Talent.com
Risk Analyst - Information Security

Risk Analyst - Information Security

WabtecChicago, IL
job_description.job_card.30_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

It’s not just about your career or job title… It’s about who you are and the impact you will make on the world. Because whether it’s for each other or our customers, we put People First. When our people come together, we Expand the Possible and continuously look for ways to improve what we create and how we do it. If you are constantly striving to grow, you’re in good company. We are revolutionizing the way the world moves for future generations, and we want someone who is ready to move with us.

Who will you be working with?

Our best-in-class Enterprise Information Security team combines knowledge of security services to areas within Information Technology and provide in-depth and highly technical information security consulting and services focused on the enterprise services IT provides to ensure confidentiality, integrity and availability of these systems.

How will you make a difference?

As a member of the IT Business Information Security Team, you will be responsible for staying abreast of developments within the field and contribute to directional strategy by considering all present risks internally and externally. You’ll work with partners to drive thoughtful remediation and enhancements to the organization’s risk posture. This role requires advanced understanding of challenges and common threats. This person will be responsible for developing, implementing, and operating a strategic, risk-based program for the Information Security Assurance team.

What do we want to know about you?

You must have :

  • Bachelor’s degree in Business, Technology, Cyber Security, Technology Risk Management or related field or hands-on and strong experience
  • 5+ years experience within IT operations, Security or Risk management
  • Strong analytical and problem-solving skills; ability to decipher and prioritize asks accordingly
  • Strong interpersonal skills.
  • Knowledge of industry Risk management frameworks, common mitigation practices, and\ Organizational control management.
  • Demonstrate professional skepticism to ensure evidence is sufficient when assessing the relevant information security controls.
  • Demonstrate an understanding of business processes, internal risk management strategies, IT controls, and how they interact together.
  • Demonstrate proficiency in process formulation and improvement.
  • Knowledge of operational security capabilities including access control, network security, secure configuration and vulnerability management, intrusion detection, security monitoring and incident response.
  • Experience with auditors, both internal and regulatory to drive positive audit results with strong remediation paths.
  • Proven solid written and oral communication skills with the ability to effectively communicate status, risks, and remediations to executive management.
  • ISO 27001 standard knowledge is highly desirable.
  • Governance and Risk Certification a plus (CRISC, CISM, CISA, or CISSP)

What will your typical day look like?

The ideal candidate will have experience building, operating, and maturing effective programs to manage Information Security Risks and their remediations.

  • Comprehensive Risk Identification, Assessment & Analysis : Lead and conduct comprehensive risk assessment to identify, prioritize and quantify potential and existing security threats and vulnerabilities across the organization’s systems, network, and applications.Utilize risk analysis methodologies and tools to assess the effectiveness of existing security controls and identify areas for improvement.Provide expert guidance on risk mitigation strategies and control implementation to minimize exposure to security risks.Develop risk management methodologies tailored to the organization’s specific risk profile and business priorities.Collaborate with stakeholders to establish risk tolerance levels and develop risk mitigation plans.
  • Risk Remediation Planning & Execution : Develop remediation plans based on the findings of risk assessments, prioritizing actions to address critical vulnerabilities and mitigate high-risk threats.Work closely with relevant stakeholders to implement security controls and measures to remediate identified risks effectively.Monitor the progress of remediation efforts and provide regular updates to management on the status of risk mitigation initiatives.Conduct post-remediation reviews and analysis to validate the effectiveness of remediation activities and identify any residual risks.
  • Risk-Awareness Culture : Drive clear, concise, pragmatic outcomes with senior business and technology leaders that balance risk with business objectives.Develop and implement security awareness programs and initiatives to educate employees on security risks, best practices, and their role in maintaining a secure environment.Foster a culture of accountability and responsibility for information security by encouraging active participation in risk identification, reporting, and mitigation efforts.Promote open communication channels for reporting concerns and potential risks, and ensure timely resolution and escalation as needed.
  • Business Awareness & Continual Improvement : Anticipate the needs of leadership and facilitate as well as motivate those around you to identify solutions that both improve the security of our environment and advance business objectives.Maintain an external network to ensure our organization continuously analyzes new threats, trends, innovations, etc. to ensure our strategy and priorities stay appropriately aligned.Present balanced viewpoints of options and recommendations based on strong front-to-back understanding of existing capabilities and frameworks combined with a strong understanding of emerging technologies and best practices.Be curious about our business and seek to understand.Create an environment of continual improvement both inside and outside of direct team.Bring new ideas, methods, and approaches to this role. Leverage own expertise to challenge the status quo and drive decisions and actions necessary to improve our business processes and related technology
  • Physical Demands :

