Position Title: IT Security Specialist V Start Date: ASAP Duration: 8 months with possible extension (based off of business needs and performance) Schedule: M-F, core business hours – 37.5 hours per week, 7.5 hours per day Work Location: 310-320 Front Street West Corporate, Toronto, Ontario
hybrid – 2 days on site, 3 days work from home – could be 4 days on site at some point.
Anchor Days (if applicable): Flexible
Travel Required: No Must-Have: 8+ years of experience in cybersecurity metrics, cyber risk/GRC or InfoSec BI, strong understanding of core security domains (SOC, IAM, vulnerability, cloud, AppSec), advanced Excel/PowerPoint skills, and hands-on experience with a BI tool (Power BI/Tableau/Qlik) with the ability to present to executives.
Story behind the need:
Reason for request/why opened: Project support
Scope of Project: uplifting reporting space within GRC groups
Team Size/Culture: 10 people, collaborative working environment
Training Period: onboarding and hit the ground running
Selling Points of Position (CVP): Opportunity for long-term, very high visibility work with leadership team, opportunity to network and grow within bank
Candidate profile details:
Degree/Level of Education: Post secondary is a nice to have – work experience is more important
Certifications Required: Nothing required
Years of Overall Experience: 8+ years with flexibility
How will performance be measured: hitting deliverables and timelines
Preferred/Ideal Candidate Background: banking or financial experience is an asset, strong BI tool experience and advanced level Excel skills
Summary of the role:
Typical Day-to-Day Responsibilities
How much time is being spent in meetings – 25% of their day will be spent in meetings
Who are they interacting with (internal/external) – internal partners
Will the contractor have access to any customer data? No
Role Summary The Senior Security Metrics and KRI Design Analyst is responsible for defining, governing, and driving adoption of enterprise security performance metrics, including Key Risk Indicators (KRIs), Key Performance Indicators (KPIs), and operational security metrics. This role partners with cyber domain leaders (IAM, SOC, Vulnerability Management, GRC, Cloud Security, AppSec, Third Party Risk, etc.) to translate security strategy and risk appetite into measurable outcomes, and to ensure metrics are implemented, trusted, automated, and consumed by operational teams and executives. This role is accountable for full lifecycle delivery: strategy -> design → stakeholder alignment → implementation → data quality → reporting → continuous improvement. Key Responsibilities 1) Metrics Strategy, Design & Standardization
Lead design and ongoing evolution of security metric taxonomy, ensuring consistent definitions for KRIs, KPIs, and operational measures.
Build/maintain a security metrics library including:
Experience with frameworks such as NIST CSF, NIST 800-53, ISO 27001, CIS Controls
Experience with metric automation sources/tools:
-Splunk, Sentinel, CrowdStrike, Qualys/Tenable
-ServiceNow (IRM/GRC/SecOps)
-Archer
Certifications (nice to have):
-CISSP / CISM / CRISC
-Security+ (if earlier-career senior)
-ITIL Foundation
Experience building KPI/KRI governance or measurement programs
Prior banking or financial institution experience
Applicant Notices & Disclaimers
For information on benefits, equal opportunity employment, and location-specific applicant notices, click here
At SPECTRAFORCE, we are committed to maintaining a workplace that ensures fair compensation and wage transparency in adherence with all applicable state and local laws. This position’s starting pay is: $ 75.00/hr.