Talent.com
Wabtec
Risk Analyst - Cybersecurity Risk & ControlsWabtec • Pittsburgh, PA
Risk Analyst - Cybersecurity Risk & Controls

Risk Analyst - Cybersecurity Risk & Controls

Wabtec • Pittsburgh, PA
Hace más de 30 días
Salario
77.400,00 US$ anual
Tipo de contrato
  • A tiempo completo
Descripción del trabajo

It’s not just about your career or job title… It’s about who you are and the impact you will make on the world. Because whether it’s for each other or our customers, we put People First. When our people come together, we Expand the Possible and continuously look for ways to improve what we create and how we do it. If you are constantly striving to grow, you’re in good company. We are revolutionizing the way the world moves for future generations, and we want someone who is ready to move with us.

Who will you be working with?

Join Enterprise Information Security (EIS) to drive cybersecurity excellence leveraging intelligence, strategic partnerships, and analysis. Collaborate daily with GRC, Architecture, Operations, and key Information Technology stakeholders to advance our information security capabilities.

How will you make a difference?

As a member of ISA team, Wabtec is looking for a Senior Cybersecurity Risk & Controls Analyst. This role reports to the ISA Sr Manager within EIS, and will be responsible for building, developing, implementing, and operating a strategic Risk & Controls Management program to protect Wabtec and its stakeholders while supporting our strategic objectives.

In this position, you will assume a leading role in driving the organization’s information security risk management efforts through the identification, assessment, and remediation of security risks, ensuring the protection of critical assets, the implementation of adequate security controls and compliance with legal, statutory, regulatory and contractual requirements. Additionally, you will play a pivotal role in fostering a risk-aware culture across the organization, promoting awareness of security risks and empowering employees to actively contribute to the organization’s risk posture. You will collaborate cross-functionally with IT and with Business stakeholders to develop and implement robust security strategies and practices, guiding the organization towards a mature and resilient security posture.

What do we want to know about you?

You must have:

  • Bachelor’s degree in Business, Technology, Cyber Security, Technology Risk Management or related field or strong hands-on experience.

  • 3+ years experience in Security & Risk management.

  • Prior experience in IT or Cybersecurity, supporting systems or developing/supporting applications.

    Knowledge of technical controls and ability to describe them to business/system owners

  • Knowledge of industry Risk management frameworks, common mitigation practices, and Organizational control management.

  • Demonstrate professional skepticism to ensure evidence is sufficient when assessing the relevant information security controls.

  • Demonstrate an understanding of business processes, internal risk management strategies, IT controls, and how they interact together.

  • Demonstrate proficiency in process formulation and improvement.

  • Knowledge of operational security capabilities including access control, network security, secure configuration and vulnerability management, intrusion detection, security monitoring and incident response.

  • Proven solid written and oral communication skills with the ability to effectively communicate status, risks, and remediations to executive management.

We would love it if you had:

  • ISO 27001 and NIST CSF knowledge is highly desirable.

  • Governance and Risk Certification a plus (CRISC, CISM, CISA, or CISSP)

What will your typical day look like?

Risk Management Program Development:

  • Design and implement a comprehensive risk management framework tailored to the organization's needs.

  • Establish risk assessment methodologies, including threat modeling and vulnerability scoring systems.

  • Develop policies, procedures, and guidelines for risk identification, analysis, and mitigation.

  • Create risk reporting structures and dashboards for effective communication to stakeholders.

Risk Identification, Assessment, Analysis and Mitigation Strategy:

  • Conduct initial organization-wide risk assessments to establish a baseline risk profile.

  • Lead risk assessments to identify and prioritize security threats across systems.

  • Prioritize and categorize identified risks based on potential impact and likelihood.

  • Analyze the effectiveness of existing controls and recommend improvements.

  • Collaborate with stakeholders to formulate risk treatment plans and mitigation strategies aligned with business objectives.

  • Implement and oversee the execution of risk remediation initiatives.

Control Assessment and Policy Alignment

  • Develop and maintain a comprehensive inventory of security controls and associated policies across the organization

  • Perform gap analysis between existing controls/policies and industry best practices or regulatory requirements

  • Implement processes to regularly evaluate the effectiveness of security controls and the adherence to established policies

  • Recommend improvements to controls and policies based on assessment findings

  • Collaborate with relevant teams to enhance or implement new controls and policies to address identified gaps

Risk-Aware Culture Cultivation:

  • Drive pragmatic outcomes balancing risk with business objectives

  • Establish channels for risk reporting and feedback from employees across departments.

  • Foster a culture of accountability in risk management across the organization.

  • Collaborate with leadership to integrate risk considerations into decision-making processes.

Continuous Improvement and Adaptation:

  • Establish metrics and KPIs to measure the effectiveness of the risk management program.

