Risk Management Lead Jobs in Pennsylvania
Risk Management Lead jobs in Pennsylvania are in steady demand, with the strongest concentration in financial services, healthcare systems, and insurance, drawing candidates from entry-level analysts through senior program leads. Philadelphia, Pittsburgh, and Harrisburg are the primary hiring centers, where organizations like Cigna, Lincoln Financial Group, and UPMC consistently maintain risk management functions. Operational risk, enterprise risk management, and compliance oversight are the most in-demand specialties across Pennsylvania employers. Find a role that fits below and apply directly.
Find Risk Management Lead JobsOverview
Showing 5 of 28+ Risk Management Lead jobs











Work You'll Do
As a US Delivery Center Delivery Senior Consultant, Software Engineering Solutions on the team, you will:
- Advise Government & Public Services clients in executing the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) lifecycle to mitigate cyber risk and threats
- Advise federal agency clients on cyber risk posture and RMF compliance strategies aligned to FISMA, NIST, and agency-specific requirements
- Lead the development and/or review of Authority to Operate (ATO) packages (e.g., System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action & Milestones (POA&Ms))
- Assess or develop an organization's cyber risk strategy as it relates to data risk, cyber risk management, risk frameworks and policies, and risk measures and reporting
- Strategically drive the development and execution of risk assessments and mitigation plans to enhance the client's ability to identify, evaluate, prioritize, and mitigate risks
- Implement risk management solutions aligned to the client's vision and strategic priorities
- Drive development and implementation of cyber strategies grounded in leading practices, industry frameworks, and targeted to the client's risk and business needs
- Synthesize technical findings and risk data into actionable reports and executive-level briefings
- Develop impactful presentations that support engagement goals, communicate technical findings clearly to both technical and executive audiences
- Deliver key messages with clarity and confidence; tailor communication style to the audience
- Understand how business functions operate and how industry trends impact a client's cyber posture and risk profile
- Identify and evaluate complex business and technology risks, and connect findings to business impact
- Provide guidance and quality review to junior team members on RMF documentation, assessment artifacts, and deliverable development
- Participate in team problem-solving efforts and offer ideas to address client challenges
- Identify opportunities for efficiencies in work processes and innovative approaches to completing scope of work
- Own assigned work products through final review, client submission, and resolution of quality-review comments
- Assist in proposal development, as requested
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The Team
Deloitte's Government & Public Services (GPS) practice - our people, ideas, technology and outcomes - is designed for impact. Serving federal, state, & local government clients as well as public higher education institutions, our team of professionals brings fresh perspective to help clients anticipate disruption, reimagine the possible, and fulfill their mission promise.
Our Cyber Strategy & Transformation offering develops and transforms cyber programs in line with a client's strategic objectives, regulatory requirements, and risk appetite. It keeps the enterprise a step ahead of the evolving threat landscape and gives stakeholders confidence in the organization's cyber posture. Includes design of the cyber organization, governance, and risk assessments.
This opportunity sits within our Deloitte US Delivery Center model, which is dedicated to driving impactful business services. It leverages Deloitte's scale and talent, as well as a center delivery model to provide high-quality, cost-effective service with standardized processes and procedures to service businesses across Deloitte.
The Deloitte US Delivery Center has a small-business feel with a big-business impact. With the resources of Deloitte and a community feel, the delivery center model provides high-quality services to our clients. USDC professionals work out of one of our specific delivery center locations, and each location presents dynamic career opportunities for professionals to focus on their work with nominal travel requirements.
Qualifications
Required:
- Bachelor's degree in cybersecurity, information technology, information systems, computer science, risk management, business, mathematics, decision sciences, or a related field, or an equivalent combination of education, professional training, and relevant cybersecurity experience in accordance with applicable talent policies.
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future
- 4+ years of professional experience in cybersecurity, information assurance, governance, risk and compliance, cybersecurity risk management, or federal security compliance, including at least 2 years supporting NIST RMF or an equivalent authorization process including participation in at least one end-to-end authorization cycle or multiple lifecycle phases across two or more systems.
- 2+ years of experience applying NIST RMF concepts and NIST SP 800-37 to information-system authorization, security assessment, or continuous-monitoring activities, including 1+ year applying NIST SP 800-53 controls. Experience with the NIST CSF, FedRAMP, or agency-specific security requirements is preferred.
- 2+ years of experience implementing, documenting, assessing, or managing NIST SP 800-53 security controls, including at least 1 year preparing control narratives, reviewing implementation evidence, documenting assessment results, or tracking remediation activities.
- 2+ years of experience developing, updating, or quality-reviewing cybersecurity policies, procedures, standards, or implementation guidance mapped to NIST SP 800-53 controls or an equivalent federal security baseline, including experience supporting at least one moderate-impact information system.
- At least 2 years of experience in RMF documentation and control implementation, plus at least 1 year in three of the following: system categorization, boundary definition, control tailoring, continuous monitoring, risk assessment, vulnerability management, or GRC tool administration.
