1

Security Risk Management Jobs in Philadelphia, PA

Risk Manager

Media, PA · On-site

$75K - $98K/yr

The Risk Manager ensures compliance with applicable federal, Commonwealth of Pennsylvania, and ... management practices. Ability to identify and evaluate cyber and information security risks in ...

Risk Manager

Media, PA · On-site

$75K - $98K/yr

The Risk Manager ensures compliance with applicable federal, Commonwealth of Pennsylvania, and ... management practices. * Ability to identify and evaluate cyber and information security risks in ...

Engineer

New Castle, DE · On-site

$100K - $110K/yr

We are seeking a skilled Information Security Analyst to support enterprise security operations with a strong focus on vulnerability management, patching, and risk remediation. The ideal candidate ...

Showing results 41-60

Security Risk Management information

See Philadelphia, PA salary details

$10

$50

$70

How much do security risk management jobs pay per hour?

As of Aug 19, 2026, the average hourly pay for security risk management in Philadelphia, PA is $50.87, according to ZipRecruiter salary data. Most workers in this role earn between $41.25 and $60.62 per hour, depending on experience, location, and employer.

What is security risk management?

Security Risk Management is the process of identifying, assessing, and mitigating risks to an organization's information, assets, and operations. It involves evaluating potential threats and vulnerabilities, determining their potential impact, and implementing strategies to minimize or control these risks. The goal is to protect the organization from security breaches, data loss, and other threats while ensuring compliance with legal and regulatory requirements. Security Risk Management is essential for maintaining business continuity and safeguarding reputation.

What are the key skills and qualifications needed to thrive in security risk management, and why are they important?

To excel in Security Risk Management, you need a solid understanding of risk assessment frameworks, cybersecurity principles, and compliance standards, often supported by a degree in information security or related fields. Familiarity with risk management tools, security incident response systems, and certifications such as CISSP or CISM is typically required. Strong analytical thinking, communication, and decision-making skills help professionals navigate complex threats and collaborate across departments. These competencies are crucial for effectively identifying, mitigating, and communicating risks to protect organizational assets and ensure regulatory compliance.

What are the typical challenges faced by professionals in security risk management, and how can they be addressed?

Professionals in Security Risk Management often encounter challenges such as rapidly evolving threats, balancing security with business operations, and ensuring organization-wide compliance with regulations. Staying current with the latest risk trends and fostering cross-department collaboration are key strategies for overcoming these obstacles. Additionally, clear communication of risks to non-technical stakeholders and ongoing training are essential for building a proactive security culture and effective risk mitigation.

What is the difference between Security Risk Management vs Security Analyst?

AspectSecurity Risk ManagementSecurity Analyst
CertificationsCRISC, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentStrategic, policy-focused, risk assessmentOperational, monitoring, incident response
Employer & Industry UsageOrganizations managing enterprise security risksSecurity teams, cybersecurity firms, IT departments

Security Risk Management focuses on identifying, assessing, and mitigating security risks at an organizational level, often involving policy development and strategic planning. In contrast, Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential but differ in scope and responsibilities within the cybersecurity field.

What do you need to be a security risk manager?

A security risk manager typically needs a bachelor's degree in security management, information technology, or a related field, along with experience in security or risk assessment. Certifications such as Certified Information Systems Security Professional (CISSP) or Certified Risk and Information Systems Control (CRISC) can enhance qualifications. Strong analytical skills, knowledge of security protocols, and familiarity with risk management tools are also important for the role.

What does security risk management do?

Security risk management involves identifying, assessing, and prioritizing potential security threats to an organization, then implementing measures to mitigate or eliminate those risks. Professionals in this field analyze vulnerabilities, develop security policies, and often use tools like risk assessment frameworks and security audits to protect assets and ensure safety.

What are popular job titles related to Security Risk Management jobs in Philadelphia, PA?

For Security Risk Management jobs in Philadelphia, PA, the most frequently searched job titles are:

What job categories do people searching Security Risk Management jobs in Philadelphia, PA look for?

