We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results

Senior Information Security Risk and Compliance Specialist

PPG Industries, Inc
United States, Pennsylvania, Pittsburgh
One PPG Place (Show on map)
Apr 28, 2026

PPG is looking for a Senior Information Security Risk and Compliance Specialist to join the team! In this role, you will support the identification, evaluation, treatment, and reporting of information security risks in alignment with business objectives, regulatory requirements, and industry frameworks such as NIST Cybersecurity Framework (CSF), NIST 800-53, ISO 27001, and internal security standards. You will also assist in areas such as governance, control assurance, policy compliance, third-party risk assessments, and remediation tracking. This is a hybrid role at our Pittsburgh, PA office.

Key Responsibilities

  • Participate in global IT risk management, cybersecurity compliance, and governance projects from planning through execution, reporting, and remediation tracking.
  • Perform information security risk assessments for applications, infrastructure, cloud solutions, and business initiatives.
  • Support control testing and compliance assessments against frameworks such as NIST CSF, NIST 800-53, ISO 27001, and internal policies.
  • Assist with third-party / vendor cybersecurity risk assessments during onboarding and periodic reviews.
  • Evaluate vendors based on security questionnaires, penetration testing results, and contractual security requirements.
  • Collaborate with business and IT teams to mitigate identified risks through practical and achievable action plans.
  • Review work papers, planning documents, audit reports, and technical evidence to ensure accurate identification of risks and issues.
  • Communicate findings timely and partner with control owners to develop remediation plans.
  • Assist with security governance committees, metrics reporting, and risk dashboards.
  • Develop and document risks for critical systems, crown jewel assets, cloud environments, and key business processes.
  • Review IT processes for control weaknesses and non-compliance issues and initiate corrective actions.
  • Provide support for Disaster Recovery, Business Continuity, and operational resilience planning.
  • Assist in tabletop exercises, incident response governance, and lessons learned remediation tracking.
  • Assist with identity and access governance reviews including privileged access, segregation of duties, and user recertifications.
  • Develop methods to monitor and measure risk, compliance, and assurance efforts using metrics and KPIs.
  • Interpret and apply applicable laws, regulations, and industry requirements into security controls and policy requirements.
  • Perform Security Site Assessments at manufacturing plants, warehouses, laboratories, and office locations to evaluate physical security, cybersecurity controls, network infrastructure, operational technology (OT) environments, and compliance with corporate security standards.

Qualifications

  • 5+ years of experience in IT, cybersecurity, audit, risk management, or related discipline.
  • Bachelor's degree in information technology, Cybersecurity, Computer Science, Business, or related field preferred.
  • Working knowledge of security frameworks such as NIST CSF, NIST 800-53, ISO 27001, and SOC frameworks.
  • Experience supporting regulatory compliance programs such as SOX, PCI DSS, GDPR, or similar is a plus.
  • Experience performing Third-Party Risk Assessments / Vendor Security Reviews is strongly preferred.
  • Understanding of common security domains including IAM, network security, endpoint security, vulnerability management, logging/monitoring, and incident response.
  • Familiarity with cloud security concepts for Azure, AWS, or Google Cloud is a plus.
  • Experience using governance, risk, and compliance (GRC) tools such as AuditBoard, Archer, ServiceNow, OneTrust, or similar is preferred.
  • Relevant certifications such as Security+, CISA, CRISC, CISSP, ISO 27001 Lead Implementer/Auditor are a plus.

About us:

PPG: WE PROTECT AND BEAUTIFY THE WORLD

Through leadership in innovation, sustainability and color, PPG helps customers in industrial, transportation, consumer products, and construction markets and aftermarkets to enhance more surfaces in more ways thandoes any other company. To learn more, visit www.ppg.com and follow @PPG onX.

The PPG Way 2030

We are customer champions

Proactive. Bold. Trustworthy. Everything we do starts with our customers. We listen, movefastanddon'tstop until we solve their biggest challenges. When our customers win, we all grow.

We act with purpose and speed

Agile. Data-driven. Empowered. We take smart risks to stay ahead of the competition. We work proactively with agility, using quality data to develop solutions that create value.

We are excellentoperators

Productive. Collaborative. Accountable. No matter our role, weidentifyproblems, takeownershipand always bring solutions. We are both proactive and responsive to drive continuous improvement and deliver results. We support ourfrontline,the faces of PPG to our customers.

We compete to win

Future-focused. Driven. Ambitious. We are passionate about growing our business and winning with our customers. We deliver results, embrace newtechnologiesand leverage agility and speed as strengths.

We are PPG proud

Strong. United. Passionate. We work safely, act withintegrityand value our diverse perspectives. We celebrate achievements and take pride in the positive impact we create together to protect and beautify the world.

At PPG we use AI in the hiring process to make the process more efficient. AI tools do not make hiring decisions. You can learn more by going tohttps://careers.ppg.com/us/en/candidate-resources.

PPGprovidesequal opportunity to all candidates and employees. We offer an opportunity to grow and develop your career in an environment that provides a fulfilling workplace for employees, creates an environment for continuous learning, and embraces the ideas and diversity of others. All qualified applicants will receive consideration for employment without regard to sex, pregnancy, race, color, creed, religion, national origin, age, disability status, marital status, veteran status, sexual orientation, genderidentityor expression.

If you need an adjustment due to a disability, please emailrecruiting@ppg.com.

PPG pay ranges and benefits can vary bylocationwhich allows us to compensate employees competitively in different geographic markets. PPG considers several factors in making compensation decisions including, but not limited to, skill sets, experience and training, qualifications and education, licensure and certifications, and other organizational needs. Other incentives may apply.
Our employee benefits programs are designed to support the health and well-being of our employees. Any insurancecoveragesand benefits will bein accordance withthe terms and conditions of the applicable plans and associated governing plan documents.Benefits will be discussed with you by your recruiter during the hiring process.

PPG values your feedback on our recruiting process. We encourage you to visit Glassdoor.com and provide feedback on the process,so that we can do better today than yesterday.

Applied = 0

(web-bd9584865-g58x8)