Jobs · Legal · Pennsylvania

Governance, Risk and Compliance Analyst

Crown Holdings, Inc. · Yardley, PA · 4 days ago
Legal$12/hrFull-time

Crown Holdings, Inc., through its subsidiaries, is a world leader in metal packaging production, designing and manufacturing innovative and sustainable metal packaging solutions for some of the largest and most respected companies globally. With operations in 39 countries, over 23,000 employees, and net sales of nearly $12 billion, Crown is uniquely positioned to deliver high-quality, sustainable packaging solutions.

About the role

We are seeking a Global Information Security GRC Analyst – Third Party Risk to support the execution and continuous improvement of Crown’s cybersecurity governance program. This role will help expand and mature the company’s global GRC capabilities, with a primary focus on third-party security risk management. The position also supports related cyber risk and governance activities, including cybersecurity risk assessments, risk register maintenance, remediation tracking, risk reporting, AI governance, policy governance, compliance, and audit readiness.

The ideal candidate is analytical, collaborative, and passionate about helping the organization manage risk while enabling business objectives.

Responsibilities

  • Manage the end-to-end third-party security risk assessment process.
  • Assess vendor security controls and assurance documentation using ISO 27001, NIST frameworks, and SOC 2 reports.
  • Review vendor security documentation, identify risks, and track remediation activities.
  • Maintain third-party risk registers and support ongoing vendor monitoring and reporting.
  • Conduct cybersecurity risk assessments and maintain risk registers.
  • Support AI governance activities, including risk assessments and inventory management.
  • Coordinate cybersecurity policy development, review, approval, and lifecycle activities.
  • Support compliance and audit readiness through control testing, evidence collection, and remediation tracking.
  • Develop cybersecurity metrics, dashboards, and leadership reporting.
  • Identify opportunities to improve and automate GRC processes.

Requirements

  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, or a related field, or equivalent professional experience.
  • 3–5 years of experience in cybersecurity, GRC, cyber risk, or third-party risk management.
  • Experience conducting security assessments and reviewing vendor security documentation.
  • Knowledge of cybersecurity frameworks such as ISO 27001, NIST CSF, and SOC 2.
  • Strong analytical, communication, and stakeholder management skills.

Qualifications

  • Certifications such as CISSP, CISM, CISA, CRISC, Security+, or ISO 27001 Lead Implementer/Auditor.
  • Experience with GRC platforms such as LogicGate, ServiceNow GRC, Archer, OneTrust, or AuditBoard.
  • Familiarity with AI governance frameworks including NIST AI RMF and ISO/IEC 42001.
  • Experience supporting cloud security and regulatory compliance initiatives.
  • Experience supporting GRC and TPRM activities across multiple countries and cultures.

Schedule

This is a full-time, on-site position based in Yardley, Pennsylvania. Employees are expected to work from the office five days per week, with flexibility in daily start and end times.

Benefits

  • Strong commitment to employee safety and well-being.
  • Opportunity to build a meaningful career.
  • Professional development through training and work experiences.
  • Exposure to global cybersecurity and risk management initiatives.
  • Inclusive work environment valuing and respecting each individual.

Similar jobs