Risk Analyst - Information Security

1 Month ago • 5 Years + • Cyber Security • $77,400 PA - $110,300 PA

Job Summary

Job Description

As a Cybersecurity Risk Analyst within the Information Security Assurance (ISA) team, you will design, implement, and operate a strategic Risk Management program to protect the organization and its stakeholders. This role involves leading comprehensive risk assessments, identifying threats, and developing mitigation strategies. You will collaborate across departments to embed risk practices, drive governance, and foster a risk-aware culture. The ideal candidate will continuously evaluate and streamline risk management processes, ensuring effective remediation and adaptation to emerging threats, balancing risk with business objectives.
Must have:
  • Bachelor’s degree in Business, Technology, Cyber Security, Technology Risk Management or related field.
  • 5+ years experience within IT operations, Security or Risk management.
  • Strong analytical and problem-solving skills.
  • Strong interpersonal skills.
  • Knowledge of industry Risk management frameworks.
  • Knowledge of common mitigation practices.
  • Knowledge of Organizational control management.
  • Demonstrate professional skepticism.
  • Understanding of business processes, internal risk management strategies, and IT controls.
  • Proficiency in process formulation and improvement.
  • Knowledge of operational security capabilities including access control and network security.
  • Knowledge of secure configuration and vulnerability management.
  • Knowledge of intrusion detection, security monitoring, and incident response.
  • Experience with internal and regulatory auditors.
  • Proven solid written and oral communication skills.
  • Design and implement a comprehensive risk management framework.
  • Establish risk assessment methodologies, including threat modeling and vulnerability scoring systems.
  • Develop policies, procedures, and guidelines for risk identification, analysis, and mitigation.
  • Create risk reporting structures and dashboards for effective communication to stakeholders.
  • Continuously evaluate and streamline risk management processes to improve efficiency.
  • Lead and conduct comprehensive risk assessment to identify, prioritize, and quantify security threats.
  • Utilize risk analysis methodologies and tools to assess existing security controls.
  • Provide expert guidance on risk mitigation strategies and control implementation.
  • Develop risk management methodologies tailored to the organization’s specific risk profile.
  • Collaborate with stakeholders to establish risk tolerance levels and develop mitigation plans.
  • Develop remediation plans based on risk assessment findings, prioritizing critical vulnerabilities.
  • Work closely with stakeholders to implement security controls and measures for remediation.
  • Monitor remediation progress and provide regular updates to management.
  • Conduct post-remediation reviews to validate effectiveness and identify residual risks.
  • Drive clear, concise, pragmatic outcomes balancing risk with business objectives.
  • Foster a culture of accountability for information security.
  • Promote open communication channels for reporting concerns and potential risks.
  • Establish channels for risk reporting and feedback from employees.
  • Establish metrics and KPIs to measure risk management program effectiveness.
  • Regularly review and update the risk management framework for emerging threats.
  • Stay informed on industry best practices and regulatory changes.
  • Foster partnerships with internal and external stakeholders to evolve capabilities.
  • Be curious about the business and seek to understand.
  • Bring new ideas, methods, and approaches to this role.
  • Leverage expertise to challenge the status quo and drive decisions.
Good to have:
  • ISO 27001 knowledge
  • NIST CSF knowledge
  • Governance and Risk Certification (CRIS, CISM, CISA, or CISSP)
Perks:
  • Health benefits
  • Welfare benefits
  • Retirement benefits
  • Annual bonus (if eligible)
  • Hybrid work schedule

Job Details

It’s not just about your career or job title…

It’s about who you are and the impact you will make on the world. Because whether it’s for each other or our customers, we put People First. When our people come together, we Expand the Possible and continuously look for ways to improve what we create and how we do it. If you are constantly striving to grow, you’re in good company. We are revolutionizing the way the world moves for future generations, and we want someone who is ready to move with us.

Who will you be working with?

Join Enterprise Information Security (EIS) to drive cybersecurity excellence leveraging intelligence, strategic partnerships, and analysis. Collaborate daily with GRC, Architecture, Operations, and key Information Technology stakeholders to advance our information security capabilities.

