×
Register Here to Apply for Jobs or Post Jobs. X

Analyst, IT Security

Job in Toronto, Ontario, C6A, Canada
Listing for: Bank of Montreal
Full Time position
Listed on 2026-08-20
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Network Security
Salary/Wage Range or Industry Benchmark: 90000 - 120000 CAD Yearly CAD 90000.00 120000.00 YEAR
Job Description & How to Apply Below

Final date to receive applications: 10/30/2026 Address: 250 Yonge Street

BMO BLUE REWARDS is seeking an experienced IT Vulnerability Security Analyst to join our Security Operations team. This role operates in a fast‑paced environment where responsibilities such as vulnerability management, SIEM monitoring, incident response, security awareness activities, and metrics reporting may occur simultaneously—often alongside troubleshooting and internal consulting.

In addition to detecting and responding to security threats across the organization’s digital infrastructure, the Security Analyst will be expected to demonstrate strong expertise in vulnerability management, system hardening, endpoint security, and cybersecurity incident response.

The ideal candidate will bring a proven track record in these areas, supported by relevant industry‑recognized certifications. Join a team where you can make a measurable security impact, continuously grow your expertise, and advance your career while helping protect the business.

This role offers the opportunity to protect the organisation from cyber threats while developing highly valuable cybersecurity skills and experience.

This role follows a hybrid work model, with employees expected to work from the office three days per week.

The successful candidate will be based at Blue Rewards (BR), part of the Bank of Montreal family of companies, at its downtown Toronto office located at 250 Yonge Street, Toronto, Ontario.

This position follows a standard Monday to Friday schedule from 9:00 a.m. to 5:00 p.m., with no shift work required.

As part of the role, the successful candidate will participate in a 24/7 pager‑based on‑call rotation, typically one week per month (Tuesday to Tuesday), including coverage during statutory holidays when scheduled. Additional compensation is provided for participation in the on‑call rotation.

CORE/KEY SKILLS and experience :
  • 3-4 years of expertise with enterprise vulnerability management tools (Tenable, Qualys, Rapid7, etc.).
  • 3-4 years of demonstrated success in understanding of vulnerabilities, CVEs, CVSS, and risk prioritization, specially nowadays with AI‑enabled threats.
  • Strogn experience with analyzing scan results and validating remediation actions (including suggestion of security controls to be implemented to reduce the exploitability of the vulnerability).
  • Ability to collaborate with technical teams to drive timely vulnerability remediation efforts.
  • Strong analytical and communication skills with experience reporting on security risk and remediation metrics.
  • Proficiency with cloud‑based vulnerability scan tools, SIEM(s), endpoint protection platforms, email security solutions, and incident response frameworks.
  • Experience monitoring, analysing, and responding to cybersecurity threats and security alerts.
  • Strong understanding of cybersecurity principles, technologies, and security controls.
  • Experience with security tools such as SIEM, EDR, email security, and mainly on vulnerability management platforms.
  • Ability to investigate security incidents and perform root cause analysis.
  • Strong analytical and problem‑solving skills with attention to detail.
  • Ability to communicate security risks, findings, and recommendations clearly to stakeholders (sometimes, non‑technical).
  • Knowledge of common cyber threats, attack techniques, and mitigation strategies.
  • Ability to deal with many initiatives/work at the same time.
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Proven experience in security operations, vulnerability management, endpoint security, and incident response.
  • Analytical and Communication

    Skills:

    Strong analytical abilities, attention to detail, prioritization skills, and excellent written and verbal communication skills.
  • Teamwork:
    Ability to work collaboratively in a fast‑paced environment and communicate effectively with technical and non‑technical stakeholders.
  • Recognized professional certifications such as GIAC Incident Handler (GCIH), Certified Ethical Hacker (CEH or CEH‑Practical).
  • Vendor‑based and relevant cloud certifications from major public cloud providers (e.g., AWS, GCP, Azure) are highly…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary