Cybersecurity Analyst, Mining

🗓️ Posted 2026-08-22 Greater Toronto Area, Canada Full-time Hybrid ICT

Company shared salary

NA

Market rate

8,000 CAD–14,000 CAD/mo (96,000 CAD–168,000 CAD/yr)

Based on similar roles (title + domain + location).

About the Company

Hybrid: 2-3X per week in office Blue Moon Metals is seeking a Cybersecurity Analyst to join its growing IT & Cybersecurity function at the Toronto headquarters. This role is responsible for monitoring, assessing, and strengthening the security posture of both corporate IT systems and operational technology (OT) / industrial control system (ICS) environments across the company's offices, project sites, and mining operations. The successful candidate will work closely with the Lead, IT Infrastructure Engineer and cross-functional stakeholders to implement security controls aligned to NIST CSF 2.0 and IEC 62443, and to support the company's broader cybersecurity maturity program.

Responsibilities

  • Monitor security events and alerts across IT and OT environments, investigating and responding to potential incidents in a timely manner.
  • Support day-to-day administration of security tooling, including endpoint detection and response (EDR), SIEM/log management, vulnerability scanning, email security, and identity protection platforms.
  • Conduct vulnerability assessments and coordinate remediation activities across corporate IT and industrial control system (ICS/SCADA) assets, in partnership with OT and engineering teams.
  • Assist in the design, implementation, and continuous improvement of security controls aligned to NIST CSF 2.0 and IEC 62443, including IT/OT network segmentation initiatives.
  • Contribute to security policies, standards, and procedures, and help translate framework requirements into practical, site-appropriate controls for corporate, project, and remote/underground mining locations.
  • Support identity and access management activities, including access reviews, provisioning/deprovisioning, and privileged access oversight.
  • Participate in risk assessments, security audits, and third-party assessments (e.g., cybersecurity maturity assessments), helping track findings through to remediation.
  • Assist with incident response planning and execution, including documentation, root-cause analysis, and post-incident reporting.
  • Deliver security awareness content and training to employees and contractors across corporate and site locations.
  • Maintain accurate documentation of security architecture, controls, and asset inventories for both IT and OT environments.
  • Stay current on emerging threats, vulnerabilities, and regulatory requirements relevant to the mining and critical infrastructure sector.

Requirements

  • 2-5 years of experience in a cybersecurity, IT security, or security operations role, ideally with some exposure to industrial/OT environments.
  • Working knowledge of the NIST Cybersecurity Framework (CSF 2.0) and/or IEC 62443 for industrial automation and control systems security.
  • Familiarity with common security tools such as SIEM, EDR/XDR, vulnerability scanners, and firewall/network monitoring platforms.
  • Understanding of IT/OT network architecture, segmentation concepts, and the unique risk considerations of industrial control systems (SCADA, PLCs, HMIs).
  • Solid understanding of core security domains: identity and access management, network security, endpoint security, and incident response.
  • Post-secondary education in Computer Science, Information Security, Engineering, or a related field, or equivalent practical experience.
  • Strong analytical and problem-solving skills, with the ability to communicate technical risk clearly to both technical and non-technical audiences.
  • Ability to travel occasionally to project and mine sites as required.
  • Industry certifications such as Security+, GICSP, GRID, CISSP (or working toward), or similar.
  • Prior experience in mining, energy, manufacturing, or another critical infrastructure sector.
  • Exposure to regulatory or compliance frameworks relevant to publicly traded companies (e.g., SOX IT general controls).
  • Experience supporting cybersecurity maturity assessments or working alongside external consultants/auditors.
  • Blue Moon Metals Inc. is a publicly traded metals and mining company advancing a global portfolio of mineral development and operating projects. As the company grows its corporate, project, and remote site operations, the IT & Cybersecurity team is building the internal capability required to protect both enterprise IT and operational technology (OT) environments across the business.
  • The opportunity to help build a cybersecurity program from the ground up across a global mining organization.
  • Exposure to both enterprise IT and industrial OT/ICS security in a hands-on, high-impact role.
  • A collaborative team environment based at our Toronto headquarters.
  • Competitive compensation and benefits package.
  • Compensation and benefits details will be discussed during the interview process.
  • We are committed to diversity and inclusivity in our hiring practices and encourage applications from all qualified individuals. We thank all applicants for their interest; only those selected for an interview will be contacted.