S&P Global
Cyber Security Risk Analyst
S&P GlobalCanada7 hours ago
Full-timeRemote FriendlyInformation Technology

S&P Dow Jones Indices


The Role: Cyber Security Engineer


The Team:

Are you passionate about cyber security? Do you enjoy solving complex problems and collaborating with diverse teams? The Cyber Security Risk Analyst will support and help coordinate activities across the department to drive process improvement. The Cyber Security Risk Analyst will join a team responsible for safeguarding the sensitive financial data and systems of the organization. Our team typically operates in a dynamic environment and values the ability to adapt to evolving cyber threats while maintaining the confidentiality, integrity, and availability of our critical financial assets.


The Impact:

As the embedded Cyber Security Risk Analyst, you will participate in tasks and projects from inception to completion, build relationships with IT and Business partners, recommend process solutions and approaches that tackle challenging cyber problems and minimize risk for the business.


What’s in it for you:

Enhance your complex problem-solving skills by collaborating with diverse IT teams. The Cyber Security Risk Analyst will support and help coordinate activities across the department to drive process improvement. Strengthen your Cloud compute skills by working in an Agile and Cloud environment.


Responsibilities:

  • Escalate, manage, and report on divisional cyber security risk
  • Prioritize the mitigation of identified vulnerabilities within the business division. Work with the various platform teams to resolve vulnerabilities, resolve false positives with the team and/or vendor to remain or bring platforms in compliance with the organizations policies and standards
  • Collaborate with internal and external stakeholders to ensure compliance with regulatory requirements
  • Assists in the review of standards, policies, and procedures and performs rationalization per compliance guidelines. Supports the development and maintenance of system level documentation
  • Assists in the performance of application risk assessments. Internal Audit and Client requests for information
  • Influence and manage the onboarding of developers for secure code training to augment the enterprise security awareness training
  • Serve as the divisional security champion for developers


What We’re Looking For:

  • Bachelor's or Master’s degree in Computer Science, Information Systems or similar fields
  • 5+ years’ experience in Information Security, Audit or Compliance
  • Experience with Vulnerability Patch Management
  • Experience with Application Security
  • Experience in Offensive or Defensive Security techniques
  • Exposure with Software Security Architecture, System Design and Analysis Skills
  • Experience with ISO 27001, NIST SP 800-53, or other relevant standards (preferred)
  • Financial services industry experience
  • Certification in CISSP, CISM, CRISC, CISA, or equivalent
  • Project management skills
  • Excellent communication, analytical, and problem-solving skills


The Location: Toronto, Canada (Hybrid - 2 days onsite)

Key Skills

Ranked by relevance