Compugen is Canada's largest privately-owned Technology Ally. To innovate industries, transform businesses, connect communities, and drive meaningful change, we must think bigger, reach broader, and act bolder. Through knowledge, curiosity, and collaboration, Compugen helps organizations delivering experience by design. This is what it means to be human-centered and technology-enabled.
Dreaming, designing, and delivering isn't just a mantra for us — it's a way of life. We believe that technology is the conduit, but our people – they are the connection that truly makes the magic happen!
We are a human-centered culture where we prioritize your well-being and are invested in helping you reach your fullest potential. We're not only focused on achieving our goals — we're dedicated to helping you achieve yours.
If you're relentlessly curious, driven to make a difference, and collaborative at the core, then you belong with us.
We are seeking an experienced Security Analyst – Intermediate to support IT Security (ITSEC) governance, cybersecurity risk management, compliance, audit, and third-party risk management activities within a large enterprise environment.
The successful candidate will have 4–6 years of progressive IT/Cybersecurity experience, with strong hands-on knowledge of cybersecurity governance, risk management, vendor security assessments, regulatory compliance, audit support, and security performance reporting. This role will work closely with internal business and technology teams, Risk & Compliance, Privacy, Procurement, Finance, IT Operations, and external vendors to ensure cybersecurity risks are appropriately identified, assessed, reported, and managed.
- Support the development, implementation, and ongoing maintenance of IT Security governance and cybersecurity risk management practices.
- Ensure projects and technology initiatives adhere to established IT Security policies, standards, and governance requirements.
- Support compliance with applicable cybersecurity and privacy frameworks and standards, including NIST, ISO 27001, PCI, FIPPA, and Government of Ontario requirements.
- Identify cybersecurity risks and work with business and technology stakeholders to develop appropriate risk treatment and remediation plans.
- Collaborate with Risk & Compliance, Privacy, Records Management, Finance, and IT Operations to understand organizational risk appetite and address risks that exceed accepted thresholds.
- Provide subject matter expertise regarding cybersecurity governance standards, regulations, controls, and industry best practices.
- Support the development of cybersecurity governance awareness and training initiatives.
- Contribute to the development and implementation of the Third-Party Cyber Risk Management (TPRM) framework.
- Perform cybersecurity risk assessments of vendors, service providers, and other third parties.
- Assess third-party and contractual cybersecurity risks prior to contract execution.
- Determine appropriate cybersecurity controls and requirements to be incorporated into third-party contracts.
- Review vendor security documentation, control attestations, audit reports, and other security evidence to identify potential gaps and risks.
- Assess the implications of vendor security deficiencies, control gaps, incidents, or breaches and recommend appropriate remediation.
- Support the design and review of security-related service-level agreements, contractual requirements, and management reporting.
- Implement or support internal controls used to validate security reporting received from third-party providers.
- Provide cybersecurity risk input into vendor contract renewals, changes, and terminations.
- Gather and prepare information for reporting on the security posture and performance of services obtained from external providers.
- Provide input into penetration testing and other security assessment activities performed by third-party cybersecurity service providers.
- Support cybersecurity audit activities, including PCI audits, internal audits, external audits, and CSAE 3416 assessments.
- Coordinate the collection, review, and submission of security evidence required for audits and compliance assessments.
- Track audit findings, cybersecurity risks, remediation activities, and outstanding compliance requirements.
- Support governance activities required to maintain alignment with ISO 27001, NIST, PCI, privacy requirements, and other applicable standards.
- Design and maintain IT Security performance KPIs and cybersecurity risk metrics.
- Gather, analyze, and prepare data for reporting on security service performance, information-system security status, third-party services, risks, findings, and improvement initiatives.
- Develop clear and timely cybersecurity governance and risk reports for internal and external stakeholders.
- Provide reporting and updates to Senior Management, Audit, Finance, Risk & Compliance, and other stakeholders as required.
- Identify trends, control deficiencies, and areas requiring remediation or improvement.
- Work with IT Operations and Risk & Compliance teams to support digital asset inventory management.
- Ensure appropriate identification, classification, ownership, risk assessment, and compliance requirements are associated with digital assets.
- Assess the effectiveness and completeness of technology and business strategies as they relate to IT Security governance.
- Promote awareness and adoption of cybersecurity governance and compliance requirements throughout the organization.
- Degree in Business, Engineering, Information Systems, Computer Science, Cybersecurity, or a related discipline, or an equivalent combination of education, training, and professional experience.
- Minimum 4–6 years of progressively responsible experience within IT, Information Security, or Cybersecurity.
- Approximately 3–5 years of relevant experience in cybersecurity risk management, security governance, compliance, or related functions.
- Demonstrated experience performing vendor cybersecurity risk assessments.
- Hands-on experience with Third-Party Risk Management (TPRM) programs and processes.
- Strong understanding of cybersecurity risk management principles, security controls, and governance practices.
- Experience gathering and preparing data for cybersecurity KPI, risk, compliance, and security-service performance reporting.
- Experience assessing the security posture of services delivered by external providers.
- Experience identifying security gaps and developing or coordinating remediation and improvement actions.
- Knowledge of cybersecurity frameworks and standards such as NIST and ISO 27001.
- Experience supporting security audits and compliance assessments.
- Ability to work effectively with technical teams, business stakeholders, vendors, auditors, and senior management.
- Strong analytical, documentation, communication, and stakeholder-management skills
One or more of the following professional certifications would be considered an asset:
- CISSP – Certified Information Systems Security Professional
- CISM – Certified Information Security Manager
- CGEIT – Certified in the Governance of Enterprise IT
- CRISC – Certified in Risk and Information Systems Control
- CISA – Certified Information Systems Auditor
- Similar cybersecurity, governance, risk, or audit certifications
- Agile certifications such as Agile Certified Professional or Certified Scrum Product Owner are also considered assets.
At Compugen, we are committed to diversity, equity and inclusion. We actively recruit from all groups, including women, Indigenous people, persons with disabilities and members of visible minorities. We recognize the importance of removing barriers to participation and provide accommodation upon request to all applicants throughout the recruitment process. If you require an accommodation, our People & Culture representative will work with you to meet your needs in a confidential and respectful manner. We believe everyone deserves a seat at the table-and we are taking deliberate action to make this a reality.
#ITR
#CompugenITR
#LI-MM1