Talent.com
Alcoa
Cyber Security Risk AnalystAlcoa • Montréal, QC, Canada
Cyber Security Risk Analyst

Cyber Security Risk Analyst

Alcoa • Montréal, QC, Canada
30+ days ago
Job type
  • Full-time
Job description

Shape Your World

At Alcoa, you will become an essential part of our purpose: to turn raw potential into real progress. The way we see it, every Alcoan is a work-shaper, team-shaper, idea-shaper & world-shaper.

Alcoa is seeking a Cyber Security Risk Analyst to serve as a key contributor to the cybersecurity risk management program, providing subject matter expertise in identifying, assessing, and managing risks across both Information Technology (IT) and Operational Technology (OT) environments. This role supports informed business decision-making by translating complex technical risks into business and operational impact. The Analyst independently leads risk assessments and partners closely with IT, OT, audit, and senior leaders to ensure cybersecurity risks are understood, documented, mitigated, and monitored in accordance with corporate policies and industry standards.

As Alcoa’s Cybersecurity Risk Management program continues to mature, the Analyst plays a critical role in shaping and enhancing program capabilities.

About the Role:

  • Contribute to the development, implementation, and continuous improvement of the Cybersecurity Risk Management Program, including frameworks, methodologies, policies, standards, and supporting tools.

  • Perform cybersecurity risk assessments across IT, OT, cloud, and third-party environments, including enterprise systems and manufacturing/process control systems (PCS).

  • Facilitate risk workshops with technical and business stakeholders to evaluate risks associated with new technologies, projects, and operational changes.

  • Serve as a subject matter expert on risk methodology, scoring, and evaluation.

  • Maintain and enhance the cybersecurity risk register, including risk scoring, treatment plans, and residual risk tracking.

  • Support and guide risk treatment strategies (mitigation, acceptance, transfer, avoidance) and partner with compliance teams to design and implement appropriate controls.

  • Translate technical risk findings into clear business and operational impact statements for non-technical audiences and senior leadership.

  • Advise leadership on risk exposure, trends, and residual risks, including impacts to business operations and production.

  • Define, monitor, and report Key Risk Indicators (KRIs) and emerging threat trends.

  • Support audit, regulatory, and compliance activities (e.g., ISO 27001, NIST, SOC) related to cybersecurity risk management.

  • Collaborate with Enterprise Risk Management (ERM) and Operations Risk Management teams to ensure alignment and integration of cybersecurity risks into broader risk reporting.

  • Build and maintain strong relationships with stakeholders across IT, OT, business units, and risk management functions.

  • Continuously monitor evolving cyber threats, emerging technologies, and industry practices to enhance risk management processes and capabilities.

What you can bring to this role:

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, Risk Management, or a related discipline; equivalent professional experience may be considered in lieu of a degree.

  • 6+ years of experience in cybersecurity, IT risk management, information security, governance, compliance, or IT operations within enterprise environments.

  • Demonstrated experience assessing cybersecurity risk across IT and OT environments; experience in manufacturing or industrial organizations preferred.

  • Strong knowledge of cybersecurity frameworks and standards (e.g., ISO 27001, NIST CSF, NIST 800-53, CIS Controls, SOX).

  • Proven experience executing core GRC activities, including risk assessments, policy and standard development, control validation, audit support, and remediation tracking.

  • Expertise in cybersecurity governance, risk assessment, and compliance program implementation.

  • Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards.

  • Solid understanding of security principles, including security controls, threat modeling, vulnerability management, and incident risk analysis.

  • Excellent written, verbal, and facilitation skills, with the ability to translate complex technical risks into clear business impacts.

  • Demonstrated ability to collaborate effectively with cross-functional stakeholders, including technical teams, operations, and senior leadership, while managing multiple priorities in fast-paced environments.

Preferred Qualifications

  • Relevant industry certifications such as CISSP, CISM, CRISC, CISA, CGRC, Security+, GRCP, or equivalent.

  • Experience with third-party/vendor risk management, regulatory compliance assessments, and security awareness programs.

  • Experience supporting global environments and contributing to enterprise-wide security or compliance initiatives.

  • Experience supporting audits and assurance activities, including ISO/IEC 27001 certification and SOC report reviews.

  • Familiarity with security operations capabilities, including SIEM, log analysis, and event monitoring for compliance and incident response.

  • Understanding of enterprise security domains, including cloud security, infrastructure security, and identity and access management (IAM).

  • Working knowledge of project management methodologies and practices.

  • Experience in metals, mining, manufacturing, or other heavy industrial environments.

What we offer:

  • Competitive compensation packages, including pay-for performance variable pay, recognition and rewards programs, and stock-based compensation awards (3-year vesting schedule)

  • Flexible spending accounts and generous employer contribution to the HSA

  • 401(k), employer match up to 6%, additional employer retirement income contribution (no vesting period), and a non-qualified deferred compensation plan

  • 12 paid holidays per year.

  • 15 days of paid vacation (pro-rated from hire date).

  • Employee Assistance Program (EAP)

#LI-TL2

Create a job alert for this search

Cyber Security Risk Analyst • Montréal, QC, Canada

Similar jobs

IT Security Risk Analyst

Onico SolutionsMontreal (administrative region), QC, CA
Permanent

The IT Security Risk Analyst supports the Information Security Risk Management and Governance programs.They work with technology and business stakeholders to identify Information Security risks, co... Show more

 • Promoted

Operational Technology Cybersecurity Expert

WSP in Canadamontreal (administrative region), qc, Canada
Full-time

Join as an Operational Technology Cybersecurity Expert, focusing on safeguarding energy systems.Leverage your expertise in cybersecurity to enable safe digital transformation in critical infrastruc... Show more

 • Promoted

L1 Cyber Security Analyst

SecureOpsMontreal
Full-time

SecureOps is a Managed Security Service Provider (MSSP) delivering 24/7 security operations, managed detection and response (MDR), and SOC-as-a-Service to enterprise clients.Our ability to deliver ... Show more

 • Promoted

Cyber Security Architect

Intuitive.aiMontreal (administrative region), QC, CA
Full-time

Talent Acquisition Leader | Hiring Cloud Professionals Globally.Cloud is one of the fastest-growing (INC 5000, CRN) Cloud & SDx solution and services companies supporting enterprise customers on a ... Show more

 • Promoted

Security Analyst (SOC)

Bedard ResourcesLaval
Full-time

Our client is looking for a Junior Cybersecurity Analyst to assist with the daily management of a simulation platform, support the onboarding of new clients, and contribute to analyses related to a... Show more

 • Promoted

Contract Security Analyst for Cyber Defense

Fluid - Solutions de Talents/Workforce SolutionsMontreal (administrative region), QC, CA
Full-time

Strengthen our cybersecurity initiatives as a Security Analyst.Focus on optimizing threat detection systems, endpoint security configuration, and vulnerability management across critical platforms ... Show more

 • Promoted

Cybersecurity Analyst Role Focusing on Security Monitoring and Awareness

NOVIPROMontreal (administrative region), QC, CA
Full-time

Exciting opportunity for a Cybersecurity Analyst to join a security-focused team remotely.Play a crucial role in identifying vulnerabilities and enhancing the security framework through best practi... Show more

 • Promoted

Analyste cybersécurité

Cofina, Services Conseils en TIMontreal (administrative region), QC, CA
Permanent

Vous recherchez un défi stimulant dans une entreprise humaine? Ça tombe bien, nous avons un poste pour vous! Nous sommes à la recherche d’un Analyste en cybersécurité pour l’un de nos clients pour ... Show more

 • Promoted

Security Analyst

Prosperity Workforce SolutionsMontreal
Full-time +1

We are seeking a highly skilled.This temporary position will focus on fine-tuning threat detection models, ensuring best practices in endpoint protection, and improving the utilization of our secur... Show more

 • Promoted

Cyber Security Analyst

MindlanceMontreal, Montreal (administrative region), CA
Full-time

This range is provided by Mindlance.Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.Subject Matter Expert - Recruitment at Mindlance.Job Role: I... Show more

 • Promoted

L3 Cybersecurity Analyst at Major Bank

QUANTEAM - North America (RAINBOW PARTNERS Group)Montreal (administrative region), QC, CA
Full-time

Enhance security measures at a leading bank as an L3 Cybersecurity Analyst, facilitated by Quanteam in Montreal.Focus on incident management and advanced malware response strategies.Quanteam is in ... Show more

 • Promoted

Senior Analyst, Cybersecurity Incident Response

CynergyIQ GroupMontreal (administrative region), QC, CA
Full-time

Lead incident response efforts as a Senior Analyst within a dedicated SOC team, focusing on advanced security tools like Palo Alto CORTEX.Provide top-notch service to enterprise clients.In this key... Show more

 • Promoted

Cybersecurity Analyst - Hybrid Role

Orange Cyberdefense Canada Inc.Montreal (administrative region), QC, CA
Full-time +1

Elevate your career as a Cybersecurity Analyst in a hybrid work environment.This role focuses on safeguarding information systems while collaborating with clients and ensuring robust security measu... Show more

 • Promoted

Architectural Security Specialist in Cyber

PowerToFlymontreal (administrative region), qc, Canada
Full-time

Shape the future of security architecture at Morgan Stanley as a Senior Security Architecture Specialist.This hybrid position is designed to position compliance at the heart of development practice... Show more

 • Promoted

Security Analyst

360 IT ProfessionalsMontreal
Full-time

IT Professionals is a Software Development Company based in Fremont, California that offers complete technology services in Mobile development, Web development, Cloud computing and IT staffing.Merg... Show more

 • Promoted

Analyste principal(e) - Contrôles et indicateurs de cybersécurité | Cybersecurity Controls & Metrics

NTT DATA North Americamontreal (administrative region), qc, Canada
Full-time

NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us.If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.... Show more

 • Promoted

Cybersecurity Analyst Focusing on Threat Detection and Incident Response

Hamilton Barnes Associates LimitedMontreal
Full-time

Become a vital part of a cutting-edge cybersecurity team actively detecting threats and responding to incidents.Leverage your expertise to enhance security measures in a hybrid working environment.... Show more

 • Promoted

Senior Analyst, Security Compliance

P2PMontreal (administrative region), QC, CA
Full-time

Our Krakenites are a world-class team with crypto conviction, united by our desire to discover and unlock the potential of crypto and blockchain technology.Kraken is a mission-focused company roote... Show more

 • Promoted

Remote Information Risk & Security Analyst

DexianMontreal (administrative region), QC, CA
Remote
Full-time

A leading IT services firm is seeking an Information Control Testing Specialist to manage information risk and ensure compliance with security policies.You will work on global initiatives, conduct ... Show more

 • Promoted

Infrastructure Operations and Security Analyst

Canada Mortgage and Housing CorporationMontreal (administrative region), QC, CA
Full-time

Take charge of enterprise infrastructure operations as an Infrastructure Operations and Security Analyst.Combine expertise in virtualization and backup to enhance system performance in a hybrid set... Show more