Senior Cybersecurity Risk Analyst
- Markham, ON
- Hybride
- Publié 19 sept. 2026
- 1 poste
77 $–100 $ / heure
Ouvre un site externe
- Type d’emploi
- Contrat
- Niveau d’expérience
- Chef d’équipe · 10+ ans
- Formation minimale
- Baccalauréat
- Langue de l’offre
- anglais
- Heures de travail
- 38 heures par semaine
- Présence au bureau
- 3 jours par semaine
Résumé du poste
The Senior Cybersecurity Risk Analyst will conduct and oversee Information Security Risk Assessments and Third-Party Information Security Assessments. They will also manage cybersecurity risks, provide consulting services to business teams, and develop remediation plans to strengthen organizational security.
Détails du poste
Senior Cybersecurity Risk Analyst Bring your cybersecurity expertise to an environment where collaboration, innovation, and continuous improvement drive success. Play a key role in security assessments, risk oversight, and strategic initiatives that help strengthen organizational security and resilience. What is in it for you: • Salaried: $77-87.90 per hour. • Incorporated Business Rate: $90-100.40 per hour. • 12-month contract with the potential for permanent employment. • Day schedule, 37.50 hours per week. • Hybrid model: 3 days per week on-site, subject to change. Responsibilities: • Review and, when required, conduct Information Security Risk Assessments (ISRAs) and Third-Party Information Security Assessments (TPISAs). • Manage and mitigate cybersecurity risks and provide cybersecurity consulting services to technology and business teams. • Provide oversight on assessments, risk identification, risk management processes, and risk reporting tools. • Continuously improve the quality of cybersecurity risk management services. • Identify gaps in existing processes and technologies and develop remediation plans to address risks. • Support the development and enhancement of cybersecurity risk reporting and Key Risk Indicators (KRIs). • Ensure identified cybersecurity risks are effectively communicated and managed according to risk-prioritized timelines. • Provide senior management and executives with information on security trends, identified risks, and the effectiveness of security activities. • Increase visibility of cybersecurity risks when action plan target dates are not met. • Manage penetration testing and business impact assessment programs. • Prepare for Internal Risks and Control Assessments. • Collaborate with security and IT teams to implement security solutions that strengthen the overall security posture. • Contribute to improving team processes, efficiency, and quality standards. What you will need to succeed: Required qualifications • Post-secondary education in Computer Science, Computer Engineering, IT Security, Risk Management, or comparable professional training. • 10+ years of progressive experience in cybersecurity risk assessments, vendor assessments, and continuous risk management. • Experience conducting or reviewing Information Security Risk Assessments (ISRAs) and Third-Party Information Security Assessments (TPISAs). • Strong understanding of cybersecurity industry standards, principles, practices, and risk concepts. • Knowledge of cybersecurity controls and concepts. • Knowledge of Ariba, Archer, or other GRC management platforms. Preferred qualifications • Professional cybersecurity or IT risk certification such as CISSP, CISA, CISM, CCSP, CCSK, or GIAC. • Understanding of application security design and architecture. Soft skills • Resourceful. • Forward-thinking. • Collaborative. • Comfortable working in a fast-paced environment. • Strong communication skills. • Leadership skills. • Ability to communicate complex issues clearly and concisely to a wide range of audiences and stakeholders. • Ability to navigate ambiguity and guide teams through change. • Ability to understand complex processes and make sound judgment calls. • Ability to negotiate and influence others to achieve optimal results. Why Recruit Action? Recruit Action (agency permit: AP-2504511) provides recruitment services through quality support and a personalized approach. As part of the screening process, some applications may be reviewed using artificial intelligence tools. Only candidates who meet the hiring criteria will be contacted.
Ce que vous ferez
The Senior Cybersecurity Risk Analyst will conduct and oversee Information Security Risk Assessments and Third-Party Information Security Assessments. They will also manage cybersecurity risks, provide consulting services to business teams, and develop remediation plans to strengthen organizational security.
Exigences
Candidates must have 10+ years of progressive experience in cybersecurity risk management and relevant post-secondary education. Proficiency in industry standards, GRC platforms, and strong communication skills are essential for this role.
Avantages
• Hybrid work model • Potential for permanent employment
Compétences indiquées
- Risk Management · Souhaitée
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- Cybersecurity risk assessment
- Information security
- Risk management
- Vendor assessments
- ISRA
- TPISA
- Cybersecurity controls
- GRC platforms
- Ariba
- Archer
- Penetration testing
- Business impact assessment
- Risk reporting
- Key risk indicators
- Remediation planning
- Security consulting
- Hybrid Model
- Certified Information System Auditor (CISA)
- Team Processes
- Influencing Skills
- Resourcefulness
- Industry Standards
- Certified Cloud Security Professional (CCSP)
- Influencing Without Authority
- Security Solutions
- IT Security
- Cyber Security Assessment
- Cybersecurity Risk Management
- Resilience
- Cyber Risk
- Security Risk
- Artificial Intelligence
- Penetration Testing
- Application Security
- Business Continuity Planning
- Management
- Certificate Of Cloud Security Knowledge
- Certified Information Systems Security Professional
- Certified Information Security Manager
- Communication
- Computer Science
- Computer Engineering
- Consulting
- Continuous Improvement Process
- Cyber Security
- GIAC Certifications
- Governance Risk Management And Compliance
- Leadership
- Higher Education
- Innovation
Domaines d’emploi
- Technology
- Security & Safety
- Consulting
- Management & Leadership
- Cybersecurity Risk Analyst
- Cyber Security Consultant
- Database and Network Professionals Not Elsewhere Classified
- Security Management Specialists
- Business Operations Specialists, All Other
D’autres postes auxquels postuler directement
Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.
Desjardins
Analyste d'affaires système(BSA) Guidewire
Employeur directCandidature simplifiée- Hybride
- Lévis, QC
- Publié 21 sept. 2026
Desjardins
Administrateur ou administratrice de plateforme TI - Senior
Employeur directCandidature simplifiée- Hybride
- Montréal, QC
- Publié 17 sept. 2026
Connectability Inc.
Technical Sales Specialist
Employeur directCandidature simplifiée- Hybride
- Publié 5 sept. 2026