Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Analyste principal(e) - Contrôles et indicateurs de cybersécurité | Cybersecurity Controls & Metrics

NTT Data

Req ID: 381849

NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.

We are currently seeking a Analyste principal(e) - Contrôles et indicateurs de cybersécurité | Cybersecurity Controls & Metrics to join our team in Montreal, Quebec (CA-QC), Canada (CA).

Analyste principal(e) – Contrôles et indicateurs de cybersécurité

Sommaire du poste

Nous recherchons un(e) Analyste principal(e) – Contrôles et indicateurs de cybersécurité expérimenté(e) pour contribuer à la définition, à la mesure et à l'amélioration de l'efficacité des contrôles technologiques et de cybersécurité à l'échelle de l'entreprise.

Dans ce rôle, vous collaborerez avec les équipes de cybersécurité, des technologies, de la gouvernance et des données afin de développer des indicateurs de contrôle pertinents, de mettre en place des cadres de production de rapports et de veiller à ce que les contrôles de cybersécurité soient mesurables, efficaces et conformes aux politiques organisationnelles.

Le ou la candidat(e) idéal(e) possède une solide expertise en cybersécurité, d'excellentes capacités analytiques et une expérience dans la définition d'indicateurs clés de contrôle (KCI), de mesures de performance et de rapports soutenant les initiatives de gouvernance, de gestion des risques et de conformité.

Principales responsabilités

  • Définir et documenter les indicateurs des contrôles technologiques et de cybersécurité, les méthodologies de mesure ainsi que les exigences en matière de production de rapports.
  • Collaborer avec les responsables des contrôles et les parties prenantes de l'entreprise afin de comprendre les objectifs des contrôles et de les traduire en indicateurs clés de contrôle (KCI) et en mesures de performance mesurables.
  • Travailler en partenariat avec les équipes des politiques technologiques et de la gouvernance afin d'intégrer les exigences de mesure dans la conception et la mise à jour des politiques.
  • Collaborer étroitement avec les équipes d'ingénierie des données et des outils afin d'automatiser la collecte, le calcul et la production des indicateurs de contrôle.
  • Concevoir et améliorer des tableaux de bord et des cadres de rapports fournissant des renseignements pertinents sur l'efficacité des contrôles et les risques opérationnels.
  • Analyser les données afin d'identifier les tendances, les écarts et les occasions d'amélioration continue.
  • Veiller à l'exactitude, à la cohérence et à l'alignement des indicateurs avec les exigences de gouvernance et de conformité de l'entreprise.
  • Soutenir l'évolution continue des capacités de mesure de la cybersécurité, des processus de production de rapports et des normes de gouvernance.
  • Établir et maintenir de solides relations avec les intervenants des équipes de cybersécurité, des technologies, de la gestion des risques et de la conformité.

Qualifications requises

  • Baccalauréat ou combinaison équivalente de formation et d'expérience professionnelle.
  • Au moins cinq (5) ans d'expérience en sécurité de l'information, cybersécurité, technologies de l'information ou dans un domaine connexe.
  • Au moins deux (2) ans d'expérience pratique dans la mise en œuvre ou le soutien de contrôles technologiques ou de cybersécurité.
  • Expérience dans la définition de mesures de cybersécurité, d'indicateurs clés de contrôle (KCI), d'indicateurs clés de risque (KRI) ou d'indicateurs de performance opérationnelle.
  • Excellentes aptitudes analytiques et capacité à interpréter les données et à formuler des recommandations concrètes.
  • Expérience de collaboration avec des équipes multidisciplinaires et aptitude à traduire les besoins d'affaires en résultats mesurables.
  • Excellentes habiletés en communication orale et écrite.
  • Solides compétences en organisation, en résolution de problèmes et en gestion des parties prenantes.
  • Capacité à gérer plusieurs priorités dans un environnement dynamique et en constante évolution.

