Cyber Security Risk Analyst
Alcoa Inc
Shape Your WorldAt Alcoa, you will become an essential part of our purpose: to turn raw potential into real progress. The way we see it, every Alcoan is a work-shaper, team-shaper, idea-shaper & world-shaper.Alcoa is seeking a Cyber Security Risk Analyst to serve as a key contributor to the cybersecurity risk management program, providing subject matter expertise in identifying, assessing, and managing risks across both Information Technology (IT) and Operational Technology (OT) environments. This role supports informed business decision-making by translating complex technical risks into business and operational impact. The Analyst independently leads risk assessments and partners closely with IT, OT, audit, and senior leaders to ensure cybersecurity risks are understood, documented, mitigated, and monitored in accordance with corporate policies and industry standards. As Alcoa’s Cybersecurity Risk Management program continues to mature, the Analyst plays a critical role in shaping and enhancing program capabilities. About the Role:Contribute to the development, implementation, and continuous improvement of the Cybersecurity Risk Management Program, including frameworks, methodologies, policies, standards, and supporting tools. Perform cybersecurity risk assessments across IT, OT, cloud, and third-party environments, including enterprise systems and manufacturing/process control systems (PCS). Facilitate risk workshops with technical and business stakeholders to evaluate risks associated with new technologies, projects, and operational changes. Serve as a subject matter expert on risk methodology, scoring, and evaluation. Maintain and enhance the cybersecurity risk register, including risk scoring, treatment plans, and residual risk tracking. Support and guide risk treatment strategies (mitigation, acceptance, transfer, avoidance) and partner with compliance teams to design and implement appropriate controls. Translate technical risk findings into clear business and operational impact statements for non-technical audiences and senior leadership. Advise leadership on risk exposure, trends, and residual risks, including impacts to business operations and production. Define, monitor, and report Key Risk Indicators (KRIs) and emerging threat trends. Support audit, regulatory, and compliance activities (e.g., ISO 27001, NIST, SOC) related to cybersecurity risk management. Collaborate with Enterprise Risk Management (ERM) and Operations Risk Management teams to ensure alignment and integration of cybersecurity risks into broader risk reporting. Build and maintain strong relationships with stakeholders across IT, OT, business units, and risk management functions. Continuously monitor evolving cyber threats, emerging technologies, and industry practices to enhance risk management processes and capabilities. What you can bring to this role:Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, Risk Management, or a related discipline; equivalent professional experience may be considered in lieu of a degree. 6+ years of experience in cybersecurity, IT risk management, information security, governance, compliance, or IT operations within enterprise environments. Demonstrated experience assessing cybersecurity risk across IT and OT environments; experience in manufacturing or industrial organizations preferred. Strong knowledge of cybersecurity frameworks and standards (e.g., ISO 27001, NIST CSF, NIST 800-53, CIS Controls, SOX). Proven experience executing core GRC activities, including risk assessments, policy and standard development, control validation, audit support, and remediation tracking. Expertise in cybersecurity governance, risk assessment, and compliance program implementation. Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards. Solid understanding of security principles, including security controls, threat modeling, vulnerability management, and incident risk analysis. Excellent written, verbal, and facilitation skills, with the ability to translate complex technical risks into clear business impacts. Demonstrated ability to collaborate effectively with cross-functional stakeholders, including technical teams, operations, and senior leadership, while managing multiple priorities in fast-paced environments. Preferred Qualifications Relevant industry certifications such as CISSP, CISM, CRISC, CISA, CGRC, Security+, GRCP, or equivalent. Experience with third-party/vendor risk management, regulatory compliance assessments, and security awareness programs. Experience supporting global environments and contributing to enterprise-wide security or compliance initiatives. Experience supporting audits and assurance activities, including ISO/IEC 27001 certification and SOC report reviews. Familiarity with security operations capabilities, including SIEM, log analysis, and event monitoring for compliance and incident response. Understanding of enterprise security domains, including cloud security, infrastructure security, and identity and access management (IAM). Working knowledge of project management methodologies and practices. Experience in metals, mining, manufacturing, or other heavy industrial environments. What we offer:Competitive compensation packages, including pay-for performance variable pay, recognition and rewards programs, and stock-based compensation awards (3-year vesting schedule)Flexible spending accounts and generous employer contribution to the HSA401(k), employer match up to 6%, additional employer retirement income contribution (no vesting period), and a non-qualified deferred compensation plan12 paid holidays per year.15 days of paid vacation (pro-rated from hire date).Employee Assistance Program (EAP)#LI-TL2Employees must be legally authorized to work in the United States. Verification of employment eligibility will be required at the time of hire. Visa sponsorship is not available for this position. About the LocationAlcoa is an