Security Risk Analyst
Location: Montreal, QC
Work Model: Hybrid
Job Summary
We are seeking a Security Risk Analyst to assess, measure, and enhance the effectiveness of cybersecurity controls across the organization. The role will focus on identifying control gaps, evaluating security and operational risk exposure, validating compliance with internal security policies and applicable regulatory requirements, and providing actionable recommendations to strengthen the overall cybersecurity posture.
The ideal candidate will have experience in cybersecurity risk management, security controls assessment, compliance, metrics, reporting, and continuous control monitoring.
Key Responsibilities
- Assess the design and operating effectiveness of cybersecurity controls across technology and security environments.
- Identify control deficiencies, gaps, and weaknesses and assess their potential risk and business impact.
- Evaluate cybersecurity risk exposure and recommend appropriate risk mitigation and remediation strategies.
- Validate compliance with internal security policies, standards, frameworks, and applicable regulatory requirements.
- Perform control testing, evidence review, risk assessments, and ongoing monitoring activities.
- Support Continuous Control Monitoring (CCM) initiatives to improve visibility into control effectiveness and emerging risks.
- Develop, monitor, and maintain Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) related to cybersecurity controls and risk.
- Analyze security and risk data to identify trends, anomalies, recurring control issues, and areas requiring management attention.
- Develop dashboards, metrics, reports, and executive-level presentations for leadership, audit, risk committees, and regulatory reviews.
- Track remediation activities and work with control owners and stakeholders to ensure timely resolution of identified gaps.
- Support internal and external security audits, regulatory examinations, and compliance assessments.
- Maintain accurate documentation of control assessments, risk findings, remediation plans, and supporting evidence.
- Collaborate with cybersecurity, technology, risk, compliance, audit, and business teams to strengthen the overall control environment.
- Proactively identify emerging cybersecurity risks and recommend improvements to security processes and controls.
- Contribute to the continuous improvement and maturity of the organization's cybersecurity risk and control framework.
Required Skills & Qualifications
- 5+ years of experience in cybersecurity risk, security controls, IT risk, GRC, compliance, or a related field.
- Strong understanding of cybersecurity controls, risk assessment, control testing, and remediation.
- Experience assessing both control design and operating effectiveness.
- Experience with KRI/KPI development, risk metrics, dashboards, and management reporting.
- Knowledge of Continuous Control Monitoring (CCM) and risk-based monitoring practices.
- Understanding of cybersecurity frameworks and standards such as NIST, ISO 27001, COBIT, SOC 2, PCI DSS, or similar.
- Experience interpreting and validating compliance with security policies, standards, and regulatory requirements.
- Strong analytical skills with the ability to identify control gaps, assess risk exposure, and translate findings into actionable recommendations.
- Experience working with cross-functional stakeholders, including Cybersecurity, IT, Risk, Compliance, Audit, and Business teams.
- Strong written and verbal communication skills, with the ability to present risk findings to both technical and senior management audiences.
- Strong documentation, reporting, and attention-to-detail skills.
Preferred Qualifications
- Experience with GRC / risk management platforms such as ServiceNow GRC, Archer, RSA, MetricStream, or similar.
- Relevant certifications such as CISA, CRISC, CISSP, ISO 27001, or CGEIT.
- Experience in a financial services, banking, or highly regulated environment.
- Knowledge of third-party/vendor risk, technology risk, vulnerability management, IAM, cloud security, or security operations controls.
- Experience using Power BI, Tableau, Excel, or similar tools for risk dashboards and reporting.
Key Competencies
- Cybersecurity Risk & Controls
- Control Assessment & Testing
- Risk Identification & Mitigation
- KRI / KPI Development
- Continuous Control Monitoring
- GRC & Compliance
- Audit & Regulatory Support
- Risk Reporting & Dashboards
- Control Gap Analysis
- Stakeholder Management
- Security Policy & Regulatory Compliance