Position: Security Analyst (Cybersecurity & GRC)
Location: Toronto, ON Hybrid (4 days on-site, Downtown Toronto)
Salary: $75,000 to $85,000/year
Job Type: Permanent
Position Type: Open Vacancy
We are seeking an experienced Security Analyst to join a leading team. This is an exciting opportunity for a cybersecurity professional who is passionate about governance, risk, and compliance (GRC) and enjoys helping organizations strengthen their security posture through assessments, technical reviews, and best practices.
Your new role:
As a Security Analyst, you will support cybersecurity and GRC initiatives by conducting security assessments, technical audits, and compliance reviews across cloud and enterprise environments. You will work closely with technical and business stakeholders to evaluate security controls, identify risks, and support remediation efforts while contributing to audit readiness and continuous security improvements.
Key responsibilities:
- Assist in conducting cybersecurity and GRC assessments based on frameworks such as SOC 2, ISO 27001, NIST CSF, and CIS Controls- Perform technical audits and evidence reviews across Microsoft 365, Azure, AWS, Google Cloud Platform (GCP), Active Directory, and key SaaS environments
- Validate security configurations for access controls, logging, backups, encryption, and patch management
- Participate in interviews and discovery sessions with technical and business stakeholders
- Draft policies, control narratives, risk assessments, and audit-ready documentation
- Contribute to remediation plans, risk tracking, and report delivery
- Support tabletop exercises, incident response planning (IRP), business continuity planning (BCP), vendor assessments, and other GRC initiatives
Key requirements:
- College diploma or university degree in Information Security, Computer Science, Information Systems, or a related field- Experience supporting cybersecurity, GRC, audit, or compliance functions
- Strong understanding of cybersecurity frameworks such as SOC 2, ISO 27001, NIST CSF, and CIS Controls
- Experience performing technical reviews across Microsoft 365, Azure, AWS, GCP, Active Directory, and SaaS environments
- Strong organizational and communication skills with the ability to manage multiple priorities and client-facing responsibilities
- Experience preparing compliance documentation, risk assessments, and supporting remediation activities
Preferred qualifications:
- Certifications such as CompTIA Security+, Microsoft SC-900, AWS Certified Cloud Practitioner, or equivalent- Experience working within or alongside a GRC or audit function
- Familiarity with policy frameworks, risk registers, and compliance lifecycle documentation
Interested? Please send your resume to Shannon at Shannon.scullion@quantum-qtr.com.
REFER A NEW HIRE AND EARN A CASH BONUS! For details, click here.
All applications are reviewed by our recruitment team, and hiring decisions are made by people. We may also use AI-enabled tools to support parts of the application review process.