The Security Risk & Compliance Analyst supports the organizations global information security program by assisting in the identification, assessment, and management of information security risks and ...
The Security Risk & Compliance Analyst supports the organizations global information security program by assisting in the identification, assessment, and management of information security risks and ...
IT Security GRC Expert, Global
Center Valley, PA · Hybrid
$42.50 - $56.75/hr
The Senior IT Security GRC Analyst (Global) is responsible for the governance, oversight, and lifecycle management of IT Security risk across Olympus. This role ensures that security-related risks ...
IT Security GRC Expert, Global
Center Valley, PA · Hybrid
$42.50 - $56.75/hr
The Senior IT Security GRC Analyst (Global) is responsible for the governance, oversight, and lifecycle management of IT Security risk across Olympus. This role ensures that security-related risks ...
Senior IT Security Systems Analyst
Allentown, PA · On-site
$44.50 - $59.25/hr
Louisville, KY or Providence, RI. #LI-Hybrid #INDPPL The IT Security Systems Analyst will leverage ... Perform risk-based reviews of firewall rule requests and existing rule sets to ensure adherence to ...
Senior IT Security Systems Analyst
Allentown, PA · On-site
$44.50 - $59.25/hr
Louisville, KY or Providence, RI. #LI-Hybrid #INDPPL The IT Security Systems Analyst will leverage ... Perform risk-based reviews of firewall rule requests and existing rule sets to ensure adherence to ...
Senior IT Security Systems Analyst
Allentown, PA · Hybrid
$44.50 - $59.25/hr
Louisville, KY or Providence, RI. #LI-Hybrid #INDPPL The IT Security Systems Analyst will leverage ... Perform risk-based reviews of firewall rule requests and existing rule sets to ensure adherence to ...
Senior IT Security Systems Analyst
Allentown, PA · Hybrid
$44.50 - $59.25/hr
Louisville, KY or Providence, RI. #LI-Hybrid #INDPPL The IT Security Systems Analyst will leverage ... Perform risk-based reviews of firewall rule requests and existing rule sets to ensure adherence to ...
... or analysts * Develop and execute the information security strategy aligned with business objectives and threat landscape * Collaborate with executive leadership on security risk management ...
... or analysts * Develop and execute the information security strategy aligned with business objectives and threat landscape * Collaborate with executive leadership on security risk management ...
... and Analysis Center), CISA (Cybersecurity and Infrastructure Security Agency), ABA (American ... Third-Party Vendor Risk Management Program - Serve as the head coordinator and lead manager ...
... and Analysis Center), CISA (Cybersecurity and Infrastructure Security Agency), ABA (American ... Third-Party Vendor Risk Management Program - Serve as the head coordinator and lead manager ...
... and Analysis Center), CISA (Cybersecurity and Infrastructure Security Agency), ABA (American ... Third-Party Vendor Risk Management Program - Serve as the head coordinator and lead manager ...
... and Analysis Center), CISA (Cybersecurity and Infrastructure Security Agency), ABA (American ... Third-Party Vendor Risk Management Program - Serve as the head coordinator and lead manager ...
GRC Analyst (in-office)
Bethlehem, PA · On-site
Creation of threat and risk analyses. * Coordinate updates to training materials that support the information security policies and procedures. * Setup of training schedules for all Employees and ...
GRC Analyst (in-office)
Bethlehem, PA · On-site
Creation of threat and risk analyses. * Coordinate updates to training materials that support the information security policies and procedures. * Setup of training schedules for all Employees and ...
GRC Analyst (in-office)
Bethlehem, PA · On-site
Creation of threat and risk analyses. * Coordinate updates to training materials that support the information security policies and procedures. * Setup of training schedules for all Employees and ...
GRC Analyst (in-office)
Bethlehem, PA · On-site
Creation of threat and risk analyses. * Coordinate updates to training materials that support the information security policies and procedures. * Setup of training schedules for all Employees and ...
Triage, first categorization of potential security events * Collection of data for further analysis ... Collaborate on the implementation of immediate measures to minimize risk and initiate additional ...
Triage, first categorization of potential security events * Collection of data for further analysis ... Collaborate on the implementation of immediate measures to minimize risk and initiate additional ...
Triage, first categorization of potential security events * Collection of data for further analysis ... Collaborate on the implementation of immediate measures to minimize risk and initiate additional ...
Triage, first categorization of potential security events * Collection of data for further analysis ... Collaborate on the implementation of immediate measures to minimize risk and initiate additional ...
Security Solutions Analyst - Customer Success
$34.62 - $43.27/hr
The Security Analyst supports customer engagements by helping to deliver business and technology ... Collaborate with the EM to develop and maintain detailed project plans, milestones, risk registers ...
Security Solutions Analyst - Customer Success
$34.62 - $43.27/hr
The Security Analyst supports customer engagements by helping to deliver business and technology ... Collaborate with the EM to develop and maintain detailed project plans, milestones, risk registers ...
