1

Cybersecurity Risk Analyst Jobs (NOW HIRING)

Alcoa is seeking a Cyber Security Risk Analyst to serve as a key contributor to the cybersecurity risk management program, providing subject matter expertise in identifying, assessing, and managing ...

Cybersecurity Risk Analyst

Evansville, IN · On-site

$36.93 - $55.40/hr

Help Protect the Technology That Supports Patient Care We are seeking a skilled Cybersecurity Risk Analyst to join our Information Security team. In this role, you will help identify, evaluate ...

Alcoa is seeking a Cyber Security Risk Analyst to serve as a key contributor to the cybersecurity risk management program, providing subject matter expertise in identifying, assessing, and managing ...

Cybersecurity Risk Analyst

Cambridge, MA · On-site

$82K - $220K/yr

The Cybersecurity Risk Analyst is a member of Draper's Cybersecurity Risk Management team, responsible primarily for unclassified information system risk and compliance efforts. This role contributes ...

The Cybersecurity Risk Analyst is responsible for executing a portion of the GM Financial (GMF) Cybersecurity Program designed to advise the organization on its management of Cybersecurity risk by ...

The Cybersecurity Risk Analyst is a member of Draper's Cybersecurity Risk Management team, responsible primarily for unclassified information system risk and compliance efforts. This role contributes ...

The Cybersecurity Risk Analyst is responsible for executing a portion of the GM Financial (GMF) Cybersecurity Program designed to advise the organization on its management of Cybersecurity risk by ...

MDAEdge is seeking a Cybersecurity Risk Analyst to join their team. The role involves developing and conducting risk assessments for applications, infrastructure, and vendors, while collaborating ...

If we've described you and your dream workplace, please apply and share in the many benefits and opportunities we offer. Cyber Security Risk Analyst Work Location: Required onsite work at the client ...

ECLARO is a leading technology solutions provider seeking a Cybersecurity Risk Analyst for their client in Manassas, VA. The role involves managing Third-Party Risk Management (TPRM) operations and ...

The Cyber Security Risk Analyst will support the creation and visualization of metrics to reduce threats across the Enterprise and assist in the implementation of the Risk Management Framework and ...

next page

Showing results 1-20

Cybersecurity Risk Analyst information

See salary details

$15

$40

$65

How much do cybersecurity risk analyst jobs pay per hour?

As of Jul 3, 2026, the average hourly pay for cybersecurity risk analyst in the United States is $40.49, according to ZipRecruiter salary data. Most workers in this role earn between $29.81 and $49.28 per hour, depending on experience, location, and employer.

What is the difference between Cybersecurity Risk Analyst vs Cybersecurity Analyst?

AspectCybersecurity Risk AnalystCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP
Primary FocusAssessing and managing security risksMonitoring, detecting, and responding to security threats
Work EnvironmentRisk management teams, security departmentsSecurity operations centers, IT teams
Industry UsageFinance, healthcare, governmentAll industries with cybersecurity needs

While both roles involve cybersecurity, the Cybersecurity Risk Analyst primarily focuses on identifying and mitigating security risks, whereas the Cybersecurity Analyst concentrates on monitoring and responding to security incidents. Understanding these differences helps organizations assign the right roles for their security needs.

What are the key skills and qualifications needed to thrive as a Cybersecurity Risk Analyst, and why are they important?

To thrive as a Cybersecurity Risk Analyst, you need a deep understanding of information security principles, risk management frameworks, and typically hold a degree in computer science or a related field. Familiarity with tools like vulnerability scanners, SIEM systems, and certifications such as CISSP or CISM is highly valued. Strong analytical thinking, effective communication, and attention to detail help you identify risks and convey complex information to stakeholders. These skills and qualifications are vital to proactively safeguard organizational assets and ensure compliance in an evolving threat landscape.

Is 30 too old for cyber security?

Cybersecurity Risk Analysts can enter the field at any age, as experience, skills, and certifications like CompTIA Security+ or CISSP are often more important than age. Many professionals transition into cybersecurity later in their careers, bringing valuable perspectives and expertise. Age is generally not a barrier to starting or advancing in cybersecurity roles.

How much does a cybersecurity risk analyst make?

A cybersecurity risk analyst's average salary in the United States ranges from $70,000 to $120,000 annually, depending on experience, certifications, and location. Entry-level positions typically start around $60,000, while experienced analysts with certifications like CISSP or CISA can earn over $130,000. The role often requires knowledge of risk assessment tools and security frameworks.

What are some common challenges faced by Cybersecurity Risk Analysts when working with cross-functional teams?

Cybersecurity Risk Analysts often collaborate with IT, compliance, and business units to assess and mitigate risks. A common challenge is translating complex technical risks into language that non-technical stakeholders can understand and act upon. Additionally, balancing security requirements with business objectives may require negotiation and creative problem-solving. Effective communication and relationship-building skills are key to ensuring that security recommendations are adopted across the organization.

What does a Cybersecurity Risk Analyst do?

A Cybersecurity Risk Analyst is responsible for identifying, assessing, and mitigating risks related to an organization’s information systems and data. They evaluate potential threats and vulnerabilities, develop strategies to minimize risks, and ensure compliance with security policies and regulations. Their work helps protect sensitive data and maintain the integrity and confidentiality of digital assets. Analysts often collaborate with IT and business teams to implement security controls and respond to security incidents.

What does a cyber security risk analyst do?

A cybersecurity risk analyst evaluates an organization’s security posture by identifying vulnerabilities, assessing potential threats, and recommending measures to mitigate risks. They often use tools like risk assessment frameworks and require knowledge of security protocols, compliance standards, and threat intelligence. Their work helps organizations protect sensitive data and maintain secure systems.

Can you make $500,000 a year in cyber security?

Cybersecurity Risk Analysts typically earn between $70,000 and $130,000 annually, with top-tier professionals in senior or specialized roles potentially earning over $200,000. Achieving a salary of $500,000 usually requires advanced certifications, extensive experience, leadership positions, or working in high-paying industries or consulting roles.
More about Cybersecurity Risk Analyst jobs
What cities are hiring for Cybersecurity Risk Analyst jobs? Cities with the most Cybersecurity Risk Analyst job openings:
What states have the most Cybersecurity Risk Analyst jobs? States with the most job openings for Cybersecurity Risk Analyst jobs include:
Infographic showing various Cybersecurity Risk Analyst job openings in the United States as of June 2026, with employment types broken down into 99% Full Time, and 1% Part Time. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution, with an average salary of $84,210 per year, or $40.5 per hour.
Cyber Security Risk Analyst

Cyber Security Risk Analyst

Alcoa Corporation

Pittsburgh, PA • On-site

Full-time

Retirement, PTO

Posted 3 days ago


Alcoa rating

7.8

Company rating: 7.8 out of 10

Based on 15 frontline employees who took The Breakroom Quiz


Job description

Shape Your World
At Alcoa, you will become an essential part of our purpose: to turn raw potential into real progress. The way we see it, every Alcoan is a work-shaper, team-shaper, idea-shaper & world-shaper.
Alcoa is seeking a Cyber Security Risk Analyst to serve as a key contributor to the cybersecurity risk management program, providing subject matter expertise in identifying, assessing, and managing risks across both Information Technology (IT) and Operational Technology (OT) environments. This role supports informed business decision-making by translating complex technical risks into business and operational impact. The Analyst independently leads risk assessments and partners closely with IT, OT, audit, and senior leaders to ensure cybersecurity risks are understood, documented, mitigated, and monitored in accordance with corporate policies and industry standards.
As Alcoa's Cybersecurity Risk Management program continues to mature, the Analyst plays a critical role in shaping and enhancing program capabilities.
About the Role:
  • Contribute to the development, implementation, and continuous improvement of the Cybersecurity Risk Management Program, including frameworks, methodologies, policies, standards, and supporting tools.
  • Perform cybersecurity risk assessments across IT, OT, cloud, and third-party environments, including enterprise systems and manufacturing/process control systems (PCS).
  • Facilitate risk workshops with technical and business stakeholders to evaluate risks associated with new technologies, projects, and operational changes.
  • Serve as a subject matter expert on risk methodology, scoring, and evaluation.
  • Maintain and enhance the cybersecurity risk register, including risk scoring, treatment plans, and residual risk tracking.
  • Support and guide risk treatment strategies (mitigation, acceptance, transfer, avoidance) and partner with compliance teams to design and implement appropriate controls.
  • Translate technical risk findings into clear business and operational impact statements for non-technical audiences and senior leadership.
  • Advise leadership on risk exposure, trends, and residual risks, including impacts to business operations and production.
  • Define, monitor, and report Key Risk Indicators (KRIs) and emerging threat trends.
  • Support audit, regulatory, and compliance activities (e.g., ISO 27001, NIST, SOC) related to cybersecurity risk management.
  • Collaborate with Enterprise Risk Management (ERM) and Operations Risk Management teams to ensure alignment and integration of cybersecurity risks into broader risk reporting.
  • Build and maintain strong relationships with stakeholders across IT, OT, business units, and risk management functions.
  • Continuously monitor evolving cyber threats, emerging technologies, and industry practices to enhance risk management processes and capabilities.

