Jobs and Careers
WA

Risk Analyst - Business Information

Wabtec
Pittsburgh, United Statesfull_timeVerifiedPosted 19 Jun 2025
💰 $110,300/yr($77,400/yr$110,300/yr)

About the role

It’s not just about your career or job title… It’s about who you are and the impact you will make on the world. Because whether it’s for each other or our customers, we put People First. When our people come together, we Expand the Possible and continuously look for ways to improve what we create and how we do it. If you are constantly striving to grow, you’re in good company. We are revolutionizing the way the world moves for future generations, and we want someone who is ready to move with us.

Who will you be working with?

Our best-in-class Enterprise Information Security team combines knowledge of security services to areas within Information Technology and provide in-depth and highly technical information security consulting and services focused on the enterprise services IT provides to ensure confidentiality, integrity and availability of these systems. 

How will you make a difference?

As a member of the IT Business Information Security Team, you will be responsible for staying abreast of developments within the field and contribute to directional strategy by considering all present risks internally and externally. You’ll work with partners to drive thoughtful remediation and enhancements to the organization’s risk posture. This role requires advanced understanding of challenges and common threats. This person will be responsible for developing, implementing, and operating a strategic, risk-based program for the Information Security Assurance team.

What do we want to know about you?

You must have:

  • Bachelor’s degree in Business, Technology, Cyber Security, Technology Risk Management or related field or hands-on and strong experience
  • 5+ years experience within IT operations, Security or Risk management
  • Strong analytical and problem-solving skills; ability to decipher and prioritize asks accordingly
  • Strong interpersonal skills.
  • Knowledge of industry Risk management frameworks, common mitigation practices, and\ Organizational control management.
  • Demonstrate professional skepticism to ensure evidence is sufficient when assessing the relevant information security controls.
  • Demonstrate an understanding of business processes, internal risk management strategies, IT controls, and how they interact together.
  • Demonstrate proficiency in process formulation and improvement.
  • Knowledge of operational security capabilities including access control, network security, secure configuration and vulnerability management, intrusion detection, security monitoring and incident response.
  • Experience with auditors, both internal and regulatory to drive positive audit results with strong remediation paths.
  • Proven solid written and oral communication skills with the ability to effectively communicate status, risks, and remediations to executive management.
  • ISO 27001 standard knowledge is highly desirable.
  • Governance and Risk Certification a plus (CRISC, CISM, CISA, or CISSP)

What will your typical day look like?

The ideal candidate will have experience building, operating, and maturing effective programs to manage Information Security Risks and their remediations.

  • Comprehensive Risk Identification, Assessment & Analysis:
    • Lead and conduct comprehensive risk assessment to identify, prioritize and quantify potential and existing security threats and vulnerabilities across the organization’s systems, network, and applications.
    • Utilize risk analysis methodologies and tools to assess the effectiveness of existing security controls and identify areas for improvement.
    • Provide expert guidance on risk mitigation strategies and control implementation to minimize exposure to security risks.
    • Develop risk management methodologies tailored to the organization’s specific risk profile and business priorities.
    • Collaborate with stakeholders to establish risk tolerance levels and develop risk mitigation plans.
  • Risk Remediation Planning & Execution:
    • Develop remediation plans based on the findings of risk assessments, prioritizing actions to address critical vulnerabilities and mitigate high-risk threats.
    • Work closely with relevant stakeholders to implement security controls and measures to remediate identified risks effectively.
    • Monitor the progress of remediation efforts and provide regular updates to management on the status of risk mitigation initiatives.
    • Conduct post-remediation reviews and analysis to validate the effectiveness of remediation activities and identify any residual risks.
  • Risk-Awareness Culture:
    • Drive clear, concise, pragmatic outcomes with senior business and technology leaders that balance risk with business objectives.
    • Develop and implement s

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Wabtec

View company profile →