Security Risk Management Specialist

4 weeks ago


Pittsburgh, Pennsylvania, United States Alcoa Full time
About the Role:

As a Security Risk Analyst at Alcoa, you will play a crucial role in shaping the company's risk management program. Your input will be key in designing and implementing a comprehensive program that balances risk, compliance, and cost, aligning with the Company's business goals and IT strategy.

Key Responsibilities:
  • Contribute to the development of the IT Risk Management Program, including policy, standards development, implementation, and GRC platform configuration and adoption.
  • Conduct independent and comprehensive system risk assessments to determine the overall effectiveness of management, operational, and technical security controls.
  • Perform risk analysis, including threat, vulnerability, and probability of occurrence, for applications and systems undergoing risk assessments or major changes.
  • Assess system component configurations and baselines for currency during system risk assessments and change or updates for release management processes.
  • Provide a comprehensive assessment of information systems weaknesses and prepares the final security control gap analysis and system risk assessment report.
  • Ensure system owner corrective action plans are in place for vulnerabilities identified during risk assessments, audits, or self-assessments.
  • Provide input to the Risk Management process and maintain and update risk management policies, standards, guidelines, and procedures.
  • Validate and update security documentation reflecting application or system security design.
  • Identify opportunities to improve risk posture and develop solutions for remediating or mitigating risks and assessing residual risk.
  • Lead reporting efforts for information system weaknesses and corrective action plans.
  • Configure and manage risks and KPIs in a GRC platform.
  • Collaborate with stakeholders to provide threat awareness and education to Alcoa's users.
  • Work with project teams to ensure risk is adequately managed for new system/infrastructure/security projects.
  • Coordinate with the Enterprise Risk Management group for corporate-level risk reporting.
  • Partner with the Operations Risk Management group for overlap in information/Cybersecurity related risks.
Requirements:

To be successful in this role, you will need:

  • Bachelor's degree in Information Systems Security, Management, Cybersecurity, Computer Science, Risk Management, or equivalent degrees.
  • 6+ years of experience in Information Security/Cybersecurity risk and mitigation strategies, technologies, programs, and operations.
  • Experience with regulatory compliance and information security management frameworks (ISO-27001, ISO-27002, ISO-27005, ISO-31000, NIST800-39, NIST800-53).
  • Experience with GRC Platforms (AuditBoard) and one or more certifications such as CRISC, CGRC, GRCPTM, ISC2 CGRC - preferred but not required.
  • Knowledge of risk management processes, security architectures and technologies, data security, privacy principles, cyber defense, and vulnerability assessment tools.
  • Familiarity with application vulnerabilities, identity, access control methods, networking concepts and protocols, and security methodologies.
  • Ability to collaborate with stakeholders to make informed and balanced decisions about risk that balance the benefits of risk reduction and business performance.
  • Experience with business impact assessments, privacy impact assessments, and threat assessments.
  • Ability to interpret system vulnerability and configuration scanner results to identify vulnerabilities.
What's on Offer:

As a Security Risk Analyst at Alcoa, you will enjoy a range of benefits, including:

  • 401(k) with employer match up to 6%
  • Additional employer retirement income contribution (no vesting period)
  • Nonqualified deferred compensation plans
  • 15 days' vacation and one flexible holiday of your choice
  • Flexible spending accounts and generous employer contribution to the HAS
  • Paid annual volunteer hours
  • Career development opportunities to pursue your passions
  • Social and diversity-focused engagement opportunities


  • Pittsburgh, Pennsylvania, United States System One Holdings, LLC Full time

    Job Title: Sr Risk SpecialistJob Location: Pittsburgh, Cleveland, Birmingham, or DallasJob Type: Contract to HireJob Description:We are seeking a highly skilled Sr Risk Specialist to join our team at System One Holdings, LLC. As a Sr Risk Specialist, you will be responsible for executing the Technology Risk Management program, identifying opportunities for...


  • Pittsburgh, Pennsylvania, United States Prequel Solutions Full time

    Job Summary: We are seeking a highly skilled Risk Management Specialist to join our team at Prequel Solutions.Key Responsibilities:Lead the operating incident review program, analyzing control breakdowns and determining root causes.Oversee records management and insurance programs, ensuring regulatory compliance and adequate insurance coverage.Assist in the...


  • Pittsburgh, Pennsylvania, United States Ikea Full time

    Job SummaryWe are seeking a highly skilled Risk and Compliance Specialist to join our team at IKEA. As a key member of our unit, you will be responsible for promoting risk awareness, supporting informed decision-making, and ensuring compliance with internal and external expectations.Key ResponsibilitiesPromote risk awareness in the unit to support informed...


  • Pittsburgh, Pennsylvania, United States Saxon Global Full time

    Client: Financial firm/banking domain Title: Operational Risk Management Specialist Rate: Competitive hourly rate Location: Flexible, with options for remote work and occasional on-site meetings in Wilmington, DE, Pittsburgh, PA, or Lake Mary, FL. Duration: 4-month contractOur client is seeking a skilled Operational Risk Management Specialist to join their...


  • Pittsburgh, Pennsylvania, United States Synergy Staffing Full time

    Company Overview Synergy Staffing is a dynamic organization committed to delivering exceptional staffing solutions. Our mission is to connect top talent with leading businesses, fostering growth and success. Job Summary We are seeking an experienced Senior IT Risk Management Specialist to join our team. As a key member of our Internal Audit department,...


  • Pittsburgh, Pennsylvania, United States Citizens Bank Full time

    Citizens Bank is seeking a Physical Risk Management Specialist to join our team in managing risk across various regions.Key Responsibilities:Manage risk in Boston, Massachusetts; Short Hills, New Jersey; Johnston, Rhode Island; Pittsburgh, Pennsylvania; Chicago, IllinoisCollaborate with cross-functional teams to identify and mitigate potential risksDevelop...


