Senior Cyber Security Analyst - GRC

Metro Supply Chain

Mississauga

On-site

CAD 105,000 - 125,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A logistics company in Mississauga seeks a Senior Cybersecurity Analyst overseeing governance, risk management, and compliance aspects of the security program. The role involves developing policies, conducting assessments, and reporting to senior leaders. Candidates should possess a minimum of 5 years in information security, strong communication skills, and relevant certifications. This full-time position offers a competitive salary range of CA$105,000.00-CA$125,000.00.

Qualifications

  • Minimum 5 years of information security experience in risk management or IT leadership.
  • Proficiency in security domains including risk assessments, compliance, and vulnerability management.
  • Excellent communication and interpersonal skills.

Responsibilities

  • Develop and administer firm-wide Security Policies and Standards.
  • Report on the status of the information security program to senior leaders.
  • Conduct security and compliance assessments on systems and processes.

Skills

Information Security Management
Risk Management
Regulatory Compliance
Incident Management
Communication Skills
Project Planning

Education

Relevant professional certifications (CRISC, CISA, CISM)

Job description

Senior Cybersecurity Analyst – Governance, Risk, and Compliance (GRC)

Responsible for implementing, and maintaining a firm-wide information security governance program designed to help ensure the Security program and its supporting capabilities and processes effectively protect information and system assets.

Education & Experience
  • Minimum 5 years of information security experience in any combination of risk management, information security or information technology leadership.
  • Proficiency in information security domains, including policies and standards, risk and control assessments, access controls, regulatory compliance (SOC2, NIST), technology resiliency, risk and control governance and metrics, incident management, secure systems development lifecycle, vulnerability management and data protection.
  • Excellent communication (verbal and written) and customer service skills. Strong interpersonal, communication, and presentation skills applicable to a wide audience including senior and executive management.
  • Excellent organization/project planning, time management, and change management skills across multiple functional groups and departments.
  • CRISC, CISA, CISM or other relevant certifications are preferred.
  • Ability to work in a team-based setting and independently.
Responsibilities
  • Develops, implements, and administers firm-wide Security Policies and Standards with alignment to industry best practices such as NIST and ISO.
  • Creates and maintains operational and executive summary Security KRIs/KPIs for committee and board level reporting.
  • Provides reporting on the status of the information security program to senior business and technical leaders.
  • Managing the security metrics program which includes coordinating the collection of security metric data, tracking and reporting metrics and developing and refining new security metrics.
  • Develops and enhances an information security control assessment framework based on appropriate information security industry standards to measure the efficiency and effectiveness of the program controls.
  • Manages the organization’s Data Governance Lifecycle (discover, remediation, asset registry, data flow mapping).
  • Reviews security requirements and questionnaires from existing and potential customers.
  • Works with Audit and External consultants as appropriate on required security assessments and audits.
  • Performs security and compliance assessments on new and existing systems, processes, and technology.
  • Performs periodic gap assessments to validate compliance on an ongoing basis.
  • Develops methodologies to audit, benchmark and report compliance status.
  • Stays up to date and informed on developing regulatory concerns and changing IT and information security trends.
  • Facilitates the information security risk assessment process, including the reporting and oversight of treatment efforts to address findings.
  • Provides leadership, direction, and guidance in assessing and evaluating information security risks and monitors compliance with security standards and appropriate policies.
  • Supports the organization’s vendor management processes by performing Vendor/3rd-Party Risk Assessments.
  • Communicating and reporting status and audit findings on key information security metrics to peers and management and all other relevant individuals and groups.
  • Creates and manages targeted information security awareness and education program for all employees, contractors and approved system users, and establishes metrics to measure the effectiveness of the program.
Job Details
  • Seniority level: Associate
  • Employment type: Full-time
  • Job function: Information Technology
  • Industries: Transportation, Logistics, Supply Chain and Storage
  • Location: Mississauga, Ontario, Canada
  • Salary: CA$105,000.00-CA$125,000.00
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst - GRC
Security Analyst - GRC

Quantum Technology Recruiting Inc. (QTR) • Toronto

Hybrid
CAD 75,000 - 85,000
Senior GRC Security Analyst: Risk & Compliance Leader
Senior GRC Security Analyst: Risk & Compliance Leader

Metro Supply Chain • Mississauga

On-site
CAD 105,000 - 125,000
Cyber Security Manager
Cyber Security Manager

Akkodis • Toronto

Hybrid
CAD 120,000 - 180,000
Performance-based bonuses
Defined contribution pension plan
Professional growth opportunities
+4
Senior Security Analyst, Third Party Risk
Senior Security Analyst, Third Party Risk

Insight Global • Vancouver

On-site
Information Security, GRC Analyst
Information Security, GRC Analyst

Bennett Jones • Toronto

On-site
CAD 102,000 - 154,000
Senior Analyst - IT Security
Senior Analyst - IT Security

EECOL Electric • Calgary

On-site
CAD 90,000 - 120,000
Comprehensive insurance options
Generous paid time off
Flex benefits
+3
Cyber Security Compliance Analyst
Cyber Security Compliance Analyst

Jobtailor • Edmonton

On-site
CAD 70,000 - 100,000
Senior GRC Specialist
Senior GRC Specialist

OCS Ontario Cannabis Store • Toronto

On-site
CAD 100,000 - 120,000
IT Risk and Compliance Analyst
IT Risk and Compliance Analyst

Experis • Mississauga

Hybrid
CAD 70,000 - 100,000
Bonus program
Flexible hybrid work
Professional development
+1
Senior GRC Specialist
Senior GRC Specialist

OCS • Toronto

On-site
CAD 100,000 - 120,000