Information Security Analyst 3 (Security & Risk Advisory)
Toronto, ON, CA
Full Time Senior-level / Expert Clearance required USD 63K - 117K
Canada Life
We’ve been supporting the financial, physical and mental wellbeing of Canadians for 175 years.
Permanent Full Time
-
The Information Security Analyst III is part of the first line of cyber defense team, working with IT and business partners to help them understand and manage information security risks and comply with the organizational information security policies. The role also supports the delivery of analysis-based cyber security services to our internal clients across Canada including a security assurance assessment, responding to security inquiries from stakeholders and clients, assessing security controls, and more.
This is a senior security role which reports to the Director, Security Assurance within the Information Security Canada group. In addition to the general accountabilities below, we are particularly interested in hearing from candidates with the following specialties:
What you will do
- Focused on providing information security consultation to business and IT stakeholders.
- Provide expert security guidance to implement appropriate controls in projects and initiatives. Ensure the safeguarding and protection of Canada Life's confidential information, preventing accidental disclosure, modification, or destruction, and enhancing the organization's overall security posture.
- Conducting information security risk assessments (e.g. threat risk assessment) as needed.
- Research evolving threats and provide recommendations.
- Develops and conducts vulnerability assessments, and documenting findings in reports.
- Strong desire to work collaboratively in an unconventional and non/linear way to problem solve unique solutions.
- Be customer focused and delivery oriented to drive change in ambiguous situations.
- Work proactively with internal clients to understand their needs and deliver creative solutions.
- Strive for continuous learning and can influence others.
- Review vulnerability reports to identify security weaknesses on systems and help stakeholders prioritize their remediation based on risk. Examples of these types of reports, include:
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Interactive Application Security Testing (IAST)
- Software Composition Analysis (SCA)
- Penetration Testing
- Infrastructure and endpoint Vulnerability Testing
What you will bring
- Post-secondary degree in Business, Technology or related discipline or an equivalent combination of education and related experience.
- At least 7 years of experience in Information Security and/or Information Technology (IT), with a focus on Information Security Risk Management.
- Preferred professional designations include CISSP, CCSP, CISM, CISA, and other similar certifications.
- Proven experience in interpreting and consulting on Information Security and IT principles, protocols, practices, and industry standards.
- Extensive knowledge of security assessments, including understanding various attack/threat vectors and determining corresponding security controls to mitigate risks.
- Strong technical background with exposure to multiple aspects of information technology, such as networks, servers, application development, architecture, storage, and cloud technologies.
- In-depth understanding of existing and emerging Information Security technologies, which relate to encryption, network/web application firewalls, IDS/IPS, advanced malware protection, DDoS, DLP, and SIEM.
- Strong knowledge of cloud security and cloud-based technologies, particularly AWS and Azure.
- Familiarity with IT control frameworks such as SOC, ISO 27001, and the NIST Cybersecurity Framework.
- Working knowledge of IT audit and testing processes.
- A proactive self-starter who excels with minimal supervision, possesses strategic thinking abilities, and is skilled in negotiation and consensus building.
- Reliability Status security clearance - this is a personnel security status that is required before an employee can gain access to Protected B information, assets or work sites as outlined by the Government of Canada website
-
The base salary for this position is between $63,500.00 - $117,400.00 annually. This represents base salary only and does not represent other variable compensation components of our total compensation ( i.e. annual bonus, commission etc). If you are selected to move forward in our recruitment process, your recruiter will be able to discuss additional details of our total rewards program with you.
Career opportunities will be open a minimum of 5 business days from the date of posting, closing dates will vary depending on the search activity. All applications received will be reviewed on a rolling basis.
Be your best at Canada Life- Apply today!
Being a part of Canada Life means you have a voice. This is a place where your unique background, perspectives and talents are valued, and shape our future success.
You can be your best here. You’re part of a diverse and inclusive workplace where your career and well-being are championed. You’ll have the opportunity to excel in your way, finding new and better ways to deliver exceptional customer and advisor experiences.
Together, as part of a great team, you’ll deliver on our shared purpose to improve the well-being of Canadians. It’s our driving force. Become part of a strong and successful company that’s trusted by millions of Canadians to do the right thing.
Canada Life serves the financial security needs of more than 13 million people across Canada, with additional operations in Europe and the United States. As members of the Power Financial Corporation group of companies, we’re one of Canada’s leading insurers with interests in life insurance, health insurance, investment and retirement savings. We offer a broad portfolio of financial and benefit plan solutions for individuals, families, businesses and organizations.
We are committed to providing an inclusive, accessible environment, where all employees and customers feel valued, respected and supported. We are dedicated to building a workforce that reflects the diversity of the communities in which we live, and to creating an environment where every employee has the opportunity to reach their potential.
It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Canada Life policies. To request a reasonable accommodation in the application process, contact talentacquisitioncanada@canadalife.com.
Canada Life would like to thank all applicants, however only those who qualify for an interview will be contacted.
#LI-Hybrid
Tags: Application security Audits AWS Azure CCSP CISA CISM CISSP Clearance Cloud Cyber defense DAST DDoS Encryption Firewalls IAST IDS IPS ISO 27001 Malware NIST Pentesting Risk assessment Risk management SAST Security assessment Security Clearance SIEM SOC
Perks/benefits: Career development Salary bonus
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.