Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Security Risk Analyst

Alcoa Inc

Shape Your WorldAt Alcoa, you will become an essential part of our purpose: to turn raw potential into real progress. The way we see it, every Alcoan is a work-shaper, team-shaper, idea-shaper & world-shaper.Alcoa is seeking a Cyber Security Risk Analyst to serve as a key contributor to the cybersecurity risk management program, providing subject matter expertise in identifying, assessing, and managing risks across both Information Technology (IT) and Operational Technology (OT) environments. This role supports informed business decision-making by translating complex technical risks into business and operational impact. The Analyst independently leads risk assessments and partners closely with IT, OT, audit, and senior leaders to ensure cybersecurity risks are understood, documented, mitigated, and monitored in accordance with corporate policies and industry standards. As Alcoa’s Cybersecurity Risk Management program continues to mature, the Analyst plays a critical role in shaping and enhancing program capabilities. About the Role:Contribute to the development, implementation, and continuous improvement of the Cybersecurity Risk Management Program, including frameworks, methodologies, policies, standards, and supporting tools. Perform cybersecurity risk assessments across IT, OT, cloud, and third-party environments, including enterprise systems and manufacturing/process control systems (PCS). Facilitate risk workshops with technical and business stakeholders to evaluate risks associated with new technologies, projects, and operational changes. Serve as a subject matter expert on risk methodology, scoring, and evaluation. Maintain and enhance the cybersecurity risk register, including risk scoring, treatment plans, and residual risk tracking. Support and guide risk treatment strategies (mitigation, acceptance, transfer, avoidance) and partner with compliance teams to design and implement appropriate controls. Translate technical risk findings into clear business and operational impact statements for non-technical audiences and senior leadership. Advise leadership on risk exposure, trends, and residual risks, including impacts to business operations and production. Define, monitor, and report Key Risk Indicators (KRIs) and emerging threat trends. Support audit, regulatory, and compliance activities (e.g., ISO 27001, NIST, SOC) related to cybersecurity risk management. Collaborate with Enterprise Risk Management (ERM) and Operations Risk Management teams to ensure alignment and integration of cybersecurity risks into broader risk reporting. Build and maintain strong relationships with stakeholders across IT, OT, business units, and risk management functions. Continuously monitor evolving cyber threats, emerging technologies, and industry practices to enhance risk management processes and capabilities. What you can bring to this role:Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, Risk Management, or a related discipline; equivalent professional experience may be considered in lieu of a degree. 6+ years of experience in cybersecurity, IT risk management, information security, governance, compliance, or IT operations within enterprise environments. Demonstrated experience assessing cybersecurity risk across IT and OT environments; experience in manufacturing or industrial organizations preferred. Strong knowledge of cybersecurity frameworks and standards (e.g., ISO 27001, NIST CSF, NIST 800-53, CIS Controls, SOX). Proven experience executing core GRC activities, including risk assessments, policy and standard development, control validation, audit support, and remediation tracking. Expertise in cybersecurity governance, risk assessment, and compliance program implementation. Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards. Solid understanding of security principles, including security controls, threat modeling, vulnerability management, and incident risk analysis. Excellent written, verbal, and facilitation skills, with the ability to translate complex technical risks into clear business impacts. Demonstrated ability to collaborate effectively with cross-functional stakeholders, including technical teams, operations, and senior leadership, while managing multiple priorities in fast-paced environments. Preferred Qualifications Relevant industry certifications such as CISSP, CISM, CRISC, CISA, CGRC, Security+, GRCP, or equivalent. Experience with third-party/vendor risk management, regulatory compliance assessments, and security awareness programs. Experience supporting global environments and contributing to enterprise-wide security or compliance initiatives. Experience supporting audits and assurance activities, including ISO/IEC 27001 certification and SOC report reviews. Familiarity with security operations capabilities, including SIEM, log analysis, and event monitoring for compliance and incident response. Understanding of enterprise security domains, including cloud security, infrastructure security, and identity and access management (IAM). Working knowledge of project management methodologies and practices. Experience in metals, mining, manufacturing, or other heavy industrial environments. What we offer:Competitive compensation packages, including pay-for performance variable pay, recognition and rewards programs, and stock-based compensation awards (3-year vesting schedule)Flexible spending accounts and generous employer contribution to the HSA401(k), employer match up to 6%, additional employer retirement income contribution (no vesting period), and a non-qualified deferred compensation plan12 paid holidays per year.15 days of paid vacation (pro-rated from hire date).Employee Assistance Program (EAP)#LI-TL2Employees must be legally authorized to work in the United States. Verification of employment eligibility will be required at the time of hire. Visa sponsorship is not available for this position. About the LocationAlcoa is an international company with multiple locations and joint ventures across six continents. Wherever you choose to join us, you'll be joining a global team committed to advancing sustainability and delivering excellence and innovation. As industry pioneers, we are redefining what it means to be a sustainable aluminum company, bridging the journey from mines to metal.We are values led, vision driven and united by our purpose of transforming raw potential into real progress. Our commitments to Inclusion, Diversity & Equity include providing trusting workplaces that are safe, respectful and inclusive of all individuals, free from discrimination, bullying and harassment and that our workplaces reflect the diversity of the communities in which we operate.As a proud equal opportunity workplace and affirmative action employer, Alcoa is dedicated to providing equal opportunities and equal access to all individuals regardless of a person’s gender, age, race, ethnicity, sexual orientation, gender identity, religion, nation of origin, disability, veteran status, language spoken or any other characteristic or status protected by the laws or regulations in the places where we operate.If you have visited our website in search of information on U.S. employment opportunities or to apply for a position, and you require an accommodation, please contact Alcoa Recruiting via email at View email address on click.appcast.io is a place where you are empowered to do your best work, be your authentic self, and feel a true sense of belonging. Come join us and shape your career!Your work. Your world. Shape them for the better.SummaryLocation: United States, PA, Pittsburgh; Canada, QC, Bécancour; US ATR New Kensington, Pennsylvania; Canada, QC, Montréal; Canada, QC, Baie-Comeau; Canada, QC, DeschambaultType: Full time

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Cyber Security Risk Analyst in New Kensington, PA vacancy
  • $117k - $187.2k

    Job TitleInformation Security ManagerJob DescriptionThe Information Security Manager will help strengthen information security across Philips...  ...IT and operational environments. You will focus on identifying risks, driving security improvements, supporting incident response... 
    Suggested
    Full time
    Work at office
    Local area
    Immediate start
    Work visa
    3 days per week

    Philips

    Murrysville, PA
    2 days ago
  • $112k - $168k

     ...forYou will be responsible for implementing and monitoring technical security controls to ensure compliance with Re:Build's requirements and...  ...implement processes and technology that systematically reduce risk to the organization.What you get to do!Design, implement, and... 
    Suggested
    Permanent employment
    Work at office
    Remote work
    1 day per week

    Re:Build Manufacturing

    New Kensington, PA
    2 days ago
  • $10 per hour

    About Re:Build ManufacturingRe:Build Manufacturing is a growing family of industrial and engineering businesses combining enabling technologies, operational superiority, and strategic M&A to build America’s next generation industrial company. At Re:Build we deploy deep ...
    Suggested
    Permanent employment
    Contract work
    Work at office

    Re:Build Manufacturing

    New Kensington, PA
    2 days ago
  • $68.3k - $146.5k

     ...SummaryAs an Experienced Supply Chain Systems Analyst at BPMI, you will work under limited...  ...e.g., classified shipment reports, asset risk assessment reports, production status reports...  ...States Navy in their pursuit of national security.Competitive and attractive pay and... 
    Suggested
    Full time
    Contract work
    For contractors
    Work at office

    Bechtel Plant Machinery

    Monroeville, PA
    3 days ago
  • $117k - $187.2k

    Information Security Manager The Information Security Manager will be responsible for developing, implementing and monitoring strategic and...  ..., and mitigate operational technology, cloud, network, and IoT risk and/or threats on Integrated Supply Chain manufacturing security... 
    Suggested
    Full time
    Work at office
    Immediate start
    Work visa
    3 days per week

    Philips Iberica SAU

    Murrysville, PA
    1 day ago
  •  ...This is a 1099 position with a 6-month contract to hire. Rate is dependent upon experience level. As a Business Analyst, you are a highly effective liaison between clients and the software development team. This role requires you to develop a deep understanding of as-is... 
    Contract work
    Work experience placement
    Local area

    Method Automation Services Inc.

    New Kensington, PA
    3 days ago
  •  ...Position Summary: Analyst II is a mid-level laboratory technician who performs technical testing and analytical procedures with moderate supervision for the Inorganic Chemistry Department. This position requires working knowledge of laboratory protocols, data analysis... 
    Work at office

    RJ Lee Group

    Monroeville, PA
    3 days ago
  • $98k - $155k

     ...actionable insights and translate them into production and supply plans. Present detailed reports to senior leadership, highlighting trends, risks, and opportunities for improvement.Supply Strategy, Risk Management & Compliance: Determine optimal supply levels, coordinate with... 
    Full time
    Work experience placement
    Work at office
    Immediate start
    Work visa
    Relocation package
    3 days per week

    Philips

    Murrysville, PA
    3 days ago
  • $60.48k - $77.12k

    Salary : $60,482.52 - $77,115.20 (starting salary based on qualifications and experience). Overview Performs difficult professional, advanced analytical work preparing, analyzing and assisting in the management of the County’s Budget and intermediate technical work performing...
    Local area

    County of Davidson

    Penn Hills, PA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Security Risk Analyst. Be the first to apply!