Business AnalystDepartment: IT Security and Governance, Information Technology Operations and Security
Type: Full-Time - Permanent
Location: Toronto (Hybrid)
Posting Date: September 11, 2026
About the role The successful candidate will be responsible for executing activities in ITOS division, specifically within IT Security and Governance team under Technology Risk and Control department. This will include business process re-engineering and gathering new business requirements, supporting IT audit, risk management, IT general controls, as well as executing user acceptance testing and training. The analyst will also provide project leadership for projects more routine in nature and provide business and technical application support.
What you'll do IT Audit and Compliance
- Gathers evidence from IT operations and business units for both internal and external audits, documenting, analyzing, and performing audit tests to assess controls and compliance. Develops remediation action plans based on findings.
- Implements, maintains, and communicates IT General Controls (ITGC) policies, procedures, and programs. Reviews and ensures alignment with actual practices, corporate objectives, and government standards.
- Audit Planning & Reporting: Plans and conducts internal audits of IT systems, applications, and processes. Prepares working papers, audit reports, and recommendations to management, ensuring proper controls and accuracy of system-generated information.
Change Management, Access Management and IT General Controls
- Independently manage the change management process, including organizing CAB meetings, reviewing RFCs, stakeholder engagement, and identifying risks. Develop contingency plans and ensure communication, business processes, and training are aligned with changes.
- Conduct periodic reviews of user access rights to ensure compliance with the principle of least privilege. Implement and monitor IT General Controls (ITGC) to align with organizational objectives and regulatory requirements, providing recommendations for improvements based on audit findings and emerging risks.
Remediation, Process Enhancement, and Documentation
- Effectively document/review and business requirement documents.
- Perform data research and analysis.
- Play a bridging role between business and technical teams.
- Conduct research to determine best practices for work processes and make recommendations to the user group as to how the processes can be improved.
- Organize and lead work process review and redesign meetings to arrive at decisions.
- Conducting research for the development and defining of product specifications.
- Identify deficiencies in the specifications and in existing products that could affect the functionality of the product and introduce potential issues into the work processes.
- Document deficiencies and provide recommendations to address them for review and approval of Management.
- Provide project leadership from concept to implementation for more routine projects by carrying out project control activities, developing plans and schedules, and ensuring the project is executed in accordance with the OPTrust project management methodology.
- Assess and accurately define and address issues and risks; employ effective strategies to proactively mitigate risks and facilitate resolution of problems and issues.
- Develop and maintain deports using various tools such as Power BI/ Excel.
- Manage small/medium-size projects/phases of the projects.
- Coordinate project team for effective implementation.
- Performs other duties as assigned.
- Ensure clear understanding and adherence of all OPTrust's policies, procedures, guidelines as well as living our values and fostering an inclusive culture.
What you bring- Post-secondary education in Technology Risk, Audit or a related field.
- 2 - 4 years experience in IT audit, IT change management, access management, IT and security governance, risk and control is a must.
- Proven experience preparing policies, procedures, process maps and workflows.
- Proven ability to prepare effective training materials, lead training sessions and one-on-one support.
- Excellent communication skills.
- Strong judgement, analytical and Project Management skills.
- Ability to work with ambiguity, conceptualize and think creatively.
- Exceptional organizational and time-management skills.
- Excellent interpersonal skills; proven track record as an effective team player and contributor, and participation in consultative processes.
- Holds one or combination of designations in relevant audit or industry standard certifications, (e.g. CISA, CRISC, CIA, CISSP etc.).
- Knowledge of pension industry or Big 4 work experience is an asset.
This posting is for an existing vacancy.
The range of expected compensation for this position is $98,398 to $120,869 per year.
Please submit your application via Workday by September 25, 2026.