Qualifications privilégiées

  • Expérience des programmes de gouvernance, de gestion des risques et de conformité (GRC) en cybersécurité.
  • Connaissance des cadres de contrôle technologique et de cybersécurité utilisés en entreprise.
  • Expérience des contrôles de sécurité infonuagique dans des environnements de nuage public (Microsoft Azure, Amazon Web Services [AWS] ou Google Cloud Platform [GCP]).
  • Connaissance des domaines de sécurité suivants :
    • Gestion des identités et des accès (IAM)
    • Protection des données
    • Sécurité des réseaux
    • Sécurité des applications
    • Sécurité des postes de travail (Endpoint Security)
    • Sécurité des infrastructures
  • Connaissance des processus de journalisation de sécurité, de surveillance, de détection des menaces et de réponse aux incidents.
  • Expérience des outils de production de rapports de sécurité, de tableaux de bord, d'intelligence d'affaires ou de visualisation de données.
  • Des certifications professionnelles telles que CISSP, CISM, Security+, CRISC, CGRC ou l'équivalent constituent un atout.

Compétences recherchées

  • Contrôles de cybersécurité
  • Gestion des risques technologiques
  • Gouvernance, gestion des risques et conformité (GRC)
  • Mesure de l'efficacité des contrôles
  • Indicateurs clés de contrôle (KCI)
  • Indicateurs clés de risque (KRI)
  • Indicateurs de cybersécurité et production de rapports
  • Analyse de données
  • Développement de tableaux de bord
  • Gestion des parties prenantes
  • Amélioration continue des processus
  • Sécurité infonuagique (Azure, AWS, GCP)

Pourquoi vous joindre à nous?

En tant que membre de notre équipe de cybersécurité, vous jouerez un rôle essentiel dans le renforcement de la sécurité de l'entreprise en développant des indicateurs significatifs qui favorisent une meilleure gestion des risques et une prise de décision éclairée.

Vous collaborerez avec des leaders en cybersécurité, en technologies et dans les secteurs d'affaires tout en contribuant à l'évolution des pratiques de gouvernance de la cybersécurité et des initiatives d'amélioration continue de l'organisation.

___________________________________________________________________________________________________________________________________________________________________________

Cybersecurity Controls & Metrics Analyst

Position Summary

We are seeking an experienced Cybersecurity Controls & Metrics Analyst to help define, measure, and enhance technology and cybersecurity control effectiveness across the enterprise. In this role, you will collaborate with security, technology, governance, and data teams to develop meaningful control metrics, establish reporting frameworks, and ensure cybersecurity controls are measurable, effective, and aligned with organizational policies.

The ideal candidate combines strong cybersecurity knowledge with analytical skills and experience developing key control indicators (KCIs), metrics, and reporting that support governance, risk management, and compliance initiatives.

Key Responsibilities

  • Define and document cybersecurity and technology control metrics, measurement methodologies, and reporting requirements.
  • Partner with control owners and business stakeholders to understand control objectives and translate them into measurable Key Control Indicators (KCIs) and performance metrics.
  • Collaborate with Technology Policy and Governance teams to ensure measurement requirements are incorporated into policy design and updates.
  • Work closely with data engineering and tooling teams to automate the collection, calculation, and reporting of control metrics.
  • Design and improve dashboards and reporting frameworks that provide meaningful insights into control effectiveness and operational risk.
  • Analyze data to identify trends, gaps, and opportunities for continuous improvement.
  • Ensure metrics are accurate, consistent, and aligned with enterprise governance and compliance requirements.
  • Support ongoing enhancements to cybersecurity measurement capabilities, reporting processes, and governance standards.
  • Build strong relationships with cross-functional stakeholders across Security, Technology, Risk, and Compliance teams.

Required Qualifications

  • Bachelor's degree or equivalent professional experience.
  • 5+ years of experience in Information Security, Cybersecurity, Information Technology, or a related field.
  • 2+ years of hands-on experience implementing or supporting cybersecurity or technology controls.
  • Experience defining cybersecurity metrics, Key Control Indicators (KCIs), Key Risk Indicators (KRIs), or operational performance metrics.
  • Strong analytical skills with the ability to interpret data and communicate actionable insights.
  • Experience collaborating with cross-functional stakeholders and translating business requirements into measurable outcomes.
  • Excellent written and verbal communication skills.
  • Strong organizational, problem-solving, and stakeholder management skills.
  • Ability to manage multiple priorities in a fast-paced environment.

