1

Security Risk Analyst Jobs in Philadelphia, PA (NOW HIRING)

The GRC Security Analyst II will focus on ensuring the security and integrity of the organization ... Responsibilities : • Manage execution of both enterprise-wide and focused risk, threat, and ...

Sr. Specialist - Information Security

Philadelphia, PA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Prepare security risk analysis reports and develop response procedures to support informed decision-making across the organization. Required Qualifications * Active certification from a recognized ...

Sr. Specialist - Information Security

Philadelphia, PA · Hybrid

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Prepare security risk analysis reports and develop response procedures to support informed decision-making across the organization. Required Qualifications * Active certification from a recognized ...

... risk analysis, proactively identify potential issues before risk is realized, and support executive reporting on application security exposure and broader cybersecurity risk. You will also play a key ...

Senior Legal Director, Cyber & Data Risk

Titusville, NJ · On-site

$99K - $128K/yr

  • Retirement

  • PTO

Serve as the principal legal advisor to the Chief Information Security Officer (CISO) and Information Security & Risk Management (ISRM) Leadership Team, providing strategic counsel on cybersecurity ...

... risk analysis, proactively identify potential issues before risk is realized, and support executive reporting on application security exposure and broader cybersecurity risk. You will also play a key ...

Engineer

New Castle, DE · On-site

$100K - $110K/yr

We are seeking a skilled Information Security Analyst to support enterprise security operations with a strong focus on vulnerability management, patching, and risk remediation. The ideal candidate ...

Credit Portfolio Senior Analyst

Wilmington, DE · On-site

$112.60 - $138/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Develop quantitative techniques to inform securities and equities investing, pricing, and valuation ... Create mathematical or statistical models for risk management, asset optimization, pricing, or ...

Showing results 41-60

Security Risk Analyst information

See Philadelphia, PA salary details

$10

$50

$70

How much do security risk analyst jobs pay per hour?

As of Aug 19, 2026, the average hourly pay for security risk analyst in Philadelphia, PA is $50.87, according to ZipRecruiter salary data. Most workers in this role earn between $41.25 and $60.62 per hour, depending on experience, location, and employer.

What does a security risk analyst do?

A Security Risk Analyst is responsible for identifying, assessing, and mitigating risks to an organization's information systems and data. They analyze security measures, conduct vulnerability assessments, and recommend strategies to protect against threats such as cyberattacks, data breaches, and unauthorized access. Their work helps ensure that a company's digital assets remain safe and compliant with industry regulations. Security Risk Analysts collaborate with IT teams and management to implement effective security policies and respond to incidents as needed.

What are the key skills and qualifications needed to thrive as a security risk analyst?

To thrive as a Security Risk Analyst, you need a strong background in risk assessment, information security principles, and analytical thinking, often supported by a degree in cybersecurity, IT, or a related field. Familiarity with risk management frameworks (such as NIST or ISO 27001), security assessment tools, and certifications like CISSP or CISM is highly valuable. Excellent communication, attention to detail, and problem-solving abilities help you translate complex risks for varied stakeholders and drive mitigation strategies. These skills and qualities are crucial for identifying vulnerabilities, minimizing threats, and maintaining organizational security and compliance.

What are some common challenges security risk analysts face when collaborating with other departments?

Security Risk Analysts often work closely with IT, compliance, and business units to assess and mitigate risks. A common challenge is bridging the gap between technical security requirements and business objectives, as not all stakeholders may have a cybersecurity background. Effective communication and education are key to ensuring that risk recommendations are understood and adopted. Additionally, prioritizing risks with limited resources and balancing security with operational needs can be complex, requiring strong collaboration and negotiation skills.

What is the difference between Security Risk Analyst vs Security Analyst?

AspectSecurity Risk AnalystSecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentRisk assessment, vulnerability analysis, policy developmentMonitoring security systems, incident response, security audits
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk mitigationIT departments across various industries focusing on security operations

While both roles focus on cybersecurity, Security Risk Analysts primarily assess and manage potential security threats and vulnerabilities, emphasizing risk mitigation strategies. Security Analysts tend to monitor security systems, respond to incidents, and ensure ongoing security measures. Both roles often require similar certifications and work environments but differ in their core responsibilities within cybersecurity teams.

What is a security risk analyst?

A security risk analyst is a professional who identifies, assesses, and mitigates security threats to an organization’s information systems. They analyze vulnerabilities, develop security strategies, and often use tools like risk assessment frameworks and security software to protect data and infrastructure.

What are popular job titles related to Security Risk Analyst jobs in Philadelphia, PA?

For Security Risk Analyst jobs in Philadelphia, PA, the most frequently searched job titles are:

What job categories do people searching Security Risk Analyst jobs in Philadelphia, PA look for?

The top searched job categories for Security Risk Analyst jobs in Philadelphia, PA are:

What cities near Philadelphia, PA are hiring for Security Risk Analyst jobs?

Cities near Philadelphia, PA with the most Security Risk Analyst job openings:

Infographic showing various Security Risk Analyst job openings in Philadelphia, PA as of August 2026, with employment types broken down into 85% Full Time, 12% Part Time, and 3% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $105,801 per year, or $50.9 per hour.

