Talent.com
Source Code
RQ00226 - Security Analyst - IntermediateSource Code • Toronto, ON, Canada
RQ00226 - Security Analyst - Intermediate

RQ00226 - Security Analyst - Intermediate

Source Code • Toronto, ON, Canada
1 day ago
Salary
CA$48.66 hourly
Job type
  • Full-time
  • Quick Apply
Job description

RQ00226 - Security Analyst - Intermediate

Duration: 6 Months (131 Business Days)

Location: Hybrid, 3 days in office, 2 days remote at 20 Bay St

Must Haves:

  • Minimum 4-6 years of experience in progressively advancing roles within IT or a related function, with a focus on IT Security/Cybersecurity. Strong track record of competency in risk management and cybersecurity management in IT, with 3 to 5 years of relevant experience. Certifications or Designations
  • Professional security management certification is an asset, such as, Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Governance of Enterprise IT (CGEIT), Certified Risk and Information Systems Controls (CRISC), Certified Information Systems Auditor (CISA) or other similar credentials an asset
  • Perform vendor risk assessments and enhanced the Third-Party Risk Management (TPRM) program by Gathering and preparing data for reporting security service performance metrics that includes status of information systems, services obtained from external providers, and actions for improvement and Providing input into security pen testing activities conducted by a third-party security services provider 4-6 years experience

Description

Responsibilities Perform real time monitoring and analysis of events with a focus on identifying potential security incidents. Respond and investigate potential alerts and tickets. Collect and analyze evidence including network traffic, volatile data, logs and other indicators. General Skills Experience in IT Security, operational security monitoring, incident response. Understanding of TCP/IP stack, *nix/Windows systems Knowledge of network infrastructure and internet applications Understanding of different cyber-attacks Knowledge of security threats and attack types Analysis of cyber threats and experience in providing action plans Ability to investigate, evaluate and recommend Cyber Security products and intrusion detection technology to minimize vulnerabilities.

ACCOUNTABILITY STATEMENT

The Governance Analyst will be responsible for supporting the development and maintenance of Payments (PRESTO) ITSEC governance, compliance, audit, and reporting capabilities. The Governance Analyst will contribute to ensuring that:

Payments (PRESTO) projects adhere to ITSEC policies.

Payments (PRESTO) complies with relevant policies, including those from the Government of Ontario, PCI, NIST, and other applicable cybersecurity standards (ISO 27001).

All security audit requirements are fulfilled. Appropriate cyber risk reporting is provided to internal and external stakeholders.

KEY CONTRIBUTIONS Functional/Technical

  • Design ITSEC performance KPIs and report on them to appropriate stakeholders as a means of measuring and evaluating cybersecurity effectiveness.
  • Foster relationships across the organization to promote awareness of compliance and ITSEC principles.
  • Contribute to development and implementation of Payments (PRESTO) Third-party Cyber Risk Management framework, participating in its design and execution to align with ITSEC governance objectives and industry best practices
  • Provide timely updates and reports to internal and external stakeholders, including Senior Management Team (SMT), Audit, Finance, and others as necessary.
  • Collaborate with Risk & Compliance, Privacy, Records Management, and Finance departments to understand the risk appetite for key business applications and coordinate appropriate treatment of identified cyber risks that exceed accepted risk levels.
  • Work with IT Operations and Risk & Compliance teams to develop and maintain digital assets inventory management systems, ensuring proper identification, classification, ownership, and associated risks and compliance requirements.
  • Manage governance activities to maintain full compliance with ISO 27001, Privacy (FIPPA), and NIST standards. IT Security Governance Analyst - 1733 Effective Date - May 12, 2023
  • Support security audit activities, including PCI audits, internal audits, and external audits such as CSAE 3416.

