Information Security Analyst

2 weeks ago


Toronto, Canada Fidelity Investments Full time

Job Description

Current work authorization for Canada is required for all openings.

You will be working on a Hybrid office schedule as part of Fidelity’s dynamic working arrangement.

At Fidelity, we’ve been helping Canadian investors build better financial futures for over 35 years. We offer individuals and institutions a range of trusted investment portfolios and services - and we’re constantly seeking to find new and better ways to help our clients. As a privately owned company, we boldly embrace innovation in all areas as we continue to grow our business into the future.

Working with us means you’ll be part of a diverse and dedicated group of people who make a real difference for our clients and communities every day. You’ll have a wide range of opportunities to grow and develop your career in an inclusive environment where you’ll feel valued and supported to be your best - both personally and professionally.

Business Overview:
The Information Security Analyst supports the risk mitigation efforts of the Information Security group primarily through the technical support of the procedures and policies established to safeguard information assets.

What You Will Do:
1. Ensure the development life cycle complies with the information security policy requirements on secure coding and secure access controls.
- No overdue SCR/PEN test findings without valid exception
- Meet compliance deadlines (Patching/Upgrades, Anti-virus/Anti-spyware).
- Meet or exceed required verified level (DLP Program).

2. Tests for compliance with security policies and procedures. May assist in the creation, implementation, and/or management of security solutions.
- Participate in projects, reviews, and meetings, and provide guidance and feedback on security policies and issues.
- Implement and support compliance directives based on risk scores (NIST).

3. Ensure the information security policy requirements are communicated and taken into account by internal Infrastructure & development teams as well as third party vendors.
- Meet or exceed required verified level (Monthly CISO Scorecard).
- Meet or exceed required verified level (Monthly Nexpose scans).
- Analyze Nexpose findings, weeding out false positives, validating criticality of vulnerability and producing reporting to assist in tracking and remediation.
- Develop and maintain scripts for automation of various IT audits and processes.

6. Assist with assessment and integration of cloud vendors and SaaS from an Information Security requirements perspective.
- Maintain knowledge of cloud security and integration best practices.
- Participate in cloud /SaaS projects and provide security expertise and implementation requirements.
- Maintain data integrity in Fidelity’s asset registry

8. Conduct External Security Reviews on Fidelity vendors who have access to confidential information or perform critical functions.
- Conduct External Security Reviews (ESR) to identify risks with critical vendors.
- Create ESR report and conduct remediation activities with the vendor.
- Review and provide input on vendor contracts and security schedules.

9. Assist in monitoring Fidelity’s Data Loss Prevention (DLP) tool and conduct investigations.
- Monitor DLP queue, triage incidents and conduct DLP investigations.
- Escalate privacy breaches, HR issues as required.

10. Assist in conducting Security Training & Awareness.
- Provide security and awareness content to ISO’s security site.
- Participate in Cyber Awareness week.
- Meet with BU groups to discuss security policy, best practices.

11. Provide assistance for Disaster Recovery (DR) team including support of DR tests.
- Attend and support DR tests in support of FCAM, FCC and FIC DR tests.

The Expertise You Bring:

- 2-5 years of relevant experience in financial services industry
- Knowledge of SDLC methodologies and tools. Development background is highly desirable
- Knowledge of secure access modeling, threat modeling, digital security methodologies and deployments, and security architecture
- Understanding of Cloud Security and capabilities of Amazon, Microsoft Azure etc.
- Understanding of industry audit standards, i.e. SSAE-16, FFIEC, and PCI-DSS
- Strong interpersonal skills like being a team player and effective collaborator with many different types of audiences
- Independent problem-solving and self-directing abilities
- Self-driven and flexible with high motivation
- Ability to multitask and handle multiple projects
- Ability to practice tolerance and professionalism in times of high stress
- Strong presentation and written skills
- Nice to have Knowledge of Fortify, Veracode, Checkmarks, Appscan, ServiceNow
- Bachelor's in Information Technology, Computer Science or a related discipline
- Nice to have CISSP and Cloud Security certification

Some of the ways we’ll help you feel valued and supported as part of our team:

- Flexible working arrangements - 100% remote, hybrid, and in office options. This job is H



  • Toronto, Canada CB Canada Full time

    Information Security Analyst On behalf of our client in the Banking Sector, PROCOM is looking for an Information Security Analyst. Information Security Analyst – Job Description Manage assigned security platforms, following clients' procedures if required, which includes: Device health and availability monitoring Device health incident resolution and...


  • Toronto, Canada Investment Industry Regulatory Organization of Canada (IIROC) Full time

    **Position Title: Information Security Analyst** **Department: Information Technology** **Location: Toronto** **Status: Permanent Full-time (Hybrid)** The Information Security Analyst will implement the information security program initiatives, administer information security systems, and assist with monitoring information security policy compliance. The...


  • Toronto, Canada CanDeal Full time

    JOB PURPOSE Reporting to the Information Security Officer, the Information Security Analyst will possess a strong background in managing infrastructure, coupled with significant experience and expertise in cybersecurity. This role will involve analyzing threats, implementing security controls, resp


  • toronto, Canada CanDeal Full time

    JOB PURPOSE Reporting to the Information Security Officer, the Information Security Analyst will possess a strong background in managing infrastructure, coupled with significant experience and expertise in cybersecurity. This role will involve analyzing threats, implementing security controls, respo


  • Toronto, Canada Toyota North America Full time

    Description Information Security Analyst About Toyota Financial Services Toyota Financial Services (TFS) provides retail, leasing and wholesale financial services to Toyota and Lexus dealerships and customers across Canada. TFS is a member of Toyota Financial Services Corporation (TFSC), a wholly owned subsidiary of Toyota Motor Corporation in...


