Talent.com
US Tech Solutions, Inc.
Security Analyst Intermediate # 26-21779US Tech Solutions, Inc. • Toronto, ON
Security Analyst Intermediate # 26-21779

Security Analyst Intermediate # 26-21779

US Tech Solutions, Inc. • Toronto, ON
1 day ago
Job type
  • Full-time
Job description

Duration: 06 Months

Position Overview:

  • We are seeking an experienced IT Security Governance Analyst to support the development and maintenance of cybersecurity governance, risk, compliance, audit, and reporting capabilities.
  • The successful candidate will help ensure that projects and operations comply with applicable cybersecurity policies, regulatory requirements, and industry standards, including PCI DSS, NIST, ISO 27001, privacy requirements, and applicable government policies.
  • The role will work closely with Cybersecurity, Risk & Compliance, Privacy, Procurement, Finance, IT Operations, and business stakeholders.

Key Responsibilities
IT Security Governance & Compliance

  • Support the development, implementation, and maintenance of IT Security Governance frameworks, policies, standards, and controls.
  • Ensure projects align with applicable IT security policies and requirements.
  • Maintain compliance with ISO 27001, NIST, PCI DSS, privacy requirements, and other applicable cybersecurity standards.
  • Provide cybersecurity governance guidance and subject matter expertise to business and technology teams.
  • Support security awareness and governance training initiatives.

Cybersecurity Risk Management

  • Identify, assess, document, and monitor cybersecurity risks across business applications and technology environments.
  • Work with Risk & Compliance and business stakeholders to understand risk appetite and develop appropriate risk treatment plans.
  • Escalate and report risks that exceed accepted risk thresholds.
  • Support the development and maintenance of cybersecurity risk registers and reporting.

Third-Party Cyber Risk Management

  • Support the design and implementation of a Third-Party Cyber Risk Management framework.
  • Conduct security and cyber risk assessments of third parties and vendors.
  • Identify appropriate security controls and requirements for third-party engagements.
  • Review vendor security assessments, attestations, SOC reports, and other security documentation.
  • Assess security control gaps and potential risks associated with third-party services.
  • Provide cybersecurity input into contracts, SLAs, renewals, and termination of vendor relationships.
  • Collaborate with Procurement, Vendor Management, Legal, and other stakeholders on third-party cybersecurity requirements.

Security Audit & Assurance

  • Support internal and external cybersecurity audits.
  • Assist with PCI audits, ISO 27001 assessments, internal audits, and CSAE 3416/SOC-related activities.
  • Coordinate audit evidence, documentation, findings, remediation activities, and reporting.
  • Monitor remediation of identified security and compliance gaps.

Security Metrics & Reporting

  • Develop and maintain cybersecurity KPIs, KRIs, dashboards, and performance reports.
  • Provide timely security governance and risk reports to senior management and other stakeholders.
  • Track security compliance and control effectiveness.
  • Support reporting on cybersecurity risks, audit findings, remediation, and governance performance.

Asset & Information Risk Management

  • Work with IT Operations and Risk & Compliance teams to maintain digital asset inventories.
  • Support identification, classification, ownership, and risk assessment of technology assets and business applications.
  • Ensure appropriate security, compliance, and risk requirements are associated with relevant assets.

Stakeholder Management

  • Build strong working relationships across business and technology teams.
  • Communicate cybersecurity governance requirements clearly to end users and stakeholders.
  • Provide security guidance and support to teams without direct supervisory responsibility.
  • Collaborate with Privacy, Records Management, Finance, Procurement, Vendor Management, IT Operations, and Risk & Compliance teams.

Requirements:

  • 4–6 years of progressive experience in IT, cybersecurity, information security, risk, compliance, or a related discipline.
  • 3–5 years of relevant cybersecurity / IT security experience, preferably within a Governance, Risk & Compliance environment.
  • Hands-on experience with cybersecurity risk management and security governance.
  • Experience with third-party/vendor cybersecurity risk assessments.
  • Experience supporting cybersecurity audits, compliance assessments, and remediation activities.
  • Experience developing security metrics, KPIs/KRIs, dashboards, and management reports.
  • Strong understanding of security controls, policies, risk assessment methodologies, and compliance requirements.
  • Experience working collaboratively with cross-functional business and technology teams.