Customer/Stakeholder

Communicates with the organization's end users regarding appropriate Governance activities and issues as necessary

Works closely with business units to manage and execute contractual and legal governance requirements dealing with Payments cyber security requirements

Assists the extended teams (VMO, Procurement etc.) with the alignment of the design and operationalization of Metrolinx Cybersecurity risk management practices as they apply to third party contracts including:

  • Assessment of third party and contract risks prior to execution o Determines relevant security controls that should be embedded with security controls that are applicable to third parties
  • Designs and review of service level agreements and management reporting templates for third parties
  • Ensures the appropriate involvement of internal/external stakeholders during the design of the proposed third-party solution contract
  • Implementation of internal control measures to corroborate security reports from third parties
  • Reviews of vendor security control attestation reports and assesses the implications of gaps/breaches as they occur.
  • Provides input into the renewal/termination of contractual arrangements for outsourced services as contract periods lapse.

Operational Excellence

  • Identifies the effectiveness and completeness of business and technologies strategies applicable to ITSEC Governance and ensures alignment with I&IT, Payments (PRESTO) and other applicable cross organization strategies
  • Assist in developing ITSEC governance awareness-training program for resources as necessary and applicable (employees, contractors and/or approved system users)
  • Provides subject matter expertise regarding industry standards, regulations and best practices relevant to the ITSEC Governance

People Leadership

Provides security guidance and assists others in the performance of their day-to-day activities without direct supervisory responsibility

Education

  • Completion of a degree in Business, Engineering, Information Systems, Computer Science or a related discipline – or a combination of education, training and experience deemed equivalent. Experience
  • Minimum 4-6 years of experience in progressively advancing roles within IT or a related function, with a focus on IT Security/Cybersecurity. Strong track record of competency in risk management and cybersecurity management in IT, with 3 to 5 years of relevant experience. Certifications or Designations
  • Professional security management certification is an asset, such as, Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Governance of Enterprise IT (CGEIT), Certified Risk and Information Systems Controls (CRISC), Certified Information Systems Auditor (CISA) or other similar credentials an asset
  • Agile certification (Agile Certified Professional, Certified Scrum Product Owner) an asset
  • Experience in IT Project Delivery or Operations an asset

AI Disclaimer: Source Code may use artificial intelligence (AI) tools to assist in certain aspects of its recruiting and business operations.

Note: The higher end of the range is intended for absolutely exceptional candidates who meet all must-have requirements and most or all nice-to-have qualifications. The client will evaluate candidates based on both rate expectations and overall skill set when shortlisting.

INCORPORATED RATE RANGE (7.25 billable hours per day)

  • $48.66/hr - $52.14/hr Inc.

T4 RATE RANGE (7.25 billable hours per day)

  • $38.93/hr - $41.71/hr T4
Create a job alert for this search

RQ00226 - Security Analyst - Intermediate • Toronto, ON, Canada

Similar jobs

Security Analyst

Obsidiantoronto, on, Canada
Full-time

Mercor is partnering with leading AI labs to engage experienced cybersecurity professionals — security analysts, penetration testers, incident responders, threat intelligence specialists, and secur... Show more

 • Promoted

Security Analyst - Security & Governance Compliance

Staples CanadaRichmond Hill, York Region, CA
Full-time

Some of what you will do: The Security Analyst, Security Risk & Compliance will support the management and continuous improvement of Staples Canada’s PCI compliance program and broader cybersecurit... Show more

 • Promoted

Senior Security Analyst: Incident Response & Threat Defense

MindlanceToronto, ON, CA
Full-time

A global cybersecurity firm is seeking a Senior Security Analyst to join their team in Toronto.This role involves providing technical security consulting, ensuring timely incident resolution, and c... Show more

 • Promoted

Information Security Analyst in Downtown Toronto

DelpathToronto, ON, CA
Full-time

Become a key player in cybersecurity as an Information Security Analyst, working hybrid in downtown Toronto.Focus on data loss prevention and optimize security measures across the organization.This... Show more

 • Promoted

Security Analyst, Lawful Acces

Rogers CommunicationsToronto, ON, CA
Full-time

We are committed to connecting Canadians through unique partnerships, our world-class network and content Canadians love—and our innovative team is growing.We are looking for dedicated team members... Show more

