18 Sep
|
AceStack
|
Montreal
Job Title: Security Risk Analyst Job Type: Full Time Location: Montreal, QC (Hybrid) Job Description We are seeking a skilled Security Risk Analyst to assess, measure, and enhance the effectiveness of cybersecurity controls across the organization.
The ideal candidate will have strong experience in cybersecurity risk assessment, security controls, compliance, risk monitoring, and reporting .
The Security Risk Analyst will be responsible for identifying control gaps, evaluating risk exposure, validating compliance with security policies and regulatory requirements, and providing actionable recommendations to strengthen the organization''s overall cybersecurity posture. A key focus of this role will be Metrics, Reporting, and Continuous Monitoring , including the development and tracking of Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) to measure control effectiveness and proactively identify potential security risks.
Key Responsibilities Assess and evaluate the effectiveness of cybersecurity controls across the organization.
Identify control gaps, weaknesses, and areas of risk exposure.
Perform security risk assessments and provide actionable recommendations for risk mitigation.
Validate compliance with organizational security policies, standards, and regulatory requirements.
Support Continuous Control Monitoring (CCM) initiatives to identify and address control deficiencies.
Develop, monitor, and maintain KRIs and KPIs to measure cybersecurity and control effectiveness.
Create dashboards, metrics,
and reports for leadership, audit, and regulatory reviews.
Analyze security risk trends and proactively identify emerging risks.
Collaborate with cybersecurity, IT, compliance, audit, and business teams to strengthen the control environment.
Track remediation activities and ensure identified control gaps are appropriately addressed.
Support internal and external audits by providing risk assessments, control evidence, metrics, and reporting.
Continuously recommend improvements to cybersecurity controls, processes, and risk management practices.
Required Skills & Experience Strong experience in cybersecurity risk management and security control assessment.
Knowledge of cybersecurity frameworks, security policies, and regulatory requirements.
Experience identifying control gaps and evaluating cybersecurity risk exposure.
Hands-on experience with KRI/KPI development, metrics, reporting, and continuous monitoring .
Experience supporting Continuous Control Monitoring (CCM) programs.
Strong analytical and problem-solving skills with the ability to translate findings into actionable recommendations.
Experience developing dashboards and management reports for leadership and audit stakeholders.
Robust communication and stakeholder management skills.
Ability to work effectively with cybersecurity, technology, compliance, audit, and business teams.
Job Details Job Type: Full Time Location: Montreal, QC Work Model: Hybrid
📌 Security Risk Analyst (Montreal)
🏢 AceStack
📍 Montreal