Sr. Cybersecurity Analyst/Security Specialist

Randstad

Toronto

Hybrid

CAD 110,000 - 160,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Randstad Canada seeks a Sr. Cybersecurity Analyst (Security Specialist) to lead governance, risk, and compliance efforts from Toronto in a hybrid work setup. You will drive PIAs/TRAs, policy development, and vendor risk management across IT, cloud, and OT environments.

The role requires CISSP or CRISC certification, 7+ years in GRC, and deep knowledge of Canadian privacy regulations such as PHIPA, MFIPPA, and CASL. A multi-year contract with a substantial impact on security posture is offered.

Qualifications

  • University degree in Computer Science, Information Security, Cybersecurity, or a related field.
  • Active CISSP or CRISC certification.
  • 7+ years in Governance, Risk, and Compliance (GRC).
  • 5+ years of Privacy Impact Assessments (PIAs).
  • 10+ years of progressive Enterprise IT experience.
  • Extensive experience with NIST CSF, ISO/IEC 27001/27002, ISA/IEC 62443, NERC CIP, CIS Controls, and SOC2.
  • Strong knowledge of PHIPA, MFIPPA, CASL, CCSPA and related regulations.

Responsibilities

  • Conduct security and privacy risk assessments across information systems, networks, cloud environments, and OT.
  • Analyze existing controls, perform vulnerability evaluations, and assess architectures to identify risks.
  • Recommend actionable security controls and communicate findings to technical and business stakeholders.
  • Provide predictive analytics on cybersecurity and privacy risks to support strategic decisions.
  • Develop and refresh governance frameworks, standards, and procedures for enterprise security.
  • Design and implement controls to comply with Canadian privacy and security regulations.
  • Lead periodic gap assessments and remediation planning with leadership exposure.
  • Oversee third-party vendor due diligence and supplier risk inventory.
  • Review procurement documents for data protection terms and gaps.

Skills

GRC
CISSP
CRISC
PIAs
NIST CSF
ISO/IEC 27001
SOC2
Policy development
Contract risk

Education

University degree in Computer Science, Information Security, Cybersecurity, or related field

Tools

GRC tooling
Vendor risk tooling

Job description

We are seeking a highly accomplished Sr. Cybersecurity Analyst (Security Specialist) for an enterprise-level contract opportunity based in Toronto. In this role, you will take on a premier strategic capacity within cybersecurity governance, risk management, and regulatory compliance streams, specializing in identifying vulnerabilities, evaluating security architectures, and enforcing enterprise risk controls.

As a principal GRC specialist, you will bridge the gap between technical infrastructure, privacy legislation, and enterprise security frameworks. Operating within a hybrid work model, you will lead comprehensive security and privacy impact assessments (PIAs/TRAs), develop and refresh corporate cybersecurity policies, manage third-party vendor risk programs, and ensure strict alignment with industry security standards and Canadian privacy regulations. This position is tailored for a certified security authority (CISSP or CRISC) who can deliver actionable risk analytics, evaluate third-party vendor contracts, and govern compliance across IT, cloud, and operational technology (OT) environments.

Location: Toronto, ON

Assignment Type: Hybrid (2 to 3 days per week onsite)

Contract Duration: 24-month contract (with potential for 1-year extension)

Advantages
  • High-Impact Risk Leadership: Drive enterprise-wide Security Risk Assessments, Privacy Impact Assessments (PIAs), and Threat and Risk Assessments (TRAs).
  • Broad Framework Exposure: Govern compliance across leading standards including NIST CSF, ISO/IEC 27001/27002, ISA/IEC 62443, NERC CIP, CIS Controls, and SOC2.
  • Complex Multi-Environment Scope: Evaluate risk profiles across enterprise IT, cloud platforms, hybrid networks, and industrial/OT infrastructure.
  • Long-Term Enterprise Engagement: Secure a foundational multi-year contract runway with potential for further extension.
Responsibilities
  • Conduct comprehensive security and privacy risk assessments across new and existing information systems, network infrastructure, cloud environments, and operational technologies.
  • Analyze existing security controls, perform vulnerability evaluations, and assess technical architectures to identify threats and operational risks.
  • Formulate, document, and recommend actionable security controls to mitigate identified risks and communicate findings effectively to technical and business stakeholders.
  • Identify, assess, and monitor cybersecurity and privacy risks, providing predictive analytics to support strategic business decisions.
  • Develop, refresh, enhance, and communicate enterprise cybersecurity governance frameworks, policies, standards, and operational procedures.
  • Design technical, administrative, and physical security controls to ensure organizational compliance with Canadian privacy and cyber security legislation (PHIPA, MFIPPA, CASL, CCSPA).
  • Execute periodic gap assessments across the information security program, validate ongoing control compliance, facilitate remediation plans, and elevate critical issues to leadership.
  • Manage the security exception review and approval lifecycle, ensuring all risk acceptances are documented and re-evaluated on a defined schedule.
  • Perform initial and ongoing third-party vendor security due diligence, vendor risk monitoring, and maintain the enterprise supplier risk inventory.
  • Review information security and privacy clauses within procurement documents (RFIs, RFPs, MPSAs, contracts, and purchase orders) to identify gaps and enforce data protection terms.
  • Provide expert GRC advisory services across enterprise projects, IT initiatives, and technology modernization programs.
Qualifications
Core Requirements & Mandatory Certifications
  • Education: University degree in Computer Science, Information Security, Cybersecurity, or a related field (or an equivalent combination of education and professional experience).
  • Mandatory Professional Certification: Active credential in at least one of the following:
    • Certified Information Systems Security Professional (CISSP)
    • Certified in Risk and Information Systems Control (CRISC)
  • GRC Experience: 7+ years of relevant cybersecurity experience focused on Governance, Risk, and Compliance (GRC).
  • Privacy Impact Assessments: 5+ years of hands-on experience conducting Privacy Risk Assessments and Privacy Impact Assessments (PIAs).
  • Enterprise IT Experience: 10+ years of progressive Information Technology experience.
  • Security Framework Depth: Significant experience applying enterprise security frameworks and standards, such as NIST CSF, ISO/IEC 27001/27002, ISA/IEC 62443, NERC CIP, CIS Controls, and SOC2.
  • Policy & Governance Development: Demonstrated experience developing, refreshing, and implementing cybersecurity policies, standards, guidelines, and procedures.
  • Canadian Regulatory Mastery: In-depth understanding and practical application of Canadian privacy and security legislation, including PHIPA, MFIPPA, CASL, Critical Cyber Systems Protection Act (CCSPA), and related digital security acts.
Preferred Technical & Architecture Skills
  • Architecture & Infrastructure Depth: Strong background in enterprise IT and Security Architecture, spanning cloud, hybrid, and OT/industrial operational environments.
  • Networking & Protocols: Solid understanding of networking principles (TCP/IP, WAN/LAN) and core security/internet protocols (SMTP, HTTP, FTP, LDAP, SAMLv2, OAuth, SSL/TLS).
  • Vendor & Contract Risk: Direct experience evaluating vendor risk, reviewing RFP/contractual security terms, and utilizing GRC risk management tooling.
Soft Skills & Professional Attributes
  • Analytical Problem Solving: Superior diagnostic capabilities to evaluate complex risk scenarios, weigh costs versus benefits, and recommend pragmatic mitigations.
  • Consultative Communication: Exceptional written and verbal communication skills with meticulous attention to detail when presenting risk findings to diverse audiences.
  • Time Management & Adaptability: Proven ability to manage competing priorities, deliver under tight deadlines, and navigate fast-paced environments effectively.

Randstad Canada is committed to fostering a workforce reflective of all peoples of Canada. As a result, we are committed to developing and implementing strategies to increase the equity, diversity and inclusion within the workplace by examining our internal policies, practices, and systems throughout the entire lifecycle of our workforce, including its recruitment, retention and advancement for all employees. In addition to our deep commitment to respecting human rights, we are dedicated to positive actions to affect change to ensure everyone has full participation in the workforce free from any barriers, systemic or otherwise, especially equity-seeking groups who are usually underrepresented in Canada's workforce, including those who identify as women or non-binary/gender non-conforming; Indigenous or Aboriginal Peoples; persons with disabilities (visible or invisible) and; members of visible minorities, racialized groups and the LGBTQ2+ community.

Randstad Canada is committed to creating and maintaining an inclusive and accessible workplace for all its candidates and employees by supporting their accessibility and accommodation needs throughout the employment lifecycle.

This posting is for existing and upcoming vacancies.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cybersecurity GRC Analyst/ Security Specialist
Senior Cybersecurity GRC Analyst/ Security Specialist

Randstad • Toronto

On-site
CAD 120,000 - 160,000
Client Support Specialist - Work From Home
Client Support Specialist - Work From Home

American Income Life Insurance Company • Regina

Remote
CAD 110,000 - 150,000
Senior Communications Advisor, External Communications & Thought Leadership ( 18 month contract )
Senior Communications Advisor, External Communications & Thought Leadership ( 18 month contract )

mcd mc kesson canada la mc kesson canada • Mississauga

On-site
CAD 100,000 - 140,000
Director, Governance, Risk & Compliance (GRC)
Director, Governance, Risk & Compliance (GRC)

Robertson & Company Ltd. • Toronto

On-site
CAD 170,000 - 190,000
Sr. Cyber Security Analyst
Sr. Cyber Security Analyst

10 Percent Recruiting Ltd. • Canada

Hybrid
CAD 110,000 - 140,000
Lead, Strategic Communications (Hybrid)
Lead, Strategic Communications (Hybrid)

national bank • Toronto

Hybrid
CAD 85,000 - 110,000
Enterprise Security Specialist
Enterprise Security Specialist

Cprvision • Whitchurch-Stouffville

On-site
CAD 120,000 - 135,000
Flexible working arrangements
Comprehensive benefits package
Annual bonus program
+1
Senior Information Security, GRC Analyst
Senior Information Security, GRC Analyst

Cassels Brock & Blackwell LLP • Toronto

On-site
CAD 100,000 - 125,000
Extended Health & Dental Care
RRSP Matching
Fitness Reimbursement
+6
Senior Specialist Risk Management
Senior Specialist Risk Management

TEEMA • Toronto

On-site
CAD 126,000 - 176,000
Cyber Security Manager
Cyber Security Manager

Akkodis • Toronto

On-site
CAD 120,000 - 180,000
Performance-based bonuses
Defined contribution pension plan
Professional growth opportunities
+4