  • Toronto, ON, Canada Canadian Investment Regulatory Organization Full time

    40 Temperance Street Suite 2600 Toronto, ON M5H0B4, CAN Description Position Title: Information Security Analyst Department:Information Technology Location:Toronto Status: Permanent Full-time (Hybrid) The Information Security Analyst will implement the information security program initiatives, administer information security systems, and assist...


  • Old Toronto, Canada Canadian Investment Regulatory Organization Full time

    40 Temperance Street Suite 2600 Toronto, ON M5H0B4, CAN DescriptionPosition Title: Information Security AnalystDepartment:Information TechnologyLocation:TorontoStatus: Permanent Full-time (Hybrid)The Information Security Analyst will implement the information security program initiatives, administer information security systems, and assist with...


  • Old Toronto, Canada Canadian Investment Regulatory Organization Full time

    40 Temperance Street Suite 2600 Toronto, ON M5H0B4, CAN DescriptionPosition Title: Information Security AnalystDepartment:Information TechnologyLocation:TorontoStatus: Permanent Full-time (Hybrid)The Information Security Analyst will implement the information security program initiatives, administer information security systems, and assist with...


  • Old Toronto, Canada Canadian Investment Regulatory Organization Full time

    40 Temperance Street Suite 2600 Toronto, ON M5H0B4, CAN DescriptionPosition Title: Information Security AnalystDepartment:Information TechnologyLocation:TorontoStatus: Permanent Full-time (Hybrid)The Information Security Analyst will implement the information security program initiatives, administer information security systems, and assist with...


  • Old Toronto, Canada TouchBistro Full time

    TouchBistro is looking for an Information Security Analyst I to join our security team! AtTouchBistro, safeguarding the confidentiality, integrity, and availability of our services and data is paramount. That's why we're on the lookout for an Information Security Analyst who shares our passion for protecting our customers. The role involves analyzing...


  • Old Toronto, Canada TouchBistro Full time

    TouchBistro is looking for an Information Security Analyst I to join our security team! AtTouchBistro, safeguarding the confidentiality, integrity, and availability of our services and data is paramount. That's why we're on the lookout for an Information Security Analyst who shares our passion for protecting our customers. The role involves analyzing...


  • Old Toronto, Canada TouchBistro Full time

    TouchBistro is looking for an Information Security Analyst I to join our security team! AtTouchBistro, safeguarding the confidentiality, integrity, and availability of our services and data is paramount. That's why we're on the lookout for an Information Security Analyst who shares our passion for protecting our customers. The role involves analyzing...


  • Toronto, Canada Canada Life Assurance Company Full time

    **Job Description**: The Information Security Analyst II is part of the first line of cyber defense team, working with IT and business partners to help them understand and manage information security risks and comply with the organizational information security policies. The role also supports the delivery of analysis-based cyber security services to our...


  • Toronto, Canada McCain Foods (Canada) Full time

    **Position Title**:Business Information Security Analyst **Position Type**: Regular - Full-Time **Position Location**:Toronto HQ **Requisition ID**: 21697 This Business Information Security Analyst will be an important member of the cyber risk management team, delivering support and advisory across the McCain organization. You will analyze security...


  • Toronto, ON, Canada Toronto, ON, Canada Full time

    Security Operations Analyst, Information Security Thursday, May 9, 2024 Working together to be our best! We are hiring a Security Operations Analyst, Information Security! Reporting To: Manager, Information Security/ Security Operations Full-Time/Part- Time: Full-time Posting Date: May 9, 2024 Closing Date: May 31, 2024 Hours of Work: 8:30...


  • Toronto, ON, Canada First National Financial LP Full time

    Security Operations Analyst, Information Security Toronto, ON, Canada Job Description Posted Thursday, May 9, 2024 at 4:00 AM | Expires Saturday, June 1, 2024 at 3:59 AM Working together to be our best! We are hiring a Security Operations Analyst, Information Security! Reporting To: Manager, Information Security/ Security Operations ...


  • Old Toronto, Canada First National Financial LP Full time

    Security Operations Analyst, Information Security Toronto, ON, Canada Job Description Posted Thursday, May 9, 2024 at 4:00 AM | Expires Saturday, June 1, 2024 at 3:59 AM Working together to be our best! We are hiring a Security Operations Analyst, Information Security! Reporting To: Manager, Information Security/ Security Operations ...


  • Old Toronto, Canada Toronto, ON, Canada Full time

    Security Operations Analyst, Information Security Thursday, May 9, 2024 Working together to be our best! We are hiring a Security Operations Analyst, Information Security! Reporting To: Manager, Information Security/ Security Operations Full-Time/Part- Time: Full-time Posting Date: May 9, 2024 Closing Date: May 31, 2024 Hours of Work: 8:30 a.m....


  • Old Toronto, Canada Toronto, ON, Canada Full time

    Security Operations Analyst, Information Security Thursday, May 9, 2024 Working together to be our best! We are hiring a Security Operations Analyst, Information Security! Reporting To: Manager, Information Security/ Security Operations Full-Time/Part- Time: Full-time Posting Date: May 9, 2024 Closing Date: May 31, 2024 Hours of Work: 8:30 a.m....


  • Old Toronto, Canada First National Financial LP Full time

    Security Operations Analyst, Information Security Toronto, ON, Canada Job Description Posted Thursday, May 9, 2024 at 4:00 AM | Expires Saturday, June 1, 2024 at 3:59 AM Working together to be our best! We are hiring a Security Operations Analyst, Information Security! Reporting To: Manager, Information Security/ Security Operations ...