Preferred Qualifications

  • Experience with cybersecurity governance, risk, and compliance (GRC) programs.
  • Knowledge of enterprise technology and cybersecurity control frameworks.
  • Experience working with cloud security controls in public cloud environments (Azure, AWS, or Google Cloud).
  • Familiarity with security domains including:
    • Identity & Access Management (IAM)
    • Data Protection
    • Network Security
    • Application Security
    • Endpoint Security
    • Infrastructure Security
  • Knowledge of security logging, monitoring, threat detection, and incident response processes.
  • Experience with security reporting, dashboards, business intelligence, or data visualization tools.
  • Professional certifications such as CISSP, CISM, Security+, CRISC, CGRC, or similar are preferred.

Preferred Skills

  • Cybersecurity Controls
  • Technology Risk
  • Governance, Risk & Compliance (GRC)
  • Control Effectiveness Measurement
  • Key Control Indicators (KCIs)
  • Key Risk Indicators (KRIs)
  • Security Metrics & Reporting
  • Data Analysis
  • Dashboard Development
  • Stakeholder Management
  • Process Improvement
  • Public Cloud Security (Azure, AWS, GCP)

Why Join Us?

As a member of our cybersecurity team, you'll play a key role in strengthening enterprise security by developing meaningful metrics that drive better risk management and decision-making. You'll collaborate with security, technology, and business leaders while helping shape the organization's cybersecurity governance and continuous improvement initiatives.

Pay Transparency

Where required by law, NTT DATA provides a reasonable range of compensation for specific roles. The starting pay range for this remote role is $74720 - $112,080. This range reflects the minimum and maximum target compensation for the position across all US locations. Actual compensation will depend on a number of factors, including the candidate’s actual work location, relevant experience, technical skills, and other qualifications. 

This position is eligible for company benefits including medical, dental, and vision insurance with an employer contribution, flexible spending or health savings account, life and AD&D insurance, short- and long-term disability coverage, paid time off, employee assistance, participation in a 401k program with company match, and additional voluntary or legally-required benefits. 

About NTT DATA

NTT DATA is a $30+ billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world’s leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services.  Our consulting and industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is part of NTT Group, which invests over $3 billion each year in R&D.

Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and effective support tailored to each client’s needs. While many positions offer remote or hybrid work options, these arrangements are subject to change based on client requirements. For employees near an NTT DATA office or client site, in-office attendance may be required for meetings or events, depending on business needs. At NTT DATA, we are committed to staying flexible and meeting the evolving needs of both our clients and employees. NTT DATA recruiters will never ask for payment or banking information and will only use @nttdata.com and @talent.nttdataservices.com email addresses. If you are requested to provide payment or disclose banking information, please submit a contact us form, .

NTT DATA endeavors to make accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact us at . This contact information is for accommodation requests only and cannot be used to inquire about the status of applications. NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For our EEO Policy Statement, please click here . If you'd like more information on your EEO rights under the law, please click here . For Pay Transparency information, please click here .

#LI-NorthAmerica

Vacancy posted 23 days ago
Similar jobs that could be interesting for youBased on the Analyste principal(e) - Contrôles et indicateurs de cybersécurité | Cybersecurity Controls & Metrics in California vacancy
  • $150k - $200k

    GFT is seeking a Principal Cybersecurity Compliance Analyst to join our Security and Safety team...  ...NERC CIP standards for PG&E’s power generation assets....  ..., risk analyses, and control testing for cybersecurity...  ...controls.Track compliance metrics, risks, and issues; prepare... 
    Principal
    Full time
    Work at office
    Remote work

    Gannett Fleming

    Roseville, CA
    5 days ago
  • $114k - $171k

     ...Classified Solutions team is seeking a Sr. / Principal Classified Cybersecurity Analyst to support information systems...  ...activities, covering all security controls and configurations, to enhance...  ...formal Security Test and Evaluation (ST&E) required by each government accrediting... 
    Principal
    Full time
    Local area
    Remote work
    Relocation
    Flexible hours
    Shift work

