1

Cyber Security Risk Management Jobs in Ontario (NOW HIRING)

... management, DevSecOps integration, and regulatory evidence for connected medical devices while ... Lead threat modeling, product cybersecurity risk assessments, and mitigation planning with global ...

Senior Analyst - Cybersecurity (M&A), SITRM Location: Krakow, Poland (Hybrid) Type: Full-time ... risk management. * Excellent oral and written communication and ability to engage with senior ...

... manage the application hygiene such as end of life, vulnerabilities and cyber security aspects, and ... Partner with Market Risk, CCR (Counterparty Credit Risk), Model Risk, Quants, Infrastructure, and ...

Manager Cyber Cloud Security and AI

Ottawa, ON · Hybrid

CA$116K - CA$166K/yr

Risk Management:Conduct risk assessments toidentifyvulnerabilities in AI systems and data management practices. Design and implement plans to address cybersecurity risks related to AI applications ...

Manager Cyber Cloud Security and AI

Toronto, ON · Hybrid

CA$116K - CA$166K/yr

Risk Management:Conduct risk assessments toidentifyvulnerabilities in AI systems and data management practices. Design and implement plans to address cybersecurity risks related to AI applications ...

Showing results 41-60

Cyber Security Risk Management information

See Ontario salary details

$28K

$118K

$171K

How much do cyber security risk management jobs pay per year?

As of Sep 9, 2026, the average yearly pay for cyber security risk management in Ontario is $118,029.00, according to ZipRecruiter salary data. Most workers in this role earn between $97,500.00 and $140,500.00 per year, depending on experience, location, and employer.

What is cyber security risk management?

Cyber security risk management is the process of identifying, assessing, and prioritizing risks to an organization's information systems and data. It involves evaluating potential threats and vulnerabilities, determining the likelihood and impact of these risks, and implementing measures to mitigate or manage them. Effective risk management helps organizations protect sensitive data, ensure regulatory compliance, and minimize the impact of cyber attacks. This process is ongoing and adapts to new threats and changes in technology.

What are the key skills and qualifications needed to thrive in cyber security risk management?

To thrive in Cyber Security Risk Management, you need a solid understanding of risk assessment methodologies, information security frameworks (such as ISO 27001 or NIST), and often a relevant degree or certification like CISSP or CISM. Familiarity with security tools, vulnerability assessment platforms, and risk management software is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for identifying threats and conveying risk to stakeholders. These skills ensure that organizations can proactively manage and mitigate cyber threats, safeguarding critical assets and maintaining compliance.

What are some typical challenges faced in cyber security risk management, and how can they be addressed?

Professionals in Cyber Security Risk Management often encounter challenges such as staying updated with rapidly evolving threats, balancing security needs with business objectives, and ensuring compliance with various regulations. Addressing these challenges requires continuous learning, effective communication with stakeholders, and the implementation of robust risk assessment frameworks. Collaboration with IT, legal, and business teams is essential to develop practical security policies that protect assets without hindering operations.

What is the difference between Cyber Security Risk Management vs Cyber Security Analyst?

AspectCyber Security Risk ManagementCyber Security Analyst
CertificationsCompTIA Security+, CISSP, CISMCompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentPolicy development, risk assessment, strategic planningMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageOrganizations focusing on risk mitigation and complianceOrganizations implementing and maintaining security measures

Cyber Security Risk Management professionals focus on identifying, assessing, and mitigating security risks at an organizational level, often involved in policy and strategy. Cyber Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the same industry, their core responsibilities differ: risk managers develop strategies, whereas analysts execute security measures and respond to threats.

What does a cyber security risk management do?

A cyber security risk management professional identifies, assesses, and prioritizes potential security threats to an organization’s information systems. They develop strategies and implement controls to mitigate risks, often using frameworks like NIST or ISO, and may conduct regular audits to ensure security measures are effective.

What are popular job titles related to Cyber Security Risk Management jobs in Ontario?

For Cyber Security Risk Management jobs in Ontario, the most frequently searched job titles are:

What job categories do people searching Cyber Security Risk Management jobs in Ontario look for?

The top searched job categories for Cyber Security Risk Management jobs in Ontario are:

What cities in Ontario are hiring for Cyber Security Risk Management jobs?

Cities in Ontario with the most Cyber Security Risk Management job openings:

Infographic showing various Cyber Security Risk Management job openings in Ontario as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 15% Part Time, and 3% Contract. Highlights an 82% Physical, 3% Hybrid, and 15% Remote job distribution, with an average salary of $118,029 per year, or $56.7 per hour.

RQ00226 - Security Analyst - Intermediate

Toronto, ON • Hybrid

Source Code
Computer and Peripheral Equipment Manufacturing • 201 - 500 employees

Full-time

Posted 11 days ago


Job description

RQ00226 - Security Analyst - Intermediate
Duration: 6 Months (131 Business Days)
Location: Hybrid, 3 days in office, 2 days remote at 20 Bay St
Must Haves:
  • Minimum 4-6 years of experience in progressively advancing roles within IT or a related function, with a focus on IT Security/Cybersecurity. Strong track record of competency in risk management and cybersecurity management in IT, with 3 to 5 years of relevant experience. Certifications or Designations
  • Professional security management certification is an asset, such as, Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Governance of Enterprise IT (CGEIT), Certified Risk and Information Systems Controls (CRISC), Certified Information Systems Auditor (CISA) or other similar credentials an asset
  • Perform vendor risk assessments and enhanced the Third-Party Risk Management (TPRM) program by Gathering and preparing data for reporting security service performance metrics that includes status of information systems, services obtained from external providers, and actions for improvement and Providing input into security pen testing activities conducted by a third-party security services provider 4-6 years experience

