Our client is seeking a contract-based Senior Business Analyst with a strong background in IT Security to support the assessment, optimization, and modernization of Security Operations Centre (SOC) processes, operating models, and supporting technologies.
Working closely with cybersecurity, infrastructure, technology, and business stakeholders, the consultant will evaluate current security operations, identify process improvements, assess enterprise and cloud platforms, and develop recommendations that strengthen operational effectiveness, governance, risk management, and compliance.
Duration: 6 months to start
Location: Onsite – Ottawa
Responsibilities
- Review and document current-state Security Operations Centre (SOC) processes, workflows, procedures, and operating models.
- Analyze security operations to identify process inefficiencies, operational risks, control gaps, and opportunities for improvement.
- Facilitate workshops and stakeholder sessions to gather business requirements and validate recommendations.
- Assess enterprise applications, SaaS platforms, and cloud environments to identify security, governance, and compliance gaps.
- Develop future-state business processes and operating models that improve the effectiveness and maturity of security operations.
- Support governance, risk, and compliance (GRC) initiatives by recommending process and operational improvements.
- Evaluate existing security processes against industry best practices and cybersecurity frameworks.
- Produce business requirements, process maps, workflow documentation, gap analyses, business cases, and executive presentations.
- Analyze operational metrics and security performance data to identify trends and improvement opportunities.
- Support implementation planning, organizational change management, and adoption activities for approved initiatives.
- Collaborate with cybersecurity, infrastructure, architecture, and project delivery teams throughout the project lifecycle.
Required Qualifications
- 8+ years of Business Analyst experience delivering enterprise technology initiatives.
- Demonstrated experience supporting IT Security or Cybersecurity programs.
- Experience reviewing, assessing, and improving Security Operations Centre (SOC) processes and operating models.
- Strong understanding of cybersecurity operations, governance, risk management, and compliance principles.
- Experience conducting current-state assessments, business process analysis, and gap analyses.
- Strong experience documenting business requirements, business processes, workflows, and future-state operating models.
- Experience working with enterprise applications, SaaS solutions, and cloud platforms from a security and governance perspective.
- Excellent facilitation, stakeholder management, communication, and documentation skills.
Preferred Qualifications
Experience with one or more of the following is considered an asset:
- Security Operations Centre (SOC) modernization initiatives
- SIEM platforms (Microsoft Sentinel, Splunk, IBM QRadar)
- Security Orchestration, Automation and Response (SOAR)
- Identity and Access Management (IAM)
- Vulnerability Management
- Cloud security (Azure, AWS, Microsoft 365)
- Governance, Risk, and Compliance (GRC) platforms
- NIST Cybersecurity Framework
- ISO 27001
- CIS Controls
- ITIL
Nice-to-Have Experience
- Public sector or broader public sector experience.
- Experience supporting SOC transformation or cybersecurity operating model initiatives.
- Experience working alongside security architects, SOC analysts, infrastructure, and cloud engineering teams.
- Knowledge of security monitoring, incident response, threat detection, and security governance processes.
- Experience preparing executive-level presentations and recommendations for senior leadership.