO 27002) and financial services industry cyber regulations and guidelines, and considered an expert in the domain.
  • Demonstrated experience with GRC solutions platform and automation capabilities.
  • Excellent communication and influencing skills.
  • Influence key stakeholders and security policy and control owners.
  • Professional certification (CISSP, CISM, CompTIA, SANS, ISC2) preferred.

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a mission-we're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.