How will you make a difference?

As a member of Information Security Assurance (ISA) team, we are looking for a Cybersecurity Risk Analyst. This role reports to the ISA Sr Manager within EIS, and will be responsible for designing, building, developing, implementing, and operating a strategic Risk Management program to protect the organization and its stakeholders while supporting our strategic objectives. This role needs a strategic thinker with a strong technical expertise and understanding of common threats, and deep knowledge of risk frameworks. The Risk Analyst will collaborate across departments to embed risk practices into business processes, drive governance, and support informed decision-making. This position plays a critical role in fostering a risk-aware culture across the organization, promoting awareness of security risks and empowering employees to actively contribute to enhancing the organization’s risk posture.

What do we want to know about you?

You must have:

  • Bachelor’s degree in Business, Technology, Cyber Security, Technology Risk Management or related field or hands-on and strong experience
  • 5+ years experience within IT operations, Security or Risk management
  • Strong analytical and problem-solving skills; ability to decipher and prioritize asks accordingly
  • Strong interpersonal skills.
  • Knowledge of industry Risk management frameworks, common mitigation practices, and Organizational control management.
  • Demonstrate professional skepticism to ensure evidence is sufficient when assessing the relevant information security controls.
  • Demonstrate an understanding of business processes, internal risk management strategies, IT controls, and how they interact together.
  • Demonstrate proficiency in process formulation and improvement.
  • Knowledge of operational security capabilities including access control, network security, secure configuration and vulnerability management, intrusion detection, security monitoring and incident response.
  • Experience with auditors, both internal and regulatory to drive positive audit results with strong remediation paths.
  • Proven solid written and oral communication skills with the ability to effectively communicate status, risks, and remediations to executive management.

We would love it if you had:

  • ISO 27001 and NIST CSF knowledge are highly desirable.
  • Governance and Risk Certification a plus (CRISC, CISM, CISA, or CISSP)

What will your typical day look like?

The ideal candidate will have experience designing, building, operating, and maturing effective programs to manage Information Security Risks and their remediations.

Risk Management Program Development:

  • Design and implement a comprehensive risk management framework tailored to the organization's needs.
  • Establish risk assessment methodologies, including threat modeling and vulnerability scoring systems.
  • Develop policies, procedures, and guidelines for risk identification, analysis, and mitigation.
  • Create risk reporting structures and dashboards for effective communication to stakeholders.
  • Continuously evaluate and streamline risk management processes to improve efficiency, reduce complexity, and enhance responsiveness to emerging risks.

Comprehensive Risk Identification, Assessment & Analysis:

  • Lead and conduct comprehensive risk assessment to identify, prioritize and quantify potential and existing security threats and vulnerabilities across the organization’s systems, network, and applications.
  • Utilize risk analysis methodologies and tools to assess the effectiveness of existing security controls and identify areas for improvement.
  • Provide expert guidance on risk mitigation strategies and control implementation to minimize exposure to security risks.
  • Develop risk management methodologies tailored to the organization’s specific risk profile and business priorities.
  • Collaborate with stakeholders to establish risk tolerance levels and develop risk mitigation plans.

Risk Remediation Planning & Execution:

  • Develop remediation plans based on the findings of risk assessments, prioritizing actions to address critical vulnerabilities and mitigate high-risk threats.
  • Work closely with relevant stakeholders to implement security controls and measures to remediate identified risks effectively.
  • Monitor the progress of remediation efforts and provide regular updates to management on the status of risk mitigation initiatives.
  • Conduct post-remediation reviews and analysis to validate the effectiveness of remediation activities and identify any residual risks.

Risk-Awareness Culture:

  • Drive clear, concise, pragmatic outcomes balancing risk with business objectives.
  • Foster a culture of accountability and responsibility for information security by encouraging active participation in risk identification, reporting, and mitigation efforts.
  • Promote open communication channels for reporting concerns and potential risks, and ensure timely resolution and escalation as needed.
  • Establish channels for risk reporting and feedback from employees across departments.

