- Provide consultation and advice on technology controls and information security programs, policies, standards, and incidents- Conduct project consulting on risk assessments, control requirements, control procedures, vulnerability assessments, and related areas- Lead or contribute to risk and control assessments for application portfolios- Document control gaps, business and enterprise impact, risk mitigation, and remediation plans- Contribute to global security management strategy and framework development and oversight- Ensure technology, processes, and governance monitor, detect, prevent, and respond to security threats- Develop technology risk reporting, monitor trends, and define control-effectiveness metrics- Work with technology partners, stakeholders, and service/platform owners to integrate security components into enterprise architecture- Consult on regulatory compliance requirements, reporting, and questions- Support audits, management responses, and remediation activities- Participate in computer security incident response- Define, develop, implement, and manage technology controls/information security policies, programs, tools, and solutions- Review internal processes, identify improvement opportunities, and advise on enterprise frameworks and methodologies- Manage relationships across technology, business, corporate, and control functions- Participate as a subject matter expert in business-specific, cross-functional, and enterprise initiatives- Prepare complex reporting, analysis, and assessments- Document and update internal processes- Manage workload, deliver quality results, and meet timelines- Establish relationships with business and technology partners, program managers, and project managers- Participate in knowledge transfer within teams and business unitsRequirements- University degree- 5–7 years of relevant experience- Advanced knowledge of one or more technology controls/security domains, disciplines, and practices- Familiarity with industry-standard frameworks, including NIST CSF/800-53, ISO 27001,
COBIT, CIS, PCI, GLBA, and SOX/ITGC- Ability to identify, assess, and monitor technology risks, including information security, cybersecurity, resilience, operations/change management quality, data quality/security, and IT compliance- Knowledge of technology, information and cybersecurity, risk management, and governance standards and best practices- Strong critical thinking and ability to decompose complex issues- Solid written, communication, and presentation skills- Ability to prioritize workload and meet timelines with limited guidance- Ability to multitask and manage multiple team and client demands- Proficiency with Jira, Confluence, SharePoint, and Microsoft Office- Data analysis experience, preferably using Power BI or Tableau- Familiarity with GRC platforms such as Archer and ServiceNow IRM- Information security certification/accreditation is an asset- Familiarity with Python and generative AI is an assetCore CompetenciesDemonstrates advanced knowledge of technology controls and information security practices, with a strong ability to assess and manage technology risks. Proficient in developing and implementing security policies, frameworks, and metrics while ensuring compliance with industry standards.Highest-signal resume keywords- Technology Controls Management- Risk Assessment and Mitigation- NIST CSF/800-53 Familiarity- Data Analysis with Power BI- Information Security CertificationHard Skills- Risk Management- Control Procedures- Vulnerability Assessment- Technology Risk Reporting- Information Security Policies- Cybersecurity- Data Quality/Security- IT Compliance- Critical Thinking- Process ImprovementSoft Skills- Strong Communication Skills- Presentation Skills- Ability to Multitask- Workload Prioritization- Relationship ManagementCertifications & Qualifications- Information Security CertificationIndustry Keywords- NIST CSF- ISO 27001- COBIT- CIS- PCI- GLBA- SOX- ITGC- Governance- Security ThreatsTools & Technologies- Jira- Confluence- SharePoint- Microsoft Office- Power BI- Tableau- Archer- ServiceNow IRM#J-18808-Ljbffr
📌 Information Security Analyst - $60,000 - $100,000 A Year (Toronto)
🏢 BDO
📍 Toronto