Cybersecurity Risk & Controls Analyst

Wabtec

Cybersecurity Risk & Controls Analyst

Fort Worth, TX +1 location
Full Time
Paid
  • Responsibilities

    Job Description

    Job Description

    Who will you be working with?

    Join Enterprise Information Security (EIS) to drive cybersecurity excellence leveraging intelligence, strategic partnerships, and analysis. Collaborate daily with GRC, Architecture, Operations, and key Information Technology stakeholders to advance our information security capabilities.

    How will you make a difference?

    As a member of ISA team, Wabtec is looking for a Senior Cybersecurity Risk & Controls Analyst. This role reports to the ISA Sr Manager within EIS, and will be responsible for building, developing, implementing, and operating a strategic Risk & Controls Management program to protect Wabtec and its stakeholders while supporting our strategic objectives.

    In this position, you will assume a leading role in driving the organization’s information security risk management efforts through the identification, assessment, and remediation of security risks, ensuring the protection of critical assets, the implementation of adequate security controls and compliance with legal, statutory, regulatory and contractual requirements. Additionally, you will play a pivotal role in fostering a risk-aware culture across the organization, promoting awareness of security risks and empowering employees to actively contribute to the organization’s risk posture. You will collaborate cross-functionally with IT and with Business stakeholders to develop and implement robust security strategies and practices, guiding the organization towards a mature and resilient security posture.

    What do we want to know about you?

    _ You must have:_

    • Bachelor’s degree in Business, Technology, Cyber Security, Technology Risk Management or related field or strong hands-on experience.

    • 3+ years experience in Security & Risk management.

    • Prior experience in IT or Cybersecurity, supporting systems or developing/supporting applications.

    Knowledge of technical controls and ability to describe them to business/system owners

    • Knowledge of industry Risk management frameworks, common mitigation practices, and Organizational control management.

    • Demonstrate professional skepticism to ensure evidence is sufficient when assessing the relevant information security controls.

    • Demonstrate an understanding of business processes, internal risk management strategies, IT controls, and how they interact together.

    • Demonstrate proficiency in process formulation and improvement.

    • Knowledge of operational security capabilities including access control, network security, secure configuration and vulnerability management, intrusion detection, security monitoring and incident response.

    • Proven solid written and oral communication skills with the ability to effectively communicate status, risks, and remediations to executive management.

    We would love it if you had:

    • ISO 27001 and NIST CSF knowledge is highly desirable.

    • Governance and Risk Certification a plus (CRISC, CISM, CISA, or CISSP)

    What will your typical day look like?

    Risk Management Program Development:

    • Design and implement a comprehensive risk management framework tailored to the organization's needs.

    • Establish risk assessment methodologies, including threat modeling and vulnerability scoring systems.

    • Develop policies, procedures, and guidelines for risk identification, analysis, and mitigation.

    • Create risk reporting structures and dashboards for effective communication to stakeholders.

    Risk Identification, Assessment, Analysis and Mitigation Strategy:

    • Conduct initial organization-wide risk assessments to establish a baseline risk profile.

    • Lead risk assessments to identify and prioritize security threats across systems.

    • Prioritize and categorize identified risks based on potential impact and likelihood.

    • Analyze the effectiveness of existing controls and recommend improvements.

    • Collaborate with stakeholders to formulate risk treatment plans and mitigation strategies aligned with business objectives.

    • Implement and oversee the execution of risk remediation initiatives.

    Control Assessment and Policy Alignment

    • Develop and maintain a comprehensive inventory of security controls and associated policies across the organization

    • Perform gap analysis between existing controls/policies and industry best practices or regulatory requirements

    • Implement processes to regularly evaluate the effectiveness of security controls and the adherence to established policies

    • Recommend improvements to controls and policies based on assessment findings

    • Collaborate with relevant teams to enhance or implement new controls and policies to address identified gaps

    Risk-Aware Culture Cultivation:

    • Drive pragmatic outcomes balancing risk with business objectives

    • Establish channels for risk reporting and feedback from employees across departments.

    • Foster a culture of accountability in risk management across the organization.

    • Collaborate with leadership to integrate risk considerations into decision-making processes.

    Continuous Improvement and Adaptation:

    • Establish metrics and KPIs to measure the effectiveness of the risk management program.

    • Regularly review and update the risk management framework to address emerging threats.

    • Stay informed on industry best practices and regulatory changes to enhance the program.

    • Foster partnerships with internal and external stakeholders to evolve risk management capabilities.

    What about the physical demands of the job? (Usual office job examples)

    • Regularly remaining in a stationary position, often standing or sitting for prolonged periods

    • Regularly communicating with others to exchange information

    • Regularly required to attend meetings in person and virtually using video and audio computer equipment

    • Regularly repeating motions that may include the wrists, hands and/or fingers, such as typing

    • Occasionally moving about to accomplish tasks or moving from one worksite to another

    • Occasionally light work that includes moving objects up to 20 pounds

    Work Environment:

    • Hybrid work schedule (both on-site and remote)

    • The employee will normally work in a temperature-controlled office environment, with frequent exposure to electronic office equipment. During visits to areas of operations, may be exposed to extreme cold or hot weather conditions. Is occasionally exposed to fumes or airborne particles, toxic or caustic chemicals, and loud noise

    • There is no relocation offered for this role.

  • Qualifications

    Additional Information

    Our job titles may span more than one career level. The salary rate for this role is currently $77400-110300 The actual salary offered to a candidate may be influenced by a variety of factors, such as: training, transferable skills, work experience, education, business needs, market demands and work location. The base pay range is subject to change and may be modified in the future. More information on offered benefits, which include health, welfare, and retirement, are available at mywabtecbenefits.com. Other benefit offerings for this role may include annual bonus, if eligible.

    What could you accomplish in a place that puts People First?

    At Wabtec, it’s not just about a job - it’s about the impact you make. When our people come together, we’re Expanding the Possible by continuously improving what we do and how we do it - for our clients and each other.

    If you’re ready to revolutionize how the world moves for future generations, Wabtec is the place for you.

    Who are we?

    Wabtec is a leading global provider of equipment, systems, digital solutions, and value-added services for the freight and transit rail sectors. Drawing on more than 150 years of experience, we are leading the way in safety, efficiency, reliability, innovation, and productivity. Whether it’s freight, transit, ports, logistics, mining, industrial, or marine, our expertise, technologies, and people together – are accelerating the future of transportation. With roots that date back to George Westinghouse, Thomas Edison, and Louis Faiveley, Wabtec has always built technologies and implemented solutions for a variety of sectors that are critical to meeting the needs of customers and governments alike.

    Our global team of about 30,000 employees worldwide delivers performance that moves the world forward. We’re lifelong learners, obsessed with better. Learn more at www.WabtecCorp.com.

    Culture powers us and the possibilities.

    We believe the best ideas come from a mix of experiences and backgrounds. At Wabtec, we strive every day to create a place where everyone belongs. We’re building a culture where leadership, inclusion and your unique perspective fuel progress.

    We’re proud to be an Equal Opportunity Employer. We welcome talent of all backgrounds, experiences, and identities, including race, gender, age, disability, veteran status and more.

    Need accommodation? Just let us know - we’ve got you.

  • Industry
    Manufacturing
  • Locations
    Pittsburgh, PA • Fort Worth, TX