Security Analyst - Intermediate (ONSITE) JP226

Pathlion

Toronto

On-site

CAD 90,000 - 120,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Pathlion is seeking a Governance Analyst to support ITSEC governance, compliance, audit, and reporting for Payments (PRESTO). You will ensure adherence to policies from the Government of Ontario, PCI, NIST, ISO 27001, and other cybersecurity standards.

You will design ITSEC KPIs, report security performance, and collaborate across Risk, Compliance, Privacy, and Finance to manage cyber risk aligned with cross-organisation strategies.

Qualifications

  • Degree in Business, Engineering, Information Systems, Computer Science, or related field.
  • 4–6 years in IT/IT security with risk management focus.
  • Professional security certifications are assets (CISSP, CISM, CGEIT, CRISC, CISA).

Responsibilities

  • Design ITSEC KPIs and report to stakeholders on cyber security effectiveness.
  • Collaborate with Risk, Compliance, Privacy and Finance to manage cyber risk across apps.
  • Support PCI, CSAE 3416 audits and ITSEC governance activities.
  • Coordinate third-party risk management and SLA reviews with vendors.
  • Maintain asset inventory and ensure compliance with ISO 27001, NIST, and privacy standards.

Skills

IT Security
Incident response
TCP/IP
Unix/Linux
Windows systems
Network infrastructure
Threats analysis
Cyber risk management

Education

Degree in Computer Science/IT/Engineering

Job description

Responsibilities Perform real time monitoring and analysis of events with a focus on identifying potential security incidents. Respond and investigate potential alerts and tickets. Collect and analyze evidence including network traffic, volatile data, logs and other indicators. General Skills Experience in IT Security, operational security monitoring, incident response. Understanding of TCP/IP stack, *nix/Windows systems Knowledge of network infrastructure and internet applications Understanding of different cyber-attacks Knowledge of security threats and attack types Analysis of cyber threats and experience in providing action plans Ability to investigate, evaluate and recommend Cyber Security products and intrusion detection technology to minimize vulnerabilities.

ACCOUNTABILITY STATEMENT

The Governance Analyst will be responsible for supporting the development and maintenance of Payments (PRESTO) ITSEC governance, compliance, audit, and reporting capabilities. The Governance Analyst will contribute to ensuring that:

Payments (PRESTO) projects adhere to ITSEC policies.

Payments (PRESTO) complies with relevant policies, including those from the Government of Ontario, PCI, NIST, and other applicable cybersecurity standards (ISO 27001).

All security audit requirements are fulfilled. Appropriate cyber risk reporting is provided to internal and external stakeholders.

KEY CONTRIBUTIONS Functional/Technical

Design ITSEC performance KPIs and report on them to appropriate stakeholders as a means of measuring and evaluating cybersecurity effectiveness.

Foster relationships across the organization to promote awareness of compliance and ITSEC principles.

Contribute to development and implementation of Payments (PRESTO) Third-party Cyber Risk Management framework, participating in its design and execution to align with ITSEC governance objectives and industry best practices

Provide timely updates and reports to internal and external stakeholders, including Senior Management Team (SMT), Audit, Finance, and others as necessary.

Collaborate with Risk & Compliance, Privacy, Records Management, and Finance departments to understand the risk appetite for key business applications and coordinate appropriate treatment of identified cyber risks that exceed accepted risk levels.

Work with IT Operations and Risk & Compliance teams to develop and maintain digital assets inventory management systems, ensuring proper identification, classification, ownership, and associated risks and compliance requirements.

Manage governance activities to maintain full compliance with ISO 27001, Privacy (FIPPA), and NIST standards. IT Security Governance Analyst - 1733 Effective Date - May 12, 2023

Support security audit activities, including PCI audits, internal audits, and external audits such as CSAE 3416.

Customer/Stakeholder

Communicates with the organization's end users regarding appropriate Governance activities and issues as necessary

Works closely with business units to manage and execute contractual and legal governance requirements dealing with Payments cyber security requirements

Assists the extended teams (VMO, Procurement etc.) with the alignment of the design and operationalization of Metrolinx Cybersecurity risk management practices as they apply to third party contracts including:

  • Assessment of third party and contract risks prior to execution
  • Determines relevant security controls that should be embedded with security controls that are applicable to third parties
  • Designs and review of service level agreements and management reporting templates for third parties
  • Ensures the appropriate involvement of internal/external stakeholders during the design of the proposed third-party solution contract
  • Implementation of internal control measures to corroborate security reports from third parties
  • Reviews of vendor security control attestation reports and assesses the implications of gaps/breaches as they occur.
  • Provides input into the renewal/termination of contractual arrangements for outsourced services as contract periods lapse.
Operational Excellence

Identifies the effectiveness and completeness of business and technologies strategies applicable to ITSEC Governance and ensures alignment with I&IT, Payments (PRESTO) and other applicable cross organization strategies

Assist in developing ITSEC governance awareness-training program for resources as necessary and applicable (employees, contractors and/or approved system users)

Provides subject matter expertise regarding industry standards, regulations and best practices relevant to the ITSEC Governance

People Leadership

Provides security guidance and assists others in the performance of their day-to-day activities without direct supervisory responsibility

Education

Completion of a degree in Business, Engineering, Information Systems, Computer Science or a related discipline – or a combination of education, training and experience deemed equivalent. Experience

Minimum 4-6 years of experience in progressively advancing roles within IT or a related function, with a focus on IT Security/Cybersecurity. Strong track record of competency in risk management and cybersecurity management in IT, with 3 to 5 years of relevant experience. Certifications or Designations

Certifications or Designations

Professional security management certification is an asset, such as, Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Governance of Enterprise IT (CGEIT), Certified Risk and Information Systems Controls (CRISC), Certified Information Systems Auditor (CISA) or other similar credentials an asset

Agile certification

Agile certification (Agile Certified Professional, Certified Scrum Product Owner) an asset

Experience in IT Project Delivery or Operations

Experience in IT Project Delivery or Operations an asset

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst - Intermediate JP226
Security Analyst - Intermediate JP226

P@thlion Staffing Careers • Toronto

On-site
CAD 90,000 - 130,000
RQ00226 - Security Analyst - Intermediate
RQ00226 - Security Analyst - Intermediate

Source Code • Toronto

Hybrid
CAD 101,000 - 109,000
RQ09054 - Security Specialist - Threat Risk Assessment - Senior
RQ09054 - Security Specialist - Threat Risk Assessment - Senior

Rubicon Path • Toronto

On-site
CAD 85,000 - 110,000
RQ08753 - Security Specialist - Senior
RQ08753 - Security Specialist - Senior

Rubicon Path • Toronto

On-site
CAD 90,000 - 130,000
Security Analyst – Intermediate # 26-21779
Security Analyst – Intermediate # 26-21779

US Tech Solutions • Toronto

On-site
CAD 62,000 - 69,000
RQ08437 - Security Specialist - Penetration Testing - Senior
RQ08437 - Security Specialist - Penetration Testing - Senior

Rubicon Path • Toronto

On-site
CAD 85,000 - 110,000
IT Security Analyst (Governance, Risk & Compliance)
IT Security Analyst (Governance, Risk & Compliance)

Affinity • Hamilton

On-site
CAD 75,000 - 110,000
Affinity Earn referral program
RQ08587 - Security Specialist - Senior
RQ08587 - Security Specialist - Senior

Rubicon Path • Toronto

On-site
CAD 90,000 - 130,000
RQ08347 - Specialized IT Consultant - Senior
RQ08347 - Specialized IT Consultant - Senior

Rubicon Path • Toronto

Hybrid
CAD 90,000 - 110,000
RQ08438 - Security Specialist - Penetration Testing - Senior
RQ08438 - Security Specialist - Penetration Testing - Senior

Rubicon Path • Toronto

On-site
CAD 90,000 - 120,000