1

Job Analyst Jobs in Toronto, ON (NOW HIRING)

Analyst

Toronto, ON · On-site

$70K - $110K/hr

Hydropower Analyst - Asset Management Location: Toronto, ON - 4 days per week in office Salary: $70,000 - $85,000 Reporting to the Hydropower Asset Manager, you will work as a member of a ...

Analyst

Toronto, ON · Hybrid

CA$40K - CA$50K/yr

This position is an Analyst, Valuation & Advisory Services role based out of our Downtown Toronto Office. This is a hybrid role. About you You're an aspiring appraisal professional looking to learn ...

Analyst

Toronto, ON · Hybrid

CA$40K - CA$50K/yr

This position is an Analyst, Valuation & Advisory Services role based out of our Downtown Toronto Office. This is a hybrid role. About you You're an aspiring appraisal professional looking to learn ...

Analyst

Toronto, ON · On-site

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential ...

As a Product Analyst you will drive data informed product decisions by delivering actionable insights designing robust experiments and deeply understanding user behaviour You will partner closely ...

Data Analyst

Toronto, ON · Hybrid

CA$75K - CA$100K/yr

We hire exceptionally smart, analytical, and hard-working people who are lifelong learners. About The Role This role sits on our Digital team, where your internal title will be Specialist, Digital ...

Business Analyst

Toronto, ON · Hybrid

CA$85K - CA$105K/yr

Business Analyst, Data & Insights (Power BI) Location: Etobicoke Corporate Office (Hybrid - In office Monday, Tuesday, Wednesday) Compensation: $85,000 - $105,000 Annually with additional Bonus Job ...

Data and Analytics Job Subfunction: Data Science and Analytics WHO WE ARE: We are TRACK - a member of the RAPP family- world leaders in activating growth with precision and empathy at scale. As a ...

We are looking for a data-driven Operations Analyst to join our team. The ideal candidate will combine strong analytical skills with industry knowledge to drive continuous improvement in our damage ...

The Financial Analyst plays a key role in supporting financial planning, forecasting, reporting, and business decision-making across the organization. This position is responsible for analyzing ...

next page

Showing results 1-20

Job Analyst information

What is a job analyst?

Job Analysts are human resources professionals who study and evaluate job roles within an organization. They collect and analyze data about job duties, responsibilities, necessary skills, and working conditions to create accurate job descriptions. This information helps employers with recruitment, performance evaluations, compensation, and compliance with labor regulations. Job Analysts play a critical role in ensuring that organizations have well-defined job structures and that employees' roles are clearly understood.

How does a job analyst typically collaborate with HR teams and department managers during the job evaluation process?

Job Analysts work closely with HR professionals and department managers to gather detailed information about job duties, required qualifications, and organizational needs. This often involves conducting interviews, job observations, and reviewing existing job descriptions to ensure accuracy and relevance. Effective collaboration is crucial, as it helps align job specifications with both operational objectives and compliance requirements. Regular communication and feedback sessions are common, ensuring that the resulting job analyses support fair compensation, recruitment, and workforce planning decisions.

What are the key skills and qualifications needed to thrive as a job analyst, and why are they important?

To thrive as a Job Analyst, you need expertise in job evaluation, compensation analysis, and organizational structure, typically supported by a degree in human resources, business, or a related field. Familiarity with HR information systems (HRIS), job analysis software, and data analytics tools is often required. Strong analytical thinking, attention to detail, and effective communication skills help Job Analysts gather, interpret, and present complex job data. These capabilities are crucial for ensuring that job roles are clearly defined, fairly compensated, and aligned with organizational goals.

What is the difference between Job Analyst vs Job Coordinator?

AspectJob AnalystJob Coordinator
Required CredentialsBachelor's degree in HR, Business, or related field; often certifications in job analysisBachelor's degree; certifications may include project management or HR
Work EnvironmentOffice setting, analyzing job roles, conducting interviews, and documenting job requirementsOffice or on-site, coordinating tasks, schedules, and communication among teams
Employer & Industry UsageHR departments, consulting firms, government agenciesHR teams, project management offices, corporate settings
Common Search & ComparisonUnderstanding job roles, HR analysis, workforce planningManaging projects, team coordination, scheduling

The main difference is that a Job Analyst focuses on evaluating and defining job roles and requirements, while a Job Coordinator manages the scheduling and coordination of tasks within projects or teams. Both roles are essential in HR and organizational operations but serve distinct functions.