Technical / Functional Knowledge

  • Strong knowledge or practical experience with:
  • ISO 27001
  • NIST Cybersecurity Framework
  • PCI DSS
  • Privacy and data protection requirements
  • IT Security Governance and GRC
  • Cybersecurity Risk Management
  • Third-Party / Vendor Risk Management
  • Security Controls and Control Assessments
  • Security Audits and Compliance
  • Security KPIs / KRIs and Management Reporting
  • IT Asset Inventory and Risk Classification

Education

  • Completion of a degree in Business, Engineering, Information Systems, Computer Science, Cybersecurity, or a related discipline.
  • A combination of relevant education, training, and professional experience may be considered equivalent.

Certifications

  • The following certifications are considered an asset:
  • CISSP – Certified Information Systems Security Professional
  • CISM – Certified Information Security Manager
  • CISA – Certified Information Systems Auditor
  • CRISC – Certified in Risk and Information Systems Control
  • CGEIT – Certified in the Governance of Enterprise IT
  • Other relevant cybersecurity, risk, audit, or governance certifications.
  • Agile certifications such as Agile Certified Professional (ACP) or Certified Scrum Product Owner (CSPO) are also considered an asset.

Additional Assets

  • Experience supporting IT project delivery or IT Operations.
  • Experience within a regulated, public-sector, financial services, payments, or transportation environment.
  • Experience working with enterprise cybersecurity governance frameworks.
  • Experience working with senior management, audit, procurement, and external vendors.

Key Competencies

  • Cybersecurity Governance
  • Risk Management
  • Third-Party Risk Management
  • Security Compliance

Audit & Assurance

  • Policy & Control Management
  • Security Metrics & Reporting
  • Stakeholder Management
  • Analytical & Problem-Solving Skills
  • Strong Written and Verbal Communication
  • Ability to work independently and collaboratively


About US Tech Solutions:
US Tech Solutions is a global staff augmentation firm providing a wide range of talent on-demand and total workforce solutions. To know more about US Tech Solutions, please visit www.ustechsolutions.com.

US Tech Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

AI Statement: By applying, you acknowledge that AI-assisted tools may be used during hiring.

#LI-AS140

Create a job alert for this search

Security Analyst Intermediate # 26-21779 • Toronto, ON

Similar jobs

Security Analyst

Obsidiantoronto, on, Canada
Full-time

Mercor is partnering with leading AI labs to engage experienced cybersecurity professionals — security analysts, penetration testers, incident responders, threat intelligence specialists, and secur... Show more

 • Promoted

Security Analyst - Security & Governance Compliance

Staples CanadaRichmond Hill, York Region, CA
Full-time

Some of what you will do: The Security Analyst, Security Risk & Compliance will support the management and continuous improvement of Staples Canada’s PCI compliance program and broader cybersecurit... Show more

 • Promoted

Senior Security Analyst: Incident Response & Threat Defense

MindlanceToronto, ON, CA
Full-time

A global cybersecurity firm is seeking a Senior Security Analyst to join their team in Toronto.This role involves providing technical security consulting, ensuring timely incident resolution, and c... Show more

 • Promoted

Security Analyst, Lawful Acces

Rogers CommunicationsToronto, ON, CA
Full-time

We are committed to connecting Canadians through unique partnerships, our world-class network and content Canadians love—and our innovative team is growing.We are looking for dedicated team members... Show more

 • Promoted

Principal Security Analyst - Remote

CyderesToronto, ON, CA
Remote
Full-time

Be among the first 25 applicants.Cyderes (Cyber Defense and Response) is a pure-play, full life-cycle cybersecurity services provider with award-winning managed security services, identity and acce... Show more

 • Promoted

Security Analyst

York UniversityToronto, ON, CA
Permanent

The Security Analyst contributes to the mission of the University by supporting the delivery of information security program.This includes security investigations, assessments, monitoring and incid... Show more

