Talent.com
Source Code
RQ00226 - Security Analyst - IntermediateSource Code • Toronto, ON, Canada
RQ00226 - Security Analyst - Intermediate

RQ00226 - Security Analyst - Intermediate

Source Code • Toronto, ON, Canada
Il y a 3 jours
Salaire
48,66 $CA par heure
Type de contrat
  • Temps plein
  • Quick Apply
Description de poste

RQ00226 - Security Analyst - Intermediate

Duration: 6 Months (131 Business Days)

Location: Hybrid, 3 days in office, 2 days remote at 20 Bay St

Must Haves:

  • Minimum 4-6 years of experience in progressively advancing roles within IT or a related function, with a focus on IT Security/Cybersecurity. Strong track record of competency in risk management and cybersecurity management in IT, with 3 to 5 years of relevant experience. Certifications or Designations
  • Professional security management certification is an asset, such as, Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Governance of Enterprise IT (CGEIT), Certified Risk and Information Systems Controls (CRISC), Certified Information Systems Auditor (CISA) or other similar credentials an asset
  • Perform vendor risk assessments and enhanced the Third-Party Risk Management (TPRM) program by Gathering and preparing data for reporting security service performance metrics that includes status of information systems, services obtained from external providers, and actions for improvement and Providing input into security pen testing activities conducted by a third-party security services provider 4-6 years experience

Description

Responsibilities Perform real time monitoring and analysis of events with a focus on identifying potential security incidents. Respond and investigate potential alerts and tickets. Collect and analyze evidence including network traffic, volatile data, logs and other indicators. General Skills Experience in IT Security, operational security monitoring, incident response. Understanding of TCP/IP stack, *nix/Windows systems Knowledge of network infrastructure and internet applications Understanding of different cyber-attacks Knowledge of security threats and attack types Analysis of cyber threats and experience in providing action plans Ability to investigate, evaluate and recommend Cyber Security products and intrusion detection technology to minimize vulnerabilities.

ACCOUNTABILITY STATEMENT

The Governance Analyst will be responsible for supporting the development and maintenance of Payments (PRESTO) ITSEC governance, compliance, audit, and reporting capabilities. The Governance Analyst will contribute to ensuring that:

Payments (PRESTO) projects adhere to ITSEC policies.

Payments (PRESTO) complies with relevant policies, including those from the Government of Ontario, PCI, NIST, and other applicable cybersecurity standards (ISO 27001).

All security audit requirements are fulfilled. Appropriate cyber risk reporting is provided to internal and external stakeholders.

KEY CONTRIBUTIONS Functional/Technical

  • Design ITSEC performance KPIs and report on them to appropriate stakeholders as a means of measuring and evaluating cybersecurity effectiveness.
  • Foster relationships across the organization to promote awareness of compliance and ITSEC principles.
  • Contribute to development and implementation of Payments (PRESTO) Third-party Cyber Risk Management framework, participating in its design and execution to align with ITSEC governance objectives and industry best practices
  • Provide timely updates and reports to internal and external stakeholders, including Senior Management Team (SMT), Audit, Finance, and others as necessary.
  • Collaborate with Risk & Compliance, Privacy, Records Management, and Finance departments to understand the risk appetite for key business applications and coordinate appropriate treatment of identified cyber risks that exceed accepted risk levels.
  • Work with IT Operations and Risk & Compliance teams to develop and maintain digital assets inventory management systems, ensuring proper identification, classification, ownership, and associated risks and compliance requirements.
  • Manage governance activities to maintain full compliance with ISO 27001, Privacy (FIPPA), and NIST standards. IT Security Governance Analyst - 1733 Effective Date - May 12, 2023
  • Support security audit activities, including PCI audits, internal audits, and external audits such as CSAE 3416.

Customer/Stakeholder

Communicates with the organization's end users regarding appropriate Governance activities and issues as necessary

Works closely with business units to manage and execute contractual and legal governance requirements dealing with Payments cyber security requirements

Assists the extended teams (VMO, Procurement etc.) with the alignment of the design and operationalization of Metrolinx Cybersecurity risk management practices as they apply to third party contracts including:

  • Assessment of third party and contract risks prior to execution o Determines relevant security controls that should be embedded with security controls that are applicable to third parties
  • Designs and review of service level agreements and management reporting templates for third parties
  • Ensures the appropriate involvement of internal/external stakeholders during the design of the proposed third-party solution contract
  • Implementation of internal control measures to corroborate security reports from third parties
  • Reviews of vendor security control attestation reports and assesses the implications of gaps/breaches as they occur.
  • Provides input into the renewal/termination of contractual arrangements for outsourced services as contract periods lapse.

Operational Excellence

  • Identifies the effectiveness and completeness of business and technologies strategies applicable to ITSEC Governance and ensures alignment with I&IT, Payments (PRESTO) and other applicable cross organization strategies
  • Assist in developing ITSEC governance awareness-training program for resources as necessary and applicable (employees, contractors and/or approved system users)
  • Provides subject matter expertise regarding industry standards, regulations and best practices relevant to the ITSEC Governance

People Leadership

Provides security guidance and assists others in the performance of their day-to-day activities without direct supervisory responsibility

Education

  • Completion of a degree in Business, Engineering, Information Systems, Computer Science or a related discipline – or a combination of education, training and experience deemed equivalent. Experience
  • Minimum 4-6 years of experience in progressively advancing roles within IT or a related function, with a focus on IT Security/Cybersecurity. Strong track record of competency in risk management and cybersecurity management in IT, with 3 to 5 years of relevant experience. Certifications or Designations
  • Professional security management certification is an asset, such as, Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Governance of Enterprise IT (CGEIT), Certified Risk and Information Systems Controls (CRISC), Certified Information Systems Auditor (CISA) or other similar credentials an asset
  • Agile certification (Agile Certified Professional, Certified Scrum Product Owner) an asset
  • Experience in IT Project Delivery or Operations an asset

AI Disclaimer: Source Code may use artificial intelligence (AI) tools to assist in certain aspects of its recruiting and business operations.

Note: The higher end of the range is intended for absolutely exceptional candidates who meet all must-have requirements and most or all nice-to-have qualifications. The client will evaluate candidates based on both rate expectations and overall skill set when shortlisting.

INCORPORATED RATE RANGE (7.25 billable hours per day)

  • $48.66/hr - $52.14/hr Inc.

T4 RATE RANGE (7.25 billable hours per day)

  • $38.93/hr - $41.71/hr T4
Créer une alerte emploi pour cette recherche

RQ00226 - Security Analyst - Intermediate • Toronto, ON, Canada

Offres similaires

Security Analyst - Security & Governance Compliance

Staples CanadaRichmond Hill, York Region, CA
Temps plein

Some of what you will do: The Security Analyst, Security Risk & Compliance will support the management and continuous improvement of Staples Canada’s PCI compliance program and broader cybersecurit... Voir plus

 • Offre sponsorisée

Senior Security Analyst: Incident Response & Threat Defense

MindlanceToronto, ON, CA
Temps plein

A global cybersecurity firm is seeking a Senior Security Analyst to join their team in Toronto.This role involves providing technical security consulting, ensuring timely incident resolution, and c... Voir plus

 • Offre sponsorisée

Information Security Analyst in Downtown Toronto

DelpathToronto, ON, CA
Temps plein

Become a key player in cybersecurity as an Information Security Analyst, working hybrid in downtown Toronto.Focus on data loss prevention and optimize security measures across the organization.This... Voir plus

 • Offre sponsorisée

Security Analyst, Lawful Acces

Rogers CommunicationsToronto, ON, CA
Temps plein

We are committed to connecting Canadians through unique partnerships, our world-class network and content Canadians love—and our innovative team is growing.We are looking for dedicated team members... Voir plus

 • Offre sponsorisée

Application Security Software Engineer

PointClickCareToronto, Ontario, Canada
Temps plein

This range is provided by PointClickCare.Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.PointClickCare is a leading North American healthcare t... Voir plus

 • Offre sponsorisée

Security Systems Application Specialist

AinsworthToronto, ON, CA
Temps plein

Reporting to the Project Manager, you will have the opportunity to execute and lead various security system projects.Your role will encompass estimation, engineering design, programming, commission... Voir plus

 • Offre sponsorisée

Senior Application Security Engineer

CognizantToronto, ON, CA
Temps plein

Job Title - App Security Specialist.DevOps, with at least 2 - 3 years hands-on security exposure (secure coding, pipeline security, API security, threat modeling).Seniority level: Mid-Senior level.... Voir plus

 • Offre sponsorisée

Akamai API Security or NoName API Security Analyst

Net2Source Inc.Toronto, ON, CA
Temps plein

Akamai API Security or NoName API Security Analyst.This position is offered by Net2Source Inc.Your actual pay will depend on your skills and experience — please consult with your recruiter for more... Voir plus

 • Offre sponsorisée

Intermediate Security Engineer - $51.6 - $76.6 An Hour

NewFound RecruitingEast York, Canada
Temps plein

The Security Engineer will design, implement, and integrate security solutions for military systems, focusing on network, communication, and endpoint security. Voir plus

 • Offre sponsorisée

Information Security Analyst

BDO CanadaToronto, ON, CA
Temps plein

BDO is a firm built on a foundation of positive relationships with our people and clients.Reporting to the Manager, Information Security, the Information Security Analyst supports security operatio... Voir plus

 • Offre sponsorisée

RQ08437 - Security Specialist - Penetration Testing - Senior

Rubicon PathToronto, ON, CA
Temps plein

RQ08437 - Security Specialist - Penetration Testing - Senior.Conducts penetration tests, web application vulnerability assessments, code reviews and network vulnerability assessments of all environ... Voir plus

 • Offre sponsorisée

Security Analyst - Part Time

Equifax, Inc.Toronto, ON, CA
Temps partiel

As our IT Security Analyst, this role requires a motivated self-starter.Someone who has strong analytical and problem-solving skills, a deep understanding of risk and compliance management principl... Voir plus

 • Offre sponsorisée

RQ00689 - Int. Security Specialist

Source CodeToronto, Ontario, Canada
Temps plein

Develops and implements cyber security strategy program and architecture.Experience with Control Testing and Assurance.Audit against NIST, CIS and ISO.Experience with implementing Risk Management F... Voir plus

 • Offre sponsorisée

Penetration Testing & Application Security Consultant

Rsm Us Llp.Toronto, ON, CA
Temps plein

A leading professional services firm in Toronto is seeking a Security Analyst with expertise in web security.The role involves performing security assessments, conducting penetration testing, and c... Voir plus

 • Offre sponsorisée

Senior Application Security Engineer

PaymentusRichmond Hill, York Region, CA
Temps plein

Senior Application Security Engineer.Paymentus SaaS platform by partnering directly with software engineering, product, cloud infrastructure, DevOps, and security teams to identify, assess, and rem... Voir plus

 • Offre sponsorisée

Senior Application Security Specialist

AIR MILES Reward ProgramToronto, Ontario, Canada
Temps plein

The AIR MILES Reward Program is one of Canada’s most recognized loyalty programs, with over 10 million active collector accounts, representing more than half of all Canadian households.AIR MILES co... Voir plus

 • Offre sponsorisée

Senior Security Engineer Focused on Infrastructure and Incident Management

RootlyToronto, Ontario, Canada
Temps plein

Take on the role of a Senior Security Engineer specializing in incident management and infrastructure security.Your skills will shape our critical security initiatives as customer demand grows.You ... Voir plus

 • Offre sponsorisée

Security Analyst - Security & Governance Compliance

TVET CollegeRichmond Hill, York Region, CA
Temps plein

Security Analyst - Security & Governance Compliance.The Security Analyst, Security Risk & Compliance will support the management and continuous improvement of Staples Canada’s PCI compliance progra... Voir plus

 • Offre sponsorisée

Workday Security Analyst

neteffectsToronto, ON, CA
Temps plein

Remote from the UK - to work for an International US-based company.Workday security area – focusing on Workday HR user, domain, business process, and integrations security, privacy, audit, controls... Voir plus

 • Offre sponsorisée

Hybrid Security Operations Analyst: Cloud & Threat Detection

IFSToronto, ON, CA
Temps plein

A leading tech company in Toronto is seeking a Security Operations Analyst to enhance security in a hybrid environment combining on-premise and cloud systems.The candidate will manage incident resp... Voir plus