Security Analyst – Intermediate # 26-21779

US Tech Solutions

Toronto

On-site

CAD 62,000 - 69,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

US Tech Solutions is seeking an experienced IT Security Governance Analyst for a 6-month contract in Toronto to support governance, risk, and compliance across cybersecurity programs. You will work with Cybersecurity, Risk & Compliance, Privacy, Procurement, Finance, IT Operations and business stakeholders to ensure adherence to PCI DSS, NIST, ISO 27001 and privacy requirements.

The role covers governance frameworks, risk monitoring, third-party risk management, security audits, and KPI

Qualifications

  • 4-6 years in IT/cybersecurity/risk/compliance
  • 3-5 years in governance, risk & compliance
  • Hands-on cybersecurity risk management
  • Experience with third-party/vendor risk assessments
  • Experience supporting cybersecurity audits and remediation
  • Experience developing security metrics and reports
  • Strong understanding of security controls and compliance requirements
  • Experience collaborating with cross-functional teams

Responsibilities

  • Support development and maintenance of IT Security Governance frameworks, policies, standards, and controls
  • Ensure projects align with IT security policies and requirements
  • Maintain ISO 27001, NIST, PCI DSS compliance and privacy requirements
  • Provide governance guidance to business and tech teams
  • Support security awareness and governance training
  • Identify and monitor cybersecurity risks across applications and environments
  • Collaborate with Risk & Compliance to understand risk appetite and treatment plans
  • Coordinate third-party cyber risk assessments and vendor security reviews
  • Assist with security audits and remediation activities
  • Develop and maintain cybersecurity KPIs, KRIs, dashboards and reports
  • Track security compliance and control effectiveness
  • Maintain digital asset inventories and risk assessments
  • Build relationships across teams and communicate governance requirements

Skills

Cybersecurity Governance
Risk Management
Third-Party Risk Management
Security Compliance
Stakeholder Management
Audit & Assurance

Education

Bachelor's or higher in Business or IT/Cybersecurity
Equivalent experience considered

Tools

ISO 27001
NIST CSF
PCI DSS
Privacy & Data Protection
Security Controls & Assessments
Security Audits & Compliance

Job description

C$45-C$50 per hour

Toronto, ON

Contract

Duration: 06 Months
Position Overview:
  • We are seeking an experienced IT Security Governance Analyst to support the development and maintenance of cybersecurity governance, risk, compliance, audit, and reporting capabilities.

  • The successful candidate will help ensure that projects and operations comply with applicable cybersecurity policies, regulatory requirements, and industry standards, including PCI DSS, NIST, ISO 27001, privacy requirements, and applicable government policies.

  • The role will work closely with Cybersecurity, Risk & Compliance, Privacy, Procurement, Finance, IT Operations, and business stakeholders.

Key Responsibilities
IT Security Governance & Compliance
  • Support the development, implementation, and maintenance of IT Security Governance frameworks, policies, standards, and controls.

  • Ensure projects align with applicable IT security policies and requirements.

  • Maintain compliance with ISO 27001, NIST, PCI DSS, privacy requirements, and other applicable cybersecurity standards.

  • Provide cybersecurity governance guidance and subject matter expertise to business and technology teams.

  • Support security awareness and governance training initiatives.

Cybersecurity Risk Management
  • Identify, assess, document, and monitor cybersecurity risks across business applications and technology environments.

  • Work with Risk & Compliance and business stakeholders to understand risk appetite and develop appropriate risk treatment plans.

  • Escalate and report risks that exceed accepted risk thresholds.

  • Support the development and maintenance of cybersecurity risk registers and reporting.

Third-Party Cyber Risk Management
  • Support the design and implementation of a Third-Party Cyber Risk Management framework.

  • Conduct security and cyber risk assessments of third parties and vendors.

  • Identify appropriate security controls and requirements for third-party engagements.

  • Review vendor security assessments, attestations, SOC reports, and other security documentation.

  • Assess security control gaps and potential risks associated with third-party services.

  • Provide cybersecurity input into contracts, SLAs, renewals, and termination of vendor relationships.

  • Collaborate with Procurement, Vendor Management, Legal, and other stakeholders on third-party cybersecurity requirements.

Security Audit & Assurance
  • Support internal and external cybersecurity audits.

  • Assist with PCI audits, ISO 27001 assessments, internal audits, and CSAE 3416/SOC-related activities.

  • Coordinate audit evidence, documentation, findings, remediation activities, and reporting.

  • Monitor remediation of identified security and compliance gaps.

Security Metrics & Reporting
  • Develop and maintain cybersecurity KPIs, KRIs, dashboards, and performance reports.

  • Provide timely security governance and risk reports to senior management and other stakeholders.

  • Track security compliance and control effectiveness.

  • Support reporting on cybersecurity risks, audit findings, remediation, and governance performance.

Asset & Information Risk Management
  • Work with IT Operations and Risk & Compliance teams to maintain digital asset inventories.

  • Support identification, classification, ownership, and risk assessment of technology assets and business applications.

  • Ensure appropriate security, compliance, and risk requirements are associated with relevant assets.

Stakeholder Management
  • Build strong working relationships across business and technology teams.

  • Communicate cybersecurity governance requirements clearly to end users and stakeholders.

  • Provide security guidance and support to teams without direct supervisory responsibility.

  • Collaborate with Privacy, Records Management, Finance, Procurement, Vendor Management, IT Operations, and Risk & Compliance teams.

Requirements:
  • 4-6 years of progressive experience in IT, cybersecurity, information security, risk, compliance, or a related discipline.

  • 3-5 years of relevant cybersecurity / IT security experience, preferably within a Governance, Risk & Compliance environment.

  • Hands-on experience with cybersecurity risk management and security governance.

  • Experience with third-party/vendor cybersecurity risk assessments.

  • Experience supporting cybersecurity audits, compliance assessments, and remediation activities.

  • Experience developing security metrics, KPIs/KRIs, dashboards, and management reports.

  • Strong understanding of security controls, policies, risk assessment methodologies, and compliance requirements.

  • Experience working collaboratively with cross-functional business and technology teams.

Technical / Functional Knowledge
  • Strong knowledge or practical experience with:

  • ISO 27001

  • NIST Cybersecurity Framework

  • PCI DSS

  • Privacy and data protection requirements

  • IT Security Governance and GRC

  • Cybersecurity Risk Management

  • Third-Party / Vendor Risk Management

  • Security Controls and Control Assessments

  • Security Audits and Compliance

  • Security KPIs / KRIs and Management Reporting

  • IT Asset Inventory and Risk Classification

Education
  • Completion of a degree in Business, Engineering, Information Systems, Computer Science, Cybersecurity, or a related discipline.

  • A combination of relevant education, training, and professional experience may be considered equivalent.

Certifications
  • The following certifications are considered an asset:

  • CISSP - Certified Information Systems Security Professional

  • CISM - Certified Information Security Manager

  • CISA - Certified Information Systems Auditor

  • CRISC - Certified in Risk and Information Systems Control

  • CGEIT - Certified in the Governance of Enterprise IT

  • Other relevant cybersecurity, risk, audit, or governance certifications.

  • Agile certifications such as Agile Certified Professional (ACP) or Certified Scrum Product Owner (CSPO) are also considered an asset.

Additional Assets
  • Experience supporting IT project delivery or IT Operations.

  • Experience within a regulated, public-sector, financial services, payments, or transportation environment.

  • Experience working with enterprise cybersecurity governance frameworks.

  • Experience working with senior management, audit, procurement, and external vendors.

Key Competencies
  • Cybersecurity Governance

  • Risk Management

  • Third-Party Risk Management

  • Security Compliance

Audit & Assurance
  • Policy & Control Management

  • Security Metrics & Reporting

  • Stakeholder Management

  • Analytical & Problem-Solving Skills

  • Strong Written and Verbal Communication

  • Ability to work independently and collaboratively

About US Tech Solutions :

US Tech Solutions is a global staff augmentation firm providing a wide range of talent on-demand and total workforce solutions. To know more about US Tech Solutions, please visit www.ustechsolutions.com.

US Tech Solutions is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

AI Statement:

By applying, you acknowledge that AI-assisted tools may be used during hiring.

#LI-AS140

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Analyst (Governance, Risk & Compliance)
IT Security Analyst (Governance, Risk & Compliance)

Affinity • Hamilton

On-site
CAD 75,000 - 110,000
Affinity Earn referral program
Senior Analyst, IT Risk Analytics & Reporting (Global Security)
Senior Analyst, IT Risk Analytics & Reporting (Global Security)

RBC • Toronto

On-site
CAD 110,000 - 140,000
Total rewards program including bonus
Bonuses and flexible benefits
Career development opportunities
Senior Cyber Security Analyst - GRC
Senior Cyber Security Analyst - GRC

Metro Supply Chain • Mississauga

On-site
CAD 105,000 - 125,000
Security Analyst
Security Analyst

EIZIE • West Hawk Lake

On-site
CAD 80,000 - 110,000
Competitive salary
Health and dental benefits
Professional development
+5
IT - Info Security Analyst IV
IT - Info Security Analyst IV

Robertson & Company Ltd. • Toronto

Hybrid
CAD <100,000
Cybersecurity Risk Advisor
Cybersecurity Risk Advisor

Insight Global • Toronto

On-site
CAD 110,000 - 160,000
Cybersecurity Architect - REMOTE
Cybersecurity Architect - REMOTE

Pave Talent • Canada

On-site
CAD 90,000 - 100,000
Competitive compensation
Professional development opportunities
Collaborative work environment
Security Analyst - Intermediate JP226
Security Analyst - Intermediate JP226

P@thlion Staffing Careers • Toronto

On-site
CAD 90,000 - 130,000
Specialist
Specialist

LTM • Mississauga

On-site
CAD 70,000 - 90,000
Comprehensive Medical Plan covering Medical, Dental, Vision
Health Care Spending Account
Short Term and Long Term Disability Coverage
+4
OT Cyber Security Analyst
OT Cyber Security Analyst

RECRUITMENT PARTNERS INC. • Calgary

On-site
CAD 90,000 - 120,000