Senior Analyst - Cyber Threat Modeling and Risk

EQ Bank
Toronto
On-site
Full-time
Posted 3 months ago
Information Security

Job Description

The Work
 
The Senior Analyst - Cyber Threat Modeling and Risk supports the Threat Modeling and Risk Assessment program by assisting with the identification, assessment, and tracking of cyber security risks across technology. The role works under the guidance of senior team members to help ensure appropriate security controls are identified early in the design lifecycle, enabling secure and resilient technology solutions while supporting business growth. 

Responsibilities

The Core Responsibilities!

  • Provide security advisory support to technology and business teams under supervision.
  • Help conduct threat modeling and security assessments for applications and infrastructure.
  • Review solution designs with senior analysts and SMEs to identify threats, attack paths, and risks.
  • Document outputs like data flow and architecture diagrams, along with basic threat scenarios.
  • Assist in tracking and addressing design flaws and security findings from threat modeling.
  • Support onboarding of security services (e.g., MFA, logging, vulnerability scanning) guided by senior team members.
  • Keep accurate records in risk tracking repositories.
  • Aid continuous improvement of threat modeling processes, templates, and documentation.
  • Build foundational knowledge of the organization’s enterprise security frameworks, policies, and standards.
  • Review solution designs for risk and threat assessment.
  • Record risks, threat scenarios, and control gaps in tracking tools.
  • Track remediation actions and assist risk discussions with stakeholders.
  • Build knowledge of cyber security controls and their technology applications.
  • Requirements

    Let's Talk About You!

  • A college diploma or university degree in Computer Science, Information Technology, Cyber Security, or a related discipline is required.
  • 2–3 years of experience in information security, IT risk, or technology roles is preferred.
  • Foundational understanding of threat modeling concepts or methodologies; practical experience is an asset.
  • Basic understanding of application security principles and common vulnerabilities (e.g., OWASP Top 10).
  • Exposure to cloud and hybrid environments is an asset.
  • Ability to support IT security risk assessments and document findings clearly.
  • Familiarity with security diagrams and documentation such as data flow diagrams and architecture diagrams.
  • Understanding of APIs, CI/CD pipelines, or secure software development practices is an asset.
  • Strong communication, documentation, and collaboration skills. 
  • Interest in pursuing security certifications (e.g., Security+, CCSP, CISSP in future) is an asset.
  • Ready to Apply?

    Take the next step in your career journey

    Apply Now

    Explore more

    Browse more jobs like this

    Disclaimer: Real Jobs From Anywhere is an independent platform dedicated to providing information about job openings. We are not affiliated with, nor do we represent, any company, agency, or agent mentioned in the job listings. Please refer to our Terms of Services for further details.