  • Regularly review and update the risk management framework to address emerging threats.

  • Stay informed on industry best practices and regulatory changes to enhance the program.

  • Foster partnerships with internal and external stakeholders to evolve risk management capabilities.

What about the physical demands of the job? (Usual office job examples)

  • Regularly remaining in a stationary position, often standing or sitting for prolonged periods

  • Regularly communicating with others to exchange information

  • Regularly required to attend meetings in person and virtually using video and audio computer equipment

  • Regularly repeating motions that may include the wrists, hands and/or fingers, such as typing

  • Occasionally moving about to accomplish tasks or moving from one worksite to another

  • Occasionally light work that includes moving objects up to 20 pounds

Work Environment:

  • Hybrid work schedule (both on-site and remote)

  • The employee will normally work in a temperature-controlled office environment, with frequent exposure to electronic office equipment. During visits to areas of operations, may be exposed to extreme cold or hot weather conditions. Is occasionally exposed to fumes or airborne particles, toxic or caustic chemicals, and loud noise

#LI-TD1

Our job titles may span more than one career level. The salary range for this role is between

$77,400.00-$110,300.00

The actual salary offered to a candidate may be influenced by a variety of factors, such as: training, transferable skills, work experience, education, business needs, market demands and work location. The base pay range is subject to change and may be modified in the future. More information on offered benefits, which include health, welfare, and retirement, are available at mywabtecbenefits.com. Other benefit offerings for this role may include an annual bonus, if eligible.

Who are we?

Wabtec Corporation is a leading global provider of equipment, systems, digital solutions, and value-added services for freight and transit rail as well as the mining, marine, and industrial markets. Drawing on nearly four centuries of collective experience across Wabtec, GE Transportation, and Faiveley Transport, the company has grown to become One Wabtec, with unmatched digital expertise, technological innovation, and world-class manufacturing and services, enabling the digital-rail-and-transit ecosystems.

Wabtec is focused on performance that drives progress and unlocks our customers’ potential by delivering innovative and lasting transportation solutions that move and improve the world. We are lifelong learners obsessed with making things better to drive exceptional results. Wabtec has approximately 27K employees in facilities throughout the world. Visit our website to learn more!

Our Commitment to Embrace Diversity:

Wabtec is a global company that invests not just in our products, but also our people by embracing diversity and inclusion. We care about our relationships with our employees and take pride in celebrating the variety of experiences, expertise, and backgrounds that bring us together. At Wabtec, we aspire to create a place where we all belong and where diversity is welcomed and appreciated.

To fulfill that commitment, we rely on a culture of leadership, diversity, and inclusion. We aim to employ the world’s brightest minds to help us create a limitless source of ideas and opportunities. We have created a space where everyone is given the opportunity to contribute based on their individual experiences and perspectives and recognize that these differences and diverse perspectives make us better.

We believe in hiring talented people of varied backgrounds, experiences, and styles… People like you! Wabtec Corporation is committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or expression, or protected Veteran status. If you have a disability or special need that requires accommodation, please let us know.

Crear una alerta de empleo para esta búsqueda

Risk Analyst - Cybersecurity Risk & Controls • Pittsburgh, PA

Ofertas similares

Senior Manager Product Cybersecurity COE 60024

SOMERSET STAFFINGPittsburgh, PA, United States
154.000,00 US$ anual
A tiempo completo
Quick Apply

Job Description:</b><div></div><div>Industry: Manufacturing & Production</div><div>Job Category: Research & Development</div><div><div>... Mostrar más

Project Manager

TEKsystemsWarrendale, Pennsylvania, United States
A tiempo completo

Looking for a new project manager role?.We are seeking a Project Manager to join our our clients security team.This role will be responsible for managing and delivering security-related projects, p... Mostrar más

 • Oferta promocionada

Director, Commodity Risk Controller

ArconicPittsburgh, PA, United States
A tiempo completo

At Arconic, we are looking for people who share our values of integrity, inclusion, and diversity, and who demonstrate agility, results commitment, and the capability to grow themselves and others.... Mostrar más

 • Oferta promocionada

Substation Protection and Controls Engineer

Leidos IncSeven Fields, Pennsylvania, United States
A tiempo completo

Looking for an opportunity to make an impact?.Everything we do is built on a commitment to do the right thing for our customers, our people, and our community.Our Mission, Vision, and Values guide ... Mostrar más

 • Oferta promocionada

Strategic Enterprise Security Architect — Hybrid

Federated HermesWarrendale, Allegheny County, United States
A tiempo completo

A global investment firm based in Warrendale, Pennsylvania, is seeking a Technical Security Architect to join their Global Technology Organization.The role involves creating and executing an Inform... Mostrar más