- Ability to obtain and maintain the level of federal security clearance or Public Trust designation required for client engagements
-
Delivery Center Location & Travel Requirements:
- Hybrid Work Model: Operate under a hybrid system requiring residence within a commutable distance to one of the US Delivery Center locations (Gilbert, Lake Mary, or Mechanicsburg) or Geo-Hub locations (Atlanta, Charlotte, Dallas, Houston, and Philadelphia)
- Co-location Expectation: Spend up to 30% of working time co-located at an assigned office for orchestrated opportunities, including projects, practice sessions, training, and Moments That Matter at a Deloitte Delivery Center location, Geo-Hub location, approved site, or project location
- Travel Requirement: Maximum of 10% overnight travel for client or project purposes
- Relocation Requirement: If relocation is necessary, complete the move within 12 weeks from the start date to reside within a commutable distance
Preferred:
- Previous federal or government consulting experience
- 1+ year applying NIST SP 800-171, CMMC, or equivalent controlled-unclassified-information security requirements.
- 1+ year of experience analyzing or documenting enterprise, mission-critical, cloud, or multi-system technology environments, including business processes, system dependencies, data flows, security vulnerabilities, or operational risks.
- 1+ year of experience supporting a FedRAMP authorization, cloud security assessment, or RMF activity for AWS GovCloud, Azure Government, or an equivalent federal cloud environment.
- 1+ year of experience delivering cybersecurity or RMF work in an Agile, hybrid-Agile, or iterative federal program environment, including sprint planning, backlog management, or incremental deliverable reviews.
- 2+ years of experience in at least one technical domain relevant to RMF, such as security architecture, network security, cloud infrastructure, identity and access management, endpoint security, or vulnerability management.
- CISSP, CISM, CISA, or CEH certification
See All 28 Risk Management Lead Jobs in Pennsylvania
Find roles in Pennsylvania that match your experience and apply in just a few clicks.
Find Risk Management Lead JobsRisk Management Lead Jobs by City in Pennsylvania
Where Pennsylvania roles are concentrated, by current openings.
Risk Management Lead Job Market in Pennsylvania
A snapshot from current Pennsylvania openings, updated as new roles post.
Who's Hiring



Top Industries Hiring
- Energy
- Education
- Science & Research
What Pennsylvania Employers Look For
The qualifications that appear most often in risk management lead jobs across Pennsylvania.
- Bachelor's degree in finance, business, risk management, or a related field required
- Professional certification such as ARM, CRISC, or PRM preferred by most Pennsylvania employers
- Five or more years of experience in risk management, compliance, or audit functions
- Demonstrated ability to develop and implement enterprise risk frameworks and controls
- Proficiency with risk management platforms and data analysis tools such as Excel or Tableau
- Strong communication skills to present risk findings to executive and board-level stakeholders
Risk Management Lead Jobs in Pennsylvania: Frequently Asked Questions
How do you become a risk management lead in Pennsylvania?
Most risk management lead roles in Pennsylvania require a bachelor's degree in finance, business administration, or a related field, followed by several years in risk, compliance, or audit roles. Pennsylvania does not issue a state-specific license for risk management leads, but employers strongly favor candidates holding credentials such as the Associate in Risk Management, CRISC, or a Certified Risk Manager designation. Building experience at a Pennsylvania financial institution, health system, or insurer is the most common path to a lead-level role.
How much do risk management leads make in Pennsylvania?
Risk management leads in Pennsylvania earn a median of about $103,040 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $64,700 for the lowest 10% to over $172,820 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire risk management leads in Pennsylvania?
Employers hiring risk management leads in Pennsylvania right now include Deloitte, Chubb Insurance, and UGI, based on current listings on Migrate Mate as of September 2026. Pennsylvania's concentration of large insurers, regional banks, and integrated health systems means consistent demand for risk management leads across the state.
Which Pennsylvania cities have the most risk management lead jobs?
The cities with the most risk management lead openings in Pennsylvania are Philadelphia, Pittsburgh, and Radnor. Philadelphia leads because of its dense cluster of insurance carriers, financial services firms, and large hospital networks, while Pittsburgh's strength in healthcare and banking drives hiring there, and Harrisburg draws demand from state government agencies and the regulated industries that cluster near the capital.
Are there remote risk management lead jobs in Pennsylvania?
Yes, and they are more common than in many fields, since much of risk management lead work centers on analysis, reporting, and policy development that can be done remotely. About 100% of risk management lead openings tied to Pennsylvania are remote or hybrid as of September 2026, reflecting how broadly the role has shifted toward desk-based and digital work. Policy development, enterprise risk reporting, and vendor risk assessment are the functions most frequently offered on a fully remote or hybrid basis.
How can I get hired as a risk management lead in Pennsylvania with little or no experience?
The most realistic entry path is moving into a risk analyst or compliance associate role first, then building toward a lead position. Large Pennsylvania employers like UPMC, Cigna, and major regional banks such as Citizens Bank run rotational finance and risk programs that accept candidates without direct risk experience. Roles in internal audit, insurance underwriting, or financial analysis provide the lateral foundation most Pennsylvania hiring managers look for. Earning an entry-level credential like the Associate in Risk Management while in one of those roles strengthens a candidacy noticeably.
Where can I find and apply to risk management lead jobs in Pennsylvania?
You can find and apply to risk management lead jobs in Pennsylvania on Migrate Mate, which lists current openings across the state. Find roles that fit your experience and location, then apply directly to the employer. No sign-up is required to search or view listings.
See All 28 Risk Management Lead Jobs in Pennsylvania
Find roles in Pennsylvania that match your experience and apply in just a few clicks.
Find Risk Management Lead Jobs