Governance, Risk and Compliance Analyst
Crown Holdings
- Location
- PA - Yardley
- Work model
- On-Site
- Level
- Mid
- Posted
- Aug 24, 2026
Skills
About this role
About Crown Crown Holdings, Inc. through it's subsidiaries, is a world leader in the metal packaging production process. We design and manufacture a wide range of innovative and sustainable metal packaging solutions and products. Our clients are some of the largest and most respected companies in the world. Crown is dedicated to building a team of highly talented, dedicated, and driven individuals. It's an exciting time to join our business because Crown offers you the opportunity to grow and develop your skills in an expanding industry. Crown was founded with the goal of valuing and promoting sustainability and this vision continues to be essential to our long-term future.
Job Description
Global Information Security GRC Analyst – Third-Party Risk The Company: CROWN Cork & Seal USA, Inc., a wholly owned company of Crown Holdings, Inc. is a global leader in the design, manufacture and sale of packaging products for consumer goods. At Crown, we are passionate about helping our customers build their brands and connect with consumers around the world. We do this by delivering innovative packaging that offers significant value for brand owners, retailers, and consumers alike. With operations in 39 countries employing over 23,000 people and net sales of nearly $12 billion, we are uniquely positioned to bring best practices in quality and manufacturing to our customers to drive their businesses locally and globally. Sustaining a leadership position requires us to build a team of highly talented, dedicated, and driven individuals.
The Team
The mission of the Global Information Security team is to protect Crown’s global information systems, data and employees from cyber-based security threats while ensuring the confidentiality, integrity and availability of information used by the Crown business units to produce world class sustainable packaging solutions to our customers. You will join a cohesive and collaborative team who love what they do and are committed to creating a safe and secure environment for the Crown family. We are nimble with dynamic backgrounds that foster an environment of continuous learning and growth. The Job: We are seeking a Global Information Security GRC Analyst – Third Party Risk to support the execution and continuous improvement of Crown’s cybersecurity governance program. This role is part of Crown’s Global Cybersecurity team and will help expand and mature the company’s global GRC capabilities, with primary responsibility for supporting third-party security risk management. The role will also support related cyber risk and governance activities, including cybersecurity risk assessments, risk register maintenance, remediation tracking, risk reporting, AI governance, policy governance, compliance, and audit readiness. The ideal candidate is analytical, collaborative, and passionate about helping the organization manage risk while enabling business objectives.
Key Responsibilities
Third-Party Security Risk Management Manage the end-to-end third-party security risk assessment process. Assess vendor security controls and assurance documentation using ISO 27001, NIST frameworks, and SOC 2 reports. Review vendor security documentation, identify risks, and track remediation activities. Maintain third-party risk registers and support ongoing vendor monitoring and reporting. Governance, Risk & Compliance Conduct cybersecurity risk assessments and maintain risk registers. Support AI governance activities, including risk assessments and inventory management. Coordinate cybersecurity policy development, review, approval, and lifecycle activities. Support compliance and audit readiness through control testing, evidence collection, and remediation tracking. Develop cybersecurity metrics, dashboards, and leadership reporting. Identify opportunities to improve and automate GRC processes. Location This is a full-time, on-site position based in Yardley, Pennsylvania. Employees are expected to work from the