Risk Analyst - Information Security
WabtecAbout the role
It’s not just about your career or job title… It’s about who you are and the impact you will make on the world. Because whether it’s for each other or our customers, we put People First. When our people come together, we Expand the Possible and continuously look for ways to improve what we create and how we do it. If you are constantly striving to grow, you’re in good company. We are revolutionizing the way the world moves for future generations, and we want someone who is ready to move with us.
It’s not just about your career or job title… It’s about who you are and the impact you will make on the world. Because whether it’s for each other or our customers, we put People First. When our people come together, we Expand the Possible and continuously look for ways to improve what we create and how we do it. If you are constantly striving to grow, you’re in good company. We are revolutionizing the way the world moves for future generations, and we want someone who is ready to move with us.
Who will you be working with?
Join Enterprise Information Security (EIS) to drive cybersecurity excellence leveraging intelligence, strategic partnerships, and analysis. Collaborate daily with GRC, Architecture, Operations, and key Information Technology stakeholders to advance our information security capabilities.
How will you make a difference?
As a member of Information Security Assurance (ISA) team, Wabtec is looking for a Senior Cybersecurity Risk Analyst. This role reports to the ISA Sr Manager within EIS, and will be responsible for designing, building, developing, implementing, and operating a strategic Risk Management program to protect Wabtec and its stakeholders while supporting our strategic objectives. This role needs a strategic thinker with a strong technical expertise and understanding of common threats, and deep knowledge of risk frameworks. The Risk Analyst will collaborate across departments to embed risk practices into business processes, drive governance, and support informed decision-making. This position plays a critical role in fostering a risk-aware culture across the organization, promoting awareness of security risks and empowering employees to actively contribute to enhancing Wabtec’s risk posture.
What do we want to know about you?
You must have:
- Bachelor’s degree in Business, Technology, Cyber Security, Technology Risk Management or related field or hands-on and strong experience
- 5+ years experience within IT operations, Security or Risk management
- Experience with Risk Register management, including categorizing risk and determining the level of the risk to be entered.
- Prior experience in IT or Cybersecurity, supporting systems or developing/supporting applications.
- Knowledge of industry Risk management frameworks, common mitigation practices, and\ Organizational control management.
- Demonstrate professional skepticism to ensure evidence is sufficient when assessing the relevant information security controls.
- Demonstrate an understanding of business processes, internal risk management strategies, IT controls, and how they interact together.
- Demonstrate proficiency in process formulation and improvement.
- Knowledge of operational security capabilities including access control, network security, secure configuration and vulnerability management, intrusion detection, security monitoring and incident response.
- Experience with auditors, both internal and regulatory to drive positive audit results with strong remediation paths.
- Proven solid written and oral communication skills with the ability to effectively communicate status, risks, and remediations to executive management.
We would love it if you had:
- ISO 27001 and NIST CSF knowledge are highly desirable.
- Governance and Risk Certification a plus (CRISC, CISM, CISA, or CISSP)
What will your typical day look like?
The ideal candidate will have experience designing, building, operating, and maturing effective programs to manage Information Security Risks and their remediations.
- Risk Management Program Development:
- Design and implement a comprehensive risk management framework tailored to the organization's needs.
- Establish risk assessment methodologies, including threat modeling and vulnerability scoring systems.
- Develop policies, procedures, and guidelines for risk identification, analysis, and mitigation.
- Create risk reporting structures and dashboards for effective communication to stakeholders.
- Continuously evaluate and streamline risk management processes to improve efficiency, reduce complexity, and enhance responsiveness to emerging risks.
- Comprehensive Risk Identi
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s