Onico Solutions

Exceptional IT Staffing

IT Security Risk Analyst

The IT Security Risk Analyst supports the Information Security Risk Management and Governance programs. They work with technology and business stakeholders to identify Information Security risks, conduct risk assessments, recommend risks mitigation strategies, and monitor identified risks throughout its lifecycle. They also update and monitor Key Performance Indicators (KPI’s), Key Risk Indicators (KRI’s), Service Level Agreements (SLA’s), and other documentation related to the Information Security program. They contribute to the creation of management reporting to convey the status of Information Security risks and governance metrics across the organization.    

This role requires an experienced subject matter expert who has in-depth understanding of Information Security controls across a broad range of technologies and platforms.


  • Identification, assessment and monitoring of Information Security risks.
  • Recommendation of compensating controls to reduce inherited risk to an acceptable level.
  • Development and maintenance of Information Security risk and governance KPI’s, KRI’s, and SLA’s.
  • Support for security audits, prioritization and remediation of identified gaps.
  • Creation and maintenance of Information Security policies and other risk and governance documentation
  • Implementation and operation of risk and governance technology tools and processes
  • Collaboration with different stakeholders to manage Information Security risks in a timely matter


  • 3+ years of experience with IT Security Risk Management/Risk Assessments
  • 3+ year of experience with IT Security policies, standards, procedures and guidelines
  • KPI (Key Performance Indicators) & KRI (Key Risk Indicators)
  • Experience working with and managing external vendors
  • Strong knowledge of Information Security controls for Mobile, IoT, Cloud, Applications, Network and System infrastructure
  • Excellent knowledge of security technologies which are commonly used in enterprises to protect information systems, both on premise and in the Cloud. Hands-on design, implementation and management of variety security technologies are strong assets.
  • Working knowledge of Information Security and Risk Management frameworks like ISO27001, ISO27005 and NIST CSF and NIST 800-30
  • Understanding of legal and regulatory compliance standards and requirements like PCI-DSS and PIPEDA
  • CISSP, CISA, CRISC and other security certifications are a strong asset.

This is a permanent position located in Toronto (work from home until deemed safe).