What job categories do people searching Job Analyst jobs in Toronto, ON look for?

The top searched job categories for Job Analyst jobs in Toronto, ON are:

What cities near Toronto, ON are hiring for Job Analyst jobs?

Cities near Toronto, ON with the most Job Analyst job openings:

Infographic showing various Job Analyst job openings in Toronto, ON as of August 2026, with employment types broken down into 1% As Needed, 74% Full Time, 20% Part Time, and 5% Contract. Highlights an 91% Physical, 4% Hybrid, and 5% Remote job distribution.

Senior Security Specialist for DxH - RQ00742

Analyst Technical Solutions

Toronto, ON

Full-time

Posted 3 days ago

New


Job description

Job TitleRQ-2026-009872 -Security Specialist - Senior for DxHDescription

Background Information:

This engagement involves driving the end-to-end execution of a Threat Risk Assessment (TRA) to evaluate the security posture of the information system, application, infrastructure, and business process. The objective is to identify potential threats, assess vulnerabilities, and determine the likelihood and impact of various risk scenarios affecting confidentiality, integrity, and availability.

Key activities included:

  • Scoping the assessment in collaboration with business and technical stakeholders.
  • Conducting structured risk analysis using recognized frameworks such as ISO 31000, NIST RMF, or FAIR.
  • Performing threat modeling (e.g., STRIDE, MITRE ATT&CK) to map potential attack vectors and security gaps.
  • Reviewing system architecture, data flows, and existing controls.
  • Assessing compliance with relevant regulatory and organizational security requirements.
  • Documenting findings in a detailed TRA report, including risk ratings and actionable mitigation recommendations.
  • Presenting results to executive leadership and supporting integration of risk treatments into the broader security strategy.

Must haves:

  • In-depth knowledge of risk management frameworks (e.g., ISO 31000, NIST RMF – Risk Management Framework) and threat modelling methodologies (e.g., STRIDE, DREAD).
  • Expertise in identifying, evaluating, and prioritizing threats and vulnerabilities across physical, cyber, and operational domains.
  • Strong analytical skills to assess potential impacts and likelihoods of various threat scenarios.
  • Proficiency risk assessment matrices
  • Excellent communication and reporting abilities to effectively present findings and risk mitigation strategies to both technical teams and executive stakeholders.
  • Familiarity with legal, regulatory, and compliance requirements, ensuring assessments align with organizational and industry standards (e.g., PHIPAA - Personal Health Information Protection Act).
  • Proactive mindset and situational awareness to anticipate and adapt to emerging threats in a dynamic risk environment.

Responsibilities:

  • Drive end-to-end Threat Risk Assessment (TRA) initiatives across systems, processes, and assets.
  • Develop and apply threat models to assess organizational security posture.
  • Collaborate with stakeholders to align assessments with business objectives and risk tolerance.
  • Analyze vulnerabilities and assess threats to determine likelihood and potential impact.
  • Produce detailed TRA reports, documenting findings, recommendations, and risk ratings.
  • Maintain risk registers and track remediation efforts.
  • Propose actionable mitigation strategies based on assessment outcomes.
  • Ensure alignment with:
    • Regulatory requirements
    • Industry standards
    • Organizational security policies
  • Communicate findings effectively to both technical teams and executive leadership.
  • Support audit and compliance activities as needed.
  • Contribute to the continuous improvement of risk management frameworks and methodologies.
  • Stay informed on emerging threats, vulnerabilities, and security best practices.

Desired Skills:

  • Demonstrated expertise in enterprise risk analysis, with a solid background in applying risk management frameworks such as ISO 31000, FAIR (Factor Analysis of Information Risk), and NIST RMF to identify, evaluate, and prioritize organizational security risks.
  • Hands-on experience conducting structured threat analysis, utilizing methodologies like STRIDE, PASTA (Process for Attack Simulation and Threat Analysis), and MITRE ATT&CK. Familiarity with creating threat models, mapping attack surfaces, and visualizing system flows to uncover security weaknesses.
  • Strong command of cybersecurity governance practices, including the development and enforcement of information security policies and standards. Practical understanding of how to align internal controls with recognized frameworks like ISO 27001, NIST CSF, and the CIS Critical Security Controls.
  • Proven ability to translate technical risk findings into clear business language, producing high-quality documentation such as executive summaries, detailed risk reports, and stakeholder presentations. Skilled in managing communication between technical teams and leadership to drive informed decision-making.

Required Skills:

  • Risk Management & Assessment – 5–7 years - Proven experience in conducting threat risk assessments using frameworks like ISO 31000, NIST RMF, or FAIR.
  • Threat Modeling – 3–5 years - Practical knowledge of threat modeling techniques (e.g., STRIDE, PASTA, MITRE ATT&CK), including development of data flow diagrams and attack vectors.
  • Information Security Governance – 5+ years-Strong understanding of security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls.
  • Communication & Reporting – 5+ years-skilled in writing technical and executive-level reports, risk registers, and presenting to stakeholders and leadership.

Evaluation Criteria:

  • Threat Modeling: - 5-7 years of hands-on experience with threat modeling techniques such as STRIDE, PASTA, and MITRE ATT&CK, including the development of data flow diagrams and identification of attack vectors to inform secure design decisions and guide risk mitigation strategies across systems and applications. 20 Points
  • TRA Report: - 5–7 years of experience conducting comprehensive threat and risk assessments using frameworks such as ISO 31000, NIST RMF, and FAIR, with a strong focus on identifying vulnerabilities, analyzing potential impacts, and delivering actionable risk mitigation strategies to stakeholders. 20 Points
  • Gap Analysis: - 5–7 years of extensive experience with security controls and architecture, with a strong ability to identify gaps between the current security posture and industry standards, best practices, and regulatory requirements. 20 Points
  • Team Player: - Demonstrates strong collaboration skills by working effectively with colleagues across functions, openly sharing information, supporting others to achieve shared goals, and contributing to a positive, respectful team environment. 30 Points
  • Presentation Deck: - Over 5 years of experience authoring technical and executive-level reports, developing risk registers, and delivering presentations to stakeholders and senior leadership. 10 Points

Total: 100 Points


Deliverables

Deliverables:

  • TRA (Threat, Risk Assessment) Report: - A comprehensive document outlining identified threats, vulnerabilities, risks, and proposed mitigation strategies, tailored to the organization’s context.
  • Risk Register: - A structured log of all identified risks, including severity, likelihood, risk rating, responsible owners, and mitigation actions.
  • Threat Modeling Diagrams: - Visual representations of systems, data flows, and potential threat vectors using models like STRIDE or attack trees.
  • Risk Assessment Matrix: - A visual tool mapping the likelihood and impact of risks to prioritize them effectively.
  • Asset Inventory & Classification: - A list of assets in scope (e.g., systems, applications, data) categorized by value and sensitivity.
  • Vulnerability Assessment Results: - A summary of technical vulnerabilities discovered during the assessment, often with outputs from tools like Nessus or OpenVAS.
  • Gap Analysis: - Identification of discrepancies between current security posture and industry standards, best practices, or regulatory requirements.
  • Mitigation & Remediation Plan: - Detailed action plans with timelines and responsibilities for reducing identified risks to acceptable levels.
  • Executive Summary: - A high-level summary tailored for senior leadership, focusing on key findings, business impact, and strategic recommendations.
  • Compliance Mapping: - Documentation showing how risks and controls align with regulatory or standards frameworks (e.g., NIST, ISO 27001, SOC 2).
  • Presentation Deck: - Slide-based briefing to communicate findings, risks, and recommendations to stakeholders in a clear and digestible format.

Must Haves:

  • Risk Management & Assessment – 5–7 years - Proven experience in conducting threat risk assessments using frameworks like ISO 31000, NIST RMF, or FAIR.
  • Threat Modeling – 3–5 years - Practical knowledge of threat modeling techniques (e.g., STRIDE, PASTA, MITRE ATT&CK), including development of data flow diagrams and attack vectors.
  • Information Security Governance – 5+ years-Strong understanding of security policies, standards, and controls aligned with ISO 27001, NIST CSF, and CIS Controls.
  • Communication & Reporting – 5+ years-skilled in writing technical and executive-level reports, risk registers, and presenting to stakeholders and leadership.

Location: Hybrid (upto 3 days onsite at manager's discretion)

Office Location  525 University Avenue