Analyst, IT Security and Risk

1 week ago


Montréal, Canada CMHC Full time

**Job Requisition ID**: 11432

**Position Status**: Permanent Full Time

**Position Type**:Hybrid

**Office Location**:Ottawa (ON); Montreal (QC); Toronto (ON)

**Travel Requirement**: Limited

**Language Designation**: English Essential

**Language Skill Levels (Read/Write/Speak)**: ZZZ

**Security Requirement**: Secret

**Salary**: Our salaries generally range from $ $60,871.49 to $ $76,089.36 and are based on qualifications and experience.

About CMHC

The work you do and the work we do together matters. We come to work every day with a common purpose: to contribute to a well-functioning housing system.

At CMHC, we hold ourselves accountable for our **results** and support our colleagues in their achievements. We thrive on collaboration, connecting across CMHC and involving the right people to get our work done. Our leadership style is guided by **trust**, where our leaders favour an adaptive approach based on the needs of their teams.

Join us and be part of a team that's committed to making a real difference and be part of something meaningful.

What’s in it for you

We’ve got the purpose, the people and the perks you need for a fulfilling career. Here’s the comprehensive and generous benefits you get when you’re a permanent employee:

- Annual paid vacation.
- Annual individual performance incentive.
- Defined benefit pension plan.
- Comprehensive group insurance plan to support your well-being from day one.
- Support towards your personal and professional growth with training, mentorship and more.
- An inclusive workplace culture and environment.

About the role

We are seeking a detail-oriented and proactive IT Analyst - IT Security & Risk to support the organization’s cybersecurity posture and risk management initiatives. This role is responsible for identifying, assessing, and mitigating IT security risks, ensuring compliance with internal policies and external regulations, and supporting the implementation of security technologies and controls.

**What you’ll do**:

- Support the implementation, maintenance, and monitoring of security controls, risk assessments, and compliance activities.
- Collaborate with business and IT teams to identify, analyze, and report on risks to organizational information assets.
- Assist in incident response, vulnerability management, and security awareness programs.
- Contribute to the development of policies, procedures, and best practices in cybersecurity and IT risk management.
- Help ensure compliance with regulatory requirements (e.g., OSFI B-13, NIST, ITSG-33) and CMHC’s internal frameworks.

**DevSecOps & Security Operations**:

- Be part of our Security Operations and DevSecOps teams to deliver secure, robust, and automated solutions across our platforms and cloud environments.
- Participate in the deployment, integration, and daily monitoring of modern security tools, including:

- **Microsoft Defender** (Endpoint, Identity, Cloud, etc.)
- **SIEM solutions** (e.g., Azure Sentinel)
- **Copilot**:

- **Data Loss Prevention (DLP)**:

- **Azure DevOps** (CI/CD security integration)
- **AquaSec** (container and cloud-native security)
- And other cutting-edge security and automation technologies
- Actively contribute to the automation and continuous improvement of our security processes, supporting both IT and business delivery.

**What you should have**:

- Knowledge of cybersecurity, DevSecOps and IT security best practices.
- Strong analytical, communication, and teamwork skills.
- Proactive attitude, willingness to learn, and ability to work in a fast-paced environment.

**It would be great if you also had**:

- Hands-on experience or strong interest in security operations and automation tools (Defender, SIEM, DLP, Azure DevOps, AquaSec, etc.) is an asset.

**Posting closing date**:Note, the competition will remain active until filled.

Our commitment to diversity, equity, and inclusion

CMHC is an inclusive workplace where diversity of thought - and of people - are recognized, valued, and considered essential to achieving our mission.

**Learn more about our commitment to diversity and inclusion**

What happens after you apply

If you applied before and you were not successful don’t worry - we're always posting new positions, so don’t hesitate to give it another shot. We’re excited to see what you bring to the table this time around



  • Montréal, Canada WSP Full time

    WSP’s Information Security Office (ISO) is responsible for the deployment and maintenance of the information security framework for both the IT organization and wider business community. This includes the Governance mechanisms, policies and processes, tools and technologies, and employee training required to protect WSP information and that of our...


  • Montréal, QC, Canada NTT DATA Full time

    We are currently seeking a **Security Risk Assessment Analyst** to join our team in Montreal, Quebec (CA-QC), Canada (CA). **Job Responsibilities Include**: - Conducting remote/in-person interviews with system owners/vendors to get all the required information for assessment and to identify any gaps. - Reviewing system-related material including...


  • Montréal, Canada NTT DATA Full time

    We are currently seeking a **Information Security Risk Assessment Analyst** to join our team in Montreal, Quebec (CA-QC), Canada (CA). **Job Responsibilities Include**: - Conducting remote/in-person interviews with system owners/vendors to get all the required information for assessment and to identify any gaps. - Reviewing system-related material...


  • Montréal, Canada NTT DATA Full time

    We are currently seeking a **Security Risk Assessment Analyst (Onsite Hybrid)** to join our team in Montreal, Quebec (CA-QC), Canada (CA). **Job Responsibilities Include**: - Conducting remote/in-person interviews with system owners/vendors to get all the required information for assessment and to identify any gaps. - Reviewing system-related material...

  • Risk Analyst

    4 weeks ago


    Montréal, QC, Canada Compunnel Inc. Full time

    Job Title : Risk Analyst or Domain Control Support Location: Montreal (Day 1 onboarding onsite / in office presence 3x week) Organization: Technology, Risk, Governance and Controls (TRGC), support specializing in Distributed Ledger Technologies (Crypto) Skills Required: 1. Experience writing Technology policies, Standards and Procedures 2. Awareness of...

  • Risk Analyst

    3 weeks ago


    Montréal, Qc, Canada Compunnel Inc. Full time

    Job Title : Risk Analyst or Domain Control Support Location: Montreal (Day 1 onboarding onsite / in office presence 3x week) Organization: Technology, Risk, Governance and Controls (TRGC), support specializing in Distributed Ledger Technologies (Crypto) Skills Required: 1. Experience writing Technology policies, Standards and Procedures 2. Awareness of...

  • Security Analyst

    7 days ago


    Montréal, QC, Canada Ubisoft Full time

    **Company Description** Ubisoft’s 19,000 team members, working across more than 30 countries around the world, are bound by a common mission to enrich players’ lives with original and memorable gaming experiences. Their commitment and talent have brought to life many acclaimed franchises such as Assassin’s Creed, Far Cry, Watch Dogs, Just Dance,...

  • Security Analyst

    7 days ago


    Montréal, Canada Ubisoft Full time

    **Company Description** Ubisoft’s 20,000 team members, working across more than 30 countries around the world, are bound by a common mission to enrich players’ lives with original and memorable gaming experiences. Their commitment and talent have brought to life many acclaimed franchises such as Assassin’s Creed, Far Cry, Watch Dogs, Just Dance,...

  • Security Analyst

    2 weeks ago


    Montréal, Canada Shakepay Full time

    Join our small, fiery team on our mission to usher in the Bitcoin golden age. **About Shakepay** Shakepay is on a mission to usher in a Bitcoin golden age, where Canadians have access to Bitcoin-friendly, secure, and rewarding financial services. When Shakepay launched in 2015, it quickly became one of Canada's fastest-growing financial institutions....

  • Security Analyst

    2 weeks ago


    Montréal, Canada GoSecure Full time

    **Summary** The VMaaS Analyst is responsible for supporting the delivery and operation of Vulnerability Management as a Service. This includes identifying, analyzing, prioritizing, and reporting vulnerabilities across client environments or internal systems. The analyst ensures timely remediation and maintains compliance with relevant security frameworks....