    Northrop Grumman

    Redondo Beach, CA
    3 days ago
  • $114k - $171k

     ...Classified Solutions CIDO team is seeking a Principal Classified Cybersecurity Analyst to support information systems...  ...activities, covering all security controls, configurations, and operational processes...  ...Security Test and Evaluation (ST&E) required by each government... 
    Principal
    Full time
    Local area
    Remote work
    Relocation
    Flexible hours
    Shift work

    Northrop Grumman

    Redondo Beach, CA
    1 day ago
  • $112.5k - $147.5k

     ...is looking for an experienced Senior Analyst, IT Internal Controls & SOX Compliance to join the Internal...  ...access management, SDLC processes, and cybersecurity controls.Experience with ERP systems,...  ..., Circle participates in the E-Verify Program in certain locations,... 
    Suggested
    Flexible hours

    Circle

    Los Angeles, CA
    5 days ago
  • $94.2k - $141.2k

     ...Aeronautics Systems (NGAS) is seeking a qualified Principal (level 3) or Senior Principal Program Cost Schedule Control Analyst (Level 4) to join our F-35 Finance Team...  ...Conducting financial analysis of traditional financial metrics (Awards, Acquisitions, Sales, Operating Margin... 
    Principal
    Full time
    Work from home
    Relocation package
    Shift work

    Northrop Grumman

    Redondo Beach, CA
    1 day ago
  • $117.5k - $176.3k

     ...allies.We’re looking for you to join our team as a Senior Principal Program Cost Control Analyst based out of of Sunnyvale, CA. This position offers the...  ...system. This will include performing Earned Value Metric (EVM) tasks such as Work Breakdown Structure (WBS) development... 
    Principal
    Full time
    Contract work
    Relocation package
    Shift work

    Northrop Grumman

    Sunnyvale, CA
    1 day ago
  • $117.5k - $176.3k

     ...Northrop Grumman Defense Systems (NGDS) Sector is seeking a Principal Program Cost Control Analyst (level 3) or SrProgram Cost Control Analyst (Level 4)...  ...Responsibilities:Accurately forecast program financial metrics including Orders, Sales, OM and Cash Flow for both... 
    Principal
    Full time
    Contract work
    Work at office
    Remote work
    Relocation package
    Shift work

    Northrop Grumman

    Northridge, CA
    5 days ago
  •  ...Bilingual Benefits Analyst Sr...  ...data, AI, cybersecurity, and analytics...  ...processing and controlling benefit...  ...notre bureau de Montréal au...  ...où succès et accomplissement...  ...leur IA, leur cybersécurité et leur analyse...  ...et le contrôle des programmes...  ...gime, sert de principal point de... 
    Temporary work
    Work at office

    Insight

    California
    15 days ago
  • $147k - $237.5k

     ...Who We AreIn order to be the cybersecurity partner of choice, we must trailblaze...  ....Job SummaryWe are seeking a Principal Software Engineer to join our...  ...systems that power the control plane of our platform. In...  ...and external systems/tools (e.g., Terraform, Ansible, enterprise... 
    Principal
    Full time
    Work at office

    Palo Alto Networks

    Santa Clara, CA
    3 days ago
  • $135.2k - $179.13k

     ...to an authentic experience!The Cybersecurity Risk Analyst is a cybersecurity program and control assessor and advisor in governance...  ...and maintain cybersecurity metrics for all levels of management focused...  ...activities and related documentation (e.g., system life-cycle support... 
    Temporary work
    Remote work

    Inland Empire Health Plan

    Rancho Cucamonga, CA
    1 day ago
  • $70k - $90k

     ...security architecture, controls, monitoring, detecting...  ...technologies (e.g., CrowdStrike, SIEM,...  ...track key SOC performance metrics (e.g., MTTD, MTTR, alert...  ...Mentor and develop SOC analysts and incident responders...  ...~ Bachelors degree in Cybersecurity, Computer Science, or... 
    Full time
    Local area

