alcoa

Cyber Security Risk Analyst

Apply Now

At a Glance

Location
United States, PA, Pittsburgh
Employment
Full time
Experience
6+ years
Posted
2026-06-23

Key Requirements

Certifications

  • CISA
  • CISM
  • CISSP

Domain Knowledge

  • Manufacturing
  • Mining
  • Regulatory

Requirements

Relevant industry certifications such as CISSP, CISM, CRISC, CISA, CGRC, Security+, GRCP, or equivalent.

Experience with third-party/vendor risk management, regulatory compliance assessments, and security awareness programs.

Experience supporting global environments and contributing to enterprise-wide security or compliance initiatives.

Experience supporting audits and assurance activities, including ISO/IEC 27001 certification and SOC report reviews.

Familiarity with security operations capabilities, including SIEM, log analysis, and event monitoring for compliance and incident response.

Understanding of enterprise security domains, including cloud security, infrastructure security, and identity and access management (IAM).

Compensation & Benefits

Competitive compensation packages, including pay-for performance variable pay, recognition and rewards programs, and stock-based compensation awards (3-year vesting schedule)

Flexible spending accounts and generous employer contribution to the HSA

401(k), employer match up to 6%, additional employer retirement income contribution (no vesting period), and a non-qualified deferred compensation plan

12 paid holidays per year.

15 days of paid vacation (pro-rated from hire date).

Employee Assistance Program (EAP)

Responsibilities

Contribute to the development, implementation, and continuous improvement of the Cybersecurity Risk Management Program, including frameworks, methodologies, policies, standards, and supporting tools.

Perform cybersecurity risk assessments across IT, OT, cloud, and third-party environments, including enterprise systems and manufacturing/process control systems (PCS).

Maintain and enhance the cybersecurity risk register, including risk scoring, treatment plans, and residual risk tracking.

Support and guide risk treatment strategies (mitigation, acceptance, transfer, avoidance) and partner with compliance teams to design and implement appropriate controls.

Translate technical risk findings into clear business and operational impact statements for non-technical audiences and senior leadership.

Advise leadership on risk exposure, trends, and residual risks, including impacts to business operations and production.

About the Company

Alcoa is an international company with multiple locations and joint ventures across six continents. Wherever you choose to join us, you'll be joining a global team committed to advancing sustainability and delivering excellence and innovation. As industry pioneers, we are redefining what it means to be a sustainable aluminum company, bridging the journey from mines to metal.

We are values led, vision driven and united by our purpose of transforming raw potential into real progress.  Our commitments to

Inclusion, Diversity & Equity

include providing trusting workplaces that are safe, respectful and inclusive of all individuals, free from discrimination, bullying and harassment and that our workplaces reflect the diversity of the communities in which we operate.

As a proud equal opportunity workplace and affirmative action employer, Alcoa is dedicated to providing equal opportunities and equal access to all individuals regardless of a person’s gender, age, race, ethnicity, sexual orientation, gender identity, religion, nation of origin, disability, veteran status, language spoken or any other characteristic or status protected by the laws or regulations in the places where we operate.

If you have visited our website in search of information on U.S. employment opportunities or to apply for a position, and you require an accommodation, please contact Alcoa Recruiting via email at gssrecruiting@alcoa.com.