  • Pittsburgh, Pennsylvania, United States United Software Group Full time

    Job Title: Data Security SpecialistJob Summary: We are seeking a highly skilled Data Security Specialist to join our team at United Software Group. As a Data Security Specialist, you will be responsible for partnering with our Physical Security Technology Team and SaaS vendors to build out solutions and drive the creation of logical designs for non-prod and...


  • Pittsburgh, Pennsylvania, United States Thermo Fisher Scientific Inc. Full time

    Job SummaryWe are seeking a highly skilled Compliance Risk Management Specialist to join our team at Thermo Fisher Scientific Inc. The ideal candidate will have a strong background in risk management and compliance, with experience in identifying, assessing, and mitigating risks within supply chains.Key ResponsibilitiesDevelop and implement risk management...

  • Security Specialist

    4 weeks ago


    Pittsburgh, Pennsylvania, United States PNC Full time

    Job Title: Security SpecialistJob Summary:We are seeking a highly skilled Security Specialist to join our team at PNC. As a Security Specialist, you will be responsible for designing, building, and maintaining technology solutions to ensure the security and integrity of our data.Key Responsibilities:* Develop and implement security protocols to protect...


  • Pittsburgh, Pennsylvania, United States Securitas Electronic Security Inc Full time

    Embark on a rewarding career with Securitas Electronic Security Inc as an Electronic Security Systems Specialist. This role offers a unique blend of hands-on experience, virtual training, and industry mentorship through our one-year Technology Apprentice Program.As a specialist, you'll gain practical skills in low-voltage electronic security systems and have...


  • Pittsburgh, Pennsylvania, United States PNC Bank NA Full time

    Job SummaryPNC Bank NA is seeking a skilled Vendor Relationship Risk Management Specialist to join our team. As a key member of our risk management team, you will be responsible for identifying and managing risks associated with our vendors, ensuring compliance with applicable regulations, and providing risk mitigation solutions.Key ResponsibilitiesIdentify...

  • Security Specialist

    1 month ago


    Pittsburgh, Pennsylvania, United States Security Industry Specialists, Inc. Full time

    About the RoleThe Security Specialist, under the direct supervision of the Shift Supervisor, ensures SIS standards and policies are met in overall field services, operations, and functions in assigned areas such as site inspections, emergency response, camera review, client liaison, and special projects as assigned. All duties must be performed in accordance...


  • Pittsburgh, Pennsylvania, United States Huntington Bancshares, Inc. Full time

    Risk Governance Specialist - Model Risk ManagementHuntington Bancshares, Inc. is seeking a highly skilled Risk Governance Specialist to join its Corporate Risk Management team. The successful candidate will be responsible for the independent oversight of models and non-statistical tools developed, acquired, and used by Risk, Management, and other...


  • Pittsburgh, Pennsylvania, United States Edgeworth Security Full time

    Secure the Future with Edgeworth SecurityAt Edgeworth Security, we're committed to providing top-notch security solutions to our clients. As a Monitoring Center Agent, you'll play a vital role in protecting our clients' people, property, and assets from intrusion, theft, and other unauthorized activities.Key Responsibilities:Provide 24/7 monitoring and...


  • Pittsburgh, Pennsylvania, United States United Software Group Full time

    Job Summary:We are seeking a highly skilled API Security Specialist to join our team at United Software Group. The ideal candidate will have a deep understanding of API security best practices and experience with API security tools and methodologies.Key Responsibilities:Design a secure API architecture, utilizing secure design patterns, encryption protocols,...


  • Pittsburgh, Pennsylvania, United States Aro Talent Full time

    Cyber Security Specialist Job DescriptionAt Aro Talent, we are seeking a highly skilled Cyber Security Specialist to join our team. The ideal candidate will have a strong background in cyber logistics and experience in supporting network operations centers, Cyber Security Service Providers, or Cyber Red Teams within the DoD or Federal...

  • Security Specialist

    4 weeks ago


    Pittsburgh, Pennsylvania, United States ConsultUSA Full time

    Job Title: Security SpecialistJob Summary:We are seeking a highly skilled Security Specialist to join our team at ConsultUSA. As a Security Specialist, you will be responsible for working on multiple initiatives and deliverables simultaneously, interfacing with other initiatives that impact your domain.Key Responsibilities:Lead the delivery of security...


  • Pittsburgh, Pennsylvania, United States Virtual Full time

    About the Role:We are seeking a highly skilled GRC Security Specialist to join our team at Virtual. As a key member of our organization, you will play a critical role in expanding our knowledge in the GRC practice and driving the growth of our security services.Key Responsibilities:Advise clients on information security concepts using presentations, reports,...


  • Pittsburgh, Pennsylvania, United States Prequel Solutions Full time

    Job OverviewPrequel Solutions is seeking a seasoned Senior Internal Auditor to lead our internal audit function. This role will be responsible for scoping, testing, and reporting on audits across various risk areas, including financial, operational, IT, compliance, and fraud.Key Responsibilities:Develop and execute audit plans to ensure key risks and...


  • Pittsburgh, Pennsylvania, United States The PNC Financial Services Group, Inc Full time

    Job DescriptionPNC is seeking a highly skilled Regulatory Affairs Risk Specialist to join our team. As a key member of our Regulatory Affairs organization, you will play a critical role in managing and coordinating the regulatory exam lifecycle.Key Responsibilities:Manage and coordinate the regulatory exam lifecycle, including pre-exam work, coordinating and...