Retour à la recherche
BM
Blue Moon Metals Inc.Source d’offres vérifiée

Cybersecurity Analyst, Mining/Mineral Processing

Offre en anglais

The Cybersecurity Analyst will monitor and secure both corporate IT and industrial OT/ICS environments across mining operations. They will also implement security controls, conduct vulnerability assessments, and support incident response planning.

  • Hybride
  • Toronto, ON
  • Publié 21 août 2026
  • 1 poste

D’autres postes auxquels postuler directement

Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.

Résumé du poste

Cybersecurity Analyst, Mining/Mineral Processing Toronto, ON Hybrid: 2-3X per week in office. Position Summary Blue Moon Metals is seeking a Cybersecurity Analyst to join its growing IT & Cybersecurity function at the Toronto headquarters. This role is responsible for monitoring, assessing, and strengthening the security posture of both corporate IT systems and operational technology (OT) / industrial control system (ICS) environments across the company's offices, project sites, and mining operations. The successful candidate will work closely with the Lead, IT Infrastructure Engineer and cross-functional stakeholders to implement security controls aligned to NIST CSF 2.0 and IEC 62443, and to support the company's broader cybersecurity maturity program. Key Responsibilities Monitor security events and alerts across IT and OT environments, investigating and responding to potential incidents in a timely manner. Support day-to-day administration of security tooling, including endpoint detection and response (EDR), SIEM/log management, vulnerability scanning, email security, and identity protection platforms. Conduct vulnerability assessments and coordinate remediation activities across corporate IT and industrial control system (ICS/SCADA) assets, in partnership with OT and engineering teams. Assist in the design, implementation, and continuous improvement of security controls aligned to NIST CSF 2.0 and IEC 62443, including IT/OT network segmentation initiatives. Contribute to security policies, standards, and procedures, and help translate framework requirements into practical, site-appropriate controls for corporate, project, and remote/underground mining locations. Support identity and access management activities, including access reviews, provisioning/deprovisioning, and privileged access oversight. Participate in risk assessments, security audits, and third-party assessments (e.g., cybersecurity maturity assessments), helping track findings through to remediation. Assist with incident response planning and execution, including documentation, root-cause analysis, and post-incident reporting. Deliver security awareness content and training to employees and contractors across corporate and site locations. Maintain accurate documentation of security architecture, controls, and asset inventories for both IT and OT environments. Stay current on emerging threats, vulnerabilities, and regulatory requirements relevant to the mining and critical infrastructure sector. Qualifications 2-5 years of experience in a cybersecurity, IT security, or security operations role, ideally with some exposure to industrial/OT environments. Working knowledge of the NIST Cybersecurity Framework (CSF 2.0) and/or IEC 62443 for industrial automation and control systems security. Familiarity with common security tools such as SIEM, EDR/XDR, vulnerability scanners, and firewall/network monitoring platforms. Understanding of IT/OT network architecture, segmentation concepts, and the unique risk considerations of industrial control systems (SCADA, PLCs, HMIs). Solid understanding of core security domains: identity and access management, network security, endpoint security, and incident response. Post-secondary education in Computer Science, Information Security, Engineering, or a related field, or equivalent practical experience. Strong analytical and problem-solving skills, with the ability to communicate technical risk clearly to both technical and non-technical audiences. Ability to travel occasionally to project and mine sites as required. Preferred Qualifications Industry certifications such as Security+, GICSP, GRID, CISSP (or working toward), or similar. Prior experience in mining, energy, manufacturing, or another critical infrastructure sector. Exposure to regulatory or compliance frameworks relevant to publicly traded companies (e.g., SOX IT general controls). Experience supporting cybersecurity maturity assessments or working alongside external consultants/auditors. About Blue Moon Metals Blue Moon Metals Inc. is a publicly traded metals and mining company advancing a global portfolio of mineral development and operating projects. As the company grows its corporate, project, and remote site operations, the IT & Cybersecurity team is building the internal capability required to protect both enterprise IT and operational technology (OT) environments across the business. What Blue Moon Metals Offers The opportunity to help build a cybersecurity program from the ground up across a global mining organization. Exposure to both enterprise IT and industrial OT/ICS security in a hands-on, high-impact role. A collaborative team environment based at our Toronto headquarters. Competitive compensation and benefits package. Pay Range and Compensation Package Compensation and benefits details will be discussed during the interview process. Equal Opportunity Statement We are committed to diversity and inclusivity in our hiring practices and encourage applications from all qualified individuals. We thank all applicants for their interest; only those selected for an interview will be contacted.

Ce que vous ferez

The Cybersecurity Analyst will monitor and secure both corporate IT and industrial OT/ICS environments across mining operations. They will also implement security controls, conduct vulnerability assessments, and support incident response planning.

Exigences

Candidates must have 2-5 years of experience in cybersecurity or IT security, with knowledge of NIST CSF 2.0 or IEC 62443 frameworks. A post-secondary degree in a related field is required, along with strong analytical skills and the ability to travel to project sites.

Avantages

• Competitive compensation • Benefits package

Autres compétences pertinentes

Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.

  • Cybersecurity
  • NIST CSF 2.0
  • IEC 62443
  • OT Security
  • ICS/SCADA
  • SIEM
  • EDR
  • Vulnerability scanning
  • Identity and access management
  • Network segmentation
  • Incident response
  • Risk assessment
  • Security architecture
  • Endpoint security
  • Security awareness training
  • Security Tools
  • Email Security
  • Endpoint Detection And Response
  • Industrial Automation
  • IT Security
  • NIST Cybersecurity Framework (CSF)
  • Endpoint Security
  • IT Infrastructure
  • Planning
  • IT Security Architecture
  • GIAC Global Industrial Cyber Security Professional
  • Mineral Processing
  • Auditing
  • Certified Information Systems Security Professional
  • Communication
  • Computer Science
  • CompTIA Security+
  • Continuous Improvement Process
  • Control Systems
  • Security Controls
  • Cyber Security
  • Incident Response
  • Firewall
  • GIAC Certifications
  • Supervisory Control And Data Acquisition (SCADA)
  • Identity And Access Management
  • Incident Reporting
  • Security Engineering
  • Problem Solving
  • IT General Controls (ITGC)
  • Network Security
  • Log Management And Intelligence
  • Network Architecture
  • Network Monitoring
  • Vulnerability Scanning

Domaines d’emploi

  • Security & Safety
  • Technology
  • Energy
  • Manufacturing
  • Engineering
  • Cybersecurity Analyst
  • Security Operations Center Analyst
  • Database and Network Professionals Not Elsewhere Classified
  • Software Quality Assurance Analysts and Testers

Renseignements supplémentaires

Formation minimale
Baccalauréat
Expérience minimale
2+ ans
Langue de l’offre
anglais
Heures de travail
40 heures par semaine
Présence au bureau
3 jours par semaine