19 Aug
|
Dexian
|
Toronto
Job Title: Information Security
Location: Toronto, ON
Work Mode : Hybrid – 2 days
Contract: 3 months
Role Overview
We are looking for a senior Information Security / Cyber Risk professional with strong experience in third-party/vendor risk assessments . The person will be responsible for leading cyber security assessments of suppliers and vendors, identifying potential security risks, and working with stakeholders to develop and implement appropriate remediation plans.
Key Responsibilities
- Lead and manage third-party cyber risk assessments for new and existing vendors.
- Coordinate with internal risk, security, technology, and business stakeholders to define assessment scope and requirements.
- Review vendor security controls, processes, policies, and risk information.
- Identify cyber security risks, control gaps, and vulnerabilities .
- Provide recommendations and guidance to reduce identified risks.
- Develop and coordinate risk mitigation and remediation plans .
- Validate that remediation activities have been completed effectively.
- Prepare and communicate assessment findings to both technical and non-technical stakeholders .
- Work directly with external vendors/suppliers when required.
- Ensure assessments align with internal security policies, technology control standards, regulatory requirements, and industry best practices.
- Support process improvement and initiatives related to technology risk management.
- Act as a subject matter expert on Information Security, Cyber Risk, and Technology Controls .
Must-Have Skills
- 10+ years of experience in Third-Party Cyber Risk / Vendor Risk Assessments .
- Strong knowledge of Information Security, IT Risk, Cyber Risk,
and Technology Controls .
- Experience leading complex security assessments and projects.
- Strong understanding of security frameworks, controls, and risk management practices.
- Ability to independently assess risks and provide practical remediation recommendations.
- Robust written and verbal communication skills.
- Strong stakeholder management and collaboration skills.
- Ability to communicate effectively with both technical and business audiences.
Nice to Have
- CISSP or another relevant Information Security certification.
- Experience within banking, financial services, or other highly regulated environments .
- Experience with enterprise-level third-party/vendor risk management programs.
Dexian is a leading provider of staffing, IT, and workforce solutions with over 12,000 employees and 70 locations worldwide. As one of the largest IT staffing companies and the 2nd largest minority-owned staffing company in the U.S., Dexian was formed in 2023 through the merger of DISYS and Signature Consultants. Combining the best elements of its core companies, Dexian's platform connects talent, technology, and organizations to produce game-changing results that help everyone achieve their ambitions and goals. Dexian's brands include Dexian DISYS, Dexian Signature Consultants, Dexian Government Solutions, Dexian Talent Development and Dexian IT Solutions. Visit https://dexian.com/ to learn more. Dexian is an Equal Opportunity Employer that recruits and hires qualified candidates without regard to race, religion, sex, sexual orientation, gender identity, age, national origin, ancestry, citizenship, disability, or veteran status
📌 Information Technology Security Analyst (Toronto)
🏢 Dexian
📍 Toronto