    Astound

    Rocklin, CA
    2 days ago
  • $40.52 - $46.56 per hour

     ...Cybersecurity Compliance Analyst Information Technology Department At Father Joe...  ...risk assessments, and control validation activities. Participate...  .... Develop security metrics, reports, and risk...  ...compliance-driven environments (e.g., HIPAA, PCI-DSS, HUD/HMIS... 
    Hourly pay
    Full time
    Casual work
    Work at office
    Remote work
    Monday to Friday
    Afternoon shift

    Father Joe's Villages

    San Diego, CA
    4 days ago
  • $140k - $165k

     ...TO BE CONSIDERED. WE USE E-VERIFY TO ELECTRONICALLY...  ...competencies in Information Assurance, Cybersecurity and Systems Engineering. With...  ...! Senior Cybersecurity Analyst – CONTINGENT - 26-022 –...  ...documentation of NIST 800-53 Security Control implementation and... 
    Full time
    Contract work
    For contractors
    Work experience placement
    Remote work

    AUSGAR Technologies Inc.

    San Diego, CA
    1 day ago
  • $69.3k - $158k

     ...Cybersecurity Engineer and Risk Analyst Are you looking for an opportunity to share your experience in cybersecurity...  ...and implement infrastructure controls. In this role, you’ll closely impact...  ...schedule, performance, and quality metrics within the systems development... 
    Contract work
    Local area

    Booz Allen Hamilton

    San Diego, CA
    3 days ago
  • $117.5k - $176.3k

     ...only part of history, they're making history.Northrop Grumman Aeronautics Systems is seeking a qualified Sr. Principal Program Cost Schedule & Control Analyst (Level 4) to join our Research & Advanced Design Division of qualified, diverse individuals. This position will... 
    Principal
    Full time
    Contract work
    Work at office
    Relocation package
    Flexible hours
    Shift work

    Northrop Grumman

    Redondo Beach, CA
    5 days ago
  • $120k

     ...Information Security Analyst is responsible for supporting...  ...maintaining security controls across systems,...  ...frameworks such as the NIST Cybersecurity Framework (CSF) to...  ...standards and regulations (e.g., ISO 27001, NIST,...  ...report basic security metrics and KPIs. Security... 
    Work at office
    Immediate start
    Night shift

    Vesync

    Tustin, CA
    3 days ago
  • $120k - $140k

     ...Cyber Detection and Response Analyst supports day-to-day detection...  ...detection logic and improve security controls.Produce clear, concise...  ...3-5 years of experience in cybersecurity, with a focus on incident response...  ...XDR, and log analysis tools (e.g., Splunk, Sentinel,... 
    Full time
    Work at office
    Remote work
    Flexible hours
    Shift work

    Control Risks

    San Francisco, CA
    4 days ago
  • $94.2k - $141.2k

     ...are not only part of history, they're making history.Northrop Grumman Aeronautics Systems has an opening for a Principal Program Cost and Schedule Control Analyst (Level 3) or Sr. Principal Program Cost and Schedule Control Analyst (Level 4) to join our team of qualified,... 
    Principal
    Full time
    Remote work
    Relocation package
    Flexible hours
    Shift work

    Northrop Grumman

    Palmdale, CA
    4 days ago
  •  ...a talented Senior QA Analyst to join our AI & Threat...  ...Security is transforming cybersecurity for organizations...  ...behavior Analyze logs, metrics, and model outputs to...  ...participant in the U.S. Federal E-Verify program. We...  ...and location, the Controller of personal data (the... 
    Temporary work
    Remote work

    Keeper Security, Inc.