  • Employee is required to work on a computer for up to 8 hours per day
  • Employee may be in a sitting position for several hours per day
  • Employee must be able to read small text on computer screens / monitors
  • Employee is regularly required to talk and hear
  • Work Environment :

    The employee will normally work in a temperature-controlled office environment, with frequent exposure to electronic office equipment. During visits to areas of operations, may be exposed to extreme cold or hot weather conditions, fumes or airborne particles, toxic or caustic chemicals, and loud noise.

    #LI-AZ1

    Our job titles may span more than one career level. The salary range for this role is between

    The actual salary offered to a candidate may be influenced by a variety of factors, such as : training, transferable skills, work experience, education, business needs, market demands and work location. The base pay range is subject to change and may be modified in the future. More information on offered benefits, which include health, welfare, and retirement, are available at mywabtecbenefits.com. Other benefit offerings for this role may include an annual bonus, if eligible.

    Who are we?

    Wabtec Corporation is a leading global provider of equipment, systems, digital solutions, and value-added services for freight and transit rail as well as the mining, marine, and industrial markets. Drawing on nearly four centuries of collective experience across Wabtec, GE Transportation, and Faiveley Transport, the company has grown to become One Wabtec, with unmatched digital expertise, technological innovation, and world-class manufacturing and services, enabling the digital-rail-and-transit ecosystems.

    Wabtec is focused on performance that drives progress and unlocks our customers’ potential by delivering innovative and lasting transportation solutions that move and improve the world. We are lifelong learners obsessed with making things better to drive exceptional results. Wabtec has approximately 27K employees in facilities throughout the world. Visit our website to learn more!

    Our Commitment to Embrace Diversity :

    Wabtec is a global company that invests not just in our products, but also our people by embracing diversity and inclusion. We care about our relationships with our employees and take pride in celebrating the variety of experiences, expertise, and backgrounds that bring us together. At Wabtec, we aspire to create a place where we all belong and where diversity is welcomed and appreciated.

    To fulfill that commitment, we rely on a culture of leadership, diversity, and inclusion. We aim to employ the world’s brightest minds to help us create a limitless source of ideas and opportunities. We have created a space where everyone is given the opportunity to contribute based on their individual experiences and perspectives and recognize that these differences and diverse perspectives make us better.

    We believe in hiring talented people of varied backgrounds, experiences, and styles… People like you! Wabtec Corporation is committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or expression, or protected Veteran status. If you have a disability or special need that requires accommodation, please let us know.

    serp_jobs.job_alerts.create_a_job

    Information Security Analyst • Chicago, IL

    Job_description.internal_linking.related_jobs
    • serp_jobs.job_card.promoted
    Security Compliance Analyst

    Security Compliance Analyst

    VirtualVocationsLincolnwood, Illinois, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Governance Risk & Compliance (GRC) Analyst.Key Responsibilities Manage and implement complex controls frameworks for large systems, including Cloud infrastruct...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Cyber Threat Analyst

    Cyber Threat Analyst

    VirtualVocationsGary, Indiana, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cyber Threat Analyst to support a major federal client in cybersecurity efforts.Key Responsibilities Support overall cyber threat analysis efforts and produce intellige...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Illinois Licensed Senior Threat Manager

    Illinois Licensed Senior Threat Manager

    VirtualVocationsGary, Indiana, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Manager, Global Threat Response.Key Responsibilities Lead incident response operations during high-impact security events and ensure alignment with enterprise pr...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior SOC Analyst

    Senior SOC Analyst

    VirtualVocationsChicago, Illinois, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior SOC Analyst to enhance the security posture and efficiency of its computer systems.Key Responsibilities Perform incident triage and response actions to mitigate ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Security Analyst

    Security Analyst

    VirtualVocationsGary, Indiana, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Analyst to secure its infrastructure and product.Key Responsibilities Support compliance strategy and audits, improving tools and processes Represent the secu...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Associate, Internal Audit Information Technology & Security

    Senior Associate, Internal Audit Information Technology & Security

    The Options Clearing CorporationChicago, IL, United States
    serp_jobs.job_card.full_time
    THIS POSITION IS NOT ELIGIBLE FOR VISA SPONSORSHIP • • • • •.This role will support and lead independent assessments of OCC's Information Technology and Security environment, risk management, and other ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Security Business Systems Analyst

    Security Business Systems Analyst

    VirtualVocationsGary, Indiana, United States
    serp_jobs.job_card.full_time
    A company is looking for a Business Systems Analyst (Security) to support business objectives and optimize security systems. Key Responsibilities Gather and analyze business requirements, and assi...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Information Security Engineer

    Senior Information Security Engineer

    VirtualVocationsGary, Indiana, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Information Security Lead to oversee security operations and engineering in a healthcare-pharmacy environment. Key Responsibilities Own the technical roadmap for ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Information Security Engineer

    Information Security Engineer

    VirtualVocationsGary, Indiana, United States
    serp_jobs.job_card.full_time
    A company is looking for an Information Security Engineer II to develop and support enterprise security tools for cloud environments. Key Responsibilities Implement and maintain new features and c...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Information Security Analyst

    Senior Information Security Analyst

    VirtualVocationsGary, Indiana, United States
    serp_jobs.job_card.full_time
    A company is looking for an Information Security Policy Analyst Senior.Key Responsibilities Develop, update, and implement security directives, policies, and procedures Perform gap analysis of e...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Application Security Analyst

    Application Security Analyst

    VirtualVocationsChicago, Illinois, United States
    serp_jobs.job_card.full_time
    A company is looking for an Application Security Analyst to provide security guidance to application development teams.Key Responsibilities Provide application security guidance and educate devel...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Security Operations Analyst

    Senior Security Operations Analyst

    VirtualVocationsGary, Indiana, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Security Operations Center (SOC) Analyst to respond to cyber threats and incidents.Key Responsibilities Respond to security alerts and incidents, collecting and ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Federal Compliance Analyst

    Federal Compliance Analyst

    VirtualVocationsGary, Indiana, United States
    serp_jobs.job_card.full_time
    A company is looking for a Principal Federal Compliance Analyst to identify risks and lead process improvements in compliance with federal regulations. Key Responsibilities Serve as the subject ma...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Information Security Analyst

    Information Security Analyst

    VirtualVocationsLincolnwood, Illinois, United States
    serp_jobs.job_card.full_time
    A company is looking for an Information Security Controls Analyst to manage the transition to a new maturity model in the banking industry. Key Responsibilities Manage the translation from Holisti...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Application Analyst II - Cerner Security

    Application Analyst II - Cerner Security

    VirtualVocationsNaperville, Illinois, United States
    serp_jobs.job_card.full_time
    A company is looking for an Application Analyst II - Cerner Core Security.Key Responsibilities Design, build, document, test, and troubleshoot Core Security components and applications Provide s...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Mid-Level SOC Analyst

    Mid-Level SOC Analyst

    VirtualVocationsGary, Indiana, United States
    serp_jobs.job_card.full_time
    A company is looking for a Mid-Level SOC Analyst - Hybrid.Key Responsibilities Conduct event triage and security investigations for potential threats Perform deep-dive forensic investigations an...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Risk Analyst

    Risk Analyst

    VirtualVocationsLincolnwood, Illinois, United States
    serp_jobs.job_card.full_time
    A company is looking for a Risk Analyst II to support the development and oversight of its Risk Management Program.Key Responsibilities Designs and implements risk management processes, including...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Information Systems Security Officer

    Senior Information Systems Security Officer

    VirtualVocationsGary, Indiana, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Information System Security Officer (ISSO) - Federal Modernization.Key Responsibilities Serve as security lead for assigned systems through design, modernization...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Risk Control Analyst

    Risk Control Analyst

    VirtualVocationsGary, Indiana, United States
    serp_jobs.job_card.full_time
    A company is looking for a Risk Control Consultant.Key Responsibilities Manage the implementation and maintenance of the Compliance Risk and Control Assessment Program Monitor and inventory trig...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    State Licensed Risk Management Analyst

    State Licensed Risk Management Analyst

    VirtualVocationsGary, Indiana, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Risk Management Analyst.Key Responsibilities Identify and resolve key risk factors and develop mitigation methodologies Analyze risk components and prepare repo...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days