The Security Analyst supports customer engagements by helping to deliver business and technology ... Collaborate with the EM to develop and maintain detailed project plans, milestones, risk registers ...
The Security Analyst supports customer engagements by helping to deliver business and technology ... Collaborate with the EM to develop and maintain detailed project plans, milestones, risk registers ...
... security risk by working across MSSP resources and regional business and operational teams ... Good analytical and problem-solving skills. * Demonstrable business and tech acumen. Why join ...
... security risk by working across MSSP resources and regional business and operational teams ... Good analytical and problem-solving skills. * Demonstrable business and tech acumen. Why join ...
... security risk by working across MSSP resources and regional business and operational teams ... Good analytical and problem-solving skills. * Demonstrable business and tech acumen. Why join ...
... security risk by working across MSSP resources and regional business and operational teams ... Good analytical and problem-solving skills. * Demonstrable business and tech acumen. Why join ...
Cloud Architect Lead II
Allentown, PA · On-site
$64.25 - $81.75/hr
... a security risk management plan, and execute strategies to mitigate/address identified risk ... Strong analytical skills to assess risks and vulnerabilities in complex systems. PREFERRED ...
Quick apply
Cloud Architect Lead II
Allentown, PA · On-site
$64.25 - $81.75/hr
... a security risk management plan, and execute strategies to mitigate/address identified risk ... Strong analytical skills to assess risks and vulnerabilities in complex systems. PREFERRED ...
Risk & Compliance Manager
Fleetwood, PA · On-site
$80K - $100K/yr
... Security. Primary Responsibilities: · The position serves as the compliance manager for the Bank ... Must have excellent analytical, research, and troubleshooting skills as well as strong written ...
Quick apply
Risk & Compliance Manager
Fleetwood, PA · On-site
$80K - $100K/yr
... Security. Primary Responsibilities: · The position serves as the compliance manager for the Bank ... Must have excellent analytical, research, and troubleshooting skills as well as strong written ...
Cloud Architect
Allentown, PA · Remote
$64.25 - $81.75/hr
... a security risk management plan, and execute strategies to mitigate/address identified risk ... Strong analytical skills to assess risks and vulnerabilities in complex systems. ALLERE GROUP is a ...
Quick apply
Cloud Architect
Allentown, PA · Remote
$64.25 - $81.75/hr
... a security risk management plan, and execute strategies to mitigate/address identified risk ... Strong analytical skills to assess risks and vulnerabilities in complex systems. ALLERE GROUP is a ...
Risk & Compliance Manager
Fleetwood, PA · On-site
$80K - $100K/yr
... Security. Primary Responsibilities: • The position serves as the compliance manager for the Bank ... Excellent analytical and research skills * Strong written and verbal communication skills The ideal ...
Risk & Compliance Manager
Fleetwood, PA · On-site
$80K - $100K/yr
... Security. Primary Responsibilities: • The position serves as the compliance manager for the Bank ... Excellent analytical and research skills * Strong written and verbal communication skills The ideal ...
Risk & Compliance Manager
$80K - $100K/yr
... Security. Primary Responsibilities: · The position serves as the compliance manager for the Bank ... Excellent analytical and research skills * Strong written and verbal communication skills The ideal ...
Risk & Compliance Manager
$80K - $100K/yr
... Security. Primary Responsibilities: · The position serves as the compliance manager for the Bank ... Excellent analytical and research skills * Strong written and verbal communication skills The ideal ...
Security Risk Analyst information
See Allentown, PA salary details
$10.20 - $15.55
2% of jobs
$15.55 - $20.90
0% of jobs
$20.90 - $26.24
1% of jobs
$26.24 - $31.59
1% of jobs
$31.59 - $36.94
1% of jobs
$40.95 is the 25th percentile. Wages below this are outliers.
$36.94 - $42.29
26% of jobs
$42.29 - $47.64
11% of jobs
The median wage is $49.55 / hr.
$47.64 - $52.99
22% of jobs
$52.99 - $58.33
9% of jobs
$58.75 is the 75th percentile. Wages above this are outliers.
$58.33 - $63.68
17% of jobs
$63.68 - $69.03
9% of jobs
$10
$49
$69
How much do security risk analyst jobs pay per hour?
What does a security risk analyst do?
What are the key skills and qualifications needed to thrive as a security risk analyst?
What are some common challenges security risk analysts face when collaborating with other departments?
What is the difference between Security Risk Analyst vs Security Analyst?
| Aspect | Security Risk Analyst | Security Analyst |
|---|---|---|
| Certifications | CompTIA Security+, CISSP, CISA | CompTIA Security+, CISSP, CEH |
| Work Environment | Risk assessment, vulnerability analysis, policy development | Monitoring security systems, incident response, security audits |
| Employer & Industry Usage | Financial, healthcare, government sectors focusing on risk mitigation | IT departments across various industries focusing on security operations |
While both roles focus on cybersecurity, Security Risk Analysts primarily assess and manage potential security threats and vulnerabilities, emphasizing risk mitigation strategies. Security Analysts tend to monitor security systems, respond to incidents, and ensure ongoing security measures. Both roles often require similar certifications and work environments but differ in their core responsibilities within cybersecurity teams.
What is a security risk analyst?

Full-time
Re-posted 26 days ago
Victaulic rating
7.2
Based on 35 frontline employees who took The Breakroom Quiz
351st of 536 rated manufacturers
Job description
Job Description
The Security Risk & Compliance Analyst supports the organizations global information security program by assisting in the identification, assessment, and management of information security risks and compliance demands across Victaulic's entire organization. This position plays an integral role in ensuring the company meets its obligations under domestic and international regulatory frameworks, including but not limited to, NIST CSF, ISO27001, CMMC and the EU's NIS2 Directive. The analyst will work closely with internal stakeholders, external auditors, and third-party vendors to support a culture of security awareness and continuous compliance improvement.
The ideal candidate for this role will have knowledge of, if not actual experience, in the processes of obtaining and maintaining compliance with security frameworks as well as an understanding of industry standard Information Technology auditing.
Responsibilities
Risk Assessment & Management
Assist in conducting information security risk assessments across business units, systems, and processes in accordance with established methodologies.
Document risk findings, assign risk ratings, and track remediation activities through the risk register.
Support the development and maintenance of risk treatment plans in coordination with system owners and IT teams.
Participate in annual and ad hoc enterprise risk reviews, contributing analysis and supporting materials.
Compliance & Framework Management
Support compliance activities related to NIST Cybersecurity Framework (CSF), ISO/IEC 27001, CMMC (Cybersecurity Maturity Model Certification), and the EU NIS2 Directive.
Conduct gap analyses against applicable frameworks and assist in developing remediation roadmaps.
Maintain compliance documentation, including policies, procedures, control evidence, and assessment reports.
Monitor regulatory changes and emerging framework updates; summarize implications for the security program.
Third-Party & Audit Management
Coordinate and support third-party security audits and assessments, including scheduling, evidence collection, and stakeholder communication.
Assist in managing vendor risk assessments for new and existing third-party vendors and suppliers.
Track audit findings and corrective action plans, ensuring timely remediation and closure.
Serve as a liaison between internal teams and external auditors during certification audits.
Policy, Documentation & Awareness
Assist in drafting, reviewing, and updating information security policies, standards, and procedures.
Support the delivery of security awareness training and phishing simulation programs.
Maintain organized records of all compliance and risk management activities in the Governance, Risk & Compliance platform.
Collaboration & Reporting
Collaborate with IT, Legal, Operations, and other business functions to integrate security requirements into business processes.
Prepare regular status reports and metrics dashboards for management review.
Contribute to the continuous improvement of the information security program by identifying process gaps and recommending enhancements.
Qualifications
Technical Experience
Foundational understanding of information security principles, including confidentiality, integrity, and availability (CIA).
Basic understanding of risk assessment methodologies and risk management concepts.
Familiarity with third-party risk management and audit processes.
Strong analytical and problem-solving skills with attention to detail.
Capacity to understand legacy and progressive technology and security controls along with respective risk.
Working knowledge of technologies such as cloud computing, DevOps, and application security is required.
General Requirements
Analytical Thinking - applies structured reasoning to evaluate risk and compliance data objectively
Integrity & Accountability - Handles sensitive security information with discretion and professionalism.
Communication - Clearly translates security requirements and findings for varied audiences across the organization
Continuous Learning - Proactively keeps pace with evolving security frameworks, threats, and regulatory requirements
Collaboration - Builds effective working relationships across IT, operations, and business functions globablly
Detail Orientation - Produces thorough, accurate documentation and maintains meticulous records of compliance activities
Education & Certifications
0 - 2 years' experience in information security, IT audit, risk management, or a related field.
Bachelor's degree, cybersecurity certification, or equivalent experience in an information security or related field.
A minimum of an entry-level certification such as the CompTIA Security+ certification
Additional Risk & Compliance certification(s), such as CISA, a plus
Work Environment & Physical Requirements
This position is primarily office-based with hybrid flexibility. The role may require occasional visits to manufacturing facilities domestically and internationally. Ability to work across global time zones may be required for coordination with European and Asian teams.
Victaulic is an Equal Employment Opportunity (EOE/M/F/Vets/Disabled) employer and welcomes all qualified applicants. Applicants will receive fair and impartial consideration without regard to race, gender, color, religion, national origin, age, disability, veteran status, sexual orientation, genetic data, or other legally protected status. (Background checks may be required as part of our pre-employment process).
What Victaulic employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Victaulic
Sourced by ZipRecruiter
Industry
Industrial machinery manufacturing
Company size
1,001 - 5,000 Employees
Headquarters location
Easton, PA, US
Year founded
1919