1

Security Risk Analyst Jobs in Allentown, PA (NOW HIRING)

Cloud Architect Lead II

Allentown, PA · On-site

$64.25 - $81.75/hr

... a security risk management plan, and execute strategies to mitigate/address identified risk ... Strong analytical skills to assess risks and vulnerabilities in complex systems. PREFERRED ...

Risk & Compliance Manager

Fleetwood, PA · On-site

$80K - $100K/yr

... Security. Primary Responsibilities: · The position serves as the compliance manager for the Bank ... Must have excellent analytical, research, and troubleshooting skills as well as strong written ...

Cloud Architect

Allentown, PA · Remote

$64.25 - $81.75/hr

... a security risk management plan, and execute strategies to mitigate/address identified risk ... Strong analytical skills to assess risks and vulnerabilities in complex systems. ALLERE GROUP is a ...

Risk & Compliance Manager

Fleetwood, PA · On-site

$80K - $100K/yr

... Security. Primary Responsibilities: • The position serves as the compliance manager for the Bank ... Excellent analytical and research skills * Strong written and verbal communication skills The ideal ...

... Security. Primary Responsibilities: · The position serves as the compliance manager for the Bank ... Excellent analytical and research skills * Strong written and verbal communication skills The ideal ...

next page

Showing results 1-20

Security Risk Analyst information

See Allentown, PA salary details

$10

$49

$69

How much do security risk analyst jobs pay per hour?

As of Aug 7, 2026, the average hourly pay for security risk analyst in Allentown, PA is $49.74, according to ZipRecruiter salary data. Most workers in this role earn between $40.34 and $59.33 per hour, depending on experience, location, and employer.

What does a security risk analyst do?

A Security Risk Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security measures, conduct vulnerability assessments, and recommend strategies to protect against threats such as cyberattacks, data breaches, and unauthorized access. Their work helps ensure that a company's digital assets remain safe and compliant with industry regulations. Security Risk Analysts collaborate with IT teams and management to implement effective security policies and respond to incidents as needed.

What are the key skills and qualifications needed to thrive as a security risk analyst?

To thrive as a Security Risk Analyst, you need a strong background in risk assessment, information security principles, and analytical thinking, often supported by a degree in cybersecurity, IT, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security assessment tools, and certifications like CISSP or CISM is highly valuable. Excellent communication, attention to detail, and problem-solving abilities help you translate complex risks for varied stakeholders and drive mitigation strategies. These skills and qualities are crucial for identifying vulnerabilities, minimizing threats, and maintaining organizational security and compliance.

What are some common challenges security risk analysts face when collaborating with other departments?

Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks. A common challenge is bridging the gap between technical security requirements and business objectives, as not all stakeholders may have a cybersecurity background. Effective communication and education are key to ensuring that risk recommendations are understood and adopted. Additionally, prioritizing risks with limited resources and balancing security with operational needs can be complex, requiring strong collaboration and negotiation skills.

What is the difference between Security Risk Analyst vs Security Analyst?

AspectSecurity Risk AnalystSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, vulnerability analysis, policy developmentMonitoring security systems, incident response, security audits
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk mitigationIT departments across various industries focusing on security operations

While both roles focus on cybersecurity, Security Risk Analysts primarily assess and manage potential security threats and vulnerabilities, emphasizing risk mitigation strategies. Security Analysts tend to monitor security systems, respond to incidents, and ensure ongoing security measures. Both roles often require similar certifications and work environments but differ in their core responsibilities within cybersecurity teams.

What is a security risk analyst?

A security risk analyst is a professional who identifies, assesses, and mitigates security threats to an organization’s information systems. They analyze vulnerabilities, develop security strategies, and often use tools like risk assessment frameworks and security software to protect data and infrastructure.
What are popular job titles related to Security Risk Analyst jobs in Allentown, PA? For Security Risk Analyst jobs in Allentown, PA, the most frequently searched job titles are:
What job categories do people searching Security Risk Analyst jobs in Allentown, PA look for? The top searched job categories for Security Risk Analyst jobs in Allentown, PA are:
What cities near Allentown, PA are hiring for Security Risk Analyst jobs? Cities near Allentown, PA with the most Security Risk Analyst job openings:
Infographic showing various Security Risk Analyst job openings in Allentown, PA as of August 2026, with employment types broken down into 79% Full Time, and 21% Contract. Highlights an 79% In-person, 5% Hybrid, and 16% Remote job distribution, with an average salary of $103,467 per year, or $49.7 per hour.

Information Security - Risk & Compliance Analyst

Victaulic

Easton, PA • Hybrid

Full-time

Re-posted 26 days ago


Victaulic rating

7.2

Company rating: 7.2 out of 10

Based on 35 frontline employees who took The Breakroom Quiz

351st of 536 rated manufacturers


Job description

Job Description

The Security Risk & Compliance Analyst supports the organizations global information security program by assisting in the identification, assessment, and management of information security risks and compliance demands across Victaulic's entire organization. This position plays an integral role in ensuring the company meets its obligations under domestic and international regulatory frameworks, including but not limited to, NIST CSF, ISO27001, CMMC and the EU's NIS2 Directive. The analyst will work closely with internal stakeholders, external auditors, and third-party vendors to support a culture of security awareness and continuous compliance improvement.

The ideal candidate for this role will have knowledge of, if not actual experience, in the processes of obtaining and maintaining compliance with security frameworks as well as an understanding of industry standard Information Technology auditing.

Responsibilities

Risk Assessment & Management

Assist in conducting information security risk assessments across business units, systems, and processes in accordance with established methodologies.

Document risk findings, assign risk ratings, and track remediation activities through the risk register.

Support the development and maintenance of risk treatment plans in coordination with system owners and IT teams.

Participate in annual and ad hoc enterprise risk reviews, contributing analysis and supporting materials.

Compliance & Framework Management

Support compliance activities related to NIST Cybersecurity Framework (CSF), ISO/IEC 27001, CMMC (Cybersecurity Maturity Model Certification), and the EU NIS2 Directive.

Conduct gap analyses against applicable frameworks and assist in developing remediation roadmaps.

Maintain compliance documentation, including policies, procedures, control evidence, and assessment reports.

Monitor regulatory changes and emerging framework updates; summarize implications for the security program.

Third-Party & Audit Management

Coordinate and support third-party security audits and assessments, including scheduling, evidence collection, and stakeholder communication.

Assist in managing vendor risk assessments for new and existing third-party vendors and suppliers.

Track audit findings and corrective action plans, ensuring timely remediation and closure.

Serve as a liaison between internal teams and external auditors during certification audits.

Policy, Documentation & Awareness

Assist in drafting, reviewing, and updating information security policies, standards, and procedures.

Support the delivery of security awareness training and phishing simulation programs.

Maintain organized records of all compliance and risk management activities in the Governance, Risk & Compliance platform.

Collaboration & Reporting

Collaborate with IT, Legal, Operations, and other business functions to integrate security requirements into business processes.

Prepare regular status reports and metrics dashboards for management review.

Contribute to the continuous improvement of the information security program by identifying process gaps and recommending enhancements.

Qualifications

Technical Experience

Foundational understanding of information security principles, including confidentiality, integrity, and availability (CIA).

Basic understanding of risk assessment methodologies and risk management concepts.

Familiarity with third-party risk management and audit processes.

Strong analytical and problem-solving skills with attention to detail.

Capacity to understand legacy and progressive technology and security controls along with respective risk.

Working knowledge of technologies such as cloud computing, DevOps, and application security is required.

General Requirements

Analytical Thinking - applies structured reasoning to evaluate risk and compliance data objectively

Integrity & Accountability - Handles sensitive security information with discretion and professionalism.

Communication - Clearly translates security requirements and findings for varied audiences across the organization

Continuous Learning - Proactively keeps pace with evolving security frameworks, threats, and regulatory requirements

Collaboration - Builds effective working relationships across IT, operations, and business functions globablly

Detail Orientation - Produces thorough, accurate documentation and maintains meticulous records of compliance activities

Education & Certifications

0 - 2 years' experience in information security, IT audit, risk management, or a related field.

Bachelor's degree, cybersecurity certification, or equivalent experience in an information security or related field.

A minimum of an entry-level certification such as the CompTIA Security+ certification

Additional Risk & Compliance certification(s), such as CISA, a plus

Work Environment & Physical Requirements

This position is primarily office-based with hybrid flexibility. The role may require occasional visits to manufacturing facilities domestically and internationally. Ability to work across global time zones may be required for coordination with European and Asian teams.

Victaulic is an Equal Employment Opportunity (EOE/M/F/Vets/Disabled) employer and welcomes all qualified applicants. Applicants will receive fair and impartial consideration without regard to race, gender, color, religion, national origin, age, disability, veteran status, sexual orientation, genetic data, or other legally protected status. (Background checks may be required as part of our pre-employment process).


What Victaulic employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom