Cybersecurity Advisor; North America)
Listed on 2026-09-06
-
IT/Tech
Cybersecurity, IT Consultant, Information Security & Data Protection
Cybersecurity Advisor
At Alcoa, you will become an essential part of our purpose: to turn raw potential into real progress. The way we see it, every Alcoan is a work-shaper, team-shaper, idea-shaper & world-shaper.
We are seeking a Cybersecurity Advisor who can partner with business leaders, project teams, and technology stakeholders to identify cybersecurity risks, influence secure technology decisions, and ensure security is embedded into new initiatives from the start. This is a highly collaborative, advisory-focused role that combines cybersecurity architecture, risk management, governance, and stakeholder engagement across both Information Technology (IT) and Operational Technology (OT) environments.
About the Role:
As a trusted cybersecurity advisor, you will:
- Lead cybersecurity guidance for system implementations, upgrades, and digital transformation initiatives.
- Review and influence secure architecture across IT and OT environments (ICS/SCADA, IoT, industrial networks)
- Conduct threat modeling and security design reviews for business and industrial systems
- Enable and advance Alcoa initiatives in Cloud security, Zero Trust architecture, Identity Management and AI governance, ensuring appropriate controls, monitoring, and protection of sensitive data.
- Identify, assess, and prioritize cybersecurity risks across IT, mining/manufacturing operations
- Support risk mitigation plans and execution
- Perform risk assessments for projects, vendors, and operational technologies
- Support incident response planning and risk-based decision making
- Consult & advise on definition, implementation and revision of policies, standards, and procedures for IT/OT security
- Drive oversight of security controls implementation across projects in IT and OT
- Recommend security policy, standards and controls enhancements aligned with customer needs, NIST, CIS, ISO and other frameworks and best practices.
- Enable institutional cybersecurity risk management activities, including risk assessments, audits, mitigation planning and execution activities across Alcoa systems.
- Support post-incident reviews and continuous improvement efforts.
- Ensure adherence to relevant frameworks and regulations (e.g., ISO 27001, NIST, IEC 62443)
- Support internal and external audits
- Maintain compliance documentation and evidence
- Act as a trusted advisor to business and technical stakeholders
- Foster a collaborative, inclusive, and service-oriented team culture across all Alcoa teams
- Work closely with IT teams to ensure secure design, implementation, and operation of systems including cloud and application environments.
- Provide technical guidance on configurations, integrations and remediation.
- Support company-wide awareness programs and continuously improve security posture by addressing emerging threats, including cloud and AI-related risks.
What you can bring to this role:
- Bachelor's degree in Information Security, Computer Science, Information Systems, STEM, or related field (or degree with equivalent depth of experience in cybersecurity leadership).
- Significant experience in cybersecurity, Information Security, or related domains.
- Domain specific experience in 2 or more of the following:
Cloud, IAM/Zero Trust, Data/DLP, and AI - Demonstrated experience advising and consulting internal customers to achieve organizational objectives
- Strong knowledge of security frameworks and standards (e.g., NIST CSF, NIST SP 800-53, CIS Critical Security Controls).
- Experience with incident response, risk assessment, and security operations.
- Ability to communicate effectively with technical and non-technical stakeholders.
- Experience working in or supporting complex, decentralized business units.
- Demonstrated ability to successfully handle sensitive discussions, maintain confidentiality, strong personal ethics commitment, strong personal integrity, and demonstrated sound judgment.
- Ability to collaborate effectively with enterprise teams, plant operations, engineering, and other key stakeholders to advance global cybersecurity maturity.
- Strong interpersonal skills, with the ability to collaborate effectively with internal and external stakeholders, including customers, vendors, analysts, CIOs, and leaders across and beyond the IT organization.
- Ability to lead and motivate the information security team to achieve tactical and strategic goals.
- Excellent analytical skills, the ability to support multiple projects under strict timelines, as well as the ability to work well in a demanding, dynamic environment and meet overall objectives.
- Effective written and verbal communication skills in English; proficiency in additional languages is preferred.
- Strong knowledge of ITIL, COBIT, and compliance requirements.
- Bilingual English/French candidates are highly desired.
- CISSP, CISM, CRISC, or comparable cybersecurity certification.
- Experience in manufacturing, mining, industrial, or other highly regulated environments.
- Experience supporting cloud transformation, Zero Trust, or enterprise modernization…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).