We are seeking a highly accomplished Security Analyst - Intermediate for an enterprise-level contract opportunity based in Toronto. In this role, you will take on a premier cybersecurity, governance, and risk management capacity, specializing in performing vendor risk assessments, monitoring operational security events, and enhancing Third-Party Risk Management (TPRM) programs.
...
As an intermediate security analyst, you will bridge the gap between technical threat monitoring, regulatory compliance frameworks, and external vendor governance. Operating within a hybrid work model, you will monitor real-time security alerts, evaluate cyber threats, report on key security performance metrics, and align internal IT security policies with industry standards such as ISO 27001, NIST, PCI-DSS, and FIPPA. This position is tailored for an analytical security authority who can conduct vendor risk reviews, assist with internal and external audits, and drive continuous improvements across cybersecurity governance programs.
Location: Toronto, ON
Assignment Type: Hybrid (3 days per week onsite, 2 days remote)
Contract Duration: 6-month contract
Advantages
Broad Cybersecurity Scope: Combines hands-on incident monitoring and analysis with high-level cybersecurity governance, risk management, and compliance (GRC).
Robust TPRM Program Engagement: Lead third-party risk assessments, review vendor security attestations, and define contractual security controls.
Industry Standards Alignment: Gain direct experience managing compliance against ISO 27001, NIST, PCI-DSS, and FIPPA standards.
Balanced Hybrid Model: Enjoy a flexible work arrangement combining collaborative onsite teamwork in Toronto with remote work.
Responsibilities
Perform real-time monitoring and analysis of security events, investigating alerts, network traffic, logs, and indicators of compromise to respond to potential incidents.
Support the design, implementation, and execution of Third-Party Risk Management (TPRM) frameworks and conduct vendor risk assessments prior to contract execution.
Gather, prepare, and report cybersecurity performance metrics and KPIs to measure security service effectiveness and report status to senior management and audit teams.
Ensure organizational adherence to IT security policies, governance requirements, and regulatory standards including ISO 27001, NIST, PCI-DSS, and FIPPA.
Support internal and external security audits (such as PCI and CSAE 3416 audits), assisting with evidence collection and remediation tracking.
Collaborate with Risk & Compliance, Privacy, Finance, and Procurement teams to evaluate risk appetite, coordinate risk treatments, and integrate security controls into vendor contracts.
Review vendor security control attestation reports, assess gaps, and provide security input into third-party penetration testing activities.
Assist with digital asset inventory management, ensuring proper identification, classification, ownership, and risk mapping for key business applications.
Deliver security guidance, promote compliance awareness across business units, and assist in developing cybersecurity training materials.
Qualifications
Core Technical & Risk Management Requirements
IT Security & Risk Experience: 4 to 6 years of experience in progressively advancing IT security/cybersecurity roles, with 3 to 5 years of focused competency in IT risk management and cybersecurity governance.
Third-Party Risk Management (TPRM): Proven experience performing vendor risk assessments, evaluating third-party security attestations, and gathering security performance metrics.
Standards & Compliance Knowledge: Working knowledge of enterprise cybersecurity and privacy frameworks, including ISO 27001, NIST, PCI-DSS, and FIPPA.
Operational Monitoring & Analysis: Familiarity with operational security monitoring, log analysis, network traffic analysis, and incident response fundamentals.
Education: Degree in Business, Engineering, Information Systems, Computer Science, or a related discipline (or equivalent combination of education, training, and experience).
Preferred Certifications & Assets
Professional Certifications: Professional security certifications such as CISSP, CISM, CISA, CRISC, CGEIT, or similar credentials are considered strong assets.
Methodology & Operations: Agile certifications (e.g., ACP, CSPO) and experience in IT project delivery or operations are assets.
Public Sector Context: Prior experience within a public sector or broader public sector environment is nice to have.
Soft Skills & Professional Attributes
Communication & Collaboration: Excellent written and verbal communication skills to articulate complex cybersecurity risks and compliance requirements to technical teams and executive management.
Stakeholder Management: Strong interpersonal and consultative capabilities to build cross-departmental relationships across Procurement, Legal, Finance, and Operations.
Summary
If you're interested in the "Security Analyst - Intermediate" role based in Toronto, we encourage you to apply online at www.randstad.ca.
Only qualified candidates will be contacted for the next steps. We look forward to hearing from you!
Randstad Canada is committed to fostering a workforce reflective of all peoples of Canada. As a result, we are committed to developing and implementing strategies to increase the equity, diversity and inclusion within the workplace by examining our internal policies, practices, and systems throughout the entire lifecycle of our workforce, including its recruitment, retention and advancement for all employees. In addition to our deep commitment to respecting human rights, we are dedicated to positive actions to affect change to ensure everyone has full participation in the workforce free from any barriers, systemic or otherwise, especially equity-seeking groups who are usually underrepresented in Canada's workforce, including those who identify as women or non-binary/gender non-conforming; Indigenous or Aboriginal Peoples; persons with disabilities (visible or invisible) and; members of visible minorities, racialized groups and the LGBTQ2+ community.
Randstad Canada is committed to creating and maintaining an inclusive and accessible workplace for all its candidates and employees by supporting their accessibility and accommodation needs throughout the employment lifecycle. We ask that all job applications please identify any accommodation requirements by sending an email to accessibility@randstad.ca to ensure their ability to fully participate in the interview process.
