Industry: All
Term: Contract
Province: ON
Category: Information Technology
Experience: 5 - 10 Years
On behalf of our client, Affinity is seeking an IT Security Analyst who will support the organization's Information Security Governance, Risk, and Compliance program by helping identify, assess, document, and monitor information security risks and control obligations. The role partners with IT, business stakeholders, Legal, Privacy, Internal Audit, and third-party vendors to support audit readiness, risk assessments, policy governance, compliance evidence collection, vendor reviews, and management reporting.
The successful candidate will bring strong analytical, documentation, and stakeholder management skills, with the ability to translate technical control requirements and risk findings into practical business language suitable for a regulated, global enterprise environment.
Role alignment: supports ISO 27001/ISMS activities, security risk assessments, corrective action tracking, control evidence management, policy governance, vendor reviews, and security reporting.
Key Responsibilities
Governance & Compliance
• Support development, maintenance, and periodic review of information security policies, standards, procedures, and guidelines.
• Coordinate compliance evidence collection for internal audits, external audits, ISO 27001 activities, and other assurance requirements.
• Maintain accurate governance documentation, control records, exception records, and supporting artifacts in approved repositories or GRC platforms.
• Assist in preparing security metrics, dashboards, management summaries, and committee materials.
• Track policy review cycles, control attestations, audit requests, and management action items to closure.
Risk Management
• Conduct or support information security risk assessments for systems, applications, cloud services, vendors, projects, and business initiatives.
• Document risks, likelihood, impact, existing controls, treatment plans, residual risk, and ownership in the risk register.
• Facilitate risk reviews with risk owners, process owners, technology teams, and business stakeholders.
• Track risk treatment plans, remediation actions, security exceptions, and risk acceptance decisions.
• Support reporting of risk posture, key risk indicators, and remediation status to management.
Third-Party & Vendor Risk Management
• Perform vendor security due diligence and third-party risk assessments using questionnaires, interviews, and document reviews.
• Review SOC 1/SOC 2 reports, ISO certifications, penetration test summaries, policies, and other vendor assurance documentation.
• Identify vendor control gaps, document risks, and recommend practical mitigation actions.
• Monitor vendor remediation commitments, reassessment timelines, and security review outcomes.
• Maintain vendor security assessment records and provide concise reporting to stakeholders.
Audit & Control Assurance
• Support audit planning, evidence gathering, control walkthroughs, and responses to auditor requests.
• Perform control testing and compliance reviews against internal security requirements and recognized frameworks.
• Track audit observations, corrective actions, root cause analysis outcomes, and remediation evidence.
• Validate closure and effectiveness of corrective actions where assigned.
• Support continuous monitoring of key information security controls.
Security Awareness & Governance Support
• Support security awareness, compliance training, and reporting activities.
• Assist with Information Security Steering Committee or governance meeting materials, minutes, and action tracking.
• Prepare clear executive summaries, status updates, and decision materials for security leadership.
• Promote a risk-aware culture by helping business teams understand security obligations in practical terms.
Skills & Competencies
• Strong analytical and critical thinking skills.
• Excellent written and verbal communication skills, with the ability to prepare concise, business-ready documentation.
• Ability to translate technical findings, control gaps, and risk scenarios into clear business impact statements.
• Strong attention to detail and commitment to evidence quality.
• Effective stakeholder management and ability to coordinate across IT, business, audit, legal, privacy, and vendor teams.
• Ability to manage competing priorities and meet deadlines in a dynamic enterprise environment.
• Practical mindset focused on balancing security, risk reduction, and business enablement.
• Experience working in regulated or global enterprise environments is an asset
Preferred Certifications
• CISA, CRISC, CISM, CISSP, ISO 27001 Lead Implementer or Lead Auditor, Security+, or equivalent certification.
• Candidates actively pursuing relevant certifications may also be considered.
Qualifications
Education
• Bachelor's degree in Information Security, Cybersecurity, Information Technology, Risk Management, Business Administration, or a related discipline.
• Equivalent combination of education, training, and professional experience will be considered.
Top Skills Necessary
• 3+ years of experience in Information Security, IT Risk, Compliance, Internal Audit, Technology Assurance, or a related governance role.
• 3+ years of experience supporting enterprise control frameworks, audit readiness, risk assessments, and compliance programs.
• 3+ years of experience conducting vendor security reviews or third-party risk assessments.
Affinity Earn:
Know someone who’s great for this, or any of our open roles? Earn up to $4,000/year for each successful referral through Affinity Earn. You can also earn up to $50,000 for helping us find new clients. Learn about our referral program at https://affinity-group.ca/earn/ or browse our jobs & follow us at https://www.linkedin.com/company/affinity-staffing/jobs/
About Affinity:
Affinity Group is a technology and business consulting and services company. We believe in creating long term relationships between clients and consultants that foster a mutually beneficial partnership. Affinity is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All employment is decided on the basis of qualifications, merit and business need.
For more information on Affinity, please visit www.affinity-group.ca
Job Number: 13843
Follow us on LinkedIn for the most up-to-date roles
Follow Affinity Group