IT Security Risk Analyst

3 days ago


Richmond Hill, Canada Onico Solutions Full time

The IT Security Risk Analyst supports the Information Security Risk Management and Governance programs. They work with technology and business stakeholders to identify Information Security risks, conduct risk assessments, recommend risks mitigation strategies, and monitor identified risks throughout its lifecycle. They also update and monitor Key Performance Indicators (KPI’s), Key Risk Indicators (KRI’s), Service Level Agreements (SLA’s), and other documentation related to the Information Security program. They contribute to the creation of management reporting to convey the status of Information Security risks and governance metrics across the organization.

This role requires an experienced subject matter expert who has in-depth understanding of Information Security controls across a broad range of technologies and platforms.

Responsibilities

- Identification, assessment and monitoring of Information Security risks.
- Recommendation of compensating controls to reduce inherited risk to an acceptable level.
- Development and maintenance of Information Security risk and governance KPI’s, KRI’s, and SLA’s.
- Support for security audits, prioritization and remediation of identified gaps.
- Creation and maintenance of Information Security policies and other risk and governance documentation
- Implementation and operation of risk and governance technology tools and processes
- Collaboration with different stakeholders to manage Information Security risks in a timely matter

Requirements

- 3+ years of experience with IT Security Risk Management/Risk Assessments
- 3+ year of experience with IT Security policies, standards, procedures and guidelines
- Experience working with and managing external vendors
- Strong knowledge of Information Security controls for Mobile, IoT, Cloud, Applications, Network and System infrastructure
- Excellent knowledge of security technologies which are commonly used in enterprises to protect information systems, both on premise and in the Cloud. Hands-on design, implementation and management of variety security technologies are strong assets.
- Working knowledge of Information Security and Risk Management frameworks like ISO27001, ISO27005 and NIST CSF and NIST 800-30
- Understanding of legal and regulatory compliance standards and requirements like PCI-DSS and PIPEDA
- CISSP, CISA, CRISC and other security certifications are a strong asset.

This is a permanent position located in Toronto (work from home until deemed safe).

#J-18808-Ljbffr



  • Richmond Hill, Canada Onico Solutions Full time

    A leading IT security firm in Richmond Hill is looking for an IT Security Risk Analyst to support their Information Security Risk Management programs. The role requires expertise in risk assessments and strong knowledge of security technologies. Responsibilities include identifying risks, recommending mitigation strategies, and collaborating with...


  • Richmond Hill, Canada City of Richmond Hill Full time

    Posting Id - 3044 - Department - Corporate and Financial Services - Division - Information Technology - Rate of Pay - $103,967.00 -$120,603.00 Annual - Job Type - Permanent Full Time - Replacement/New Position - New Hire - Posting Type - Internal and External - Posting Date - 07/07/2025 - Application Deadline - 07/21/2025 **Position Summary**: Reporting to...


  • Richmond Hill, Canada Onico Solutions Full time

    The IT Security Analyst is responsible for managing risk related to information technology (IT) security consistent with our client’s business objectives. Responsibilities - Develop and update information security frameworks (policies, guidelines and standards) - Perform security threat and risk analysis (TRA) - Evaluate, document and follow up on...

  • Security Analyst

    3 days ago


    Richmond Hill, Canada Onico Solutions Full time

    The Security Analyst is responsible for our client’s computer, network and cyber security. The Security Analyst administers all aspects of information security and is responsible for the identification, investigation and resolution of security events; as well as for conducting vulnerability audits and taking timely action to remediate findings. The...


  • Richmond Hill, Canada Onico Solutions Full time

    The Information Security Analyst is responsible for the identification, investigation and resolution of security events across networks and Cloud environments; as well as for conducting vulnerability audits and taking timely action to remediate findings. They are involved in the design, configuration and implementation of security solutions. They are also...


  • Richmond Hill, Canada Open Text Corporation Full time

    **Lead Security Compliance Analyst**: - Req id: 33556- Richmond Hill, ON, CA Waterloo, ON, CA**OPENTEXT - THE INFORMATION COMPANY** As the Information Company, our mission at OpenText is to create software solutions and deliver services that redefine the future of digital. Be part of a winning team that leads the way in Enterprise Information...

  • Security Analyst/Lead

    4 weeks ago


    Richmond Hill, Canada Onico Solutions Full time

    The Security Analyst/Lead is responsible for our client’s computer, network and cyber security. The Security Analyst/Lead administers all aspects of information security and is responsible for the identification, investigation and resolution of security events; as well as for conducting vulnerability audits and taking timely action to remediate findings....


  • Richmond Hill, Canada Staples Full time

    **Some of what you will do**: Staples Canada is looking for a Junior Security Operations Centre (SOC) analyst who will report into the Manager of InfoSec Risk & Compliance. You will be a key member of the Staples Canada Security Operations Centre Team and responsible for executing activities relating to monitoring and responding to security events. You will...


  • Richmond Hill, Canada opentext Full time

    **OPENTEXT - THE INFORMATION COMPANY** As the Information Company, our mission at OpenText is to create software solutions and deliver services that redefine the future of digital. Be part of a winning team that leads the way in Enterprise Information Management. **The Opportunity** The Lead Security Compliance Analyst will have the opportunity to impact...


  • Richmond, British Columbia, Canada SSRG Scarlet Security & Risk Group Full time

    Scarlet SecurityRisk Group (SSRG) is one of Canada's leading security companies. We provide a portfolio of risk management and security solutions to a variety of partners and clients, some of whom are in remote areas. Our diverse and highly qualified team members and relentless commitment to excellence provide superior results for our clients.We are looking...