Senior Analyst, IT Security, Risk and Audit Management (Permanent) (Etobicoke)

Senior Analyst, IT Security, Risk and Audit Management (Permanent) (Etobicoke)

02 Sep
|
Toronto District School Board
|
Etobicoke

02 Sep

Toronto District School Board

Etobicoke

Working at the TDSB

Our staff members are the backbone of our system. Becoming a part of the TDSB team means joining a talented community of educators and support staff dedicated to enriching the lives of all students and helping them to achieve success.

The TDSB is one of the largest and most culturally diverse school boards in Canada, with approximately 246,000 students in 584 schools and approximately 40,000 employees. We offer a dynamic, challenging work environment and unmatched career opportunities for our staff.

Please review the information provided and explore the exciting career possibilities the TDSB has to offer as we continue to establish ourselves as the leading school board of the new millennium.

The Toronto District School Board adheres to equitable hiring and employment practices. We strive to meet the accommodation needs of persons with disabilities. Applicants are encouraged to make their needs for accommodation known in advance during the application process.

No.: SCH II-26-2048NE

POSTED: August 31, 2026

DEADLINE: 4:30 p.m. September 22, 2026

Senior Analyst, IT Security, Risk and Audit Management

1 – Permanent Position

Information Technology and Information Management

Schedule II, Level 8

(Non-Union, 12 Month)

$108,205 - $129,846

The Toronto District School Board adheres to equitable hiring, employment and promotion practices.

Overall Purpose

Reporting to the Manager, Cyber Security & Risk Management, the Senior Analyst, IT Security, Risk and Audit Management is responsible for managing IT security risks, supporting compliance and security assurance activities, and developing cyber security governance controls, including policies, procedures, and guidelines.

The Senior

Analyst will contribute to the strategic planning, design, development, and implementation of cyber security risk management, audit, awareness and learning, and incident management programs, and serve as a key contributor to cyber security governance and the overall cyber security program at TDSB.

Summary of Duties

- Perform IT cyber security risk assessments and develop programs to ensure availability, integrity and confidentiality expectations are met, incorporating reactive and proactive security measures, including secure AI/ML use.
- Support the Governance, Risk, and Compliance (GRC) program by identifying, assessing, and monitoring cybersecurity risks, and contributing to the implementation of security controls and compliance activities.
- Develop and maintain the cyber security incident management program and coordinate the response, remediation, and resolution of all cyber security incidents and breaches.
- Develop and maintain cyber security risk management processes to meet service level expectations and ensure integration with IT operational processes to detect and prevent cyber security risk.
- Develop and implement cyber security audit program; conduct security, risk, compliance, and privacy audits to assess controls, identify risks, and ensure alignment with Board policies, procedures and legislative requirements.
- Develop and manage cyber security awareness and learning program.




- Collaborate with IT Project teams to identify and address cyber security risk items and mitigation control recommendations.
- Develop and maintain cyber security program policies, standards and guidelines.
- Research, evaluate, recommend, and implement cyber security solutions that will mitigate TDSB specific security and risks, and address emerging trends and new developments.
- Develop and report on performance metrics for cyber security services and risk management.
- Report security exposures and implement mitigation controls as required.
- Collaborate with IT operational units to implement and track cyber security audit issues.
- Provide supervision and technical leadership for cyber security, risk, and audit initiatives, including work planning, task prioritization, resource coordination, mentorship, monitoring project deliverables, providing guidance to team members and IT stakeholders, and reviewing performance and disciplinary actions as required.
- Present cyber security topics, research, reports, risk items at various forums and committees.
- Stay current on cyber security threats, technologies, security solutions, certifications, and industry trends through continuous learning and ongoing professional development.
- Participate in architecture, procurement, and vendor review processes to ensure security requirements are incorporated into technology solutions.
- Provide leadership in fostering equity and inclusiveness in the development and implementation of programs and services.
- Other duties as assigned.

