Talent.com
Cleo Consulting
Security Analyst - IntermediateCleo Consulting • Toronto, ON, Canada
Security Analyst - Intermediate

Security Analyst - Intermediate

Cleo Consulting • Toronto, ON, Canada
22 hours ago
Job type
  • Full-time
  • Quick Apply
Job description

Assignment: RQ00226 - Security Analyst - Intermediate

Requisition: RQ00226

Job Title: Security Analyst - Intermediate

Client: Presto

Start Date: 2026-10-01

End Date: 2027-04-01

Department: Platforms and Technology

Office Location: 20 Bay St, Toronto

Business Days: 131.00

Location: hybrid, 3 days in office, 2 days remote

Public Sector Experience: nice to have

Must Haves:

  • Minimum 4-6 years of experience in progressively advancing roles within IT or a related function, with a focus on IT Security/Cybersecurity. Strong track record of competency in risk management and cybersecurity management in IT, with 3 to 5 years of relevant experience. Certifications or Designations
  • Professional security management certification is an asset, such as, Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Governance of Enterprise IT (CGEIT), Certified Risk and Information Systems Controls (CRISC), Certified Information Systems Auditor (CISA) or other similar credentials an asset
  • Perform vendor risk assessments and enhanced the Third-Party Risk Management (TPRM) program by Gathering and preparing data for reporting security service performance metrics that includes status of information systems, services obtained from external providers, and actions for improvement and Providing input into security pen testing activities conducted by a third-party security services provider 4-6 years experience

Description

Responsibilities

  • Perform real time monitoring and analysis of events with a focus on identifying potential security incidents. Respond and investigate potential alerts and tickets. Collect and analyze evidence including network traffic, volatile data, logs and other indicators. General Skills Experience in IT Security, operational security monitoring, incident response. Understanding of TCP/IP stack, *nix/Windows systems Knowledge of network infrastructure and internet applications Understanding of different cyber-attacks Knowledge of security threats and attack types Analysis of cyber threats and experience in providing action plans Ability to investigate, evaluate and recommend Cyber Security products and intrusion detection technology to minimize vulnerabilities.

ACCOUNTABILITY STATEMENT

  • The Governance Analyst will be responsible for supporting the development and maintenance of Payments (PRESTO) ITSEC governance, compliance, audit, and reporting capabilities. The Governance Analyst will contribute to ensuring that:
  • Payments (PRESTO) projects adhere to ITSEC policies.
  • Payments (PRESTO) complies with relevant policies, including those from the Government of Ontario, PCI, NIST, and other applicable cybersecurity standards (ISO 27001).
  • All security audit requirements are fulfilled. Appropriate cyber risk reporting is provided to internal and external stakeholders.

