Recherche d'emploi > Toronto, ON > Security analyst

Security Analyst

Toronto Parking Authority
Toronto, ON, CA
69.1K $-75.9K $ / an (estimé)
Temps plein
Quick Apply

POSITION SUMMARY The Security Information Analyst will assist the Toronto Parking Authority with the design, development and implementation of its security awareness plan and security initiatives to help ensure that the best possible measures are in place to maintain secure operations.

The role will be focused on executing threat risk and vulnerability analysis (TRVA). In addition, this role will oversee risk remediation activities, in order to enable both operational and project teams to safely and securely manage their departments.

This role will also be responsible to help monitor, evaluate and maintain systems and procedures to safeguard TPA information and systems while developing and implementing strategies, policies and procedures for the continued security of the organization.

RESPONSIBILITIES Threat Monitoring : Continuously monitor network traffic, security alerts, and system logs to identify potential security incidents and vulnerabilities, with a focus on cardholder data protection.

PCI-DSS Compliance : Ensure adherence to PCI-DSS requirements, including maintaining compliance with all relevant standards and controls for handling and protecting cardholder data.

Incident Response : Respond promptly to security breaches or attacks, including investigating and analyzing incidents involving cardholder data, and implementing corrective measures to address any PCI-DSS violations.

Risk Assessment : Conduct regular risk assessments and security audits with a focus on PCI-DSS compliance to identify potential threats and vulnerabilities and recommend mitigation strategies.

Security Measures : Develop, implement, and enforce security policies, procedures, and best practices to enhance overall security and ensure PCI-DSS compliance.

Vulnerability Management : Perform regular vulnerability scans and assessments, addressing identified weaknesses in systems and applications, and ensuring compliance with PCI-DSS requirements.

Compliance Monitoring : Monitor compliance with PCI-DSS controls and procedures, including data encryption, access control, and network security measures.

Documentation : Maintain detailed records of PCI-DSS compliance activities, security incidents, investigations, and responses, and prepare reports for management and regulatory bodies.

Security Awareness : Educate and train staff on PCI-DSS requirements, security best practices, and organizational policies to promote a culture of security awareness and compliance.

Collaboration : Work closely with IT, development, and management teams to integrate PCI-DSS requirements into system designs and operational procedures.

Tool Management : Utilize and manage security tools and technologies, including firewalls, intrusion detection systems, and encryption software, to safeguard the organization’s digital assets in compliance with PCI-DSS.

Engage with QSA : Collaborate with Qualified Security Assessors (QSAs) to ensure compliance with PCI-DSS standards, prepare for formal assessments, and address any identified gaps or recommendations.

QUALIFICATIONS : Bachelor's degree in computer science, Information Security, or a related field. Relevant certification (e.

g., CISSP, CEH, CompTIA Security+, PCI Professional) are considered an asset. Minimum 5 years of experience in an Information Security role.

Minimum 5 years of experience with administration of various security products such as Palo Alto, CrowdStrike, Cisco ASA and Checkpoint, Microsoft Defender, Microsoft Purview and Symantec endpoint protection, Qualys and Tenable network and web application scanner, CIS benchmarks.

Demonstrated knowledge of and / or familiarity with standards and frameworks such as PCI-DDS, ITIL, COBIT, ISO / IEC 31000 series, ISO / IEC 27000 series, SOC 2.

Demonstrated experience in undertaking security threat and risk assessment using an industry recognized framework equivalent to the Harmonized Threat and Risk Assessment methodology.

Proven experience with LogRhythm or Splunk solutions. Previous experience conducting IT audits considered an asset. Threat Risk Vulnerability Assessment (TRVA) training.

Knowledge of current network, operating systems, hardware, protocols, and standards. Excellent analytical skills Demonstrated ability in solving I.

T. issues, problems and possessing a sense of urgency. Demonstrated integrity in dealing with information and issues of a highly confidential and sensitive nature.

Diligent, detail-oriented, and possess a success-driven work ethic. Demonstrates Commitment to Environment, Health & Safety : Manages risks to protect the health and safety of employees and the public.

Able to perform forensic collections of data and to conduct detailed forensic analysis task including data recovery, production of forensic images and compilation of forensic examination reports.

Ability to collect and manage of evidence to ensure that the chain of custody is fully documented in accordance with local statutes and policies.

Experience In use of forensic and data mining tools to collect, search, recover, sort and organize large amounts of information in all phases of an investigation.

A proven team player & ability to interact and work with people with a variety of backgrounds and at different levels within the organization.

Internal candidates : No new or reclassified employee with less than one (1) year’s continuous on the job service may apply. Powered by JazzHR

Il y a 28 jours
Emplois reliés
Toyota North America
Toronto, Ontario

Preferred License or Certification in Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), Information Systems Security Architecture Professional (ISSAP), AWS Certified Security Specialty and/or Certified Cloud Security Knowledge (CCSK). TFS curr...

Konica Minolta
Mississauga, Ontario

The Cyber Security Analyst will have a “hands-on” role performing daily tasks and maintenance to security related systems, as necessary. Experience with Microsoft security solutions (Defender, Sentinel, Security Center, etc. Cisco Certified Network Administrator – Security (CCNA-Security). The analy...

BGIS
Toronto, Ontario

Proficient in monitoring various security administrative consoles as well as IT related administrative consoles to determine root causes for security events (Security Incident and Event Management, Endpoint Protection, Cloud Access Security Broker, Email Security). This position will maintain and im...

Intercast Staffing
Toronto, Ontario
Télétravail

Working remotely for one the most respected consulting firms in the world, you will assist the Incident Response team on responding to and triaging incidents that arise in your clients infrastructure.Experience with Threat Hunting, Forensics and SIEM monitoring needed....

Royal Bank of Canada>
Toronto, Ontario

As a  Senior Network and Security Analyst you will provide consistent levels of organizational and technical expertise necessary for the successful implementation, maintenance and support of the critical network and security infrastructure services across all global RBC Intranet (Core, LAN/WAN, Serv...

S.i. Systems
Toronto, Ontario

Performing ongoing security monitoring of events reported by security systems, SIEMs, and cloud security monitoring services, and assess, respond to, and resolve security events (incidents, vulnerabilities, threats, and overall risk). Security Analyst to assist in day-to-day security operations acti...

BMO Financial Group
Toronto, Ontario

BMO is an organization driven by a shared Purpose: Boldly Grow the Good in business and life.It calls on members of its team, to create lasting, positive change for its customers, its communities, and its people.By working together, innovating, and pushing boundaries, BMO transforms lives and busine...

CB Canada
Toronto, Ontario

On behalf of our client in the Banking Sector, PROCOM is looking for a Security Analyst. Security Analyst – Job Description. Security Analyst – Mandatory Skills. Security Analyst - Nice to Have Skills. ...

Intercast Staffing
Toronto, Ontario

Our client, a major post-secondary institution, is looking to bolster their security program with the addition of two Senior Security Analysts. Minimum 5 years of Information security experience, with a broad range of platforms and technologies. Minimum of 3 years of progressive experience in creati...

Intact Financial Corporation
Toronto, Ontario

We are seeking a highly skilled and experienced senior IT business analyst with expertise in security, and reporting to join our cybersecurity team. Collaborate with business stakeholders to understand their security needs, challenges, and objectives, and translate them into actionable requirements ...