31 Aug
|
US Tech Solutions
|
Toronto
31 Aug
US Tech Solutions
Toronto
C$45-C$50 per hour
Toronto, ON
Contract
**Duration: 06 Months**
**Position Overview:**
We are seeking an experienced IT Security Governance Analyst to support the development and maintenance of cybersecurity governance, risk, compliance, audit, and reporting capabilities.
The successful candidate will help ensure that projects and operations comply with applicable cybersecurity policies, regulatory requirements, and industry standards, including PCI DSS, NIST, ISO 27001, privacy requirements, and applicable government policies.
The role will work closely with Cybersecurity, Risk & Compliance, Privacy, Procurement, Finance, IT Operations, and business stakeholders.
**Key Responsibilities**
**IT Security Governance & Compliance**
Support the development, implementation, and maintenance of IT Security Governance frameworks, policies, standards, and controls.
Ensure projects align with applicable IT security policies and requirements.
Maintain compliance with ISO 27001, NIST, PCI DSS, privacy requirements, and other applicable cybersecurity standards.
Provide cybersecurity governance guidance and subject matter expertise to business and technology teams.
Support security awareness and governance training initiatives.
**Cybersecurity Risk Management**
Identify, assess, document, and monitor cybersecurity risks across business applications and technology environments.
Work with Risk & Compliance and business stakeholders to understand risk appetite and develop appropriate risk treatment plans.
Escalate and report risks that exceed accepted risk thresholds.
Support the development and maintenance of cybersecurity risk registers and reporting.
**Third-Party Cyber Risk Management**
Support the design and implementation of a Third-Party Cyber Risk Management framework.
Conduct security and cyber risk assessments of third parties and vendors.
Identify appropriate security controls and requirements for third-party engagements.
Review vendor security assessments, attestations, SOC reports, and other security documentation.
Assess security control gaps and potential risks associated with third-party services.
Provide cybersecurity input into contracts, SLAs, renewals, and termination of vendor relationships.
Collaborate with Procurement, Vendor Management, Legal, and other stakeholders on third-party cybersecurity requirements.
**Security Audit & Assurance**
Support internal and external cybersecurity audits.
Assist with PCI audits, ISO 27001 assessments, internal audits, and CSAE 3416/SOC-related activities.
Coordinate audit evidence, documentation, findings, remediation activities, and reporting.
Monitor remediation of identified security and compliance gaps.
**Security Metrics & Reporting**
Develop and maintain cybersecurity KPIs, KRIs, dashboards, and performance reports.
Provide timely security governance and risk reports to senior management and other stakeholders.
Track security compliance and control effectiveness.
Support reporting on cybersecurity risks, audit findings, remediation, and governance performance.
**Asset & Information Risk Management**
Work with IT Operations and Risk & Compliance teams to maintain digital asset inventories.
Support identification, classification, ownership, and risk assessment of technology assets and business applications.
Ensure appropriate security, compliance, and risk requirements are associated with relevant assets.
**Stakeholder Management**
Build strong working relationships across business and technology teams.
Communicate cybersecurity governance requirements clearly to end users and stakeholders.
Provide security guidance and support to teams without direct supervisory responsibility.
Collaborate with Privacy, Records Management, Finance, Procurement, Vendor Management, IT Operations, and Risk & Compliance teams.
**Requirements:**
4–6 years of progressive experience in IT, cybersecurity, information security, risk, compliance, or a related discipline.
3–5 years of relevant cybersecurity / IT security experience, preferably within a Governance, Risk & Compliance environment.
Hands-on experience with cybersecurity risk management and security governance.
Experience with third-party/vendor cybersecurity risk assessments.
Experience supporting cybersecurity audits, compliance assessments, and remediation activities.
Experience developing security metrics, KPIs/KRIs, dashboards, and management reports.
Strong understanding of security controls, policies, risk assessment methodologies, and compliance requirements.
Experience working collaboratively with cross-functional business and technology teams.
**Technical / Functional Knowledge**
Solid knowledge or practical experience with:
ISO 27001
NIST Cybersecurity Framework
PCI DSS
Privacy and data protection requirements
IT Security Governance and GRC
Cybersecurity Risk Management
Third-Party / Vendor Risk Management
Security Controls and Control Assessments
Security Audits and Compliance
Security KPIs / KRIs and Management Reporting
IT Asset Inventory and Risk Classification
**Education**
Completion of a degree in Business, Engineering, Information Systems, Computer Science, Cybersecurity, or a related discipline.
A combination of relevant education, training, and professional experience may be considered equivalent.
**Certifications**
The following certifications are considered an asset:
CISSP – Certified Information Systems Security Professional
CISM – Certified Information Security Manager
CISA – Certified Information Systems Auditor
CRISC – Certified in Risk and Information Systems Control
CGEIT – Certified in the Governance of Enterprise IT
Other relevant cybersecurity, risk, audit, or governance certifications.
Agile certifications such as Agile Certified Professional (ACP) or Certified Scrum Product Owner (CSPO) are also considered an asset.
**Additional Assets**
Experience supporting IT project delivery or IT Operations.
Experience within a regulated, public-sector, financial services, payments, or transportation environment.
Experience working with enterprise cybersecurity governance frameworks.
Experience working with senior management, audit, procurement, and external vendors.
**Key Competencies**
Cybersecurity Governance
Risk Management
Third-Party Risk Management
Security Compliance
**Audit & Assurance**
Policy & Control Management
Security Metrics & Reporting
Stakeholder Management
Analytical & Problem-Solving Skills
Strong Written and Verbal Communication
Ability to work independently and collaboratively
**About US Tech Solutions** :
US Tech Solutions is a global staff augmentation firm providing a wide range of talent on-demand and total workforce solutions.
To know more about US Tech Solutions, please visit
www.ustechsolutions.com.
US Tech Solutions is an Equal Opportunity Employer.
All qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
**AI Statement:**
By applying, you acknowledge that AI-assisted tools may be used during hiring.
#LI-AS140
📌 Security Analyst – Intermediate # 26-21779 (Toronto)
🏢 US Tech Solutions
📍 Toronto