Governance, Risk and Compliance Analyst

091 CROWN Holdings, Inc.

Yardley (WA)

On-site

USD 110,000 - 135,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Strong commitment to employee safety
Career development through training
Exposure to global cybersecurity and R
Professional development through cross

Job summary

Crown Holdings, Inc. in Yardley, PA is seeking a Global Information Security GRC Analyst – Third-Party Risk to strengthen Crown’s cybersecurity governance.

You will drive third-party risk assessment, review vendor security, and maintain risk registers to support risk-informed business decisions. The role requires 3–5 years in cybersecurity/GRC, knowledge of ISO 27001/NIST, and strong analytical and stakeholder skills.

Qualifications

  • Bachelor's degree or equivalent experience in a related field.
  • 3–5 years of experience in cybersecurity, GRC, cyber risk, or third-party risk management.
  • Experience conducting security assessments and reviewing vendor security documentation.
  • Knowledge of ISO 27001, NIST CSF, and SOC 2.

Responsibilities

  • Manage the end-to-end third-party security risk assessment process.
  • Assess vendor security controls and assurance documentation using ISO 27001, NIST frameworks, and SOC 2 reports.
  • Review vendor security documentation, identify risks, and track remediation activities.
  • Maintain third-party risk registers and support ongoing vendor monitoring and reporting.
  • Conduct cybersecurity risk assessments and maintain risk registers.
  • Support AI governance activities, including risk assessments and inventory management.
  • Coordinate cybersecurity policy development, review, approval, and lifecycle activities.
  • Support compliance and audit readiness through control testing, evidence collection, and remediation tracking.
  • Develop cybersecurity metrics, dashboards, and leadership reporting.
  • Identify opportunities to improve and automate GRC processes.

Skills

Analytical skills
Communication skills
Stakeholder management

Education

Bachelor's degree in Cybersecurity, IT, Information Systems, or related field

Tools

GRC platforms (LogicGate, ServiceNow GRC, Archer, OneTrust, AuditBoard)

Job description

About Crown Crown Holdings, Inc.

through it's subsidiaries, is a world leader in the metal packaging production process. We design and manufacture a wide range of innovative and sustainable metal packaging solutions and products. Our clients are some of the largest and most respected companies in the world. Crown is dedicated to building a team of highly talented, dedicated, and driven individuals. It's an exciting time to join our business because Crown offers you the opportunity to grow and develop your skills in an expanding industry. Crown was founded with the goal of valuing and promoting sustainability and this vision continues to be essential to our long-term future.

Job Description: Global Information Security GRC Analyst – Third-Party Risk
The Company

CROWN Cork & Seal USA, Inc., a wholly owned company of Crown Holdings, Inc. is a global leader in the design, manufacture and sale of packaging products for consumer goods. At Crown, we are passionate about helping our customers build their brands and connect with consumers around the world. We do this by delivering innovative packaging that offers significant value for brand owners, retailers, and consumers alike. With operations in 39 countries employing over 23,000 people and net sales of nearly $12 billion, we are uniquely positioned to bring best practices in quality and manufacturing to our customers to drive their businesses locally and globally. Sustaining a leadership position requires us to build a team of highly talented, dedicated, and driven individuals.

The Team

The mission of the Global Information Security team is to protect Crown’s global information systems, data and employees from cyber-based security threats while ensuring the confidentiality, integrity and availability of information used by the Crown business units to produce world class sustainable packaging solutions to our customers. You will join a cohesive and collaborative team who love what they do and are committed to creating a safe and secure environment for the Crown family. We are nimble with dynamic backgrounds that foster an environment of continuous learning and growth.

The Job

We are seeking a Global Information Security GRC Analyst – Third Party Risk to support the execution and continuous improvement of Crown’s cybersecurity governance program. This role is part of Crown’s Global Cybersecurity team and will help expand and mature the company’s global GRC capabilities, with primary responsibility for supporting third-party security risk management. The role will also support related cyber risk and governance activities, including cybersecurity risk assessments, risk register maintenance, remediation tracking, risk reporting, AI governance, policy governance, compliance, and audit readiness. The ideal candidate is analytical, collaborative, and passionate about helping the organization manage risk while enabling business objectives.

Key Responsibilities
  • Manage the end-to-end third-party security risk assessment process.
  • Assess vendor security controls and assurance documentation using ISO 27001, NIST frameworks, and SOC 2 reports.
  • Review vendor security documentation, identify risks, and track remediation activities.
  • Maintain third-party risk registers and support ongoing vendor monitoring and reporting.
  • Conduct cybersecurity risk assessments and maintain risk registers.
  • Support AI governance activities, including risk assessments and inventory management.
  • Coordinate cybersecurity policy development, review, approval, and lifecycle activities.
  • Support compliance and audit readiness through control testing, evidence collection, and remediation tracking.
  • Develop cybersecurity metrics, dashboards, and leadership reporting.
  • Identify opportunities to improve and automate GRC processes.
Location

This is a full-time, on-site position based in Yardley, Pennsylvania. Employees are expected to work from the office five days per week, with flexibility in daily start and end times.

