IT Security Risk Analyst
Remote / Online - Candidates ideally in
Toronto, Ontario, M5A, Canada
Listing for:
Onico Solutions
Full Time, Remote/Work from Home
position
Listed on 2025-12-31
Job specializations:
-
IT/Tech
Information Security, Cybersecurity, IT Consultant, Data Security
Job Description & How to Apply Below
IT Security Risk Analyst
The IT Security Risk Analyst supports the Information Security Risk Management and Governance programs. They work with technology and business stakeholders to identify Information Security risks, conduct risk assessments, recommend risks mitigation strategies, and monitor identified risks throughout its lifecycle. They also update and monitor Key Performance Indicators (KPI’s), Key Risk Indicators (KRI’s), Service Level Agreements (SLA’s), and other documentation related to the Information Security program.
They contribute to the creation of management reporting to convey the status of Information Security risks and governance metrics across the organization.
This role requires an experienced subject matter expert who has in-depth understanding of Information Security controls across a broad range of technologies and platforms.
RESPONSIBILITIES
Identification, assessment and monitoring of Information Security risks.Recommendation of compensating controls to reduce inherited risk to an acceptable level.Development and maintenance of Information Security risk and governance KPI’s, KRI’s, and SLA’s.Support for security audits, prioritization and remediation of identified gaps.Creation and maintenance of Information Security policies and other risk and governance documentationImplementation and operation of risk and governance technology tools and processesCollaboration with different stakeholders to manage Information Security risks in a timely matterREQUIREMENTS
3+ years of experience with IT Security Risk Management/Risk Assessments3+ year of experience with IT Security policies, standards, procedures and guidelinesKPI (Key Performance Indicators) & KRI (Key Risk Indicators)Experience working with and managing external vendorsStrong knowledge of Information Security controls for Mobile, IoT, Cloud, Applications, Network and System infrastructureExcellent knowledge of security technologies which are commonly used in enterprises to protect information systems, both on premise and in the Cloud. Hands-on design, implementation and management of variety security technologies are strong assets.Working knowledge of Information Security and Risk Management frameworks like ISO
27001, ISO
27005 and NIST CSF and NIST 800-30Understanding of legal and regulatory compliance standards and requirements like PCI-DSS and PIPEDACISSP, CISA, CRISC and other security certifications are a strong asset.This is a permanent position located in Toronto (work from home until deemed safe).
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here: