1

Security Risk Analyst Jobs in Malvern, PA (NOW HIRING)

Global Risk and Security (GR&S) at Vanguard enables business strategy, protects client and Vanguard ... Use analytics and model insights to identify trends, refine strategies, and improve detection ...

The Security Analyst will frequently engage with both technical teams and business process owners ... Analyze and prioritize risk, vulnerability, and compliance findings to define remediation ...

Global Risk and Security (GR&S) at Vanguard enables business strategy, protects client and Vanguard ... Use analytics and model insights to identify trends, refine strategies, and improve detection ...

The GRC Security Analyst II will focus on ensuring the security and integrity of the organization ... Responsibilities : • Manage execution of both enterprise-wide and focused risk, threat, and ...

Showing results 21-40

Security Risk Analyst information

See Malvern, PA salary details

$10

$49

$68

How much do security risk analyst jobs pay per hour?

As of Aug 21, 2026, the average hourly pay for security risk analyst in Malvern, PA is $49.46, according to ZipRecruiter salary data. Most workers in this role earn between $40.10 and $58.99 per hour, depending on experience, location, and employer.

What does a security risk analyst do?

A Security Risk Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security measures, conduct vulnerability assessments, and recommend strategies to protect against threats such as cyberattacks, data breaches, and unauthorized access. Their work helps ensure that a company's digital assets remain safe and compliant with industry regulations. Security Risk Analysts collaborate with IT teams and management to implement effective security policies and respond to incidents as needed.

What are the key skills and qualifications needed to thrive as a security risk analyst?

To thrive as a Security Risk Analyst, you need a strong background in risk assessment, information security principles, and analytical thinking, often supported by a degree in cybersecurity, IT, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security assessment tools, and certifications like CISSP or CISM is highly valuable. Excellent communication, attention to detail, and problem-solving abilities help you translate complex risks for varied stakeholders and drive mitigation strategies. These skills and qualities are crucial for identifying vulnerabilities, minimizing threats, and maintaining organizational security and compliance.

What are some common challenges security risk analysts face when collaborating with other departments?

Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks. A common challenge is bridging the gap between technical security requirements and business objectives, as not all stakeholders may have a cybersecurity background. Effective communication and education are key to ensuring that risk recommendations are understood and adopted. Additionally, prioritizing risks with limited resources and balancing security with operational needs can be complex, requiring strong collaboration and negotiation skills.

What is the difference between Security Risk Analyst vs Security Analyst?

AspectSecurity Risk AnalystSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, vulnerability analysis, policy developmentMonitoring security systems, incident response, security audits
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk mitigationIT departments across various industries focusing on security operations

While both roles focus on cybersecurity, Security Risk Analysts primarily assess and manage potential security threats and vulnerabilities, emphasizing risk mitigation strategies. Security Analysts tend to monitor security systems, respond to incidents, and ensure ongoing security measures. Both roles often require similar certifications and work environments but differ in their core responsibilities within cybersecurity teams.

What is a security risk analyst?

A security risk analyst is a professional who identifies, assesses, and mitigates security threats to an organization’s information systems. They analyze vulnerabilities, develop security strategies, and often use tools like risk assessment frameworks and security software to protect data and infrastructure.

What are popular job titles related to Security Risk Analyst jobs in Malvern, PA?

For Security Risk Analyst jobs in Malvern, PA, the most frequently searched job titles are:

What cities near Malvern, PA are hiring for Security Risk Analyst jobs?

Cities near Malvern, PA with the most Security Risk Analyst job openings:

Infographic showing various Security Risk Analyst job openings in Malvern, PA as of August 2026, with employment types broken down into 85% Full Time, 5% Part Time, and 10% Contract. Highlights an 80% In-person, 15% Hybrid, and 5% Remote job distribution, with an average salary of $102,885 per year, or $49.5 per hour.

Security Governance Analyst - New Grad - Susquehanna International Group

Susquehanna International Group

Bala Cynwyd, PA • On-site

Full-time

Posted 28 days ago


Job description

Overview
As a Security Risk & Governance Analyst, you will be a key contributor to our Security Assurance team, doing hands-on work across the firm's cybersecurity governance, risk, and compliance (GRC) program. From day one you'll take on real work, contribute to the team's core efforts, and have a direct impact on the firm's security posture - while building the foundational skills for a long career in cybersecurity.
Success in this role hinges on your ability to collaborate with stakeholders across technical, legal, compliance, and operational teams. Working alongside experienced analysts, you'll contribute to security control assessments, third-party security assessments, and policy and exception reviews - gathering evidence, documenting findings, and tracking remediation. You'll help monitor the firm's adherence to cybersecurity regulatory requirements and internal policies, flagging areas of concern for stakeholder review, while also contributing to the automation and tooling that keeps our GRC program running efficiently.
A genuine interest in cybersecurity and risk - paired with curiosity, attention to detail, and a willingness to ask questions - will set you up for success. You'll thrive in our collaborative environment, where curiosity is celebrated and every challenge is an opportunity to grow. At Susquehanna, we invest in our people - you'll learn directly from experienced practitioners on a team that values curiosity over credentials.
In this role you will:

  • Identify opportunities and build the tools to improve the efficiency and effectiveness of our GRC program through automation and AI (e.g., PowerShell, Python, and LLMs).
  • Support the security policy exception and risk-decision workflow, gathering the information needed for stakeholder review.
  • Support third-party (vendor) security assessments - gathering documentation, evaluating vendors' security controls, and summarizing identified risks for stakeholder review.
  • Help manage security control gaps - assessing newly identified gaps, updating records, and tracking remediation to closure.
  • Assist in coordinating internal and external audits, collecting documentation and tracking responses to findings.
  • Help keep cybersecurity policies and standards current and accurate.
  • Support security awareness and training efforts that promote strong cybersecurity behaviors across the firm.

What we're looking for
  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a related field.
  • 0-2 years of experience in cybersecurity, IT, risk, or compliance - internship, co-op, or academic experience welcome.
  • Strong written and verbal communication skills, with the ability to document findings clearly and summarize information for different audiences.
  • A foundational understanding of risk - how to assess it, weigh tradeoffs, and prioritize what matters.
  • Scripting and automation skills (e.g., PowerShell, Python, AI) - you'll contribute and build new tooling for the team.
  • Hands-on experience using AI tools to get work done more effectively.

If you're a recruiting agency and want to partner with us, please reach out to recruiting@sig.com . Any resume or referral submitted in the absence of a signed agreement will not be eligible for an agency fee.
#LI-RH1