The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards.
The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards.
Senior GRC Analyst
Pittsburgh, PA · On-site
$114K - $163K/yr
Senior GRC Analyst Department: Compliance & Fraud Employment Type: Full Time Location: Pittsburgh ... Execute third-party risk assessments across our vendor portfolio, including security questionnaire ...
Senior GRC Analyst
Pittsburgh, PA · On-site
$114K - $163K/yr
Senior GRC Analyst Department: Compliance & Fraud Employment Type: Full Time Location: Pittsburgh ... Execute third-party risk assessments across our vendor portfolio, including security questionnaire ...
Configure and implement SAP GRC Access Control capabilities, including Access Risk Analysis, Access Request Management, Emergency Access Management, and Business Role Management * Support SAP GRC ...
Configure and implement SAP GRC Access Control capabilities, including Access Risk Analysis, Access Request Management, Emergency Access Management, and Business Role Management * Support SAP GRC ...
Senior GRC Analyst
$114K - $163K/yr
As Senior GRC Analyst, you will be the hands-on owner of the control and evidence work behind our ... Execute third-party risk assessments across our vendor portfolio, including security questionnaire ...
Quick apply
Senior GRC Analyst
$114K - $163K/yr
As Senior GRC Analyst, you will be the hands-on owner of the control and evidence work behind our ... Execute third-party risk assessments across our vendor portfolio, including security questionnaire ...
Sr Manager, InfoSec Governance Risk and Compliance (GRC) (Pittsburgh, Pennsylvania, US) Founded in ... Excellent project management, analytical, and problem-solving skills with keen attention to detail.
Sr Manager, InfoSec Governance Risk and Compliance (GRC) (Pittsburgh, Pennsylvania, US) Founded in ... Excellent project management, analytical, and problem-solving skills with keen attention to detail.
Sr Manager, InfoSec Governance Risk and Compliance (GRC) (Pittsburgh, Pennsylvania, US) Founded in ... Excellent project management, analytical, and problem-solving skills with keen attention to detail.
Sr Manager, InfoSec Governance Risk and Compliance (GRC) (Pittsburgh, Pennsylvania, US) Founded in ... Excellent project management, analytical, and problem-solving skills with keen attention to detail.
An excellent career opportunity is currently available for an entry level Risk & Compliance Analyst ... GRC's privacy and compliance initiatives Required Qualifications: * High School diploma/GED ...
An excellent career opportunity is currently available for an entry level Risk & Compliance Analyst ... GRC's privacy and compliance initiatives Required Qualifications: * High School diploma/GED ...
Risk & Compliance Analyst
Pittsburgh, PA · On-site
An excellent career opportunity is currently available for an entry level Risk & Compliance Analyst ... GRC's privacy and compliance initiatives Required Qualifications: * High School diploma/GED ...
Risk & Compliance Analyst
Pittsburgh, PA · On-site
An excellent career opportunity is currently available for an entry level Risk & Compliance Analyst ... GRC's privacy and compliance initiatives Required Qualifications: * High School diploma/GED ...
Hybrid- Senior Risk Specialist in Pittsburgh, PA, and multiple client tech hub locations
Pittsburgh, PA · On-site
$95K/yr
... GRC tool before, specifically Archer 4. Financial Institution experience Flex Skills/Nice to Have ... in 2023 by Staffing Industry Analysts - a testament to our continued growth, commitment to ...
Quick apply
Hybrid- Senior Risk Specialist in Pittsburgh, PA, and multiple client tech hub locations
Pittsburgh, PA · On-site
$95K/yr
... GRC tool before, specifically Archer 4. Financial Institution experience Flex Skills/Nice to Have ... in 2023 by Staffing Industry Analysts - a testament to our continued growth, commitment to ...
Senior Risk Specialist in Pittsburgh, PA, and multiple client tech hubs
Pittsburgh, PA · On-site
$95K/yr
... to analyze situations fully and accurately, and reach productive decisions. * Effective ... Archer GRC * Development and management of internal risks and controls * Experience/familiarity ...
Quick apply
Senior Risk Specialist in Pittsburgh, PA, and multiple client tech hubs
Pittsburgh, PA · On-site
$95K/yr
... to analyze situations fully and accurately, and reach productive decisions. * Effective ... Archer GRC * Development and management of internal risks and controls * Experience/familiarity ...
Cyber SAP Security and GRC Access & Process Control Senior Consultant / Senior Engineering Manage...
... SAP Governance, Risk, and Compliance (GRC) * 3+ years of experience designing or supporting role-based access controls, segregation of duties analysis, or sensitive access controls in SAP ...
Cyber SAP Security and GRC Access & Process Control Senior Consultant / Senior Engineering Manage...
... SAP Governance, Risk, and Compliance (GRC) * 3+ years of experience designing or supporting role-based access controls, segregation of duties analysis, or sensitive access controls in SAP ...
In the role of the Compliance Analyst on our Managed Services team, you will be responsible for ... ACA Group is the leading governance, risk, and compliance (GRC) advisor in financial services. We ...
In the role of the Compliance Analyst on our Managed Services team, you will be responsible for ... ACA Group is the leading governance, risk, and compliance (GRC) advisor in financial services. We ...
In the role of the Compliance Analyst on our Managed Services team, you will be responsible for ... ACA Group is the leading governance, risk, and compliance (GRC) advisor in financial services. We ...
In the role of the Compliance Analyst on our Managed Services team, you will be responsible for ... ACA Group is the leading governance, risk, and compliance (GRC) advisor in financial services. We ...
... Governance, Risk, and Compliance (GRC) expectations in regulated enterprise environments ... analytics and dashboards. * Implementing data quality checks, lineage, metadata, and access ...
... Governance, Risk, and Compliance (GRC) expectations in regulated enterprise environments ... analytics and dashboards. * Implementing data quality checks, lineage, metadata, and access ...
Information Security Program Lead
Cranberry Township, PA · On-site
$125K - $152K/yr
... analyses, risk assessments, and risk treatment planning in line with ISO 27001 Annex A controls ... Support and collaborate with the Third-Party Risk Management (TPRM) function, providing GRC ...
Information Security Program Lead
Cranberry Township, PA · On-site
$125K - $152K/yr
... analyses, risk assessments, and risk treatment planning in line with ISO 27001 Annex A controls ... Support and collaborate with the Third-Party Risk Management (TPRM) function, providing GRC ...
Information Security Program Lead
Cranberry Township, PA · On-site
$125K - $152K/yr
... analyses, risk assessments, and risk treatment planning in line with ISO 27001 Annex A controls ... Support and collaborate with the Third-Party Risk Management (TPRM) function, providing GRC ...
Information Security Program Lead
Cranberry Township, PA · On-site
$125K - $152K/yr
... analyses, risk assessments, and risk treatment planning in line with ISO 27001 Annex A controls ... Support and collaborate with the Third-Party Risk Management (TPRM) function, providing GRC ...
You Are: A Security and Risk professional developing and delivering solutions that protect SAP ... Security Analytics, Enterprise GRC Solutions, Automated External Application Scanning, and ...
You Are: A Security and Risk professional developing and delivering solutions that protect SAP ... Security Analytics, Enterprise GRC Solutions, Automated External Application Scanning, and ...
You Are: A Security and Risk professional developing and delivering solutions that protect SAP ... Security Analytics, Enterprise GRC Solutions, Automated External Application Scanning, and ...
You Are: A Security and Risk professional developing and delivering solutions that protect SAP ... Security Analytics, Enterprise GRC Solutions, Automated External Application Scanning, and ...
... and in-depth analytics to help risk and compliance officers simplify and streamline their ... We empower our clients to reimagine GRC and protect and grow their business. Our innovative ...
... and in-depth analytics to help risk and compliance officers simplify and streamline their ... We empower our clients to reimagine GRC and protect and grow their business. Our innovative ...
Senior Angular Engineer
Pittsburgh, PA · Hybrid
$120K - $150K/yr
Who Are We ACA Group ("ACA") is the leading governance, risk, and compliance (GRC) advisor in ... analytics to help risk and compliance officers simplify and streamline their regulatory and ...
Senior Angular Engineer
Pittsburgh, PA · Hybrid
$120K - $150K/yr
Who Are We ACA Group ("ACA") is the leading governance, risk, and compliance (GRC) advisor in ... analytics to help risk and compliance officers simplify and streamline their regulatory and ...
Grc Risk Analyst information
See Pittsburgh, PA salary details
$14.94 - $19.39
3% of jobs
$19.39 - $23.85
7% of jobs
$23.85 - $28.30
12% of jobs
$29.18 is the 25th percentile. Wages below this are outliers.
$28.30 - $32.76
15% of jobs
$32.76 - $37.21
13% of jobs
The median wage is $37.36 / hr.
$37.21 - $41.67
16% of jobs
$41.67 - $46.12
8% of jobs
$46.68 is the 75th percentile. Wages above this are outliers.
$46.12 - $50.58
11% of jobs
$50.58 - $55.03
6% of jobs
$55.03 - $59.49
6% of jobs
$59.49 - $63.94
3% of jobs
$14
$39
$63
How much do grc risk analyst jobs pay per hour?
What is a GRC Risk Analyst?
What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?
What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?
What is the difference between Grc Risk Analyst vs Compliance Analyst?
| Aspect | Grc Risk Analyst | Compliance Analyst |
|---|---|---|
| Certifications | ISO 31000, FRM, CRISC | ISO 19600, CCEP, CISA |
| Work Environment | Risk management teams, corporate offices | Regulatory departments, corporate offices |
| Industry Usage | Finance, banking, insurance, corporate risk | Financial services, healthcare, manufacturing |
| Job Focus | Identifying, assessing, and mitigating risks across enterprise | Ensuring compliance with laws and regulations |
While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.
What are popular job titles related to Grc Risk Analyst jobs in Pittsburgh, PA?
For Grc Risk Analyst jobs in Pittsburgh, PA, the most frequently searched job titles are:
What job categories do people searching Grc Risk Analyst jobs in Pittsburgh, PA look for?
The top searched job categories for Grc Risk Analyst jobs in Pittsburgh, PA are:
What cities near Pittsburgh, PA are hiring for Grc Risk Analyst jobs?
Cities near Pittsburgh, PA with the most Grc Risk Analyst job openings:

Full-time
Retirement, PTO
Re-posted 18 days ago
Alcoa rating
8.0
Based on 16 frontline employees who took The Breakroom Quiz
Job description
Shape Your World
At Alcoa, you will become an essential part of our purpose: to turn raw potential into real progress. The way we see it, every Alcoan is a work-shaper, team-shaper, idea-shaper & world-shaper.
Alcoa is seeking a Cyber Security Risk Analyst to serve as a key contributor to the cybersecurity risk management program, providing subject matter expertise in identifying, assessing, and managing risks across both Information Technology (IT) and Operational Technology (OT) environments.This role supports informed business decision-making by translating complex technicalrisksinto business and operational impact.The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior leadersto ensure cybersecurity risks are understood, documented, mitigated, and monitored in accordance with corporate policies and industry standards.
As Alcoa's Cybersecurity Risk Management program continues to mature, the Analyst plays a critical role in shaping and enhancing program capabilities.
About the Role:
Contribute to the development, implementation, and continuous improvement of the Cybersecurity Risk Management Program, including frameworks, methodologies, policies, standards, and supporting tools.
Perform cybersecurity risk assessments across IT, OT, cloud, and third-party environments, including enterprise systems and manufacturing/process control systems (PCS).
Facilitate risk workshops with technical and business stakeholders to evaluate risks associated with new technologies, projects, and operational changes.
Serve as a subject matter expert on risk methodology, scoring, and evaluation.
Maintain and enhance the cybersecurity risk register, including risk scoring, treatment plans, and residual risk tracking.
Support and guide risk treatment strategies (mitigation, acceptance, transfer, avoidance) and partner with compliance teams to design and implement appropriate controls.
Translate technical risk findings into clear business and operational impact statements for non-technical audiences and senior leadership.
Advise leadership on risk exposure, trends, and residual risks, including impacts to business operations and production.
Define, monitor, and report Key Risk Indicators (KRIs) and emerging threat trends.
Support audit, regulatory, and compliance activities (e.g., ISO 27001, NIST, SOC) related to cybersecurity risk management.
Collaborate with Enterprise Risk Management (ERM) and Operations Risk Management teams to ensure alignment and integration of cybersecurity risks into broader risk reporting.
Build and maintain strong relationships with stakeholders across IT, OT, business units, and risk management functions.
Continuously monitor evolving cyber threats, emerging technologies, and industry practices to enhance risk management processes and capabilities.
What you can bring to this role:
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, Risk Management, or a related discipline; equivalent professional experience may be considered in lieu of a degree.
6+ years of experience in cybersecurity, IT risk management, information security, governance, compliance, or IT operations within enterprise environments.
Demonstrated experience assessing cybersecurity risk across IT and OT environments; experience in manufacturing or industrial organizations preferred.
Strong knowledge of cybersecurity frameworks and standards (e.g., ISO 27001, NIST CSF, NIST 800-53, CIS Controls, SOX).
Proven experience executing core GRC activities, including risk assessments, policy and standard development, control validation, audit support, and remediation tracking.
Expertise in cybersecurity governance, risk assessment, and compliance program implementation.
Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards.
Solid understanding of security principles, including security controls, threat modeling, vulnerability management, and incident risk analysis.
Excellent written, verbal, and facilitation skills, with the ability to translate complex technical risks into clear business impacts.
Demonstrated ability to collaborate effectively with cross-functional stakeholders, including technical teams, operations, and senior leadership, while managing multiple priorities in fast-paced environments.
PreferredQualifications
Relevant industry certifications such as CISSP, CISM, CRISC, CISA, CGRC, Security+, GRCP, or equivalent.
Experience withthird-party/vendor risk management, regulatory compliance assessments, and security awareness programs.
Experience supporting global environments and contributing to enterprise-wide security or compliance initiatives.
Experience supporting audits and assurance activities, including ISO/IEC 27001 certification and SOC report reviews.
Familiarity with security operations capabilities, including SIEM, log analysis, and event monitoring for compliance and incident response.
Understanding of enterprise security domains, including cloud security, infrastructure security, and identity and access management (IAM).
Working knowledge of project management methodologies and practices.
Experience in metals, mining, manufacturing, or other heavy industrial environments.
What we offer:
Competitive compensation packages, including pay-for performance variable pay, recognition and rewards programs, and stock-based compensation awards (3-year vesting schedule)
Flexible spending accounts and generous employer contribution to the HSA
401(k), employer match up to 6%, additional employer retirement income contribution (no vesting period), and a non-qualified deferred compensation plan
12 paid holidays per year.
15 days of paid vacation (pro-rated from hire date).
Employee Assistance Program (EAP)
#LI-TL2
Employees must be legally authorized to work in the United States. Verification of employment eligibility will be required at the time of hire. Visa sponsorship is not available for this position.
About the Location
Alcoa is an international company with multiple locations and joint ventures across six continents. Wherever you choose to join us, you'll be joining a global team committed to advancing sustainability and delivering excellence and innovation. As industry pioneers, we are redefining what it means to be a sustainable aluminum company, bridging the journey from mines to metal.
We are values led, vision driven and united by our purpose of transforming raw potential into real progress. Our commitments to Inclusion, Diversity & Equity include providing trusting workplaces that are safe, respectful and inclusive of all individuals, free from discrimination, bullying and harassment and that our workplaces reflect the diversity of the communities in which we operate.
As a proud equal opportunity workplace and affirmative action employer, Alcoa is dedicated to providing equal opportunities and equal access to all individuals regardless of a person's gender, age, race, ethnicity, sexual orientation, gender identity, religion, nation of origin, disability, veteran status, language spoken or any other characteristic or status protected by the laws or regulations in the places where we operate.
If you have visited our website in search of information on U.S. employment opportunities or to apply for a position, and you require an accommodation, please contact Alcoa Recruiting via email at gssrecruiting@alcoa.com.
This is a place where you are empowered to do your best work, be your authentic self, and feel a true sense of belonging. Come join us and shape your career!
Your work. Your world. Shape them for the better.
About Alcoa
Sourced by ZipRecruiter
Alcoa is a global industry leader in the production of bauxite, alumina and aluminum, a position enhanced by a portfolio of value-added cast products and select energy assets. Since developing the aluminum industry more than 135 years ago, Alcoa has built a legacy of breakthrough innovations and best practices that have led to efficiency, safety, sustainability and stronger communities wherever we operate.
Industry
Manufacturing
Company size
10,000+ Employees
Headquarters location
Pittsburgh, PA, US
Year founded
1888