international company with multiple locations and joint ventures across six continents. Wherever you choose to join us, you'll be joining a global team committed to advancing sustainability and delivering excellence and innovation. As industry pioneers, we are redefining what it means to be a sustainable aluminum company, bridging the journey from mines to metal.We are values led, vision driven and united by our purpose of transforming raw potential into real progress. Our commitments to Inclusion, Diversity & Equity include providing trusting workplaces that are safe, respectful and inclusive of all individuals, free from discrimination, bullying and harassment and that our workplaces reflect the diversity of the communities in which we operate.As a proud equal opportunity workplace and affirmative action employer, Alcoa is dedicated to providing equal opportunities and equal access to all individuals regardless of a person’s gender, age, race, ethnicity, sexual orientation, gender identity, religion, nation of origin, disability, veteran status, language spoken or any other characteristic or status protected by the laws or regulations in the places where we operate.If you have visited our website in search of information on U.S. employment opportunities or to apply for a position, and you require an accommodation, please contact Alcoa Recruiting via email at View email address on click.appcast.io is a place where you are empowered to do your best work, be your authentic self, and feel a true sense of belonging. Come join us and shape your career!Your work. Your world. Shape them for the better.SummaryLocation: United States, PA, Pittsburgh; Canada, QC, Bécancour; US ATR New Kensington, Pennsylvania; Canada, QC, Montréal; Canada, QC, Baie-Comeau; Canada, QC, DeschambaultType: Full time
$171k - $273k
...more efficient and accessible for all.We're searching for a Staff Security Engineer to join our Enterprise Security Engineering team,... ...reviews to ensure alignment with Aurora's security posture and risk tolerance.Partner with IT, Infrastructure, and Engineering teams...SuggestedWork at officeLocal area3 days per weekEarly shift$134.5k - $265.1k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities... ...confidence, and proactively manage to secure success.Recruiting for this role ends on... ...based on new and emerging data risks.Advising clients on encryption, decryption...SuggestedLocal area$144.2k - $265.6k
Position Summary Cyber Data Protection ManagerAre you passionate about helping leading organizations reduce cyber risk, protect critical data, and build resilience in an increasingly... ...requirements, but also enable secure growth, strengthen trust, and improve operational...SuggestedWork experience placementLocal area- ...architectures that support the bank’s information security operations functions. This role performs... ...security leadership.Assists Security Analysts as an escalation point for security... ...level reports detailing assessment outcomes, risk findings, security posture, and...SuggestedRemote work
$82.6k - $162.8k
Position Summary Join our Deloitte Cyber team to deliver powerful solutions to help our clients navigate the ever-changing threat... ...resilience, grow with confidence, and proactively manage to secure success. Identity security market is undergoing a fundamental transformation...SuggestedLocal areaVisa sponsorship$171k - $273k
...safer, get crucial goods where they need to go, and make mobility more efficient and accessible for all. We’re searching for a Staff Security Engineer - Enterprise Security Architecture.This position is open to the following office locations: Mountain View, San Francisco,...Work at officeLocal area3 days per week$71.6k - $119.4k
...organization?About the role - This role supports the offensive security function within Elsevier's Security Engineering team. You will... ...code review practices is desirable.Awareness of GenAI security risks (prompt injection, LLM abuse, insecure AI integrations)Elsevier...Full timeLocal areaWork from home$105.4k - $207.8k
Position Summary Join Deloitte’s Cyber practice as a Cyber SecOps Senior Consultant... ...landscape through scalable, resilient security operations solutions. In this hands-on role... ...with security operations center analysts and threat detection engineers to prioritize...Local areaVisa sponsorship$82.6k - $162.8k
...of cybersecurity, data, and artificial intelligence, Deloitte’s Cyber Defense & Resilience team offers the scale, complexity, and... ...In this role, you will support organizations as they modernize security operations through advanced analytics, cyber data engineering,...Local areaVisa sponsorship$97.61k - $188.38k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities... ...confidence, and proactively manage to secure success.Recruiting for this role ends on 1... ...of business processes, internal control risk management, IT controls and related...Local areaVisa sponsorship$75k - $137.5k
...an opportunity to contribute to the company’s success. As a LOB Risk Specialist Senior within PNC's Corporate & Institutional Banking... ...Business/Operations/Technology Resiliency, Technology & Information Security Risk Management, and Data Risk Management. PNC is an in-...Full timeTemporary workPart timeWork experience placementWork at office$134.5k - $265.1k
Position Summary Our Deloitte Cyber team understands the unique challenges and opportunities... ...confidence, and proactively manage to secure success.Recruiting for this role ends on... ...delivery teams, managing quality and risks, and coordinating across business,...Local areaVisa sponsorship$155.6k - $306.8k
Position Summary As an Engineering Manager in Deloitte Cyber’s Digital Trust & Privacy practice, you will help clients solve complex identity, access, and data protection challenges through AI-enabled engineering solutions. This role sits at the intersection of...Local areaVisa sponsorship$118.7k - $218.6k
Position Summary Cyber Data Protection and PKI Specialist - Senior ConsultantOur... ...with confidence, and proactively manage to secure success.Recruiting for this role ends on... ...based on new and emerging data risks, advising on best practices for data encryption...Work experience placementLocal areaVisa sponsorship- ...oversight of artificial intelligence use cases throughout their lifecycle. The role exercises sound judgment in assessing AI-related risks, facilitating risk-based governance decisions, coordinating cross-functional review processes, and ensuring compliance with internal...Full timeWork at office
$87.5k - $202.8k
...opportunity to contribute to the company’s success. As a Credit Risk Review Advisor within PNC's Independent Risk Management organization... ...Deposit Insurance Act (FDIA) and, for any registered role, the Secure and Fair Enforcement for Mortgage Licensing Act of 2008 (SAFE...Full timeTemporary workPart timeWork experience placementWork at office- ...supporting or partnering with governance, security, or compliance teams in a regulated... ...enterprise environmentPosition Title: Application Analyst 2Business Unit: TechnologyReports to:... ...responsibility and the accountability to serve as risk managers for their businesses by...Full timeWork at officeLocal areaRelocation
$128k - $252.5k
...requirements. • Developing workplans, tracking milestones, coordinating dependencies across workstreams, and identifying changes in scope or risks. • Building business cases, financial analyses, and client-ready deliverables to support IT synergy, cost reduction, migration, and...Local areaVisa sponsorshipFlexible hours- ...transmission and distribution of electric energy, providing a secure supply of reliable power to more than half a million customers... ...outcomes. We want you to join our team! Summary: The Senior Risk Analyst supports the execution and continuous improvement of the...Work at officeLocal area
$151.5k - $252.5k
...This role offers the opportunity to work on complex transactions, assess information technology and software environments, identify risks and value creation opportunities, and help clients make informed investment decisions in fast-moving deal settings. Recruiting for this...Local areaVisa sponsorship- ...Integration LeadershipLead the deployment and integration of:Endpoint Security Tooling (EDR, XDR, Defender, DLP, device control)Network... ...platformsNetwork security controlsSIEM/SOC ecosystemsIdentify risks and drive remediation plansAlign acquired entities with enterprise...Work at officeRemote workFlexible hours
$102k - $208k
...services environment. Reporting to the Director of Enterprise Architecture, this role partners with business, technology, risk, compliance, security, data, and product teams to deliver scalable, secure, resilient, and business-aligned solutions.This role is ideal for a...Full timeWork at officeRemote workWork from homeFlexible hours- ...of controls within the business application environmentPerform risk assessments related to cybersecurity, data integrity, and system... ...experience preferredWorking knowledge of IT processes: network, cloud security, OS, applications, databases, information security, and ERP...Full timeLocal area
$144.9k - $265.8k
...consolidations and hybrid identity programs. ~ Translating business, security and regulatory needs into practical identity architecture,... .... ~ Guiding delivery teams across workstreams, timelines, risks, technical decisions and stakeholder communications. ~...Full timeSummer holidayFlexible hours- ...career opportunity is currently available for an entry level Risk & Compliance Analyst local to Aires Pittsburgh, PA office. This... ...are essential ~ Understanding of fundamental privacy, security, and IT concepts (access controls, data retention, data privacy...Contract workLocal areaRelocationRelocation package
- ...job works collaboratively to support all risk and compliance assessment activities across... ...including the assessment of third-party security posture, information security controls... ...Accountant (CPA) Certified Information Systems Analyst (CISA) Certified Information Privacy...Contract workFor contractorsWork at officeLocal area
- ...Identity and Access Management Engineer to join our Information Security Division team. This role is located in Pittsburgh, PA .In this role... ...controls, and code review processes in alignment with internal risk management, audit, and compliance requirements (e.g., SOC1, SOX,...Work experience placementWorldwideFlexible hours
- General information Job Posting Title Cyber Security Manager Date Friday, July 31, 2026 City Pittsburgh State PA Country United States Working time Full-time Description & Requirements The Cyber Security Manager provides integrated...Minimum wageFull timeContract workTemporary workWork experience placement
- Position Summary Deloitte’s Cyber team helps clients address evolving cybersecurity... ...You will design, implement, and optimize secure, outcome-focused solutions while... ...Collaborating with security operations center (SOC) analysts and threat detection engineers to...Local area
- ...supporting critical financial systems and interfaces that enable secure, accurate, and timely processing of transactions and message... ...change management, and implementation supportAbility to manage risk, prioritize issues, and work effectively in high-pressure production...Work experience placementWorldwideFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Security Risk Analyst. Be the first to apply!
- information security consultant Pittsburgh, PA
- entry level cyber security analyst Pittsburgh, PA
- cyber security analyst Pittsburgh, PA
- risk analyst Pittsburgh, PA
- risk officer Pittsburgh, PA
- it risk analyst Pittsburgh, PA
- operational risk specialist Pittsburgh, PA
- risk consultant Pittsburgh, PA
- operational risk consultant Pittsburgh, PA
- cyber Pittsburgh, PA