GRC Security Analyst II

Aqua

Bryn Mawr, PA • On-site

Full-time

Re-posted 22 days ago


Job description

Job Summary:
Essential Utilities, Inc. delivers safe and reliable services to improve quality of life for communities. The GRC Security Analyst II will focus on ensuring the security and integrity of the organization’s information systems, specifically managing risk and vulnerability assessments and compliance efforts.
Responsibilities:
• Manage execution of both enterprise-wide and focused risk, threat, and vulnerability assessments, including but not limited to Security Awareness, Vulnerability, Configuration, and Third-Party Assessments.
• Analyze and prioritize risk, vulnerability, and compliance findings to define remediation priorities considering all available data sources; partnering with technology and business stakeholders to socialize and implement remediation plans.
• Define and manage qualitative and quantitative metrics and reporting to measure the success of vulnerability, third party, security awareness, security awareness, configuration, and asset management remediations.
• Ability to lead ongoing vulnerability management processes, including working with IT and business stakeholders to prepare vulnerability remediation plans, track progress, and reduce overall vulnerability exposures.
• Participate in development, implementation and operation of control/compliance frameworks and security best practices based on ISO 27001/27002, NIST (800-30, Cyber Security Framework/CSF), COBIT, Critical Security Controls, CIS Configuration Benchmarks.
• Monitor compliance with security configuration standards for servers, endpoints, software, and networking platforms based on CIS Benchmarks.
• Work closely with IT, development, and operations teams to ensure the integration of security practices into the software development lifecycle (SDLC) and IT operations.
• Lead or assist with vendor and 3rd party risk assessments.
• Create/maintain documentation of security solutions, services, configurations, and processes.
• Work closely with engineers focused on intrusion detection, incident response and security operations to manage risk related to existing and emerging threats.
• Collaborate with other security engineers to analyze, process, integrate, communicate, and respond to threat intelligence.
• Ability to participate in or lead development, improvements and updates to continually improve security controls, policies, guidelines, processes and procedures.
• Develop and deliver security awareness training programs for employees to enhance their understanding of security best practice to ensure that security and risk management continue to be integrated into the corporate culture.
• Lead development and operation of the security awareness program to ensure that security and risk management continue to be integrated into the corporate culture.
• Implement and maintain controls for compliance and privacy. Act as liaison to internal and external audit teams as needed.
• Provide escalation support for the Information Technology Help Desk as required.
• Ability to work off hours maintenance windows and participate in rotating on call shift periodically.
• Ability to work alone or function effectively as part of a team.
• All other duties as assigned by management.
Qualifications:
Required:
• Bachelors in Information Technology, Computer Science, Cyber Security, Security and Risk Analysis, Information Assurance.
• 3-5 years of previous Governance & Risk experience
• Candidates must have a minimum of one of the following certifications or will be required to obtain within the first 12 months: CISSP, GIAC (GSEC, GSNA), CRISC, CISA, CISM, CCSP, SSCP, CAP, CSSLP, CSX Practitioner
• Experience working with assessment tools such as Qualys Policy Compliance and CIS-CAT.
• Experience developing and using Qualys, or other vulnerability management, platforms with experience in multiple modules and/or areas: Vulnerability Management, Policy Compliance, Continuous Monitoring, Policy Compliance, Web Application Scanning and Asset Management.
• Experience leading security awareness program development including leading regular phishing assessment campaigns, creating innovative security awareness campaigns using solution provider and custom-developed tools/trainings designed to be flexible and adaptable across a diverse employee population (executives, engineering, marketing and communications, finance, customer service, etc.), and participating in aligning the security awareness program with the enterprise’s greatest risks and measure the impact in risk reduction from security awareness efforts.
• GRC platform experience, with RSA Archer knowledge a strong positive.
• Strong written and verbal communication skills are required as this position will be responsible for working directly with technical teams and business stakeholders.
• Demonstrates strong organizational skills and the ability to multi-task, prioritize workload and delegate responsibilities.
• Strong analytical skills for assessing and prioritizing security risks.
• Ability to promote a security-conscious culture within the organization.
• Ability to adapt to evolving threats, technologies, and organizational needs.
• Ability to understand and integrate security into project and application lifecycles for enterprise IT systems.
• Minimum of 3 to 5 years experience in Information Technology focusing on information security auditing, risk analysis and vulnerability management.
• General knowledge of the following technologies from a security perspective: Active Directory, database platforms, web server platforms, Middleware, PKI, cloud computing, Office 365 and Azure.
• Experience using statistical, quantitative, and qualitative analysis techniques.
• Proactive approach to staying informed on the latest security threats, vulnerabilities, and industry best practices.
Company:
Aqua is one of the largest U.S.-based, publicly traded water and wastewater utilities, serving more than 3 million people in Illinois, Indiana, New Jersey, North Carolina, Pennsylvania, Ohio, Texas and Virginia. Founded in 1886, the company is headquartered in Bryn Mawr, USA, with a team of 1001-5000 employees. The company is currently Late Stage.