This posting is for existing and upcoming vacancies.
show more
We are seeking a highly accomplished Security Analyst - Intermediate for an enterprise-level contract opportunity based in Toronto. In this role, you will take on a premier cybersecurity, governance, and risk management capacity, specializing in performing vendor risk assessments, monitoring operational security events, and enhancing Third-Party Risk Management (TPRM) programs.
As an intermediate security analyst, you will bridge the gap between technical threat monitoring, regulatory compliance frameworks, and external vendor governance. Operating within a hybrid work model, you will monitor real-time security alerts, evaluate cyber threats, report on key security performance metrics, and align internal IT security policies with industry standards such as ISO 27001, NIST, PCI-DSS, and FIPPA. This position is tailored for an analytical security authority who can conduct vendor risk reviews, assist with internal and external audits, and drive continuous improvements across cybersecurity governance programs.
Location: Toronto, ON
Assignment Type: Hybrid (3 days per week onsite, 2 days remote)
Contract Duration: 6-month contract
Advantages
...
Broad Cybersecurity Scope: Combines hands-on incident monitoring and analysis with high-level cybersecurity governance, risk management, and compliance (GRC).
Robust TPRM Program Engagement: Lead third-party risk assessments, review vendor security attestations, and define contractual security controls.
Industry Standards Alignment: Gain direct experience managing compliance against ISO 27001, NIST, PCI-DSS, and FIPPA standards.
Balanced Hybrid Model: Enjoy a flexible work arrangement combining collaborative onsite teamwork in Toronto with remote work.
Responsibilities
Perform real-time monitoring and analysis of security events, investigating alerts, network traffic, logs, and indicators of compromise to respond to potential incidents.
Support the design, implementation, and execution of Third-Party Risk Management (TPRM) frameworks and conduct vendor risk assessments prior to contract execution.
Gather, prepare, and report cybersecurity performance metrics and KPIs to measure security service effectiveness and report status to senior management and audit teams.
Ensure organizational adherence to IT security policies, governance requirements, and regulatory standards including ISO 27001, NIST, PCI-DSS, and FIPPA.
Support internal and external security audits (such as PCI and CSAE 3416 audits), assisting with evidence collection and remediation tracking.
Collaborate with Risk & Compliance, Privacy, Finance, and Procurement teams to evaluate risk appetite, coordinate risk treatments, and integrate security controls into vendor contracts.
Review vendor security control attestation reports, assess gaps, and provide security input into third-party penetration testing activities.
Assist with digital asset inventory management, ensuring proper identification, classification, ownership, and risk mapping for key business applications.
Deliver security guidance, promote compliance awareness across business units, and assist in developing cybersecurity training materials.
Qualifications
Core Technical & Risk Management Requirements
IT Security & Risk Experience: 4 to 6 years of experience in progressively advancing IT security/cybersecurity roles, with 3 to 5 years of focused competency in IT risk management and cybersecurity governance.
Third-Party Risk Management (TPRM): Proven experience performing vendor risk assessments, evaluating third-party security attestations, and gathering security performance metrics.
Standards & Compliance Knowledge: Working knowledge of enterprise cybersecurity and privacy frameworks, including ISO 27001, NIST, PCI-DSS, and FIPPA.
Operational Monitoring & Analysis: Familiarity with operational security monitoring, log analysis, network traffic analysis, and incident response fundamentals.
Education: Degree in Business, Engineering, Information Systems, Computer Science, or a related discipline (or equivalent combination of education, training, and experience).
Preferred Certifications & Assets
Professional Certifications: Professional security certifications such as CISSP, CISM, CISA, CRISC, CGEIT, or similar credentials are considered strong assets.
Methodology & Operations: Agile certifications (e.g., ACP, CSPO) and experience in IT project delivery or operations are assets.
Public Sector Context: Prior experience within a public sector or broader public sector environment is nice to have.
Soft Skills & Professional Attributes
Communication & Collaboration: Excellent written and verbal communication skills to articulate complex cybersecurity risks and compliance requirements to technical teams and executive management.
Stakeholder Management: Strong interpersonal and consultative capabilities to build cross-departmental relationships across Procurement, Legal, Finance, and Operations.
Summary
If you're interested in the "Security Analyst - Intermediate" role based in Toronto, we encourage you to apply online at www.randstad.ca.
Only qualified candidates will be contacted for the next steps. We look forward to hearing from you!
Randstad Canada is committed to fostering a workforce reflective of all peoples of Canada. As a result, we are committed to developing and implementing strategies to increase the equity, diversity and inclusion within the workplace by examining our internal policies, practices, and systems throughout the entire lifecycle of our workforce, including its recruitment, retention and advancement for all employees. In addition to our deep commitment to respecting human rights, we are dedicated to positive actions to affect change to ensure everyone has full participation in the workforce free from any barriers, systemic or otherwise, especially equity-seeking groups who are usually underrepresented in Canada's workforce, including those who identify as women or non-binary/gender non-conforming; Indigenous or Aboriginal Peoples; persons with disabilities (visible or invisible) and; members of visible minorities, racialized groups and the LGBTQ2+ community.
Randstad Canada is committed to creating and maintaining an inclusive and accessible workplace for all its candidates and employees by supporting their accessibility and accommodation needs throughout the employment lifecycle. We ask that all job applications please identify any accommodation requirements by sending an email to accessibility@randstad.ca to ensure their ability to fully participate in the interview process.
This posting is for existing and upcoming vacancies.
show more