 • Promoted

Information Security Analyst in Downtown Toronto

DelpathToronto
Full-time

Become a key player in cybersecurity as an Information Security Analyst, working hybrid in downtown Toronto.Focus on data loss prevention and optimize security measures across the organization.This... Show more

 • Promoted

Cyber Security Analyst

Lorex TechnologyMarkham, Ontario, Canada
Full-time

For 34 years, Lorex has been creating security systems designed to protect your home and business.Founded and headquartered in Canada, we’ve grown to become leaders in DIY (Do It Yourself) security... Show more

 • Promoted

Senior Security Analyst - C$70 - C$80 An Hour

Russell TobinNorth York, Canada
Full-time

Security Analyst role focused on IT sector cybersecurity and networking.Responsibilities include handling security queues, analyzing threats, reporting, incident response, risk assessment, and stak... Show more

 • Promoted • New!

Senior Security Analyst - $70 - $95 An Hour

NewFound RecruitingNorth York, Canada
Full-time

Seeking a Security Analyst to support a Defence client in assessing and monitoring security for C2 and C4ISR systems.Responsibilities include SA&A, vulnerability analysis, penetration testing, ... Show more

 • Promoted • New!

Security Operations Analyst - Copperleaf

IFSToronto, ON, CA
Full-time

Security Operations Analyst – Copperleaf.You’ll build and refine detection logic, respond to incidents, and coordinate vulnerability remediation.The role supports compliance with ISO 27001, SOC 2 a... Show more

 • Promoted

Akamai API Security or NoName API Security Analyst

Net2Source Inc.Toronto, ON, CA
Full-time

Akamai API Security or NoName API Security Analyst.This position is offered by Net2Source Inc.Your actual pay will depend on your skills and experience — please consult with your recruiter for more... Show more

 • Promoted

Analyst, Endpoint Security - C$65,400 - C$69,490 A Year

Ontario Medical AssociationToronto County, Canada
Full-time

Analyzes and enhances endpoint security for OMA devices, applications, and user accounts, focusing on proactive improvement of endpoint technologies for employee satisfaction and productivity. Show more

 • Promoted • New!

Infrastructure Security Analyst - C$92,712 - C$109,056 A Year

City of North VancouverNorth York, Canada
Full-time

Seeking an Infrastructure Security Analyst to support daily security operations, detect and mitigate cyber threats, analyze suspicious activity, respond to incidents, and provide security awareness... Show more

 • Promoted • New!

Senior Analyst, Security Compliance

P2PToronto, ON, CA
Full-time

Our Krakenites are a world-class team with crypto conviction, united by our desire to discover and unlock the potential of crypto and blockchain technology.Kraken is a mission-focused company roote... Show more

 • Promoted

Penetration Testing & Application Security Consultant

Rsm Us Llp.Toronto, ON, CA
Full-time

A leading professional services firm in Toronto is seeking a Security Analyst with expertise in web security.The role involves performing security assessments, conducting penetration testing, and c... Show more

 • Promoted

Senior Application Security Specialist

AIR MILES Reward ProgramToronto, Ontario, Canada
Full-time

The AIR MILES Reward Program is one of Canada’s most recognized loyalty programs, with over 10 million active collector accounts, representing more than half of all Canadian households.AIR MILES co... Show more

 • Promoted

Security Analyst - Security & Governance Compliance

TVET CollegeRichmond Hill, York Region, CA
Full-time

Security Analyst - Security & Governance Compliance.The Security Analyst, Security Risk & Compliance will support the management and continuous improvement of Staples Canada’s PCI compliance progra... Show more

 • Promoted

Workday Security Analyst

neteffectsToronto, ON, CA
Full-time

Remote from the UK - to work for an International US-based company.Workday security area – focusing on Workday HR user, domain, business process, and integrations security, privacy, audit, controls... Show more

 • Promoted

Experienced Info Security Analyst Position

Haventree BankToronto, Ontario, Canada
Full-time

Elevate your career as a Senior Information Security Analyst at Haventree Bank, where your skills will directly enhance our security practices.This role combines technical execution with strategic ... Show more