- Company Name
- Cogeco Inc.
- Job Title
- Analyst, Security Services
- Job Description
-
Job title: Analyst, Security Services
Role Summary: Contribute to Governance, Risk, and Compliance (GRC) by conducting risk assessments, managing third‑party risk, overseeing Data Loss Prevention alerts, and executing compliance self‑assessments for standards such as PCI DSS and cyber insurance.
Expectations: Deliver accurate risk analysis, recommend mitigation strategies, maintain up‑to‑date GRC documentation, and collaborate cross‑functionally with cybersecurity SMEs and business units to ensure adherence to security policies.
Key Responsibilities:
- Perform third‑party risk assessments, including vendor categorization, security evaluation, evidence review, risk scoring, and mitigation recommendation.
- Manage and review contract terms related to vendor risk.
- Monitor and respond to Data Loss Prevention alerts, coordinating follow‑up actions.
- Plan, deploy, and assess annual security awareness, training, and phishing campaigns.
- Maintain GRC solutions and documentation (e.g., risk register, policies, standards, procedures).
- Process security exception requests, ensuring thorough documentation, routing, and timely resolution.
- Guide application approval processes, ensuring alignment with security policies and identifying new application risks.
- Collaborate with cybersecurity SMEs and the Lead GRC Analyst on risk assessments, threat identification, impact analysis, and control recommendations.
- Conduct compliance self‑assessment activities for frameworks such as PCI DSS, cyber insurance, privacy regulations, HIPAA, SOC 2, etc.
- Support Information Security team on ad‑hoc projects as required.
Required Skills:
- Strong knowledge of information security principles, risk management methodologies, and compliance frameworks.
- Experience in security risk assessments and compliance self‑assessment for PCI DSS, privacy laws, HIPAA, SOC 2, or similar.
- Proficiency in analytics, problem‑solving, and detail orientation.
- Excellent written and verbal communication in English and French.
- Ability to explain risk and compliance concepts to diverse audiences.
- Familiarity with third‑party risk management, data loss prevention, and security awareness programs.
Required Education & Certifications:
- Bachelor’s degree in Information Security, Business Administration, or related field (or equivalent practical experience).
- Preferred certifications: CISSP, CISM, or equivalent domain‑specific credentials.