1

Cyber Security Risk Analyst Jobs in Ottawa, ON (NOW HIRING)

From risk assessments and control testing to executive-level reporting and awareness programs, you ... Analyze cybersecurity costs to identify optimization opportunities * Assess the organizational ...

Senior Cyber Security Specialist

Ottawa, ON · Hybrid

CA$105K - CA$150K/yr

... analysis and providing expert advice and recommendations to reduce risk and improve cyber security posture. * Manages, trains, directs, and supports the work of team members allocated to ...

From risk assessments and control testing to executive-level reporting and awareness programs, you ... Analyze cybersecurity costs to identify optimization opportunities * Assess the organizational ...

Cybersecurity Incident Manager

Ottawa, ON · Hybrid

CA$112K - CA$162K/yr

... Listening, Analytical Thinking, Coaching and Feedback, Communication, Creativity, Cybersecurity Framework, Cybersecurity Governance, Cybersecurity Risk Management, Cybersecurity Strategy ...

QNX Senior Cybersecurity Manager

Ottawa, ON · On-site

CA$108K - CA$158K/yr

Be the cybersecurity authority for development teams, guiding them to meet ISO/SAE 21434 standards ... Lead Threat Analysis and Risk Assessment (TARA) activities, ensuring compliance with ISO 21434.

next page

Showing results 1-20

Cyber Security Risk Analyst information

See Ottawa, ON salary details

$67.6K

$110.1K

$162.4K

How much do cyber security risk analyst jobs pay per year?

As of Aug 16, 2026, the average yearly pay for cyber security risk analyst in Ottawa, ON is $110,141.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,498.00 and $126,222.00 per year, depending on experience, location, and employer.

What is a cyber security risk analyst?

A Cyber Security Risk Analyst is responsible for identifying, assessing, and mitigating cybersecurity risks within an organization. They analyze potential threats, evaluate security controls, and recommend improvements to protect sensitive data and systems. Their role often involves conducting risk assessments, ensuring compliance with industry regulations, and collaborating with IT and security teams to enhance defenses. They also monitor emerging threats and provide strategic insights to minimize vulnerabilities. Ultimately, they help organizations maintain a strong security posture against cyber threats.

What are some typical challenges faced by cyber security risk analysts on the job?

Cyber Security Risk Analysts commonly face the challenge of keeping up with constantly evolving threats and technology landscapes. They must balance the need for robust security with business objectives, often requiring nuanced decision-making and collaboration across departments. Analysts may also encounter difficulties in communicating complex technical risks to non-technical stakeholders. Successfully navigating these challenges is key to maintaining organizational security and fostering a culture of risk awareness.

What are the key skills and qualifications needed to thrive in the cyber security risk analyst position, and why are they important?

A Cyber Security Risk Analyst requires a solid understanding of information security principles, risk assessment methodologies, and a relevant degree such as computer science or cybersecurity. Familiarity with tools like risk management frameworks (NIST, ISO 27001), vulnerability scanners, and certifications such as CISSP, CISM, or CRISC is common in this role. Strong analytical thinking, attention to detail, effective communication, and problem-solving skills are vital soft skills. These competencies enable analysts to accurately identify, assess, and communicate cyber risks, protecting organizations from evolving threats.

How much does a cyber security risk analyst make?

The average salary for a cyber security risk analyst is around $80,000 to $110,000 per year, depending on experience, certifications, and location. Entry-level positions typically start lower, while experienced analysts with certifications like CISSP or CISA can earn higher salaries. The role often requires knowledge of risk assessment tools and security frameworks.

What does a cybersecurity risk analyst do?

A cybersecurity risk analyst evaluates an organization’s security posture by identifying vulnerabilities, assessing potential threats, and analyzing risks to information systems. They develop strategies to mitigate risks, often using tools like risk assessment frameworks and security audits, and may hold certifications such as CISSP or CISA. Their work helps organizations protect sensitive data and ensure compliance with security standards.

What are the most commonly searched types of Cyber Security Risk Analyst jobs in Ottawa, ON?

The most popular types of Cyber Security Risk Analyst jobs in Ottawa, ON are:

What job categories do people searching Cyber Security Risk Analyst jobs in Ottawa, ON look for?

The top searched job categories for Cyber Security Risk Analyst jobs in Ottawa, ON are:

Infographic showing various Cyber Security Risk Analyst job openings in Ottawa, ON as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $110,141 per year, or $53 per hour.

Senior Analyst, Governance Risk and Compliance

Telesat

Ottawa, ON • On-site

Full-time

Posted 13 days ago


Job description

Telesat (Nasdaq and TSX: TSAT) is a leading global satellite operator, providing reliable and secure satellite-delivered communications solutions worldwide to broadcast, telecommunications, corporate and government customers for over 55 years.  Backed by a legacy of engineering excellence, reliability and industry-leading customer service, Telesat has grown to be one of the largest and most successful global satellite operators.

Telesat Lightspeed, our revolutionary Low Earth Orbit (LEO) satellite network, scheduled to begin service in 2027, will revolutionize global broadband connectivity for enterprise and Government users by delivering a combination of high capacity, security, resiliency and affordability with ultra-low latency and fiber-like speeds. Telesat is headquartered in Ottawa, Canada, and has offices and facilities around the world.
The company's state-of-the-art Satellite fleet consists of 12 GEO satellites, the Canadian payload on ViaSat-1 and one LEO 3 demonstration satellite.  For more information, follow Telesat on X and LinkedIn or visit www.telesat.com


Telesat is seeking a highly collaborative and technically proficient Senior Analyst to serve as the primary liaison between Cybersecurity, Engineering, Corporate Functions, and Business Operations for the translation of contractual cybersecurity obligations into enterprise and system-level requirements. This role focuses on converting high-level cybersecurity controls and contractual mandates defined by the Cybersecurity Governance team, into actionable, verifiable, and traceable technical specifications for the Telesat Lightspeed program. The goal is to ensure the accurate implementation of these requirements within engineering deliverables.

