Analyst I, Cyber Threat and Vulnerability Management

4 months ago


Toronto, Canada Toronto District School Board Full time

**Permanent, full-time position - Toronto, ON**

Reporting to the Senior Analyst, IT Security Threat Management, the Analyst I, Cyber Threat and

Vulnerability Management, will assist the Senior Analyst to ensure that the Cyber Threat and

Vulnerability Management functions are managed and carried out.

The Analyst I, Cyber Threat and Vulnerability Management, will ensure that the Cyber Threat and

Vulnerability functions are managed in accordance with the TDSB security and risk tolerance including the functions to ensure safety and security of the users along with availability, confidentiality and

integrity of the technology assets including the data contained within.

**PRIMARY DUTIES**

More specifically, as the Analyst I, Cyber Threat and Vulnerability Management, you will:

- Perform Cyber Threat and Vulnerability management tasks in accordance with established

programs and directed by the Senior Analyst;
- Conduct regular review of Indicators of Attack (IoAs) and Indicators of Compromise (IoCs)

derived from all available sources (e.g., SIEM, NGFW, Logs from Systems and Security Tools) to

assess the real and material threats and vulnerabilities;
- Perform ethical hacking activities on the direction of management as well as perform

programming and related scripting duties;
- Tune the SIEM to recognize real and actionable threats from security information and events

collected;
- Create playbooks to automate the response for actionable threats, and link them to risk objects;
- Optimize the collection, processing, and analysing parameters to improve the efficiency of the

SIEM;
- Create and evolve new/existing rules in the SIEM to accommodate new and evolving threats;
- Collaborate/Support with/to other IT units to assess, neutralize and reconcile threats and

vulnerabilities, and report deviation;
- Perform proactive threat hunting in a systemic and iterative manner throughout the environment to detect and isolate threats;
- Perform threat-based risk assessments on systems and services and effectiveness of controls;
- Assess discovered/identified/obtained through subscribed feeds threat/vulnerability impact, and recommend appropriate actions to reduce exposure and ensuring risks remains within the tolerance levels;
- Review, develop and report on appropriate metrics for the Threat/Vulnerability Management

solutions, performance, exception and compliance, and ensure continuous improvements of such metrics and its affects;
- Track and report threat and vulnerability mitigation efforts;
- Develop and document guidelines, processes and procedures for review and approval, and

implement approved procedures to secure IT environment;
- Liaise between departments to develop and implement approved security standards and

guidelines;
- Raise awareness of good security practices to all levels of the organization, and perform security

awareness and learning duties as directed;
- Analyze and define training requirements in security matters related to Cyber Threat and

Vulnerability management for staff;
- Analyze and help define appropriate controls to manage Cyber risks for approval;
- Identify controls that require changing/adding based on the changes to the IT environment;
- Maintain broad awareness of threat and vulnerability trends including changes to legislations and regulatory frameworks;
- Advise on security practices for all IT projects as required;
- Other related duties as assigned.

**QUALIFICATIONS**

To take on the role of the **Analyst I, Cyber Threat and Vulnerability Management**, you must have:

- University degree in Computer Science or related field with three years’ progressive working experience in IT security/threat management within an Information Technology environment or an equivalent combination of education and experience;
- Training and/or technical certification in Global Information Assurance in the following areas: Security Essentials, Information Security Fundamentals, Threat Hunting, Penetration Testing, Intrusion Analysis, Forensic Analysis, Perimeter Defense, Enterprise Defense, System and Network Auditing;
- Experience in monitoring threat landscape, mapping potential applicable threats, and ethical hacking methodologies and tolls;
- Experience using Splunk SIEM technologies (Splunk enterprise security administration and management), O365 Security technologies, end-point detection and Response (EDR) technologies;
- Experience with Azure technologies, and security products;
- Maintain currency of knowledge on current and emerging security trends, including, but not limited to, cloud-based services, IoT, etc.;
- Demonstrated ability to understand the implications of legislation, insurances and regulatory frameworks;
- Understanding of IT information, process, system, technology architectures and models;
- Good oral, written, interpersonal and organizational skills;
- Strong analytical, reasoning and problem-solving skills;
- Demonstrated ability to handle matters requiring



  • Toronto, Canada Mastercard Full time

    Our Purpose We work to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments and businesses realize their greatest potential. Our...


  • Toronto, Canada Tundra Technical Solutions Full time

    We are seeking a highly skilled Cyber Security Threat Analyst to join our team at Tundra Technical Solutions. As a key member of our Cyber Security Services team, you will play a critical role in ensuring the security and integrity of our clients' networks and systems.About the RoleThis is a 10-month contract position with the possibility of extension,...


  • Greater Toronto Area, Canada AutoTrader.ca Full time

    Summary A cybersecurity and vulnerability analyst is responsible for identifying, analyzing, and mitigating cyber threats and vulnerabilities that affect the organization's information systems and assets. The analyst also performs security audits, risk assessments, and compliance reviews to ensure that the organization follows the best practices and...

