Retour à la recherche
Logo de US Tech Solutions
US Tech SolutionsSource d’offres vérifiée

Security Analyst – Intermediate # 26-21779

Offre en anglais
  • Toronto, ON
  • Sur place
  • Publié 28 août 2026
  • 1 poste

45 $–50 $ / heure

Ouvre un site externe

Connectez-vous pour enregistrer ce poste
Type d’emploi
Contrat
Niveau d’expérience
Expérimenté · 5+ ans
Formation minimale
Baccalauréat
Postuler avant le
27 sept. 2026
Langue de l’offre
anglais
Heures de travail
40 heures par semaine
Niveau d’expérience
Mid-Senior level
Mode de candidature
La candidature directe est offerte

Résumé du poste

The role focuses on developing and maintaining cybersecurity governance, risk, and compliance frameworks to ensure alignment with industry standards like ISO 27001 and NIST. Key duties include conducting third-party risk assessments, supporting security audits, and reporting security metrics to senior management.

Détails du poste

Duration: 06 Months Position Overview: We are seeking an experienced IT Security Governance Analyst to support the development and maintenance of cybersecurity governance, risk, compliance, audit, and reporting capabilities. The successful candidate will help ensure that projects and operations comply with applicable cybersecurity policies, regulatory requirements, and industry standards, including PCI DSS, NIST, ISO 27001, privacy requirements, and applicable government policies. The role will work closely with Cybersecurity, Risk & Compliance, Privacy, Procurement, Finance, IT Operations, and business stakeholders. Key Responsibilities IT Security Governance & Compliance Support the development, implementation, and maintenance of IT Security Governance frameworks, policies, standards, and controls. Ensure projects align with applicable IT security policies and requirements. Maintain compliance with ISO 27001, NIST, PCI DSS, privacy requirements, and other applicable cybersecurity standards. Provide cybersecurity governance guidance and subject matter expertise to business and technology teams. Support security awareness and governance training initiatives. Cybersecurity Risk Management Identify, assess, document, and monitor cybersecurity risks across business applications and technology environments. Work with Risk & Compliance and business stakeholders to understand risk appetite and develop appropriate risk treatment plans. Escalate and report risks that exceed accepted risk thresholds. Support the development and maintenance of cybersecurity risk registers and reporting. Third-Party Cyber Risk Management Support the design and implementation of a Third-Party Cyber Risk Management framework. Conduct security and cyber risk assessments of third parties and vendors. Identify appropriate security controls and requirements for third-party engagements. Review vendor security assessments, attestations, SOC reports, and other security documentation. Assess security control gaps and potential risks associated with third-party services. Provide cybersecurity input into contracts, SLAs, renewals, and termination of vendor relationships. Collaborate with Procurement, Vendor Management, Legal, and other stakeholders on third-party cybersecurity requirements. Security Audit & Assurance Support internal and external cybersecurity audits. Assist with PCI audits, ISO 27001 assessments, internal audits, and CSAE 3416/SOC-related activities. Coordinate audit evidence, documentation, findings, remediation activities, and reporting. Monitor remediation of identified security and compliance gaps. Security Metrics & Reporting Develop and maintain cybersecurity KPIs, KRIs, dashboards, and performance reports. Provide timely security governance and risk reports to senior management and other stakeholders. Track security compliance and control effectiveness. Support reporting on cybersecurity risks, audit findings, remediation, and governance performance. Asset & Information Risk Management Work with IT Operations and Risk & Compliance teams to maintain digital asset inventories. Support identification, classification, ownership, and risk assessment of technology assets and business applications. Ensure appropriate security, compliance, and risk requirements are associated with relevant assets. Stakeholder Management Build strong working relationships across business and technology teams. Communicate cybersecurity governance requirements clearly to end users and stakeholders. Provide security guidance and support to teams without direct supervisory responsibility. Collaborate with Privacy, Records Management, Finance, Procurement, Vendor Management, IT Operations, and Risk & Compliance teams. Requirements: 4-6 years of progressive experience in IT, cybersecurity, information security, risk, compliance, or a related discipline. 3-5 years of relevant cybersecurity / IT security experience, preferably within a Governance, Risk & Compliance environment. Hands-on experience with cybersecurity risk management and security governance. Experience with third-party/vendor cybersecurity risk assessments. Experience supporting cybersecurity audits, compliance assessments, and remediation activities. Experience developing security metrics, KPIs/KRIs, dashboards, and management reports. Strong understanding of security controls, policies, risk assessment methodologies, and compliance requirements. Experience working collaboratively with cross-functional business and technology teams. Technical / Functional Knowledge Strong knowledge or practical experience with: ISO 27001 NIST Cybersecurity Framework PCI DSS Privacy and data protection requirements IT Security Governance and GRC Cybersecurity Risk Management Third-Party / Vendor Risk Management Security Controls and Control Assessments Security Audits and Compliance Security KPIs / KRIs and Management Reporting IT Asset Inventory and Risk Classification Education Completion of a degree in Business, Engineering, Information Systems, Computer Science, Cybersecurity, or a related discipline. A combination of relevant education, training, and professional experience may be considered equivalent. Certifications The following certifications are considered an asset: CISSP - Certified Information Systems Security Professional CISM - Certified Information Security Manager CISA - Certified Information Systems Auditor CRISC - Certified in Risk and Information Systems Control CGEIT - Certified in the Governance of Enterprise IT Other relevant cybersecurity, risk, audit, or governance certifications. Agile certifications such as Agile Certified Professional (ACP) or Certified Scrum Product Owner (CSPO) are also considered an asset. Additional Assets Experience supporting IT project delivery or IT Operations. Experience within a regulated, public-sector, financial services, payments, or transportation environment. Experience working with enterprise cybersecurity governance frameworks. Experience working with senior management, audit, procurement, and external vendors. Key Competencies Cybersecurity Governance Risk Management Third-Party Risk Management Security Compliance Audit & Assurance Policy & Control Management Security Metrics & Reporting Stakeholder Management Analytical & Problem-Solving Skills Strong Written and Verbal Communication Ability to work independently and collaboratively About US Tech Solutions: US Tech Solutions is a global staff augmentation firm providing a wide range of talent on-demand and total workforce solutions. To know more about US Tech Solutions, please visit www.ustechsolutions.com. US Tech Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. AI Statement: By applying, you acknowledge that AI-assisted tools may be used during hiring.

Ce que vous ferez

The role focuses on developing and maintaining cybersecurity governance, risk, and compliance frameworks to ensure alignment with industry standards like ISO 27001 and NIST. Key duties include conducting third-party risk assessments, supporting security audits, and reporting security metrics to senior management.

Exigences

Candidates need 4-6 years of IT experience with 3-5 years specifically in cybersecurity GRC and risk management. A degree in a technical or business field is required, and certifications such as CISSP, CISM, or CISA are considered assets.

Compétences indiquées

  • Policy development · Souhaitée
  • Stakeholder Management · Souhaitée

Autres compétences pertinentes

Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.

  • IT Security Governance
  • Cybersecurity Risk Management
  • Third-Party Risk Management
  • Security Audit
  • Compliance Assessment
  • ISO 27001
  • NIST Cybersecurity Framework
  • PCI DSS
  • Security Metrics
  • KPI/KRI Development
  • Stakeholder Management
  • Asset Classification
  • Policy Development
  • Control Assessment
  • GRC
  • Privacy Requirements

Domaines d’emploi

  • Security & Safety
  • Technology
  • Consulting
  • Management & Leadership
  • Government & Public Sector

D’autres postes auxquels postuler directement

Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.

Voir tous les postes à candidature simplifiée