Required Qualifications
  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, or a related field or equivalent professional experience.
  • 3–5 years of experience in cybersecurity, GRC, cyber risk, or third-party risk management.
  • Experience conducting security assessments and reviewing vendor security documentation.
  • Knowledge of cybersecurity frameworks such as ISO 27001, NIST CSF, and SOC 2.
  • Strong analytical, communication, and stakeholder management skills.
Preferred Qualifications
  • Certifications such as CISSP, CISM, CISA, CRISC, Security+, or ISO 27001 Lead Implementer/Auditor.
  • Experience with GRC platforms such as LogicGate, ServiceNow GRC, Archer, OneTrust, or AuditBoard.
  • Familiarity with AI governance frameworks including NIST AI RMF and ISO/IEC 42001.
  • Experience supporting cloud security and regulatory compliance initiatives.
  • Experience supporting GRC and TPRM activities across multiple countries and cultures.
Additional Job Considerations

This role requires collaboration, teamwork, and regular interaction with business stakeholders, technology teams, and external partners.

What Crown Offers You
  • Strong commitment to employee safety and well-being
  • Opportunity to build a meaningful career
  • Professional development through training and work experiences
  • Exposure to global cybersecurity and risk management initiatives
  • Join us and become part of a team helping to protect Crown's business through effective cybersecurity governance, risk management, and compliance.
What Crown Offers You
  • Strong engagement and commitment to the safety of our employees
  • The opportunity to build a meaningful careerProfessional and personal development through training and work experiences
  • Join us and become part of a team of professionals who are passionate about sustainable packaging!
Working Together

Working Together is one of the five pillars that make up our Twentyby30 program. We aim to value and respect each individual and foster an environment of inclusivity. Crown Holdings, Inc. through it's subsidiaries, is a world leader in the metal packaging production process. We design and manufacture a wide range of innovative and sustainable metal packaging solutions and products.

Ready to go behind the scenes?

With hundreds of maufacturing plants and 20,000+ employees worldwide, there’s a lot that goes into the design and production of Crown packaging. We serve a variety of markets including food, beverage, household, personal care, and more. Since we were founded in 1892, we’ve been on a mission to manufacture best-in-class packaging while championing best-in-class teams. Together, we’re building something that lasts thanks to great products, made by great people.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Information Security
Director, Information Security

Crown Holdings, Inc. • Yardley

On-site
USD 140,000 - 210,000
Strong engagement and commitment to安全?
Career growth
Professional and personal development
Senior Accountant
Senior Accountant

Crowncork • Tampa (FL), Northern (KY)

Hybrid
USD 90,000 - 120,000
Safety commitment
Meaningful career
Training opportunities
+1
Front End Mechanic
Front End Mechanic

Crowncork • New York (NY), Northern (KY)

Hybrid
USD 43,000 - 50,000
Medical/dental/vision/prescription
Company funded pension plan
401(K)
+1
Senior Accountant
Senior Accountant

091 CROWN Holdings, Inc. • Tampa (FL)

On-site
USD 85,000 - 120,000
Safety focus
Career development
Training & growth
+1
Front End Mechanic
Front End Mechanic

090 CROWN Cork & Seal USA, Inc. • Nichols (SC)

On-site
USD 65,000 - 75,000
Medical Insurance
Pension plan
401(k)
+3
Back End Mechanic
Back End Mechanic

Crown Holdings, Inc. • Town of Nichols (NY)

On-site
Medical, dental, vision insurance
Company funded pension
401(k)
+3
Conversion Press Mechanic
Conversion Press Mechanic

090 CROWN Cork & Seal USA, Inc. • Winchester (VA)

On-site
USD 89,401,000 - 95,059,000
Medical, dental, vision
Pension plan
Education assistance
+2
Electrical Engineer
Electrical Engineer

090 CROWN Cork & Seal USA, Inc. • Kankakee (IL)

On-site
USD 87,000 - 138,000
Free health insurance
401(k) matching
Manufacturing Supervisor
Manufacturing Supervisor

Crowncork • Massillon (OH)

Hybrid
USD 65,000 - 85,000
Electrical Engineer
Electrical Engineer

Crowncork • Bradley (IL), Northern (KY)

Hybrid
USD 87,000 - 138,000
Company paid health insurance
401(k)