Global GRC Analyst - Third-Party Risk & Compliance

091 CROWN Holdings, Inc.

Yardley (WA)

On-site

USD 110,000 - 135,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Strong commitment to employee safety
Career development through training
Exposure to global cybersecurity and R
Professional development through cross

Job summary

Crown Holdings, Inc. in Yardley, PA is seeking a Global Information Security GRC Analyst – Third-Party Risk to strengthen Crown’s cybersecurity governance.

You will drive third-party risk assessment, review vendor security, and maintain risk registers to support risk-informed business decisions. The role requires 3–5 years in cybersecurity/GRC, knowledge of ISO 27001/NIST, and strong analytical and stakeholder skills.

Qualifications

  • Bachelor's degree or equivalent experience in a related field.
  • 3–5 years of experience in cybersecurity, GRC, cyber risk, or third-party risk management.
  • Experience conducting security assessments and reviewing vendor security documentation.
  • Knowledge of ISO 27001, NIST CSF, and SOC 2.

Responsibilities

  • Manage the end-to-end third-party security risk assessment process.
  • Assess vendor security controls and assurance documentation using ISO 27001, NIST frameworks, and SOC 2 reports.
  • Review vendor security documentation, identify risks, and track remediation activities.
  • Maintain third-party risk registers and support ongoing vendor monitoring and reporting.
  • Conduct cybersecurity risk assessments and maintain risk registers.
  • Support AI governance activities, including risk assessments and inventory management.
  • Coordinate cybersecurity policy development, review, approval, and lifecycle activities.
  • Support compliance and audit readiness through control testing, evidence collection, and remediation tracking.
  • Develop cybersecurity metrics, dashboards, and leadership reporting.
  • Identify opportunities to improve and automate GRC processes.

Skills

Analytical skills
Communication skills
Stakeholder management

Education

Bachelor's degree in Cybersecurity, IT, Information Systems, or related field

Tools

GRC platforms (LogicGate, ServiceNow GRC, Archer, OneTrust, AuditBoard)

Job description

Crown Holdings, Inc. in Yardley, PA is seeking a Global Information Security GRC Analyst – Third-Party Risk to strengthen Crown’s cybersecurity governance.

You will drive third-party risk assessment, review vendor security, and maintain risk registers to support risk-informed business decisions. The role requires 3–5 years in cybersecurity/GRC, knowledge of ISO 27001/NIST, and strong analytical and stakeholder skills.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance, Risk and Compliance Analyst
Governance, Risk and Compliance Analyst

091 CROWN Holdings, Inc. • Yardley (WA)

On-site
USD 110,000 - 135,000
Strong commitment to employee safety
Career development through training
Exposure to global cybersecurity and R
+1
Head of Global Information Security & Risk
Head of Global Information Security & Risk

Crowncork • Northern (KY)

Hybrid
USD 150,000 - 210,000
Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)
Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)

recruit22 • Chicago (IL)

On-site
USD 65,000 - 90,000
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
GRC Intern: Build Risk, Compliance & Governance
GRC Intern: Build Risk, Compliance & Governance

Jobtailor • Center Square (PA)

On-site
USD 35,000 - 52,000
GRC Analyst: Third-Party Risk & Vendor Oversight
GRC Analyst: Third-Party Risk & Vendor Oversight

United States Digital Space LLC • Boston (MA)

On-site
USD 70,000 - 110,000
Senior GRC Analyst: TPRM & Human Risk
Senior GRC Analyst: TPRM & Human Risk

Gilder Search Group • Phoenix (AZ)

On-site
USD 80,000 - 120,000
Comprehensive Benefits Package
Discretionary Annual Bonus
Flexible Spending Accounts
GRC & Third-Party Risk Analyst - Vendor Compliance
GRC & Third-Party Risk Analyst - Vendor Compliance

Whoop • Boston (MA)

On-site
USD 70,000 - 110,000
Director, Information Security
Director, Information Security

Crowncork • Northern (KY)

Hybrid
USD 150,000 - 210,000
Hybrid GRC Analyst I: Risk, Audit & Compliance
Hybrid GRC Analyst I: Risk, Audit & Compliance

Geographic Solutions, Inc. • Palm Harbor (FL)

Hybrid
USD 65,000 - 85,000