Job Title: Cybersecurity Analyst – (Senior)
Location: Markham, ON
Estimated Duration: 12 Months

Individually we are people, but together we are Client. Individually these are just words, but together they are our Values – Care, Commitment, Community, and Confidence.
About the position:
We are seeking a resourceful and forward-thinking Cybersecurity Analyst who will be primarily responsible for day-to-day basic Cybersecurity Operational tasks. These would require general knowledge in Data Loss Prevention (DLP) triaging, working on Endpoint Detection and Response platform, Cybersecurity Incidents triaging and good communication skills.
This person will work closely with Incident Response, DLP, Vulnerability management, Engineering, Risk, Infra, Business, legal and People Function teams. The role is part of client’s Canada Cybersecurity Operations team and will be primarily based out of our Markham office.

As Senior Advisor within the Security Advisory Services (SAS) team, this role will involve performing reviews of Information Security Risk Assessments (ISRAs) deliverables for internal solutions and technology projects; and Third Party Information Security Assessments (TPISA) deliverables to evaluate client partners’ security posture and contractual obligations to protect client.
Furthermore, you will assist in managing cybersecurity risks to ensure it is within risk tolerance levels as defined by the organization, conducting periodic reporting of cybersecurity activities and trends, as well as performing a wide-range of cybersecurity consulting requests for client’s technology and business teams.
You will also collaborate with other client security and IT teams to implement new security solutions that will strengthen client’s overall security posture.
You are resourceful, forward-thinking, collaborative, and are comfortable in a fast-paced environment

What you’ll do
You will review (and where required) conduct ISRAs, TPISAs, manage and mitigate cybersecurity risks and conduct and other consulting requests within client Canada’s technology and business teams
Provide oversight on assessments, risk identification and risk management processes, and tools for managing and reporting risks, and continuously improve the quality of services
Identify gaps in existing processes and technology and develop remediation plans to address risks
Assist in the development of cybersecurity risk reporting including the ongoing development and improvement of Key Risk Indicators (KRIs)
Provide oversight to ensure identified cybersecurity risks are mitigated and are effectively communicated to partners, and managed with risk-prioritized timelines aligned with client’s risk appetite

Other key responsibilities include:

  • Provide senior management and executives with information security trends, the status of identified risks, and the effectiveness of work activities
  • Increase visibility of cybersecurity risks where and when appropriate with the respective collaborators when risk action plan target dates are not met
  • Manage the pen test and business impact assessment programs
  • Preparing for Internal Risks and Control Assessments
  • Help improve team processes to continuously increase efficiency and quality standards

What you’ll bring:

  • Minimum 10 years’ of strong, progressive experience in all of cybersecurity risk assessments, vendor assessments, and continuous risk management.
  • Strong understanding of cybersecurity industry standards, principles and practices, as well as risk concepts. Understanding of application security design & architecture is an asset.

Client: Internal

  • Proven management and leadership skills in communication, prioritization and developing talent
  • Demonstrated ability to communicate complex issues in a clear and concise manner to a wide range of audiences and stakeholders
  • Demonstrated ability to navigate through ambiguity and guide team through changes
  • Ability to understand complex processes and make sound judgement calls.
  • Ability to negotiate and influence others to achieve optimal results.
  • Knowledge of Ariba and Archer or other GRC management platforms.
  • Post-secondary education in Computer Science, Computer Engineering, IT Security, risk management, or comparable professional training.
  • Professional designation relating to cybersecurity or IT risk (e.g. CISSP, CISA, CISM, CCSP/CCSK, GIAC) preferred.

The pay range that the employer reasonably expects to pay for this position is between CA$82.00 and CA$92.00

Our voluntary benefits offering includes medical, dental, vision and retirement benefits.

This posting is for an existing vacancy.

If you believe this post to be fraudulent, please report by clicking here

Tundra Technical Solutions is a global workforce and technology delivery firm, ranked by Staffing Industry Analysts as one of the largest in North America. At Tundra, we aren't just hiring top talent at the world's most recognizable brands; we are pioneers of social recruitment. We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other legally protected characteristics. We welcome and encourage diversity in the workplace.

We use artificial intelligence tools to help our recruiters screen and assess talent. These tools do not replace human decision making in the process.

Not interested in this position, but know somebody who might be? Check out our Referral Reward Program, referrals are a big secret behind our success. As always, we’re on the lookout for great people. And we know that you know great people!