Cybersecurity Analyst, Mining/Mineral Processing at Blue Moon Metals

We are redirecting you to the source. If you are not redirected in 3 seconds, please click here.

Cybersecurity Analyst, Mining/Mineral Processing at Blue Moon Metals. . Location: Toronto, Ontario. Cybersecurity Analyst, Mining/Mineral Processing. Toronto, ON. . Hybrid: 2-3X per week in office.. . Position Summary. . Blue Moon Metals is seeking a Cybersecurity Analyst to join its growing IT & Cybersecurity function at the Toronto headquarters. This role is responsible for monitoring, assessing, and strengthening the security posture of both corporate IT systems and operational technology (OT) / industrial control system (ICS) environments across the company's offices, project sites, and mining operations. The successful candidate will work closely with the Lead, IT Infrastructure Engineer and cross-functional stakeholders to implement security controls aligned to NIST CSF 2.0 and IEC 62443, and to support the company's broader cybersecurity maturity program.. . Key Responsibilities. . . Monitor security events and alerts across IT and OT environments, investigating and responding to potential incidents in a timely manner.. . Support day-to-day administration of security tooling, including endpoint detection and response (EDR), SIEM/log management, vulnerability scanning, email security, and identity protection platforms.. . Conduct vulnerability assessments and coordinate remediation activities across corporate IT and industrial control system (ICS/SCADA) assets, in partnership with OT and engineering teams.. . Assist in the design, implementation, and continuous improvement of security controls aligned to NIST CSF 2.0 and IEC 62443, including IT/OT network segmentation initiatives.. . Contribute to security policies, standards, and procedures, and help translate framework requirements into practical, site-appropriate controls for corporate, project, and remote/underground mining locations.. . Support identity and access management activities, including access reviews, provisioning/deprovisioning, and privileged access oversight.. . Participate in risk assessments, security audits, and third-party assessments (e.g., cybersecurity maturity assessments), helping track findings through to remediation.. . Assist with incident response planning and execution, including documentation, root-cause analysis, and post-incident reporting.. . Deliver security awareness content and training to employees and contractors across corporate and site locations.. . Maintain accurate documentation of security architecture, controls, and asset inventories for both IT and OT environments.. . Stay current on emerging threats, vulnerabilities, and regulatory requirements relevant to the mining and critical infrastructure sector.. . . Qualifications. . . 2-5 years of experience in a cybersecurity, IT security, or security operations role, ideally with some exposure to industrial/OT environments.. . Working knowledge of the NIST Cybersecurity Framework (CSF 2.0) and/or IEC 62443 for industrial automation and control systems security.. . Familiarity with common security tools such as SIEM, EDR/XDR, vulnerability scanners, and firewall/network monitoring platforms.. . Understanding of IT/OT network architecture, segmentation concepts, and the unique risk considerations of industrial control systems (SCADA, PLCs, HMIs).. . Solid understanding of core security domains: identity and access management, network security, endpoint security, and incident response.. . Post-secondary education in Computer Science, Information Security, Engineering, or a related field, or equivalent practical experience.. . Strong analytical and problem-solving skills, with the ability to communicate technical risk clearly to both technical and non-technical audiences.. . Ability to travel occasionally to project and mine sites as required.. . . Preferred Qualifications. . . Industry certifications such as Security+, GICSP, GRID, CISSP (or working toward), or similar.. . Prior experience in mining, energy, manufacturing, or another critical infrastructure sector.. . Exposure to regulatory or compliance frameworks relevant to publicly traded companies (e.g., SOX IT general controls).. . Experience supporting cybersecurity maturity assessments or working alongside external consultants/auditors.. . . About Blue Moon Metals. . Blue Moon Metals Inc. is a publicly traded metals and mining company advancing a global portfolio of mineral development and operating projects. As the company grows its corporate, project, and remote site operations, the IT & Cybersecurity team is building the internal capability required to protect both enterprise IT and operational technology (OT) environments across the business.. . What Blue Moon Metals Offers. . . The opportunity to help build a cybersecurity program from the ground up across a global mining organization.. . Exposure to both enterprise IT and industrial OT/ICS security in a hands-on, high-impact role.. . A collaborative team environment based at our Toronto headquarters.. . Competitive compensation and benefits package.. . . Pay Range and Compensation Package.  . . Compensation and benefits details will be discussed during the interview process. . . Equal Opportunity Statement.  . . We are committed to diversity and inclusivity in our hiring practices and encourage applications from all qualified individuals. We thank all applicants for their interest; only those selected for an interview will be contacted.. .  . .