Cybersecurity GRC Analyst
Toronto, Ontario, Canada · മുഴുവൻ സമയവും
അപേക്ഷിക്കുന്ന ആദ്യയാളാകൂ
- അനുഭവം
- 6–9 yrs
- ശമ്പളം
- CAD 92,835 – CAD 98,640 / year
- ഓപ്പണിംഗുകൾ
- 1
- പോസ്റ്റ് ചെയ്തു
- 1 മണിക്കൂർ മുമ്പ്
- പ്രവർത്തന രീതി
- ഓഫീസിൽ
- വിദ്യാഭ്യാസം
- ബാച്ചിലേഴ്സ് ഡിഗ്രി
- പുനരാരംഭിക്കുക
- അപേക്ഷിക്കാൻ നിർബന്ധം
നിങ്ങൾ എവിടെ ജോലി ചെയ്യും
ജോലി വിവരണം
Overview
The Ontario Medical Association (OMA), a leading advocate for physicians across Ontario, is seeking a Cybersecurity Governance, Risk, and Compliance (GRC) Analyst to enhance the organization's information security framework. The role operates within the second line of defense and collaborates closely with the Technology department, Information Security team, enterprise risk management, service providers, and business units to efficiently identify, assess, and manage cybersecurity risks throughout the organization.
Key Responsibilities
- Develop, maintain, and continuously improve cybersecurity policies, standards, and controls aligned with frameworks like CIS, NIST, and ISO 27001.
- Act as the primary liaison for cybersecurity audits, managing evidence gathering and remediation tracking efforts.
- Administer security exception processes and risk acceptance procedures.
- Integrate governance protocols for artificial intelligence and emerging technologies, evaluating organizational risks and guiding on regulatory and ethical issues.
- Maintain the enterprise cybersecurity risk register, including risk evaluation, remediation timelines, and escalation rules.
- Document and assess risks stemming from vulnerabilities, incidents, third-party findings, and control weaknesses.
- Create and update cybersecurity dashboards along with key risk and performance indicators.
- Report cybersecurity risks and overall security status to senior leadership regularly.
- Manage visibility into vulnerabilities in infrastructure, cloud environments, and applications, particularly those affecting sensitive data exposure.
- Track remediation efforts, escalate critical overdue items, and document residual risks.
- Oversee controls safeguarding sensitive personal and health information (PII/PHI) and collaborate on data governance efforts including classification and loss prevention.
- Engage with Senior Security Architect on threat modeling and verify secure coding practices and remediation effectiveness through SAST/DAST scanning.
- Review application risks related to identity/access management, API security, data protection, and third-party dependencies.
- Conduct quarterly privileged access and identity certification reviews.
- Analyze major security incidents, validate root cause analyses, and monitor corrective actions.
- Identify recurring control failures and systemic issues across IT infrastructure, applications, and AI systems.
- Lead third-party cybersecurity risk assessments including AI service vendors, track remediation commitments, and manage risk acceptance documentation.
- Facilitate tabletop exercises for technical and management teams to boost preparedness.
- Support cybersecurity awareness initiatives such as phishing simulations.
Qualifications and Experience
- Bachelor’s degree in Information Technology, Computer Science, Computer Engineering or equivalent discipline.
- 6 to 9 years of experience in information security and IT, particularly in governance, risk, and compliance within enterprise environments.
- Active industry certifications such as CISSP, CRISC, CISA, Certified Ethical Hacker, or equivalents are mandatory.
- Additional certifications like CISM, ISACA Advanced AI Security Management (AAISM), ITIL, PMP, or MBA credentials are advantageous.
- Experience with Microsoft Security and Compliance tools.
- Deep knowledge in identity governance and conditional access technologies like Entra ID.
- Hands-on experience with Extended Detection and Response (XDR) tools alongside SIEM/SOAR platforms and automation workflows.
- Comprehensive understanding of Zero Trust concepts and modern security architectures.
- Familiarity with MITRE ATT&CK framework and threat modeling techniques.
- Exposure to AI-driven security controls and API automation using REST and Microsoft Graph API.
- Robust expertise in cyber risk management, cybersecurity frameworks, and business continuity including disaster recovery protocols.
- Strong analytical, problem-solving, decision-making abilities combined with excellent communication skills for both technical and non-technical stakeholders.
Work Environment and Benefits
- OMA maintains a permanent hybrid working model requiring several days per week onsite in Toronto.
- The workplace culture emphasizes respect, boldness, responsiveness, and transparency.
- Opportunities for professional growth through paid training and continuous learning programs.
- Competitive salary range from $92,835 to $98,640 annually, a pension plan, bonus program, and an extensive benefits package including wellness initiatives.
- Recognition as one of Greater Toronto’s Top Employers for six consecutive years.
Additional Information
The OMA is dedicated to fostering a diverse and inclusive workplace and encourages applications from candidates of all backgrounds including racialized persons, Indigenous peoples, persons with disabilities, LGBTQ2S+ individuals, and others who enrich the diversity of perspectives. Accommodation is provided throughout the recruitment process for applicants with disabilities. Background and reference checks are mandatory prior to employment. This is a new role within the organization, and recruitment is conducted without the use of artificial intelligence technologies.