Senior Security Analyst - Cyber Security - Regular Full-Time - 2026-17134
On-siteToronto, Ontario, Canada
Job Summary
Design and develop security architecture principles, including frameworks for infrastructure, applications, and cloud services. Conduct threat modeling activities and technical security threat and risk assessments using industry-recognized standards like NIST CSF, ISO27001, and STRIDE. Collaborate with stakeholders to define cybersecurity requirements, approve control frameworks, and recommend remediation items for operational areas. Review IT security controls for new services and support project managers in executing key security initiatives. Work with external consultants for independent audits and incident response.
Required Qualifications
- University Degree in Business Administration, Information Technology, or Engineering or equivalent
- Minimum 5 - 7 years of experience in the role of Cybersecurity, Security Architecture or Security Operations
- Understanding of key technology capabilities such as Network (e.g. Router, switch and VLAN security; wireless security), API's, Cloud Services, Endpoint Detection & Response (EDR), identity and access management and other industry leading technologies
- Understanding of Windows, UNIX and Linux operating systems VB.NET, Java/J2EE, ColdFusion, API/web services, scripting languages and a relational database management system (RDBMS) such as MS SQL Server or Oracle
- Strong understanding of Risk Assessment Methodologies and Approaches
- Excellent communication skills
- Strong critical thinking, analytical and negotiation skills
- Demonstrated knowledge of and/or familiarity with standards and frameworks such as NIST CSF, ISO/IEC 27000 series, SABSA or Cloud Security Frameworks
- Demonstrated experience in undertaking supervised security threat and risk assessments, using an industry-recognized framework equivalent to the Harmonized Threat and Risk Assessment (HTRA) methodology
Desired Qualifications
- Master's degree
- Certification in one or more IT governance or control standards such as SABSA, Microsoft Tools, ISC2 (e.g. CISSP), SANS, ISACA (e.g. CISM, CISA), PMI (e.g. PMBOK) or equivalent
- Knowledge of information technology project management, technology (software or hardware) development and/or technology operations management
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.