Governance, Risk and Compliance Analyst

Crown Holdings, Inc. - Yardley, PA

Hiring: Governance, Risk and Compliance Analyst Company: Crown Holdings, Inc. Location: Yardley, PA Job Posted Time: 2026-09-16 11:20:59 Employment Type: Full-time / On-site Target Skills & Keywords : Regulatory Compliance, Risk Management, SOC 2, ServiceNow, Stakeholder Management About the job Experience: •5 years of experience in cybersecurity, GRC, cyber risk, or third-party risk management. Required Skills: •Global Information Security GRC Analyst – Third-Party Risk •The mission of the Global Information Security team is to protect Crown’s global information systems, data and employees from cyber-based security threats while ensuring the confidentiality, integrity and availability of information used by the Crown business units to produce world class sustainable packaging solutions to our customers. •Join a cohesive and collaborative team who love what they do and are committed to creating a safe and secure environment for the Crown family. We are nimble with dynamic backgrounds that foster an environment of continuous learning and growth. •The ideal candidate is analytical, collaborative, and passionate about helping the organization manage risk while enabling business objectives. •Third-Party Security Risk Management •Manage the end-to-end third-party security risk assessment process. •Assess vendor security controls and assurance documentation using ISO 27001, NIST frameworks, and SOC 2 reports. •Review vendor security documentation, identify risks, and track remediation activities. Qualifications: •Bachelor's degree in Cybersecurity, Information Technology, Information Systems, or a related field or equivalent professional experience. •3–5 years of experience in cybersecurity, GRC, cyber risk, or third-party risk management. •Knowledge of cybersecurity frameworks such as ISO 27001, NIST CSF, and SOC 2. •Strong analytical, communication, and stakeholder management skills. •Certifications such as CISSP, CISM, CISA, CRISC, Security+, or ISO 27001 Lead Implementer/Auditor. •Operational familiarity with AI governance frameworks including NIST AI RMF and ISO/IEC 42001. •This role requires collaboration, teamwork, and regular interaction with business stakeholders, technology teams, and external partners. •Strong commitment to employee safety and well-being •Opportunity to build a meaningful career Compensation: •Flexible work environment (work from home / hybrid options) Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!