 • Promoted

Security Analyst

York UniversityToronto, ON, CA
Permanent

The Security Analyst contributes to the mission of the University by supporting the delivery of information security program.This includes security investigations, assessments, monitoring and incid... Show more

 • Promoted

Cyber Security Analyst

Lorex TechnologyMarkham, ON, CA
Full-time

For 34 years, Lorex has been creating security systems designed to protect your home and business.Founded and headquartered in Canada, we’ve grown to become leaders in DIY (Do It Yourself) security... Show more

 • Promoted

Senior Application Security Specialist

AIR MILES Reward ProgramToronto
Full-time

The AIR MILES Reward Program is one of Canada’s most recognized loyalty programs, with over 10 million active collector accounts, representing more than half of all Canadian households.AIR MILES co... Show more

 • Promoted

Senior Application Security Engineer

CognizantToronto, ON, CA
Full-time

Job Title - App Security Specialist.DevOps, with at least 2 - 3 years hands-on security exposure (secure coding, pipeline security, API security, threat modeling).Seniority level: Mid-Senior level.... Show more

 • Promoted

Akamai API Security or NoName API Security Analyst

Net2Source Inc.Toronto, ON, CA
Full-time

Akamai API Security or NoName API Security Analyst.This position is offered by Net2Source Inc.Your actual pay will depend on your skills and experience — please consult with your recruiter for more... Show more

 • Promoted

Information Security Analyst

BDO CanadaToronto, ON, CA
Full-time

BDO is a firm built on a foundation of positive relationships with our people and clients.Reporting to the Manager, Information Security, the Information Security Analyst supports security operatio... Show more

 • Promoted

RQ08437 - Security Specialist - Penetration Testing - Senior

Rubicon PathToronto, ON, CA
Full-time

RQ08437 - Security Specialist - Penetration Testing - Senior.Conducts penetration tests, web application vulnerability assessments, code reviews and network vulnerability assessments of all environ... Show more

 • Promoted

Security Analyst - Part Time

Equifax, Inc.Toronto, ON, CA
Part-time

As our IT Security Analyst, this role requires a motivated self-starter.Someone who has strong analytical and problem-solving skills, a deep understanding of risk and compliance management principl... Show more

 • Promoted

Penetration Testing & Application Security Consultant

Rsm Us Llp.Toronto, ON, CA
Full-time

A leading professional services firm in Toronto is seeking a Security Analyst with expertise in web security.The role involves performing security assessments, conducting penetration testing, and c... Show more

 • Promoted

Senior Application Security Engineer

PaymentusRichmond Hill, York Region, CA
Full-time

Senior Application Security Engineer.Paymentus SaaS platform by partnering directly with software engineering, product, cloud infrastructure, DevOps, and security teams to identify, assess, and rem... Show more

 • Promoted

Senior Analyst, Security Compliance

P2PToronto, ON, CA
Full-time

Our Krakenites are a world-class team with crypto conviction, united by our desire to discover and unlock the potential of crypto and blockchain technology.Kraken is a mission-focused company roote... Show more

 • Promoted

Security Analyst - Security & Governance Compliance

TVET CollegeRichmond Hill, York Region, CA
Full-time

Security Analyst - Security & Governance Compliance.The Security Analyst, Security Risk & Compliance will support the management and continuous improvement of Staples Canada’s PCI compliance progra... Show more

 • Promoted

Workday Security Analyst

neteffectsToronto, ON, CA
Full-time

Remote from the UK - to work for an International US-based company.Workday security area – focusing on Workday HR user, domain, business process, and integrations security, privacy, audit, controls... Show more

 • Promoted

Hybrid Security Operations Analyst: Cloud & Threat Detection

IFSToronto, ON, CA
Full-time

A leading tech company in Toronto is seeking a Security Operations Analyst to enhance security in a hybrid environment combining on-premise and cloud systems.The candidate will manage incident resp... Show more

 • Promoted

Application Security Software Engineer

PointClickCareToronto
Full-time

This range is provided by PointClickCare.Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.PointClickCare is a leading North American healthcare t... Show more