16 Sep
|
AceStack
|
Montreal
Security Risk Analyst
Location: Montreal, QC
Work Model: Hybrid
Employment Type: Full-Time
Job Summary
We are seeking an experienced Security Risk Analyst to assess, monitor, and enhance the effectiveness of cybersecurity controls across the organization. The role will focus on identifying control gaps, evaluating security and operational risks, validating compliance with internal policies and regulatory requirements, and providing actionable recommendations to strengthen the overall cybersecurity risk posture.
The ideal candidate will have strong experience in cybersecurity risk management, control assessment, metrics and reporting, continuous control monitoring, and governance, risk, and compliance (GRC).
Key Responsibilities
- Assess and evaluate the design and operating effectiveness of cybersecurity controls across infrastructure, applications, cloud, data, and endpoint environments.
- Identify control deficiencies, security gaps, and risk exposures, and recommend appropriate remediation actions.
- Perform risk assessments and support the identification, evaluation, prioritization, and treatment of cybersecurity risks.
- Validate compliance with internal security policies, standards, regulatory requirements, and industry frameworks.
- Support Continuous Control Monitoring (CCM) activities to proactively identify control weaknesses and emerging risks.
- Define, track, and report Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) related to cybersecurity controls and risk posture.
- Develop and maintain dashboards, scorecards, metrics, and management reports for leadership, audit, risk, and regulatory reviews.
- Analyze control and risk trends to identify recurring issues, emerging threats, and opportunities for improvement.
- Collaborate with Cybersecurity, IT, Risk, Compliance, Audit,
and business stakeholders to drive remediation and improve control effectiveness.
- Monitor remediation plans, track risk acceptance and exceptions, and provide regular status reporting to stakeholders.
- Support internal and external audits by providing control evidence, risk assessments, metrics, and documentation.
- Maintain accurate risk and control documentation, including control objectives, testing results, findings, remediation plans, and supporting evidence.
- Contribute to the continuous improvement of cybersecurity risk management processes, control frameworks, and reporting practices.
Required Skills & Experience
- Strong experience in Cybersecurity Risk Management, IT Risk, Security Controls, or GRC.
- Hands-on experience with control assessments, control testing, risk assessments, and gap analysis.
- Solid understanding of KRI/KPI development, cybersecurity metrics, dashboards, and management reporting.
- Experience with Continuous Control Monitoring (CCM) or continuous risk/control assessment.
- Knowledge of cybersecurity frameworks and standards such as NIST CSF, ISO 27001, CIS Controls, SOC 2, or similar.
- Understanding of security controls across cloud, network, infrastructure, applications, identity, and data environments.
- Experience supporting internal/external audits, regulatory assessments, and compliance activities.
- Strong analytical, documentation, communication, and stakeholder management skills.
- Ability to translate technical security risks and control findings into clear business-level recommendations.
Preferred Qualifications
- Experience with GRC platforms such as ServiceNow GRC, Archer, MetricStream, RSA Archer, or similar.
- Experience creating cybersecurity dashboards using Power BI, Tableau, or similar reporting tools.
- Relevant certifications such as CISA, CRISC, CISSP, CISM, or ISO 27001 are an asset.
- Experience within a financial services, banking, or highly regulated environment is preferred.
📌 Security Risk Analyst / Montreal, QC / Hybrid / Full-Time FTE
🏢 AceStack
📍 Montreal