Security Risk Analyst (Toronto)

Security Risk Analyst (Toronto)

07 Aug
|
vTech Solution
|
Toronto

07 Aug

vTech Solution

Toronto

Job Summary: The Senior Security Specialist is responsible for leading comprehensive Threat Risk Assessments (TRA) to evaluate and enhance the security posture of information systems, applications, infrastructure, and business processes.

This role involves identifying potential threats, assessing vulnerabilities, and recommending risk mitigation strategies aligned with regulatory and organizational standards.

The specialist collaborates with stakeholders, produces detailed reports, and supports continuous improvement in risk management practices.

Responsibilities: Drive end-to-end Threat Risk Assessment initiatives across systems, processes, and assets.

Develop and apply threat models to assess organizational security posture.

Collaborate with business and technical stakeholders to align assessments with objectives and risk tolerance.

Analyze vulnerabilities and assess threats to determine likelihood and impact.

Produce detailed TRA reports documenting findings, risk ratings, and mitigation recommendations.

Maintain risk registers and track remediation efforts.

Propose actionable mitigation strategies based on assessment outcomes.

Ensure compliance with regulatory requirements, industry standards, and organizational security policies.

Communicate findings effectively to technical teams and executive leadership.

Support audit and compliance activities as needed.

Contribute to continuous improvement of risk management frameworks and methodologies.

Stay informed on emerging threats, vulnerabilities, and security best practices.





Required Skills & Certifications: 5 7 years of experience in Risk Management & Assessment using frameworks such as ISO 31000, NIST RMF, or FAIR. 3 5 years of practical knowledge in threat modeling techniques (e.g., STRIDE, PASTA, MITRE ATT&CK;) including data flow diagrams and attack vectors. 5+ years of experience in Information Security Governance aligned with ISO 27001, NIST CSF, and CIS Controls. 5+ years of strong communication and reporting skills, including writing technical and executive-level reports, risk registers, and delivering presentations to stakeholders and leadership.

Proficiency in using risk assessment matrices and conducting gap analyses.

Familiarity with legal, regulatory, and compliance requirements such as PHIPAA.

Preferred Skills & Certifications: Experience with additional threat modeling methodologies like DREAD and PASTA.

Hands-on expertise in cybersecurity governance practices and policy development.

Ability to translate technical risk findings into clear business language.

Experience in public sector security environments.

Proactive mindset with situational awareness to anticipate emerging threats.

Special Considerations: Hybrid work environment with up to 3 days onsite at manager''s discretion.

Role may require collaboration across multiple teams and stakeholders.

Robust emphasis on adherence to regulatory and organizational security policies.

Scheduling: Work schedule is flexible within a hybrid model, balancing onsite and remote work as determined by management.

📌 Security Risk Analyst (Toronto)
🏢 vTech Solution
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security risk analyst (toronto) / toronto

Subscribe to this job alert:

Get the latest job offers by email for: security risk analyst (toronto) / toronto