The Senior Analyst will be responsible for analyzing customer, regulatory, contractual, and cybersecurity requirements to incorporate them into Telesat Lightspeed System Specifications and supporting operational processes. This individual will work cross-functionally with Engineering, Product Management, Legal, Procurement, Information Technology, Operations, Program Management, Supply Chain, Human Resources, and other business units to ensure cybersecurity requirements are properly understood, documented, allocated, implemented, and maintained throughout the organization and across the Lightspeed program lifecycle. This includes maintaining traceability matrices that link contractual obligations to specific technical controls.

The successful candidate will bridge the gap between contractual language and practical implementation requirements by providing guidance to engineering teams on how to meet security obligations. The position requires strong systems engineering awareness and exceptional stakeholder management skills to facilitate communication between legal/contractual stakeholders and engineering teams.

Main Responsibilities
  • Serve as the primary liaison between Cybersecurity, Engineering, Corporate Functions, and Business Operations to translate contractual cybersecurity obligations into enterprise and system-level requirements.
  • Convert high-level cybersecurity controls and contractual mandates (defined by the Cybersecurity Governance team) into actionable, verifiable, and traceable technical specifications for the Telesat Lightspeed program.
  • Ensure the accurate implementation of cybersecurity requirements within engineering deliverables.
  • Analyze customer, regulatory, contractual, and cybersecurity requirements to convert them into detailed technical requirements for Telesat Lightspeed System Specifications.
  • Work cross-functionally with Engineering, Product Management, Legal, Procurement, IT, Operations, Program Management,
  • Supply Chain, HR, and other business units to ensure security requirements are understood, documented, allocated, implemented, and maintained throughout the Lightspeed program lifecycle.
  • Maintain traceability matrices that link contractual obligations to specific technical controls.
  • Bridge the gap between contractual language and practical implementation by providing guidance to engineering teams on how to meet security obligations.
Education and Experience Required
  • A Diploma or Degree in a relevant area of study with a preference for Computer Science or Engineering together with a demonstrated IT policy related experience.  
  • 5 years of experience as a Security Governance, Risk Management, and Compliance (GRC) specialist. 
  • 3 years of experience in designing and developing procedures, and processes for Information Security best practices. 
  • CISA (Certified Information Systems Auditor) certification is preferred. 
Specialized Knowledge, Skills and Abilities
  • Extensive experience leading cybersecurity risk assessments, risk management activities, and the development of risk mitigation strategies across complex enterprise and engineering environments.
  • Demonstrated ability to analyze and interpret contractual, regulatory, customer, and cybersecurity requirements, translating them into actionable, measurable, and traceable technical and operational requirements.
  • Strong understanding of cybersecurity governance, compliance frameworks, and control implementation, with the ability to bridge strategic security objectives and engineering execution.
  • Excellent written, verbal, and executive-level communication skills, with the ability to communicate complex cybersecurity and technical concepts to both technical and non-technical stakeholders.
  • Exceptional presentation and facilitation skills, including the ability to lead cross-functional workshops, requirements reviews, and stakeholder discussions at all organizational levels.
  • Proven ability to build strong relationships and collaborate effectively
  • Strong organizational, analytical, and systems-thinking skills, with experience managing complex requirements, dependencies, and competing priorities in large-scale programs.
  • Experience developing and maintaining requirements traceability matrices to ensure contractual, regulatory, and cybersecurity obligations are mapped to technical controls, system specifications, and implementation activities.
  • Experience with NIST SP 800-53, NIST SP 800-171, and related cybersecurity frameworks; experience supporting aerospace, satellite, telecommunications, or other critical infrastructure environments is considered a strong asset.
  • Knowledge of CNSSP-12, CAIQ, and other security assessment or assurance frameworks is an asset.
  • Experience with Governance, Risk, and Compliance (GRC) platforms, requirements management tools, compliance automation solutions, and traceability tools is an asset.
  • Demonstrated ability to influence decision-making, resolve conflicts, and drive consensus among diverse stakeholder groups while maintaining alignment with program objectives and security requirements.
Decision Making and Supervision
  • Serve as the primary advisor to cross-functional teams on the interpretation, implementation, and maintenance of cybersecurity, contractual, and regulatory requirements.
  • Lead the translation of cybersecurity and contractual obligations into actionable technical and operational requirements, ensuring alignment with business and program objectives.
  • Partner with senior management and cross-functional stakeholders to support risk-based decision-making, cybersecurity strategy execution, governance activities, and compliance priorities
  • Facilitate collaboration and consensus among Engineering, IT, Legal, Procurement, Operations, and business teams to balance security, operational, and business requirements.
  • Identify, assess, and escalate significant cybersecurity, compliance, or program risks, providing impact analysis and recommended mitigation strategies to leadership.
Candidates must be able to work in Canada and obtain Enhanced Reliability Status.

At Telesat, we take pride in being an equal opportunity employer that values equality in the workplace.   We are committed to providing the best candidate experience possible including any required accommodations at every stage of our interview process.   All qualified applicants that have been selected for an interview that require accommodations, are advised to inform the Telesat Talent team accordingly.  We will work with you to meet your needs.   All accommodation information provided will be treated as confidential.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
apply for this job