2

Full Time Cyber Security Risk Analyst Jobs in Pittsburgh, PA

Our approach emphasizes risk-based assessments, policy and governance improvements, and program ... Regular full-time and part-time employees (working at least 20 hours per week) have access to ...

System Cybersecurity Architect

Pittsburgh, PA · Hybrid

$235K/yr

Could you be the full-time hybrid System Cybersecurity Architect in Pittsburgh, PA, US we're ... Analytical thinking and problem-solving skills to identify and mitigate cybersecurity risks.

System Cybersecurity Architect

Pittsburgh, PA · Hybrid

$225K/yr

Could you be the full-time hybrid System Cybersecurity Architect in Pittsburgh, PA, US we're ... Analytical thinking and problem-solving skills to identify and mitigate cybersecurity risks.

Cybersecurity events System failures and outages Data loss and disclosure events Privilege misuse ... Performs Monte Carlo, scenario-based, and probabilistic analyses where applicable. Supports capital ...

System Cybersecurity Architect

Pittsburgh, PA · On-site

$225K/yr

Could you be the full-time hybrid System Cybersecurity Architect in Pittsburgh, PA, US we're ... Analytical thinking and problem-solving skills to identify and mitigate cybersecurity risks.

... · Cybersecurity events · System failures and outages · Data loss and disclosure events · ... analyses to support risk measurement activities. · Partners with Technology and Information ...

next page

Showing results 1-20

Full Time Cyber Security Risk Analyst information

See Pittsburgh, PA salary details

$41.7K

$96.5K

$145.6K

How much do full time cyber security risk analyst jobs pay per year?

As of Aug 24, 2026, the average yearly pay for full time cyber security risk analyst in Pittsburgh, PA is $96,499.00, according to ZipRecruiter salary data. Most workers in this role earn between $77,200.00 and $112,100.00 per year, depending on experience, location, and employer.

What is the difference between Full Time Cyber Security Risk Analyst vs Cyber Security Analyst?

AspectFull Time Cyber Security Risk AnalystCyber Security Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentRisk assessment teams, security compliance, policy developmentSecurity monitoring, incident response, vulnerability assessment
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk managementIT firms, tech companies, cybersecurity service providers

Full Time Cyber Security Risk Analysts focus on identifying, assessing, and mitigating security risks within organizations, often working on compliance and policy. Cyber Security Analysts primarily monitor security systems, respond to incidents, and perform vulnerability assessments. While both roles require similar certifications and work in cybersecurity, their core responsibilities differ: risk analysis versus security monitoring.

How much does a full time cyber security risk analyst make?

A full-time cybersecurity risk analyst typically earns between $70,000 and $120,000 annually, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries. The role often requires knowledge of risk assessment tools and security frameworks.

What are the most commonly searched types of Cyber Security Risk Analyst jobs in Pittsburgh, PA?

The most popular types of Cyber Security Risk Analyst jobs in Pittsburgh, PA are:

What cities near Pittsburgh, PA are hiring for Full Time Cyber Security Risk Analyst jobs?

Cities near Pittsburgh, PA with the most Full Time Cyber Security Risk Analyst job openings:

Infographic showing various Full Time Cyber Security Risk Analyst job openings in Pittsburgh, PA as of August 2026, with employment types broken down into 100% Full Time. Highlights an 88% In-person, 6% Hybrid, and 6% Remote job distribution, with an average salary of $96,499 per year, or $46.4 per hour.