    Cameron Park, CA
    4 days ago
  •  ...Cyber Threat Intelligence (CTI) Analyst to support operations for one...  ...platforms and tools (e.g., Anomali) to monitor, analyze...  ...detection logic and security controls by feeding intelligence back...  .... ~ Bachelor's Degree in Cybersecurity or active certificatiions in... 

    iQuasar

    Los Angeles, CA
    2 days ago
  •  ...Title: Cyber Security Analyst Location: Remote (U.S., New...  ...manage and measure security metrics and compliance requirements....  ...7001, CMMC, GDPR, and HIPAA controls into actionable items for clients...  ...in a Technology or Cybersecurity field OR 4+ years of direct... 
    Work experience placement
    Summer work
    Remote work

    GrabJobs

    Long Beach, CA
    1 day ago
  • $70k - $95k

     ...lifestyle management needs. Your Role The Cybersecurity Analyst will monitor, maintain, and enhance...  ...measures. Provide reporting and metrics on the information security program. Consult...  ...maintain and monitor security controls such as patch management, firewalls, MFA... 
    Summer work
    Flexible hours

    NKSFB

    Los Angeles, CA
    5 days ago
  • $94.2k - $141.2k

     ...employees are not only part of history, they're making history. Northrop Grumman Aeronautics Systems has an opening for a Principal Program Control Analyst (Level 3) to join our team of qualified, diverse individuals. This position will be located on-site in San Diego, CA.... 
    Principal
    Full time
    Work at office
    Remote work
    Relocation package
    Shift work

    Northrop Grumman

    San Diego, CA
    2 days ago
  • $102.17k

     ...Team as a Senior Cyber Security Analyst, where you will operate at the intersection of cybersecurity and DevSecOps to protect...  ...development lifecycle—embedding security controls, identifying vulnerabilities,...  ...efforts for complex incidents (e.g., APTs, data breaches),... 
    Work experience placement
    H1b

    Trinnex

    San Diego, CA
    1 day ago
  • $96.2k - $144.2k

     ...history, they're making history. Position Overview Northrop Grumman Aerospace System (NGAS) is hiring a Senior Principal Program Cost and Schedule Control Analyst (Level 4) in Oklahoma City, OK or Palmdale, CA facilities to support the Cost Management organization. This... 
    Principal
    Work at office
    Relocation package
    Shift work

    Segment (Twilio)

    Palmdale, CA
    4 days ago
  •  ...Cybersecurity Analyst (onsite Wed, Thurs, Fri and alternating Saturdays 7am-7pm) Certification requirements...  ...from a variety of cyber defense tools (e.g., IDS alerts, firewalls, network...  .... • Ensure that cybersecurity plans, controls, processes, standards, policies, and... 
    Contract work
    Work experience placement
    Work at office

    RIT Solutions, Inc.

    Glendale, CA
    5 days ago
  •  ...and "Mid-Atlantic Region" (DC, DE, MD, NC, VA, WV)), and again...  ...Provide expert guidance on cybersecurity directives and risk management...  ...remediation timeframes for security controls. Conduct deep-dive forensic...  ...- Contribution Incentives (i.e. white papers, blog posts,... 
    Work at office

    True Zero Technologies, LLC

    Seaside, CA
    5 days ago
  • $110k - $140k

    Cybersecurity Analyst About the Role We are hiring a Cybersecurity Analyst to own the day‑to‑day security...  ..., secure web access, application control, and identity management. You establish...  ...as defined by 8 U.S.C. 1324b(a)(3) (i.e., individual admitted to the U.S. as a... 
    Permanent employment
    Immediate start

    Varda Space Industries

    El Segundo, CA
    4 days ago
  • $94.2k - $141.2k

     ...employees are not only part of history, they're making history.Northrop Grumman Aerospace System (NGAS) is seeking a Principal Program Cost and Schedule Control Analyst (Level 3) in our San Diego, CA facility to support the Material Cost Management organization. This position... 
    Principal
    Full time
    Contract work
    Work at office
    Relocation package
    Shift work

    Northrop Grumman

    San Diego, CA
    5 days ago
  • $110k - $160k

     ...Role Overview: We are seeking a SOC Analyst II to join our growing Security...  ...The ideal candidate is a mid-career cybersecurity professional with a strong technical foundation...  ...frameworks such as NIST 800-171, CMMC, CIS Controls, or ISO 27001 Experience with... 
    Full time
    Contract work
    Work experience placement
    Casual work
    Relocation package

    CHAOS Industries

    San Francisco, CA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Analyste principal(e) - Contrôles et indicateurs de cybersécurité | Cybersecurity Controls & Metrics. Be the first to apply!