Senior Information Security Analyst

Jobtailor

Toronto

On-site

CAD 100,000 - 140,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Jobtailor is seeking an experienced technology risk and controls consultant in the Toronto area to advise on information security programs, conduct risk assessments, and help embed security governance across enterprise architecture. You will lead risk reviews, develop remediation plans, and support regulatory inquiries with strong communication and analytical skills.

The role requires 5–7 years of relevant experience, familiarity with major frameworks, and proficiency with Jira, Confluence,

Qualifications

  • University degree or equivalent.
  • 5–7 years of relevant experience.
  • Advanced knowledge of one or more technology controls/security domains, disciplines, and practices.
  • Familiarity with frameworks: NIST CSF/800-53, ISO 27001, COBIT, CIS, PCI, GLBA, SOX/ITGC.
  • Ability to identify, assess, and monitor technology risks including information security, cybersecurity, resilience, operations/change management quality, data quality/security, and IT compliance.
  • Knowledge of technology, information and cybersecurity, risk management, and governance standards and best practices.
  • Strong written, communication, and presentation skills.
  • Ability to prioritize workload and meet timelines with limited guidance.
  • Ability to multitask and manage multiple team and client demands.
  • Proficiency with Jira, Confluence, SharePoint, and Microsoft Office.
  • Data analysis experience, preferably using Power BI or Tableau.
  • Familiarity with GRC platforms such as Archer and ServiceNow IRM.
  • Information security certification/accreditation is an asset.
  • Familiarity with Python and generative AI is an asset.

Responsibilities

  • Provide consultation and advice on technology controls and information security programs, policies, standards, and incidents.
  • Conduct project consulting on risk assessments, control requirements, control procedures, vulnerability assessments, and related areas.
  • Lead or contribute to risk and control assessments for application portfolios.
  • Document control gaps, business and enterprise impact, risk mitigation, and remediation plans.
  • Contribute to global security management strategy and framework development and oversight.
  • Ensure technology, processes, and governance monitor, detect, prevent, and respond to security threats.
  • Develop technology risk reporting, monitor trends, and define control-effectiveness metrics.
  • Work with technology partners, stakeholders, and service/platform owners to integrate security components into enterprise architecture.
  • Consult on regulatory compliance requirements, reporting, and questions.
  • Support audits, management responses, and remediation activities.
  • Participate in computer security incident response.
  • Define, develop, implement, and manage technology controls/information security policies, programs, tools, and solutions.
  • Review internal processes, identify improvement opportunities, and advise on enterprise frameworks and methodologies.
  • Manage relationships across technology, business, corporate, and control functions.
  • Participate as a subject matter expert in business-specific, cross-functional, and enterprise initiatives.
  • Prepare complex reporting, analysis, and assessments.
  • Document and update internal processes.
  • Manage workload, deliver quality results, and meet timelines.
  • Establish relationships with business and technology partners, program managers, and project managers.
  • Participate in knowledge transfer within teams and business units.

Skills

Technology risk management
Critical thinking
Communication
Presentation skills
Workload prioritization
Multitasking
Data analysis (Power BI/Tableau)
GRC knowledge
Python (asset)

Education

University degree

Tools

Jira
Confluence
SharePoint
Microsoft Office
Power BI
Tableau
Archer
ServiceNow IRM

Job description

  • Provide consultation and advice on technology controls and information security programs, policies, standards, and incidents
  • Conduct project consulting on risk assessments, control requirements, control procedures, vulnerability assessments, and related areas
  • Lead or contribute to risk and control assessments for application portfolios
  • Document control gaps, business and enterprise impact, risk mitigation, and remediation plans
  • Contribute to global security management strategy and framework development and oversight
  • Ensure technology, processes, and governance monitor, detect, prevent, and respond to security threats
  • Develop technology risk reporting, monitor trends, and define control-effectiveness metrics
  • Work with technology partners, stakeholders, and service/platform owners to integrate security components into enterprise architecture
  • Consult on regulatory compliance requirements, reporting, and questions
  • Support audits, management responses, and remediation activities
  • Participate in computer security incident response
  • Define, develop, implement, and manage technology controls/information security policies, programs, tools, and solutions
  • Review internal processes, identify improvement opportunities, and advise on enterprise frameworks and methodologies
  • Manage relationships across technology, business, corporate, and control functions
  • Participate as a subject matter expert in business-specific, cross-functional, and enterprise initiatives
  • Prepare complex reporting, analysis, and assessments
  • Document and update internal processes
  • Manage workload, deliver quality results, and meet timelines
  • Establish relationships with business and technology partners, program managers, and project managers
  • Participate in knowledge transfer within teams and business units
Requirements
  • University degree
  • 5–7 years of relevant experience
  • Advanced knowledge of one or more technology controls/security domains, disciplines, and practices
  • Familiarity with industry-standard frameworks, including NIST CSF/800-53, ISO 27001, COBIT, CIS, PCI, GLBA, and SOX/ITGC
  • Ability to identify, assess, and monitor technology risks, including information security, cybersecurity, resilience, operations/change management quality, data quality/security, and IT compliance
  • Knowledge of technology, information and cybersecurity, risk management, and governance standards and best practices
  • Strong critical thinking and ability to decompose complex issues
  • Strong written, communication, and presentation skills
  • Ability to prioritize workload and meet timelines with limited guidance
  • Ability to multitask and manage multiple team and client demands
  • Proficiency with Jira, Confluence, SharePoint, and Microsoft Office
  • Data analysis experience, preferably using Power BI or Tableau
  • Familiarity with GRC platforms such as Archer and ServiceNow IRM
  • Information security certification/accreditation is an asset
  • Familiarity with Python and generative AI is an asset
Core Competencies

Demonstrates advanced knowledge of technology controls and information security practices, with a strong ability to assess and manage technology risks. Proficient in developing and implementing security policies, frameworks, and metrics while ensuring compliance with industry standards.

Highest-signal resume keywords
  • Technology Controls Management
  • Risk Assessment and Mitigation
  • NIST CSF/800-53 Familiarity
  • Data Analysis with Power BI
  • Information Security Certification
Hard Skills
  • Risk Management
  • Control Procedures
  • Vulnerability Assessment
  • Technology Risk Reporting
  • Information Security Policies
  • Cybersecurity
  • Data Quality/Security
  • IT Compliance
  • Critical Thinking
  • Process Improvement
Soft Skills
  • Strong Communication Skills
  • Presentation Skills
  • Ability to Multitask
  • Workload Prioritization
  • Relationship Management
Certifications & Qualifications
  • Information Security Certification
Industry Keywords
  • NIST CSF
  • ISO 27001
  • COBIT
  • CIS
  • PCI
  • GLBA
  • SOX
  • ITGC
  • Governance
  • Security Threats
Tools & Technologies
  • Jira
  • Confluence
  • SharePoint
  • Microsoft Office
  • Power BI
  • Tableau
  • Archer
  • ServiceNow IRM
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, IT & Cybersecurity
Director, IT & Cybersecurity

Jobtailor • Toronto

On-site
CAD 150,000 - 190,000
IT Governance, Risk, and Compliance Analyst
IT Governance, Risk, and Compliance Analyst

Jobtailor • Ottawa

On-site
CAD 90,000 - 120,000
Information Security Analyst
Information Security Analyst

Jobtailor • Toronto

On-site
CAD 70,000 - 110,000
Chief Information Officer
Chief Information Officer

Jobtailor • Toronto

On-site
CAD 180,000 - 280,000
Senior Security Specialist – Cloud
Senior Security Specialist – Cloud

Jobtailor • Toronto

On-site
CAD 110,000 - 150,000
Senior Infrastructure Security Specialist
Senior Infrastructure Security Specialist

Jobtailor • Toronto

On-site
CAD 110,000 - 160,000
Manager II, Governance & Control
Manager II, Governance & Control

Jobtailor • Mississauga

On-site
CAD 90,000 - 120,000
Senior Information Security Analyst
Senior Information Security Analyst

TD Bank Group • Toronto

Hybrid
CAD 90,000 - 130,000
Senior Project Manager, Cloud Services
Senior Project Manager, Cloud Services

Jobtailor • Surrey

On-site
CAD 120,000 - 180,000
IT Security Advisor (Senior)
IT Security Advisor (Senior)

CoFoMo Inc. • Montreal (administrative region)

Hybrid
CAD 110,000 - 150,000