Ir à oferta completa

SECURITY RISK ANALYST (FLEXIBLE)

Descrição da oferta de emprego

Shape Your World At Alcoa, you will become an essential part of our purpose.
to turn raw potential into real progress.
The way we see it, every Alcoan is a work-shaper, team-shaper, idea-shaper, world-shaper.
As a leader within Alcoa, you can help us fulfill our purpose and realize our vision to reinvent the aluminum industry.
Be part of the team that is helping shape a better workplace with a better work-life balance and the equal opportunities that help everyone thrive.
You have the power to shape things to make them better.
About the Role.
As the Security Risk Analyst, you will have key input in designing and implementing a new program, that is still in its developmental stage.
This professional will be joining our Governance Risk & Compliance (GRC) team within the Information Technology & Automation Systems (ITAS) department.
The Security Risk Analyst will be responsible for optimizing an IT risk management program that balances risk, compliance, and cost to align with the Company's business goals and ITAS strategy.
Contribute to the development of the IT Risk Management Program (policy, standards development, implementation, GRC platform configuration and adoption) Conduct independent and comprehensive system risk assessments of the management, operational, and technical security controls and enhancements employed within or inherited by a system to determine the overall effectiveness of the controls.
Perform risk analysis (e.
., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a risk assessment or major change.
Assess all applicable system component configurations baselines or benchmarks for currency during the system risk assessment and during change or updates for release management processes.
Provide a comprehensive assessment of the weakness or deficiencies in the information systems and prepares the final security control gap analysis and system risk assessment report containing the results and findings from the assessment.
Ensure that system owner corrective action plans (CAPs) are in place for vulnerabilities identified during risk assessments, audits, or self-assessments.
Provide input to the Risk Management process and maintain and update risk management policies, standards, guidelines, and procedures.
Validate and update security documentation reflecting the application or system security design.
Identify opportunities to improve risk posture, developing solutions for remediating or mitigating risks and assessing the residual risk.
Lead the reporting efforts for all information system weakness or deficiencies plus CAPs.
Configure and manage the risks and KPI's in a GRC platform.
In combination with the ITAS Security Awareness & Training Specialist, provide threat awareness, and education to Alcoa's users (or employees & contractors).
Collaborate with active project teams to ensure risk is adequately managed for new system/infrastructure/security projects.
Coordinate with the Enterprise Risk Management group for corporate level risk reporting.
Work in partnership with the Operations Risk Management group for overlap in information/Cybersecurity related risks.
What you can bring to the role.
Bachelor's degree Information Systems Security or Management, Cybersecurity, Computer Science, Risk Management, or equivalent degrees.
4 years of experience in Information Security/Cybersecurity risk and mitigation strategies, technologies, programs, and operations.
Experience with regulatory compliance and information security management frameworks (ISO-, ISO-, ISO-, ISO-, NIST, NIST) Experience with GRC Platforms (AuditBoard) and one or more certifications such as CRISC, CGRC, GRCP™, ISC2 CGRC – preferred but not required.
Knowledge of risk management processes, security architectures and technologies, data security, privacy principles, cyber defense, and vulnerability assessment tools.
Familiarity with application vulnerabilities, identity, access control methods, networking concepts and protocols, and security methodologies Collaborate with stakeholders to make informed and balanced decisions about risk that balance the benefits of risk reduction and business performance.
Performing business impact assessments, privacy impact assessments, and threat assessments.
Interpreting system vulnerability and configuration scanner results to identify vulnerabilities.
#LI-TL2 #LI-Remote   What's on offer.
401(k), employer match up to 6%, additional employer retirement income contribution (no vesting period), and a nonqualified deferred compensation plans​; 15 days' vacation and one flexible holiday of your choice​; Flexible spending accounts and generous employer contribution to the HAS; Paid annual volunteer hours;  Career development opportunities to pursue your passions; and Social and diversity focused engagement opportunities.
About the Location Alcoa is an international company with multiple locations and joint ventures across six continents.
Wherever you choose to join us, you'll be joining a global team committed to advancing sustainability and delivering excellence and innovation.
As industry pioneers, we are redefining what it means to be a sustainable aluminum company, bridging the journey from mines to metal.
We are values led, vision driven and united by our purpose of transforming raw potential into real progress.
Our commitments to Inclusion, Diversity & Equity include providing trusting workplaces that are safe, respectful and inclusive of all individuals, free from discrimination, bullying and harassment and that our workplaces reflect the diversity of the communities in which we operate.
As a proud equal opportunity workplace and affirmative action employer, Alcoa is dedicated to providing equal opportunities and equal access to all individuals regardless of a person's gender, age, race, ethnicity, sexual orientation, gender identity, religion, nation of origin, disability, veteran status, language spoken or any other characteristic or status protected by the laws or regulations in the places where we operate.
If you have visited our website in search of information on U.
.
employment opportunities or to apply for a position, and you require an accommodation, please contact Alcoa Recruiting via email at .
This is a place where you are empowered to do your best work, be your authentic self, and feel a true sense of belonging.
Come join us and shape your career! Your work.
Your world.
Shape them for the better.
Ir à oferta completa

Detalhes da oferta

Empresa
  • Alcoa
Localidade
  • Em todo o Brasil
Endereço
  • Indeterminado - Indeterminado
Tipo de Contrato
  • Indeterminado
Data de publicação
  • 25/05/2024
Data de expiração
  • 23/08/2024
SAP GRC and Security Consultants
Equacao IT

Requisitos do trabalho • 5+ years of experience as sap grc & security consultant;• experience in maintaining sap grc risk library, roles and authorizations (ecc, bw4hana);• proficiency with sap grc access request management configuration;• experience with suim;• knowledge of sod with understanding of......

SAP BO – Reporting and Data Analyst
Equacao IT

We are looking for a sap bo – reporting and data analyst with the following requirements: requisitos do trabalho • extraction and analysis of data from various sources;• participation in the data delivery process with the entire delivery environment;• import (incl... outros dados de posição • duration:......

Functional Analyst
JP&F Consultoria de RH e Gestão de Pessoas

Descrição: 7+ years’ experience as project techno-functional lead within a similar technical environment financial services industry experience financial system (accounting and/or financial reporting), credit risk or data warehouse itil project management... net, pl/sql unix/linux and windows environments......

LEGAL ADVISOR
Oman Jobs

Risk management:•identify and assess legal risks associated with real estate transactions and operations... •develop risk mitigation strategies and implement controls to minimize exposure to legal liabilities... dispute resolution:•assist in the resolution of legal disputes and litigation related to......

Cloud Engineer
JP&F Consultoria de RH e Gestão de Pessoas

Implementation of continuous compliance and security in the organization and the cloud... infrastructure as code deployments with cloud... regime de contratação: clt / efetivo local de trabalho: são paulo / sp – (santo amaro)... script and automation development using various aws sdks......

Online personal trainer
Happy trainers

Flexible work hours... what we offer: attractive earnings potential... professional identity card (cref card) being able to speak in english... nasm, ncsf, ace, nsca) first aid or cpr/aed certificate... we are actively seeking passionate and certified personal trainers from brazil to join our innovative......

REGISTERED NURSE
Reachjobs

Here’s how we give you a different level of support• exclusive access to nurse revalidation support and rcni decision-making tools• unlimited free training opportunities and access to newcross world, our app-based learning platform, so you can grow your nursing career• enjoy immediate access to up to......

VIM & ECM (Opentext)
Equacao IT

We are looking for a vim & ecm (opentext) with the following requirements: requisitos do trabalho • job description:opentext tester – responsible for test preparation and test execution activities;senior;additional responsibilities & characteristicsdesign, develop, and maintain test cases test data preparation......

RTR - CO
Equacao IT

•additional responsibilities & characteristics:design, develop, and maintain test cases test data preparation, security roles mappingexecute test cases, update test execution result and status, capture test execution evidencelog and maintain defects• skillset & experience requiredfunctional knowledge......

French (Canadian) Audio Data Collector - Remote
Likha Careers

Access to a laptop for recording... flexible, remote participation... requisitos do trabalho native-level proficiency in french (canadian)... position type: independent contractor project type: one-time project industry: artificial intelligence (ai) about the opportunity: are you a native-level french......