 • Oferta promocionada

Business Analyst - Cybersecurity Risk Management

NTT DATAPittsburgh, PA, United States
A tiempo completo

NTT DATA Cybersecurity Risk Management Program Management.NTT DATA's client is seeking a strategic and highly analytical Business Analyst to join our Cybersecurity Risk Management Program Managemen... Mostrar más

 • Oferta promocionada

Risk and Compliance Analyst

Highmark HealthPittsburgh, PA, United States
A tiempo completo

This job works collaboratively to support of all risk and compliance assessment activities of Highmark Health across a broad range of frameworks including NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, ... Mostrar más

 • Oferta promocionada

Senior Risk Management Analyst

Raymond James FinancialPittsburgh, PA, United States
A tiempo completo

Senior Risk Management Analyst.The Senior Risk Management Analyst assists in facilitating an effective risk framework through partnership with business, operations, and other staff units, as well a... Mostrar más

 • Oferta promocionada

Controls Management & Testing Analyst

Raymond James FinancialPittsburgh, PA, United States
A tiempo completo

Controls Management And Testing Analyst.The Controls Management and Testing Analyst is responsible for the identification, assessment, monitoring, reporting, testing, and supporting activities to m... Mostrar más

 • Oferta promocionada

Lead Risk Analyst

Westinghouse Electric Company LLCCranberry Township, PA, United States
A tiempo completo

Are you interested in being part of an innovative team that supports Westinghouse's mission to provide clean energy solutions? At Westinghouse, we recognize that our employees are our most valuable... Mostrar más

 • Oferta promocionada

Credit Risk Analyst

First National BankPittsburgh, PA, United States
A tiempo completo

This position is primarily responsible for assisting the Manager of Credit Risk and Reporting in the execution of one or more of the following: asset quality reporting, concentration analysis, the ... Mostrar más

 • Oferta promocionada

Senior Cybersecurity Operations Manager

Westinghouse Electric - USACranberry Township, PA, US
144.000,00 US$ anual
A tiempo completo
Quick Apply

As a Senior Cybersecurity Operations Manager, you will, coordinate all CISO activities to support functional priorities, such as strategic plans, programs, and operational processes.The Senior Cybe... Mostrar más

Field Risk Specialist

Datascan Technologies, LLCPittsburgh, Pennsylvania, United States, 15122
A tiempo completo
Quick Apply

In The News: Solifi Acquired DataScan on September 23, 2025: Solifi, a global leader in secured finance technology, today announced the acquisition of DataScan, a trusted North American leader in w... Mostrar más

 • Oferta promocionada

AI & Biosecurity Research Resident

RAND CorporationPittsburgh, Pennsylvania, United States
Temporal

RAND's Center on AI, Security, and Technology (CAST), part of the Global and Emerging Risks (GER) Division conducts cutting-edge research on transformative, high-impact technologies-including artif... Mostrar más

 • Oferta promocionada

Credit Risk Analyst

First National Bank of PennsylvaniaPittsburgh, Pennsylvania, United States
A tiempo completo

Make a difference - for us and for your future.Supervisor or Manager of Credit Risk.This position is primarily responsible for assisting the Manager of Credit Risk and Reporting in the execution of... Mostrar más

 • Oferta promocionada

Master at Arms

US NavyRoss Township, Pennsylvania, United States
A tiempo completo

Job Title: Security & Law Enforcement (Master-at-Arms).Category / Component: Enlisted • Active.Master-at-Arms (MA) Sailors provide the Navy's core security, antiterrorism, and law enforcement capa... Mostrar más

 • Oferta promocionada

Remote Financial Analyst

Micro1Allison Park, Pennsylvania, US
Teletrabajo
A tiempo completo +1

Investment Strategy & Advisory.Predictive Analytics & Visualization.Real-world expertise is turned into training data, evaluations, and feedback loops that improve how models perform.AI lab... Mostrar más

 • Oferta promocionada

Risk and Finance Manager

Pittsburgh Cultural TrustPittsburgh, PA, United States
A tiempo completo

The Risk and Finance Manager is responsible for monitoring financial processes and general organizational risk issues to improve safety, reduce costs, and mitigate organization risk through diligen... Mostrar más

 • Oferta promocionada

Vendor Risk Management Compliance Analyst

Brown Brothers HarrimanPittsburgh, PA, United States
A tiempo completo

Vendor Risk Management Compliance Analyst.At BBH, partnership is more than a form of ownershipit's our approach to business and relationships.We know that supporting your professional and personal ... Mostrar más

 • Oferta promocionada

InfoSec Project Manager - Lead Secure Initiatives

ConsultUSAWarrendale, Allegheny County, United States
A tiempo completo

An established industry player is seeking an experienced Information Security Project Manager to lead various initiatives within their Information Security Group.This role requires a strong backgro... Mostrar más