2

Full Time Cyber Security Risk Analyst Jobs in Quebec

Lead Risk Manager, Payment Fraud

Montreal, QC ยท Hybrid

$150K - $180K/yr

Lead Risk Manager, Payment Fraud Toronto Onsite | Full-Time | Hybrid after onboarding | Reports to ... This is a builder role for a Risk Leader with hacker instincts and raw analytical horsepower ...

Lead Risk Manager, Payment Fraud

Montreal, QC ยท Hybrid

$150K - $180K/yr

Lead Risk Manager, Payment Fraud Toronto Onsite | Full-Time | Hybrid after onboarding | Reports to ... This is a builder role for a Risk Leader with hacker instincts and raw analytical horsepower ...

... continuous cybersecurity incident intake, triage, investigative response, and data analysis ... Subject matter expertise to evaluate the risk in the context of the enterprise to mitigate risk and ...

... continuous cybersecurity incident intake, triage, investigative response, and data analysis ... Subject matter expertise to evaluate the risk in the context of the enterprise to mitigate risk and ...

next page

Showing results 1-20

Full Time Cyber Security Risk Analyst information

What is the difference between Full Time Cyber Security Risk Analyst vs Cyber Security Analyst?

AspectFull Time Cyber Security Risk AnalystCyber Security Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CEH, CISSP (preferred)
Work EnvironmentRisk assessment teams, security compliance, policy developmentSecurity monitoring, incident response, vulnerability assessment
Employer & Industry UsageFinancial, healthcare, government sectors focusing on risk managementIT firms, tech companies, cybersecurity service providers

Full Time Cyber Security Risk Analysts focus on identifying, assessing, and mitigating security risks within organizations, often working on compliance and policy. Cyber Security Analysts primarily monitor security systems, respond to incidents, and perform vulnerability assessments. While both roles require similar certifications and work in cybersecurity, their core responsibilities differ: risk analysis versus security monitoring.

What are the most commonly searched types of Cyber Security Risk Analyst jobs in Quebec? The most popular types of Cyber Security Risk Analyst jobs in Quebec are:
What cities in Quebec are hiring for Full Time Cyber Security Risk Analyst jobs? Cities in Quebec with the most Full Time Cyber Security Risk Analyst job openings:
Security Analyst - VMaaS (Quebec Province Only-Mandatory French)

Security Analyst - VMaaS (Quebec Province Only-Mandatory French)

GoSecure

Montreal, QC โ€ข On-site

Full-time

Medical, Dental, Vision, Life, PTO

Posted 13 days ago


Job description


Summary

The VMaaS Analyst is responsible for supporting the delivery and operation of Vulnerability Management as a Service. This includes identifying, analyzing, prioritizing, and reporting vulnerabilities across client environments or internal systems. The analyst ensures timely remediation and maintains compliance with relevant security frameworks. This role is critical in reducing risk exposure and enhancing the organizationโ€™s overall security posture.

Duties and responsibilities

  • Operate and maintain vulnerability scanning tools (e.g., Tenable, Qualys, Rapid7, etc.)
  • Perform regular vulnerability assessments across on-premise and cloud environments.
  • Analyze scan results to identify false positives and prioritize true findings based on risk.
  • Develop and deliver vulnerability reports and dashboards tailored to technical and non-technical audiences.
  • Collaborate with system owners, IT teams, and application developers to track remediation efforts and provide guidance on fixes.
  • Monitor threat intelligence and CVE feeds to stay current on emerging vulnerabilities.
  • Support the tuning of scanning tools to improve detection accuracy and performance.
  • Ensure service-level agreements (SLAs) for vulnerability management are met.
  • Maintain documentation for processes, playbooks, and customer engagement models.
  • Assist in audits and compliance efforts (e.g., PCI-DSS, ISO 27001, NIST CSF).
  • Participate in incident response efforts related to newly disclosed or exploited vulnerabilities.
  • Contribute to continuous improvement of the VMaaS offering.

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field; or equivalent work experience.
  • 2+ years of experience in vulnerability management or cybersecurity operations.
  • Hands-on experience with one or more vulnerability management tools (e.g., Tenable.io, Qualys, Rapid7 InsightVM).
  • Solid understanding of network protocols, operating systems, and web applications.
  • Familiarity with CVSS, NIST NVD, MITRE ATT&CK, and vulnerability scoring.
  • Strong analytical, organizational, and problem-solving skills.
  • Ability to interpret technical findings and communicate risks effectively.
  • Bilingual: English and French in order to respond effectively to our customers and colleagues outside of QC.
  • French is mandatory for this position

Preferred:

  • Experience with cloud platforms (AWS, Azure, GCP) and their security services.
  • Knowledge of patch management and secure configuration practices.
  • Certifications such as CompTIA Security+, CEH, OSCP, or GIAC GSEC/GCIH.
  • Familiarity with ticketing systems (e.g., ServiceNow, Jira) and SIEM tools (e.g., Splunk).

Why come to GoSecure?

3 weeks vacation, 5 personal days

14 paid statutory Holidays

Collective insurance: health, vision, dental, disability, life, travel

Employee Assistance Program (Dialogue)

RSP and employer matching contribution

Peers recognition program and other bonuses given along the year

Company stock options

GoSecurian perks

Young and dynamic team always looking to be better

and much more!