Cyber Security Analyst

Stantec

Pittsburgh, PA • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 4 days ago


Stantec rating

8.4

Company rating: 8.4 out of 10

Based on 84 frontline employees who took The Breakroom Quiz

123rd of 450 rated engineering


Job description


Our North America Water Utilities Cybersecurity team helps communities safeguard one of their most critical assets: water. We support utilities in understanding their overall cybersecurity posture, developing risk management plans, identifying practical improvements, and/or reconceptualizing overall cybersecurity strategy to support complete re-design across the business IT, operational technology (OT), industrial control system (ICS), and Access Control / CCTV networks.
Our approach emphasizes risk-based assessments, policy and governance improvements, and program development, while integrating findings from trusted third-party technical testing providers (e.g., penetration testing, vulnerability scans, and application assessments). Coupled with our extensive experience in design, build and operation of water treatment and conveyance facilities, we help water utilities build a complete picture of their cyber risk exposure and maturity, and guide them toward sustainable improvements.
This mid-level opportunity is intended for an experienced cybersecurity, OT/ICS, SCADA, or controls professional who can contribute independently to client engagements, perform and document cybersecurity assessments, develop practical recommendations, and support implementation of cybersecurity improvements across water and wastewater environments.
Your Opportunity
Stantec is at the forefront of the water industry, delivering thousands of projects for hundreds of communities globally. Our purpose is to conceive and develop the most impactful water projects that improve the health, quality of life and sustainability of the communities we live in and serve.
You will be part of a collaborative, client-facing team that values sound technical judgment, adaptability, and continuous improvement. This role is expected to take ownership of defined workstreams, interact directly with utility stakeholders, and clearly communicate cybersecurity and OT/ICS concepts to a range of audiences-from operators and engineers to executive leadership.
Key Responsibilities
  • Perform and support cybersecurity risk assessments, program reviews, and governance-focused security evaluations for water utility clients. Independently execute defined portions of engagements and contribute technical judgment to project findings and recommendations. This may include:
  • Collection, review, and field verification of record documents, network diagrams, asset inventories, and system configurations
  • Detailed field documentation of undocumented IT/OT/ICS installations, including lifecycle, maintenance, and obsolescence considerations
  • Capture, analysis, and summary of network monitoring, vulnerability scanning, and other technical assessment results
  • Technical research and evaluation of cybersecurity technologies, architectures, standards, and control approaches
  • Develop assessment findings, remediation recommendations, technical memoranda, and client-ready reports
  • Develop, review, and harmonize cybersecurity policies, standards, procedures, incident response plans, and strategies.
  • Manage assigned tasks, budgets, schedules, deliverables, and coordination activities; contribute to overall project management as needed
  • Evaluate and incorporate findings from third-party penetration testing, vulnerability scanning, and other technical service providers into comprehensive client risk profiles and remediation plans.
  • Participate actively in client workshops, interviews, field investigations, design reviews, and presentations; facilitate defined portions of client meetings when appropriate.
  • Maintain current technical and industry knowledge and take ownership of continued professional development, including:
  • Maintenance and pursuit of relevant cybersecurity, networking, OT/ICS, and vendor certifications
  • Continued development of practical skills with network monitoring, vulnerability assessment, system scanning, analysis, and penetration-testing tools
  • Active engagement in key manufacturer, water-sector, OT/ICS cybersecurity, and industry-sponsored user groups

Qualifications
Capabilities and Credentials
  • Working knowledge of cybersecurity principles, governance, risk management, network security, and OT/ICS security practices, with the ability to apply them in client environments.
  • Strong written and verbal communication skills, including the ability to develop client-ready technical deliverables and explain technical risk and recommendations to non-technical stakeholders.
  • Ability to work independently on assigned workstreams while collaborating effectively with clients, internal engineering teams, cybersecurity specialists, and third-party partners.
  • Strong organizational and project execution skills for balancing multiple concurrent projects, priorities, and deadlines.
  • Working knowledge of cybersecurity frameworks and guidance such as NIST CSF 2.0, NIST SP 800-53, NIST SP 800-82, ISA/IEC 62443, AWWA cybersecurity guidance, and applicable water-sector regulatory requirements. Familiarity with SCADA architectures, industrial networking, virtualization, Windows Server/Active Directory, SIEM/IDS/IPS, vulnerability management, or related OT technologies is highly desirable.
Education and Experience
  • Bachelor's degree in computer science, cybersecurity, information systems, or electrical engineering required. Other 4-year undergraduate engineering degrees will be considered. Relevant graduate education and/or evidenced directly applicable experience desirable.
  • CompTIA Security+, Systems Security Certified Practitioner (SSCP) or equivalent cybersecurity/OT security certification required
  • Certified Information Security Manager (CISA) and/or Certified Information Security Systems Professional (CISSP) desirable
  • Minimum of 8 years of relevant professional experience in cybersecurity, IT/OT networking, SCADA/industrial control networks, systems engineering, or related technology disciplines, including demonstrated cybersecurity responsibilities.
  • Water/wastewater or other critical-infrastructure experience strongly preferred.
  • Must have good driving record and valid driver's license
  1. Continued advancement will be supported through progressively greater responsibility for technical leadership, client delivery, and project management. Attainment of advanced professional certifications, including CISSP, CISA, CISM or equivalent, will be required.
Additional Information
  • Reports to: Cybersecurity Practice Lead, Water Utilities
  • Location: Partially remote (strong preference for candidates near an existing office)
  • Travel: Occasional travel to client sites or industry events (up to 50%)
  • Office work: Typical office desktop workstation environment.
  • Field work: typically at sites with treatment equipment in active use and/or active construction activities. Exposure to the elements including inclement weather is probable.

This description is not a comprehensive listing of activities, duties or responsibilities that may be required of the employee. Other duties, responsibilities and activities may be assigned or may be changed at any time with or without notice.
About the Team
Pay Transparency: In compliance with pay transparency laws, pay ranges are provided for positions in locations where required. Please note, the final agreed upon compensation is based on individual education, qualifications, experience, and work location. At Stantec certain roles are bonus eligible. Actual compensation for part-time roles will be pro-rated based on the agreed number of working hours per week.
Benefits Summary: Regular full-time and part-time employees (working at least 20 hours per week) have access to medical, dental, and vision plans, a wellness program, health saving accounts, flexible spending accounts, 401(k) plan, employee stock purchase program, life and accidental death & dismemberment (AD&D) insurance, short-term/long-term disability plans, emergency travel benefits, tuition reimbursement, professional membership fee coverage and paid family leave. Regular full-time and part-time employees will receive ten paid holidays in each calendar year. In addition, employees will be eligible to accrue vacation between 10 and 20 days per year and eligible for paid sick leave (and if more generous, in accordance with state and local law).
Temporary/casual employees have access to 401(k) plans, employee stock purchase program, and paid leave, in accordance with state and local law.
The benefits information listed above may not apply to union positions because benefits for such positions are governed by applicable collective bargaining agreements

What Stantec employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom