Security Risk Analyst

Acestack

Montreal

Hybrid

CAD 70,000 - 110,000

Full time

9 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Acestack in Montreal, hybrid, is seeking a Security Risk Analyst to assess, measure, and improve cybersecurity controls across the organization. You will drive risk assessments, validate regulatory compliance, and provide actionable recommendations to strengthen the overall security posture.

Key duties include building dashboards, KRIs/KPIs, continuous monitoring, and supporting audits. You will collaborate with cybersecurity, IT, compliance, audit, and business teams to reduce risk and enhance

Qualifications

  • Strong experience in cybersecurity risk management and security control assessment.
  • Knowledge of cybersecurity frameworks, security policies, and regulatory requirements.
  • Experience identifying control gaps and evaluating cybersecurity risk exposure.
  • Hands-on experience with KRI/KPI development, metrics, reporting, and continuous monitoring.
  • Experience supporting Continuous Control Monitoring (CCM) programs.
  • Strong analytical and problem-solving skills with the ability to translate findings into actionable recommendations.
  • Experience developing dashboards and management reports for leadership and audit stakeholders.
  • Strong communication and stakeholder management skills.
  • Ability to work effectively with cybersecurity, technology, compliance, audit, and business teams.

Responsibilities

  • Assess and evaluate the effectiveness of cybersecurity controls across the organization.
  • Identify control gaps, weaknesses, and areas of risk exposure.
  • Perform security risk assessments and provide actionable recommendations for risk mitigation.
  • Validate compliance with organizational security policies, standards, and regulatory requirements.
  • Support Continuous Control Monitoring (CCM) initiatives to identify and address control deficiencies.
  • Develop, monitor, and maintain KRIs and KPIs to measure cybersecurity and control effectiveness.
  • Create dashboards, metrics, and reports for leadership, audit, and regulatory reviews.
  • Analyze security risk trends and proactively identify emerging risks.
  • Collaborate with cybersecurity, IT, compliance, audit, and business teams to strengthen the control environment.
  • Track remediation activities and ensure identified control gaps are appropriately addressed.
  • Support internal and external audits by providing risk assessments, control evidence, metrics, and reporting.
  • Continuously recommend improvements to cybersecurity controls, processes, and risk management practices.

Skills

Cybersecurity risk mgmt
Security control assessment
KRI/KPI development
Metrics reporting
Continuous monitoring
CCM programs
Dashboard development
Stakeholder management
Analytical thinking

Job description

Job Title: Security Risk Analyst
Job Type: Full Time
Location: Montreal, QC (Hybrid)

Job Description

We are seeking a skilled Security Risk Analyst to assess, measure, and enhance the effectiveness of cybersecurity controls across the organization. The ideal candidate will have strong experience in cybersecurity risk assessment, security controls, compliance, risk monitoring, and reporting.

The Security Risk Analyst will be responsible for identifying control gaps, evaluating risk exposure, validating compliance with security policies and regulatory requirements, and providing actionable recommendations to strengthen the organization's overall cybersecurity posture.

A key focus of this role will be Metrics, Reporting, and Continuous Monitoring, including the development and tracking of Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) to measure control effectiveness and proactively identify potential security risks.

Key Responsibilities
  • Assess and evaluate the effectiveness of cybersecurity controls across the organization.
  • Identify control gaps, weaknesses, and areas of risk exposure.
  • Perform security risk assessments and provide actionable recommendations for risk mitigation.
  • Validate compliance with organizational security policies, standards, and regulatory requirements.
  • Support Continuous Control Monitoring (CCM) initiatives to identify and address control deficiencies.
  • Develop, monitor, and maintain KRIs and KPIs to measure cybersecurity and control effectiveness.
  • Create dashboards, metrics, and reports for leadership, audit, and regulatory reviews.
  • Analyze security risk trends and proactively identify emerging risks.
  • Collaborate with cybersecurity, IT, compliance, audit, and business teams to strengthen the control environment.
  • Track remediation activities and ensure identified control gaps are appropriately addressed.
  • Support internal and external audits by providing risk assessments, control evidence, metrics, and reporting.
  • Continuously recommend improvements to cybersecurity controls, processes, and risk management practices.
Required Skills & Experience
  • Strong experience in cybersecurity risk management and security control assessment.
  • Knowledge of cybersecurity frameworks, security policies, and regulatory requirements.
  • Experience identifying control gaps and evaluating cybersecurity risk exposure.
  • Hands-on experience with KRI/KPI development, metrics, reporting, and continuous monitoring.
  • Experience supporting Continuous Control Monitoring (CCM) programs.
  • Strong analytical and problem-solving skills with the ability to translate findings into actionable recommendations.
  • Experience developing dashboards and management reports for leadership and audit stakeholders.
  • Strong communication and stakeholder management skills.
  • Ability to work effectively with cybersecurity, technology, compliance, audit, and business teams.
Job Details
  • Job Type: Full Time
  • Location: Montreal, QC
  • Work Model: Hybrid
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Metrics and Controls Specialist- Need local candidate to Montreal, QC
Cybersecurity Metrics and Controls Specialist- Need local candidate to Montreal, QC

Q1 Technologies, Inc. • Montreal (administrative region)

Hybrid
CAD 90,000 - 130,000
Cybersecurity Metrics and Controls Specialist
Cybersecurity Metrics and Controls Specialist

Pacer Group • Montreal (administrative region)

Hybrid
CAD 83,000 - 90,000
Sr. Cyber Security Analyst
Sr. Cyber Security Analyst

10 Percent Recruiting Ltd. • Canada

Hybrid
CAD 110,000 - 140,000
Security Analyst - Part Time
Security Analyst - Part Time

Equifax, Inc. • Toronto

On-site
USD 49,850 - 78,336
Security Analyst
Security Analyst

EIZIE • West Hawk Lake

On-site
CAD 80,000 - 110,000
Competitive salary
Health and dental benefits
Professional development
+5
Information Security Analyst
Information Security Analyst

Glocomms • Montreal (administrative region)

On-site
CAD 70,000 - 110,000
Bonus opportunity
Generous paid time off
Wellness reimbursement programs
+3
Cyber Risk & Controls Analyst: Metrics & Monitoring
Cyber Risk & Controls Analyst: Metrics & Monitoring

Acestack • Montreal

Hybrid
CAD 70,000 - 110,000
Security Analyst
Security Analyst

Strive Recruitment Inc. • Vancouver

Hybrid
CAD 60,000 - 80,000
Health insurance
Dental coverage
Vision coverage
+2
Security Analyst
Security Analyst

TRUDELL MEDICAL LIMITED • London

On-site
CAD 90,000 - 150,000
Integrator Engineer-5
Integrator Engineer-5

Realign Llc • Montreal (administrative region)

Hybrid
CAD 100,000 - 140,000