Description

Responsibilities Perform real time monitoring and analysis of events with a focus on identifying potential security incidents. Respond and investigate potential alerts and tickets. Collect and analyze evidence including network traffic, volatile data, logs and other indicators. General Skills Experience in IT Security, operational security monitoring, incident response. Understanding of TCP/IP stack, *nix/Windows systems Knowledge of network infrastructure and internet applications Understanding of different cyber-attacks Knowledge of security threats and attack types Analysis of cyber threats and experience in providing action plans Ability to investigate, evaluate and recommend Cyber Security products and intrusion detection technology to minimize vulnerabilities.

ACCOUNTABILITY STATEMENT

The Governance Analyst will be responsible for supporting the development and maintenance of Payments (PRESTO) ITSEC governance, compliance, audit, and reporting capabilities. The Governance Analyst will contribute to ensuring that:

Payments (PRESTO) projects adhere to ITSEC policies.

Payments (PRESTO) complies with relevant policies, including those from the Government of Ontario, PCI, NIST, and other applicable cybersecurity standards (ISO 27001).

All security audit requirements are fulfilled. Appropriate cyber risk reporting is provided to internal and external stakeholders.

KEY CONTRIBUTIONS Functional/Technical

  • Design ITSEC performance KPIs and report on them to appropriate stakeholders as a means of measuring and evaluating cybersecurity effectiveness.
  • Foster relationships across the organization to promote awareness of compliance and ITSEC principles.
  • Contribute to development and implementation of Payments (PRESTO) Third-party Cyber Risk Management framework, participating in its design and execution to align with ITSEC governance objectives and industry best practices
  • Provide timely updates and reports to internal and external stakeholders, including Senior Management Team (SMT), Audit, Finance, and others as necessary.
  • Collaborate with Risk & Compliance, Privacy, Records Management, and Finance departments to understand the risk appetite for key business applications and coordinate appropriate treatment of identified cyber risks that exceed accepted risk levels.
  • Work with IT Operations and Risk & Compliance teams to develop and maintain digital assets inventory management systems, ensuring proper identification, classification, ownership, and associated risks and compliance requirements.
  • Manage governance activities to maintain full compliance with ISO 27001, Privacy (FIPPA), and NIST standards. IT Security Governance Analyst - 1733 Effective Date - May 12, 2023
  • Support security audit activities, including PCI audits, internal audits, and external audits such as CSAE 3416.

Customer/Stakeholder

Communicates with the organization's end users regarding appropriate Governance activities and issues as necessary

Works closely with business units to manage and execute contractual and legal governance requirements dealing with Payments cyber security requirements

Assists the extended teams (VMO, Procurement etc.) with the alignment of the design and operationalization of Metrolinx Cybersecurity risk management practices as they apply to third party contracts including:

  • Assessment of third party and contract risks prior to execution o Determines relevant security controls that should be embedded with security controls that are applicable to third parties
  • Designs and review of service level agreements and management reporting templates for third parties
  • Ensures the appropriate involvement of internal/external stakeholders during the design of the proposed third-party solution contract
  • Implementation of internal control measures to corroborate security reports from third parties
  • Reviews of vendor security control attestation reports and assesses the implications of gaps/breaches as they occur.
  • Provides input into the renewal/termination of contractual arrangements for outsourced services as contract periods lapse.

Operational Excellence

  • Identifies the effectiveness and completeness of business and technologies strategies applicable to ITSEC Governance and ensures alignment with I&IT, Payments (PRESTO) and other applicable cross organization strategies
  • Assist in developing ITSEC governance awareness-training program for resources as necessary and applicable (employees, contractors and/or approved system users)
  • Provides subject matter expertise regarding industry standards, regulations and best practices relevant to the ITSEC Governance

People Leadership

Provides security guidance and assists others in the performance of their day-to-day activities without direct supervisory responsibility

Education

  • Completion of a degree in Business, Engineering, Information Systems, Computer Science or a related discipline – or a combination of education, training and experience deemed equivalent. Experience
  • Minimum 4-6 years of experience in progressively advancing roles within IT or a related function, with a focus on IT Security/Cybersecurity. Strong track record of competency in risk management and cybersecurity management in IT, with 3 to 5 years of relevant experience. Certifications or Designations
  • Professional security management certification is an asset, such as, Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Governance of Enterprise IT (CGEIT), Certified Risk and Information Systems Controls (CRISC), Certified Information Systems Auditor (CISA) or other similar credentials an asset
  • Agile certification (Agile Certified Professional, Certified Scrum Product Owner) an asset
  • Experience in IT Project Delivery or Operations an asset

AI Disclaimer: Source Code may use artificial intelligence (AI) tools to assist in certain aspects of its recruiting and business operations.

Note: The higher end of the range is intended for absolutely exceptional candidates who meet all must-have requirements and most or all nice-to-have qualifications. The client will evaluate candidates based on both rate expectations and overall skill set when shortlisting.

INCORPORATED RATE RANGE (7.25 billable hours per day)

  • $48.66/hr - $52.14/hr Inc.

T4 RATE RANGE (7.25 billable hours per day)

  • $38.93/hr - $41.71/hr T4