About this role
Senior Cybersecurity Risk Analyst
Bring your cybersecurity expertise to an environment where collaboration, innovation, and continuous improvement drive success. Play a key role in security assessments, risk oversight, and strategic initiatives that help strengthen organizational security and resilience.
What is in it for you:
? Salaried: $77-87.90 per hour.
? Incorporated Business Rate: $90-100.40 per hour.
? 12-month contract with the potential for permanent employment.
? Day schedule, 37.50 hours per week.
? Hybrid model: 3 days per week on-site, subject to change.
Responsibilities:
? Review and, when required, conduct Information Security Risk Assessments (ISRAs) and Third-Party Information Security Assessments (TPISAs).
? Manage and mitigate cybersecurity risks and provide cybersecurity consulting services to technology and business teams.
? Provide oversight on assessments, risk identification, risk management processes, and risk reporting tools.
? Continuously improve the quality of cybersecurity risk management services.
? Identify gaps in existing processes and technologies and develop remediation plans to address risks.
? Support the development and enhancement of cybersecurity risk reporting and Key Risk Indicators (KRIs).
? Ensure identified cybersecurity risks are effectively communicated and managed according to risk-prioritized timelines.
? Provide senior management and executives with information on security trends, identified risks, and the effectiveness of security activities.
? Increase visibility of cybersecurity risks when action plan target dates are not met.
? Manage penetration testing and business impact assessment programs.
? Prepare for Internal Risks and Control Assessments.
? Collaborate with security and IT teams to implement security solutions that strengthen the overall security posture.
? Contribute to improving team processes, efficiency, and quality standards.
What you will need to succeed:
Required qualifications
? Post-secondary education in Computer Science, Computer Engineering, IT Security, Risk Management, or comparable professional training.
? 10+ years of progressive experience in cybersecurity risk assessments, vendor assessments, and continuous risk management.
? Experience conducting or reviewing Information Security Risk Assessments (ISRAs) and Third-Party Information Security Assessments (TPISAs).
? Strong understanding of cybersecurity industry standards, principles, practices, and risk concepts.
? Knowledge of cybersecurity controls and concepts.
? Knowledge of Ariba, Archer, or other GRC management platforms.
Preferred qualifications
? Professional cybersecurity or IT risk certification such as CISSP, CISA, CISM, CCSP, CCSK, or GIAC.
? Understanding of application security design and architecture.
Soft skills
? Resourceful.
? Forward-thinking.
? Collaborative.
? Comfortable working in a fast-paced environment.
? Strong communication skills.
? Leadership skills.
? Ability to communicate complex issues clearly and concisely to a wide range of audiences and stakeholders.
? Ability