Senior Analyst– Phishing Simulation Program
Work Location : Toronto, Ontario, Canada
Hours : 37.5
Line Of Business : Technology Solutions
Pay Details : $81,600 - $115,200 CAD
Job Description
Job Profile Summary : Reporting to the Senior Manager of Cyber Protection Readiness and Assessment (CPRA) within the Technology Operational Resilience organization to lead and develop the Phishing Simulation Program (PSP).
Preferred Qualifications :
- Direct experience in phishing simulation technologies, such as Microsoft Attack & Cofense.
- Experience in design, scheduling, and deployment of phishing simulations to financial institutions.
- Experience collaborating with awareness and technical teams to customize scenarios based on current threat trends and business context.
- Strong familiarity with Microsoft Excel reporting.
- Ability to develop dashboards and pivot tables.
- Ability to collaborate effectively with risk and compliance teams.
- Assist in preparing executive‑ready reports and presentations on phishing simulation performance.
- Proficiency with Power BI, Excel, VBA, HTML.
- Experience in vishing and smishing simulation technologies.
- 4+ years of relevant experience in cyber security.
- 4+ years of relevant experience in information technology.
- Experience working in large financial institutions.
- University degree.
- Information security certification / accreditation an asset.
Key Accountabilities :
Stay updated on trends in phishing, social engineering tactics, and simulation best practices.Provide input to enhance simulation effectiveness, tooling, and reporting frameworks.Strong attention to detail, analytical thinking, and communication skills.Identify, document, pursue and implement process improvements and enhancements as well as automation opportunities.Maintain appropriate, up‑to‑date documentation (playbooks, runbooks, etc.) and required reporting (metrics).Identify key relationships to build, establish them, and constantly manage and build upon them to the benefit of the team and function.Customer :
Adhere to internal policies / procedures, technology control standards, and applicable regulatory guidelines.Contribute to the review of internal processes and activities and assist in identifying potential opportunities for improvement.Adhere to and advise on / oversee / monitor / enforce enterprise frameworks and methodologies that relate to technology controls / information security activities.Influence behavior to reduce risk and foster a strong technology risk management culture throughout the enterprise.Remain informed of emerging issues, industry trends and / or relevant changes.Actively manage relationships with other areas of Technology / businesses / corporate and / or control functions and ensure alignment with requirements.Assess / identify key issues and escalate to appropriate levels and relevant stakeholders where required.Maintain a culture of risk management and control, supported by effective processes and sound infrastructure in alignment with risk appetite.Participate in business specific / cross‑functional / enterprise initiatives as a subject matter expert.May develop / provide / contribute to complex reporting, analysis, and assessments at the functional or enterprise level.Employee :
Continuously enhance knowledge / expertise in own area.Keep current on emerging trends / developments and grow knowledge of the business, analytical tools, and techniques.Prioritize and manage own workload to deliver quality results and meet assigned timelines.Keep manager and teammates well apprised at all times of your progress, plans and challenges.Support and directly contribute to a positive, supportive and inclusive work environment that promotes service to the business, quality, innovation, and teamwork and ensure timely communication of issues / points of interest.Identify and recommend opportunities to enhance productivity, effectiveness, and operational efficiency.Must establish effective relationships across multiple business and technology partners, program, and project managers.Participate in knowledge transfer within the team and business units.Breadth & Depth :
Expert knowledge of IT security and risk disciplines and practices.Advanced knowledge of organization, technology controls / security / risk issues.May participate on complex, comprehensive, or large projects and initiatives.Seniority level : Mid‑Senior level
Employment type : Full‑time
Job function : Business Development and Sales
Industries : Investment Banking
#J-18808-Ljbffr