KEY CONTRIBUTIONS

  • Functional/Technical
    • Design ITSEC performance KPIs and report on them to appropriate stakeholders as a means of measuring and evaluating cybersecurity effectiveness.
    • Foster relationships across the organization to promote awareness of compliance and ITSEC principles.
    • Contribute to development and implementation of Payments (PRESTO) Third-party Cyber Risk Management framework, participating in its design and execution to align with ITSEC governance objectives and industry best practices
    • Provide timely updates and reports to internal and external stakeholders, including Senior Management Team (SMT), Audit, Finance, and others as necessary.
    • Collaborate with Risk & Compliance, Privacy, Records Management, and Finance departments to understand the risk appetite for key business applications and coordinate appropriate treatment of identified cyber risks that exceed accepted risk levels.
    • Work with IT Operations and Risk & Compliance teams to develop and maintain digital assets inventory management systems, ensuring proper identification, classification, ownership, and associated risks and compliance requirements.
    • Manage governance activities to maintain full compliance with ISO 27001, Privacy (FIPPA), and NIST standards. IT Security Governance Analyst - 1733 Effective Date - May 12, 2023
    • Support security audit activities, including PCI audits, internal audits, and external audits such as CSAE 3416.
  • Customer/Stakeholder
    • Communicates with the organization's end users regarding appropriate Governance activities and issues as necessary
    • Works closely with business units to manage and execute contractual and legal governance requirements dealing with Payments cyber security requirements
    • Assists the extended teams (VMO, Procurement etc.) with the alignment of the design and operationalization of Metrolinx Cybersecurity risk management practices as they apply to third party contracts including:
    • Assessment of third party and contract risks prior to execution o Determines relevant security controls that should be embedded with security controls that are applicable to third parties
    • Designs and review of service level agreements and management reporting templates for third parties
    • Ensures the appropriate involvement of internal/external stakeholders during the design of the proposed third-party solution contract
    • Implementation of internal control measures to corroborate security reports from third parties
    • Reviews of vendor security control attestation reports and assesses the implications of gaps/breaches as they occur.
    • Provides input into the renewal/termination of contractual arrangements for outsourced services as contract periods lapse.
  • Operational Excellence
    • Identifies the effectiveness and completeness of business and technologies strategies applicable to ITSEC Governance and ensures alignment with I&IT, Payments (PRESTO) and other applicable cross organization strategies
    • Assist in developing ITSEC governance awareness-training program for resources as necessary and applicable (employees, contractors and/or approved system users)
    • Provides subject matter expertise regarding industry standards, regulations and best practices relevant to the ITSEC Governance
  • People Leadership
    • Provides security guidance and assists others in the performance of their day-to-day activities without direct supervisory responsibility

Education

  • Completion of a degree in Business, Engineering, Information Systems, Computer Science or a related discipline or a combination of education, training and experience deemed equivalent. Experience
  • Minimum 4-6 years of experience in progressively advancing roles within IT or a related function, with a focus on IT Security/Cybersecurity. Strong track record of competency in risk management and cybersecurity management in IT, with 3 to 5 years of relevant experience. Certifications or Designations
  • Professional security management certification is an asset, such as, Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Governance of Enterprise IT (CGEIT), Certified Risk and Information Systems Controls (CRISC), Certified Information Systems Auditor (CISA) or other similar credentials an asset
  • Agile certification (Agile Certified Professional, Certified Scrum Product Owner) an asset
  • Experience in IT Project Delivery or Operations an asset
Create a job alert for this search

Security Analyst - Intermediate • Toronto, ON, Canada

Similar jobs

Experienced Info Security Analyst Position

Haventree Banktoronto, on, Canada
Full-time

Elevate your career as a Senior Information Security Analyst at Haventree Bank, where your skills will directly enhance our security practices.This role combines technical execution with strategic ... Show more

 • Promoted

Security Analyst - Security & Governance Compliance

Staples CanadaRichmond Hill, York Region, CA
Full-time

Some of what you will do: The Security Analyst, Security Risk & Compliance will support the management and continuous improvement of Staples Canada’s PCI compliance program and broader cybersecurit... Show more

 • Promoted

Senior Security Analyst: Incident Response & Threat Defense

MindlanceToronto, ON, CA
Full-time

A global cybersecurity firm is seeking a Senior Security Analyst to join their team in Toronto.This role involves providing technical security consulting, ensuring timely incident resolution, and c... Show more

 • Promoted

Security Analyst - Part Time

Equifax, Inc.Toronto
Part-time

As our IT Security Analyst, this role requires a motivated self-starter.Someone who has strong analytical and problem-solving skills, a deep understanding of risk and compliance management principl... Show more

 • Promoted

Security Program Manager Stouffville ON

Cprvisionwhitchurch stouffville, on, Canada
Full-time

Drive security excellence as a Security Program Manager at Portfolio+ Inc.Stouffville, ON, focusing on enterprise risk and compliance frameworks.This specialized role involves leading the enterpris... Show more

 • Promoted

IT Security Analyst

ERCO WorldwideToronto, ON, CA
Permanent

Satellite Drive, Mississauga (Hybrid).ERCO Worldwide’s century‑long tradition of excellence has firmly established its reputation for providing reliable, intelligent, and environmentally responsibl... Show more

 • Promoted

Security Analyst, Lawful Acces

Rogers CommunicationsToronto, ON, CA
Full-time

We are committed to connecting Canadians through unique partnerships, our world-class network and content Canadians love—and our innovative team is growing.We are looking for dedicated team members... Show more

 • Promoted

Security Analyst

York UniversityToronto, ON, CA
Permanent

The Security Analyst contributes to the mission of the University by supporting the delivery of information security program.This includes security investigations, assessments, monitoring and incid... Show more

 • Promoted

Cyber Security Analyst

Lorex TechnologyMarkham, ON, CA
Full-time

For 34 years, Lorex has been creating security systems designed to protect your home and business.Founded and headquartered in Canada, we’ve grown to become leaders in DIY (Do It Yourself) security... Show more

 • Promoted

Akamai API Security or NoName API Security Analyst

Net2Source Inc.Toronto, ON, CA
Full-time

Akamai API Security or NoName API Security Analyst.This position is offered by Net2Source Inc.Your actual pay will depend on your skills and experience — please consult with your recruiter for more... Show more

 • Promoted

Penetration Testing & Application Security Consultant

Rsm Us Llp.Toronto
Full-time

A leading professional services firm in Toronto is seeking a Security Analyst with expertise in web security.The role involves performing security assessments, conducting penetration testing, and c... Show more

 • Promoted

Senior Information Security Analyst

ScotiabankToronto, ON, CA
Full-time

Senior Information Security Analyst.Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.Contributes to the successful delivery and operational supp... Show more

 • Promoted

Information Security Analyst

BDO CanadaToronto, ON, CA
Full-time

BDO is a firm built on a foundation of positive relationships with our people and clients.Reporting to the Manager, Information Security, the Information Security Analyst supports security operatio... Show more

 • Promoted

Senior Analyst, Security Compliance

P2PToronto, ON, CA
Full-time

Our Krakenites are a world-class team with crypto conviction, united by our desire to discover and unlock the potential of crypto and blockchain technology.Kraken is a mission-focused company roote... Show more

 • Promoted

Security Analyst - Security & Governance Compliance

TVET CollegeRichmond Hill, York Region, CA
Full-time

Security Analyst - Security & Governance Compliance.The Security Analyst, Security Risk & Compliance will support the management and continuous improvement of Staples Canada’s PCI compliance progra... Show more

 • Promoted

Hybrid Security Operations Analyst: Cloud & Threat Detection

IFSToronto, ON, CA
Full-time

A leading tech company in Toronto is seeking a Security Operations Analyst to enhance security in a hybrid environment combining on-premise and cloud systems.The candidate will manage incident resp... Show more

 • Promoted

Workday Security Analyst

neteffectsToronto, ON, CA
Full-time

Remote from the UK - to work for an International US-based company.Workday security area – focusing on Workday HR user, domain, business process, and integrations security, privacy, audit, controls... Show more

 • Promoted

Security Analyst

ObsidianToronto, Ontario, Canada
Full-time

Mercor is partnering with leading AI labs to engage experienced cybersecurity professionals — security analysts, penetration testers, incident responders, threat intelligence specialists, and secur... Show more

 • Promoted

Senior Application Security Specialist

AIR MILES Reward ProgramToronto, ON, CA
Full-time

The AIR MILES Reward Program is one of Canada’s most recognized loyalty programs, with over 10 million active collector accounts, representing more than half of all Canadian households.AIR MILES co... Show more

 • Promoted

Remote Information Risk & Security Analyst

DexianToronto, ON, CA
Remote
Full-time

A leading IT services firm is seeking an Information Control Testing Specialist to manage information risk and ensure compliance with security policies.You will work on global initiatives, conduct ... Show more