Continuous Improvement & Adaptation:

  • Establish metrics and KPIs to measure the effectiveness of the risk management program.
  • Regularly review and update the risk management framework to address emerging threats.
  • Stay informed on industry best practices and regulatory changes to enhance the program.
  • Foster partnerships with internal and external stakeholders to evolve risk management capabilities.
  • Be curious about our business and seek to understand.
  • Bring new ideas, methods, and approaches to this role. Leverage own expertise to challenge the status quo and drive decisions

Physical Demands:

  • Employee is required to work on a computer for up to 8 hours per day
  • Employee may be in a sitting position for several hours per day
  • Employee must be able to read small text on computer screens/monitors
  • Employee is regularly required to talk and hear

Work Environment: (Usual office job)

  • Hybrid work schedule (both on-site and remote)
  • The employee will normally work in a temperature-controlled office environment, with frequent exposure to electronic office equipment. During visits to areas of operations, may be exposed to extreme cold or hot weather conditions. Is occasionally exposed to fumes or airborne particles, toxic or caustic chemicals, and loud noise

The salary range for this role is between $77,400.00-$110,300.00. The actual salary offered to a candidate may be influenced by a variety of factors, such as: training, transferable skills, work experience, education, business needs, market demands and work location. The base pay range is subject to change and may be modified in the future. More information on offered benefits, which include health, welfare, and retirement, are available at mywabtecbenefits.com. Other benefit offerings for this role may include an annual bonus, if eligible.

Similar Jobs

Rackspace Technology - Business Operations Analyst IV

Rackspace Technology

India (Remote)
3 Weeks ago
Lilt - Translator from German to Simplified Chinese

Lilt

Beijing, China (Remote)
6 Months ago
Cineplex - General Manager

Cineplex

Dartmouth, Nova Scotia, Canada (On-Site)
1 Year ago
Guardian - Head Of Cyber Security Governance

Guardian

New York, United States (Hybrid)
3 Months ago
Aeries technology - Entity Controller

Aeries technology

Mumbai, Maharashtra, India (On-Site)
3 Weeks ago
Imanage - Security Compliance Analyst

Imanage

Bengaluru, Karnataka, India (Hybrid)
1 Month ago
Synechron - Practice Head, Cybersecurity

Synechron

New York, United States (On-Site)
2 Months ago
Google - Software Engineer, Security

Google

Munich, Bavaria, Germany (On-Site)
1 Month ago
Thales - Intern - Trainer (Cybersecurity)

Thales

Fredericton, New Brunswick, Canada (On-Site)
1 Month ago
CME Group - Security Engineer II

CME Group

Bengaluru, Karnataka, India (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Roblox - Senior Engineering Manager - Avatar

Roblox

San Mateo, California, United States (On-Site)
1 Month ago
Sonat Game Studio - HR Leader/Manager

Sonat Game Studio

Hanoi, Vietnam (On-Site)
1 Month ago
Redhorse Corp - Data Scientist - Active Secret Clearance Required

Redhorse Corp

Tampa, Florida, United States (On-Site)
1 Month ago
CD PROJEKT RED - IT Director

CD PROJEKT RED

Boston, Massachusetts, United States (On-Site)
3 Months ago
DraftKings - Operations Associate

DraftKings

Ralston, Nebraska, United States (On-Site)
1 Year ago
Paper Stacking games - Localization PM - Infinity Nikki (Xingdie)

Paper Stacking games

Shanghai, China (On-Site)
1 Month ago
Alpha Sense - Senior Cloud Security Engineer

Alpha Sense

Mumbai, Maharashtra, India (On-Site)
2 Months ago
Ruselle Investments - Manager, Application Development

Ruselle Investments

Mumbai, Maharashtra, India (On-Site)
1 Month ago
CO:Create - Data Operations Analyst