  • Cyber Analyst

    7 months ago


    Toronto, Canada IMCO Full time

    At IMCO, our talent is among the best! IMCO offers a uniquely stimulating and rewarding environment where you can help build and drive organizational transformation, all while seeking to challenge yourself, learn, and grow your career. We offer a culture of collaboration and passion, creating unwavering value for the clients we serve. Our vision is to be...


  • Toronto, Canada Canada Life Assurance Company Full time

    Cyber Threat Intelligence Specialist **Description: - Permanent Full Time**Great-West Lifeco** **Inc.** (Lifeco) is an international financial service holding company with interests in life insurance, health insurance, retirement and investment services, asset management, and reinsurance businesses. Lifeco has operations in Canada, the United States, Europe...


  • Toronto, Canada Questrade Financial Group Full time

    Questrade Financial Group (QFG) of Companies is committed to helping our customers become much more financially successful and secure. We are everything a traditional financial institution is not. At QFG, you will be constantly moving forward, bringing the future of fintech into existence. You will be a part of a collaborative team that cares deeply about...

  • Cyber Security Analyst

    7 months ago


    Toronto, Canada Roots Full time

    Roots is more than just an/the iconic Canadian retailer, we are a group of passionate employees who act with integrity, trust each other, and do what is right. We work in a space where people can grow and develop, with a team of people who own results and are dedicated to seeing Roots win. We seek to build longstanding relationships with partners who share...


  • Toronto, Canada Scotiabank Full time

    Requisition ID: 195827 Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture. Reporting to the Senior Manager of CTI, the Cyber Threat Intelligence Associate will provide technical expertise and analysis for the proactive and reactive responses to information security threats against Scotiabank. You will...


  • Toronto, Canada VortalSoft Usa Full time

    Conduct comprehensive risk assessments to identify potential security threats and vulnerabilities within the organization’s systems and processes. Policy development, compliance management, training, incident management. Pay: $40.00-$45.00 per hour Expected hours: 40 per week **Benefits**: - Dental care - Extended health care - Paid time...

  • Cyber Threat Hunter

    6 months ago


    Toronto, Canada Scotiabank Full time

    Requisition ID: 192987 Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture. **The Role** Reporting to the _Director of Cyber Threat Evaluation Center (CyTEC)_, the _Cyber Threat Hunter_ role within the _Cyber Threat Modelling_ team is responsible for identifying and assessing cyber-security and insider...


  • Toronto, Ontario, Canada Royal Bank of Canada Full time

    About the Opportunity">We are seeking an experienced Cyber Security professional to lead our Vulnerability Management Integration efforts. This role involves collaborating with internal and external stakeholders to achieve strategic objectives, leveraging industry-relevant qualifications and certifications in cyber security.">Key Responsibilities">">Lead the...


  • Toronto, Canada Royal Bank of Canada Full time

    Job Summary ...

  • Security Specialist

    4 months ago


    Toronto, Canada Softline Technology Full time

    Description Responsibilities Assesses internal and external threats and vulnerabilities of information systems and resources and the likelihood of these threats and resulting impacts. Where possible, reduce risks through system or organizational design. Implement security measures to prevent or mitigate, detect and respond to security threats and...


  • Old Toronto, Canada nugget Full time

    About the RoleWe are seeking a highly skilled Cyber Security Threat Modeler to join our team. As a key member of our security team, you will be responsible for identifying and mitigating potential threats to our cloud-based systems.Responsibilities:Work closely with cross-functional teams to identify potential vulnerabilities and introduce solutions to...


  • Toronto, Canada Royal Bank of Canada> Full time

    Job SummaryJob DescriptionWhat is the opportunity?We are looking for an energetic and enthusiastic technology infrastructure professional with curiosity and a passion for Vulnerability Management. We are a team of System Administrators and platform support specialists searching for an eager go-getter who wants to take charge and be a dependable team player...


  • Toronto, Ontario, Canada Royal Bank of Canada Full time

    About the Role">We are seeking a highly skilled Cyber Security Integration Lead to join our team at Royal Bank of Canada. As a key member of our cybersecurity department, you will be responsible for leading the integration of Infrastructure and Application vulnerability management across RBC and subsidiaries.">Key Responsibilities">">Lead the integration of...


  • Toronto, Canada ThoughtStorm Inc Full time

    The proposed resources must have a minimum of two years of experience conducting Threat Risk Assessments in Ontario and/or Canada and in a health care context based on PHIPA or other provincial health legislation. Deliverable - Participate in a kick-off/scoping meetings - provide a list of documents required from client required for conducting the TRA -...


  • Toronto, Canada Royal Bank of Canada Full time

    Job Summary ...


  • Toronto, Canada Mastercard Full time

    Our Purpose We work to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments and businesses realize their greatest potential. Our...


  • Toronto, Canada TD Bank Full time

    **Information Security Specialist (Cyber Threat Matrix)**: - 425216BR **Job Category - Primary** - Technology Solutions **Work Location** - 310-320 Front Street West Corporate **Employment Type** - Regular **City** - Toronto **Time Type** - Full Time **Province/State** - Ontario **Hours** - 37.5 **Workplace Model** - Hybrid **Pay...