Qualifications

- University Degree in Computer Science or related field with five years progressively responsible related working experience in information security in a large public sector environment or an equivalent combination of education and experience.
- Training and technical certification in Global Information Assurance in the following areas: Security Leadership, Information Security, Perimeter Protection, Enterprise Defence, Critical Controls, System and Network Auditing, and Artificial Intelligence.
- Experience conducting cyber security risk assessments, developing risk management methodologies, performing cyber security audits, and reporting findings to management.
- Experience developing and managing third-party and audit-based cyber security risk management programs, including vendor risk assessments, methodologies, risk reassessments, and mitigation techniques.
- Knowledge of cyber security risks associated with AI/ML technologies and the ability to recommend appropriate security controls.
- Thorough knowledge of cyber security frameworks (e.g., NIST CSF, ISO 27001/27002), including experience implementing and managing Governance, Risk and Compliance (GRC) modules.
- Demonstrated ability to develop cyber security policies, standards, guidelines,



and related security
- Experience developing and managing cyber security incident management programs, including incident response playbooks, tabletop exercises, incident lifecycle management, and post-incident review.
- Experience developing and delivering cyber security awareness and learning programs.
- Hands-on technical experience with networking, IT infrastructure and operations, application programming, databases, operating systems, and cloud technologies, along with an understanding of information systems, business processes, and security architectures (e.g., Azure/AWS).
- Experience reviewing cyber security requirements within TDSB legal requirements/documentation including MSAs, NDAs, and similar agreements.
- Experience and knowledge of cyber security and privacy legislations (e.g., EDTSA, MFIPPA).
- Knowledge and experience in project management methodologies, workload planning, documentation and performance standards.
- Supervisory experience with strong leadership, mentoring and team building skills.
- Excellent verbal and written communication, presentation and interpersonal skills.
- Strong analytical, reasoning, problem-solving and organizational skills.
- Proven ability to manage multiple priorities, meet deadlines, and work under pressure.
- Demonstrated ability to handle matters requiring diplomacy, sensitivity and confidentiality.
- Proven ability in promoting equitable practices which value inclusiveness and diversity.

Special Requirements

- Provision of own vehicle for Board business.
- Requires travel across TDSB sites.

Additional Information

Assets:

- Certifications in CISSP, CISM, CISA, CRISC, CEH, CCSP, SABSA, TOGAF, and Microsoft Azure.
- AI-related training.

Work Year: 12 Months, Hybrid Work Eligible

Location: 1 Civic Centre/140 Borough Drive, Wheelchair Accessible

Only applicants selected for an interview will be contacted. Applications will not be acknowledged in writing.

The Toronto District School Board is deeply committed to promoting Truth, Reconciliation and the rights of Indigenous peoples, Human Rights, Equity and Anti-Racism, and the elimination of Oppressive Practices, in our schools, our workplace and in the communities we serve. We strongly encourage applications from all individuals including those with varied lived experiences that can contribute to the diversification of the workforce at TDSB.

We strive to meet the accommodation needs of persons with disabilities. Applicants are encouraged to make their needs for accommodation known in advance during the hiring process.

The TDSB follows a hybrid work structure where some employees may be able to work remotely at times, based on operations requirements. Please refer to Policy P103, Adaptable Working Arrangements for more information.

TDSB uses artificial intelligence (AI) tools to support parts of the recruitment process, including the initial review of applications. These tools operate based on predefined criteria and do not make final hiring decisions. If you have questions or concerns about the use of AI in the recruitment process, please contact [email protected].

📌 Senior Analyst, IT Security, Risk and Audit Management (Permanent) (Etobicoke)
🏢 Toronto District School Board
📍 Etobicoke

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior analyst, it security, risk and audit management (permanent) (etobicoke) / etobicoke

Subscribe to this job alert:

Get the latest job offers by email for: senior analyst, it security, risk and audit management (permanent) (etobicoke) / etobicoke