What you can bring to this role:
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, Risk Management, or a related discipline; equivalent professional experience may be considered in lieu of a degree.
  • 6+ years of experience in cybersecurity, IT risk management, information security, governance, compliance, or IT operations within enterprise environments.
  • Demonstrated experience assessing cybersecurity risk across IT and OT environments; experience in manufacturing or industrial organizations preferred.
  • Strong knowledge of cybersecurity frameworks and standards (e.g., ISO 27001, NIST CSF, NIST 800-53, CIS Controls, SOX).
  • Proven experience executing core GRC activities, including risk assessments, policy and standard development, control validation, audit support, and remediation tracking.
  • Expertise in cybersecurity governance, risk assessment, and compliance program implementation.
  • Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards.
  • Solid understanding of security principles, including security controls, threat modeling, vulnerability management, and incident risk analysis.
  • Excellent written, verbal, and facilitation skills, with the ability to translate complex technical risks into clear business impacts.
  • Demonstrated ability to collaborate effectively with cross-functional stakeholders, including technical teams, operations, and senior leadership, while managing multiple priorities in fast-paced environments.

Preferred Qualifications
  • Relevant industry certifications such as CISSP, CISM, CRISC, CISA, CGRC, Security+, GRCP, or equivalent.
  • Experience with third-party/vendor risk management, regulatory compliance assessments, and security awareness programs.
  • Experience supporting global environments and contributing to enterprise-wide security or compliance initiatives.
  • Experience supporting audits and assurance activities, including ISO/IEC 27001 certification and SOC report reviews.
  • Familiarity with security operations capabilities, including SIEM, log analysis, and event monitoring for compliance and incident response.
  • Understanding of enterprise security domains, including cloud security, infrastructure security, and identity and access management (IAM).
  • Working knowledge of project management methodologies and practices.
  • Experience in metals, mining, manufacturing, or other heavy industrial environments.

What we offer:
  • Competitive compensation packages, including pay-for performance variable pay, recognition and rewards programs, and stock-based compensation awards (3-year vesting schedule)
  • Flexible spending accounts and generous employer contribution to the HSA
  • 401(k), employer match up to 6%, additional employer retirement income contribution (no vesting period), and a non-qualified deferred compensation plan
  • 12 paid holidays per year.
  • 15 days of paid vacation (pro-rated from hire date).
  • Employee Assistance Program (EAP)

#LI-TL2
Employees must be legally authorized to work in the United States. Verification of employment eligibility will be required at the time of hire. Visa sponsorship is not available for this position.
About the Location
Alcoa is an international company with multiple locations and joint ventures across six continents. Wherever you choose to join us, you'll be joining a global team committed to advancing sustainability and delivering excellence and innovation. As industry pioneers, we are redefining what it means to be a sustainable aluminum company, bridging the journey from mines to metal.
We are values led, vision driven and united by our purpose of transforming raw potential into real progress. Our commitments to Inclusion, Diversity & Equity include providing trusting workplaces that are safe, respectful and inclusive of all individuals, free from discrimination, bullying and harassment and that our workplaces reflect the diversity of the communities in which we operate.
As a proud equal opportunity workplace and affirmative action employer, Alcoa is dedicated to providing equal opportunities and equal access to all individuals regardless of a person's gender, age, race, ethnicity, sexual orientation, gender identity, religion, nation of origin, disability, veteran status, language spoken or any other characteristic or status protected by the laws or regulations in the places where we operate.
If you have visited our website in search of information on U.S. employment opportunities or to apply for a position, and you require an accommodation, please contact Alcoa Recruiting via email at gssrecruiting@alcoa.com.
This is a place where you are empowered to do your best work, be your authentic self, and feel a true sense of belonging. Come join us and shape your career!
Your work. Your world. Shape them for the better.

What Alcoa employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Alcoa logo

About Alcoa

Sourced by ZipRecruiter

Alcoa is a global industry leader in the production of bauxite, alumina and aluminum, a position enhanced by a portfolio of value-added cast products and select energy assets. Since developing the aluminum industry more than 135 years ago, Alcoa has built a legacy of breakthrough innovations and best practices that have led to efficiency, safety, sustainability and stronger communities wherever we operate.

Industry

Manufacturing

Company size

10,000+ Employees

Headquarters location

Pittsburgh, PA, US

Year founded

1888

Social media