The top searched job categories for Security Risk Management jobs in Philadelphia, PA are:

Infographic showing various Security Risk Management job openings in Philadelphia, PA as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 14% Part Time, and 3% Contract. Highlights an 86% Physical, 3% Hybrid, and 11% Remote job distribution, with an average salary of $105,801 per year, or $50.9 per hour.

(602) Information Systems Security Manager III

Arlo Solutions

Philadelphia, PA • On-site

Full-time

Re-posted 12 days ago


Job description

Job Summary:
Arlo Solutions is an information technology consulting services company specializing in delivering technology solutions. The Information Systems Security Manager III will support the Naval Surface Warfare Center Philadelphia Division, overseeing the implementation of information security programs and ensuring compliance with cybersecurity policies.
Responsibilities:
• Support IT security goals and objectives to reduce overall organizational risk
• Communicate the value of IT security throughout all levels of organization stakeholders
• Coordinate with various levels of the organization to oversee information security program implementation
• Manage cyber strategy, personnel, infrastructure, policy enforcement, emergency planning, security awareness, and other resources
• Assist with facilitating communication between all RMF stakeholders throughout the RMF process Security Assessment and Authorization
• Assist with the collection of data needed to meet system cybersecurity reporting requirements
• Assist with security improvement actions as they are evaluated, validated, and implemented
• Participate in information security risk assessments during the Security A&A process
• Assist with identifying security requirements specific to IT systems in all phases of the system life cycle
• Coordinate with programs to resolve findings identified during internal and external review processes Compliance and Risk Management
• Assist with cybersecurity inspections, tests, and reviews for the network environment
• Assist with identifying alternative information security strategies to address organizational security objectives
• Interpret patterns of noncompliance to determine their impact on risk levels and overall effectiveness of the enterprise's cybersecurity program
• Track audit findings and recommendations to ensure appropriate mitigation actions are taken
• Monitor systems for upcoming authorization conditions/stipulations, upcoming or past due POA&M items, and SLCM activities Documentation and Reporting •
• Develop findings reports and recommended corrective actions for identified deficiencies
• Report system compliance in DON Application and Database Management System (DADMS), Department of Defense Information Technology Portfolio Repository – Department of the Navy (DITPR-DON), and Vulnerability Remediation Asset Manager (VRAM)
• Assist with Quality Assurance (QA) reviews for RMF package submissions in accordance with NSWCPD and NAVSEA 03 SOP
• Ensure successful implementation and functionality of security requirements and appropriate IT policies and procedures consistent with the organization's mission and goals
• Track and respond to Cybersecurity data calls per Government guidance
Qualifications:
Required:
• Must be a U.S. Citizen
• Active Secret security clearance
• Master's degree in computer science, information technology, or an equivalent science, technology, engineering & mathematics (STEM) degree from an accredited college or university
• Eight (8) years of experience coordinating with various levels of an organization to oversee and manage information security program implementation
• Experience managing cyber strategy, personnel, infrastructure, policy enforcement, emergency planning, security awareness, and/or other resources
• Must possess one of the following certifications: CAP, CASP+ CE, CISM, CISSP (or Associate), GSLC, CCISO, or HCISPP
• IAM-II certification level
• Experience with DoD Information Assessment and Authorization (A&A) process and Risk Management Framework (RMF)
Preferred:
• Experience with enterprise security technologies and tools including eMASS and VRAM
• Knowledge of NIST Special Publications and DoD cybersecurity instructions
• Experience with Navy and DoD organizational structures and policies
• Familiarity with NAVSEA cybersecurity requirements and procedures
• Experience with vulnerability management and continuous monitoring
• Demonstrated leadership abilities and strong communication skills
Company:
Arlo Solutions is a dynamic team of proven data protectors, information confidantes, tech aficionados and digital innovators. Founded in 2014, the company is headquartered in Washington, USA, with a team of 51-200 employees. The company is currently Growth Stage.