CO:Create

New York, United States (Remote)
3 Months ago
GoMotive - Manager, Public Sector

GoMotive

Pakistan (Remote)
1 Month ago

Get notifed when new similar jobs are uploaded

Jobs in Pittsburgh, Pennsylvania, United States

Riot Games - Senior Motion Graphics Artist - League of Legends

Riot Games

Los Angeles, California, United States (On-Site)
1 Month ago
Next Level Business Services - Business Analyst

Next Level Business Services

Petaluma, California, United States (On-Site)
10 Months ago
Redhorse Corp - Logistics Management Support Specialist

Redhorse Corp

Arlington, Virginia, United States (On-Site)
1 Month ago
Alten Technology - Senior Structural Analyst (LS-DYNA)

Alten Technology

Mukilteo, Washington, United States (On-Site)
1 Month ago
Visa - Sr. Analyst, Regulatory Affairs

Visa

Atlanta, Georgia, United States (Hybrid)
3 Months ago
Nasdaq - QA Test Analyst

Nasdaq

New York, New York, United States (Hybrid)
3 Weeks ago
Clearwater Analytics - Sr. Subject Matter Expert - Client Servicing

Clearwater Analytics

Boise, Idaho, United States (On-Site)
2 Months ago
Self - Principal Growth Analyst

Self

Austin, Texas, United States (Remote)
1 Month ago
Next Level Business Services - Documentum Developer

Next Level Business Services

Houston, Texas, United States (On-Site)
10 Months ago
Axon - Senior Firmware Engineer I - LTE

Axon

Scottsdale, Arizona, United States (Remote)
1 Month ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Jane Street - Network Engineer, Security

Jane Street

London, England, United Kingdom (On-Site)
1 Month ago
laika games - Application Security Engineer

laika games

Hillsboro, Oregon, United States (On-Site)
1 Month ago
Anavation - Senior Information Security Specialist

Anavation

Clarksburg, West Virginia, United States (Hybrid)
3 Weeks ago
AeroSpike - Security Engineer, DevSecOps

AeroSpike

United States (Remote)
2 Months ago
Tide - Staff Backend Engineer - DevEx, Security and Technology Foundations

Tide

Belgrade, Serbia (Hybrid)
3 Months ago
QS Quacquarelli Symonds  - IT Security Specialist

QS Quacquarelli Symonds

Bengaluru, Karnataka, India (Hybrid)
1 Month ago
Vercel - Staff Security Operations Engineer

Vercel

San Francisco, California, United States (Hybrid)
3 Months ago
Nexon - Associate Security Engineer

Nexon

El Segundo, California, United States (Hybrid)
4 Months ago
appier - Security Engineer

appier

Taipei City, Taiwan (On-Site)
1 Month ago
Tesla - Security Systems Field Engineer

Tesla

Brandenburg, Germany (On-Site)
6 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Want to move the world? Want to innovate and bring that innovation to life? At Wabtec, we are in the business of realizing potential – that of the transportation industry, and yours! Drawing on nearly four centuries of collective success across the vibrant portfolios of Wabtec, GE Transportation and Faiveley Transport, we offer employees hands-on opportunities all over the world to shape the future of transportation – as well as their own. Wabtec is focused on performance that drives progress, leveraging our digital expertise, technological innovation, and world-class manufacturing and services to create transportation solutions that move and improve the world. Along with our industry-leading portfolio of products and solutions for the rail and transit industries, Wabtec is a leader in mining, marine, and industrial solutions.

State Of Minas Gerais, Brazil (On-Site)

Guadalajara, Jalisco, Mexico (On-Site)

Milwaukee, Wisconsin, United States (On-Site)

Erie, Pennsylvania, United States (On-Site)

Crown Point, Indiana, United States (On-Site)

Lincoln, England, United Kingdom (On-Site)

Barnsley, England, United Kingdom (On-Site)

Export, Pennsylvania, United States (On-Site)

Kansas City, Missouri, United States (On-Site)

View All Jobs

Get notified when new jobs are added by WebTech Corporation

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug