Information Security Analyst

2 weeks ago


Toronto, Canada CIRO OCRI Full time

**Position Title: Information Security Analyst**

**Department: Information Technology**

**Location: Toronto**

**Status: Fixed-term Full-time - 12 months (Hybrid)**

**Day in the life of**:
The Information Security Analyst will implement the information security program initiatives, administer information security systems, and assist with monitoring information security policy compliance. The Analyst along with the Information Security team will be developing the information security maturity of the organization as well as performing operational activities on implemented information security controls to ensure information security policies are being followed. The role will be responsible for various activities to build information security including developing appropriate documentation, building awareness, implementing technologies, and identifying information security weaknesses with the objective of protecting of CIRO information assets.

**Core Responsibilities**:

- Work with the Information Security team, businesses, vendors, and IT teams to ensure that corporate policies and procedures are being understood and followed
- Write procedures and technical standards to meet corporate policies and industry best practices
- Evolve corporate security policies and procedures to stay aligned with the security industry best practices
- Develop and improve internal processes to manage information security corporate wide
- Lead initiatives related to the remediation of security weaknesses or information security solution implementation while working with corporate wide businesses, vendors, and the IT team as needed
- Review technical configurations from various operating systems and security solutions (Windows, Linux, AD, VMware, IDS/IPS, FIM, SIEM, WAF, AV, endpoint encryption, etc.) to determine/enhance the parameters to meet industry-accepted hardening standards such as NIST, CIS, SANS, etc.
- Review security reports from various security technologies (vulnerability assessment reports, cyber security reports, audit reports, access privileges, etc.) to identify violations, intrusion attempts, or security weaknesses
- Provide recommendations and guide development and operations team to address security weaknesses and identify potential new security solutions
- Monitor the information security industry and be proactive with implementing appropriate information protection controls to mitigate risks on the latest types of vulnerabilities
- Conduct security product research and assess their appropriateness for the organization
- Produce report and presentation deliverables with attention on content as well as format
- Perform security incident investigations and document findings/root causes
- Perform Identity and Access management tasks
- Respond to alerts and notifications from users/vendors related to information security
- Develop and improve internal team processes to effectively manage information security corporate wide
- Review potential new service provider or outsourcing relationships for business units and provide advisory services for information security due diligence
- Evolve corporate security policies, procedures, and standards to align with the security industry best practices
- Review new IT implementations and identify security risks in network design and configuration

**Skills and Competencies**:
**Must-Haves**
- Post-secondary degree or equivalent education in computer science, computer engineering, or similar studies
- Information security certifications such as CISSP, GIAC, CRISC, etc.
- Previous experience of 4-6 years specifically in the information security industry preferred
- Knowledge of current network and endpoint security technologies important (next generation tools, APT tools, and tools utilizing heuristics analysis for protection)
- Strong knowledge of technical configurations from various operating systems and security solutions (Windows, Linux, VMware, IDS/IPS, HIPS, FIM, SIEM, WAF, Cyber Security, encryption, etc.)
- Working knowledge of industry security standards such as ISO27001/ISO27002, NIST, etc.
- Demonstrated experience working with security technologies
- Demonstrated experience with implementing internal processes to manage information security initiatives
- Working knowledge of network architecture with multiple layers of defense
- High attention to details and accuracy
- Results driven
- Self-motivated and able to work unsupervised
- Ability to take projects to completion from beginning to end
- Strong written and oral communication skills
- Strong analytical and problem-solving abilities with keen attention to detail
- Experience working in a team-oriented, collaborative environment
- Strong aptitude for learning

**Why the Canadian Investment Regulatory Organization (CIRO)**:
**Our purpose and our impact**

With offices across Canada - from Vancouver to Montreal, our mission is to promote healthy capital markets by regulating fairly and effectively so that invest



  • Toronto, Canada TVO Ontario Educational Comms. Authority Full time

    **Position**: Information Security Analyst **Division**: Finance and Technology Services **Salary Range**: $93,382.32 - $99,991.20 (40 hours per week) **Reports To**: Director, Technology Services **Location**: Toronto, Yonge & Eglinton (Hybrid Work: 3 days in office) TVO Media Education Group (TVO) is a social impact organization devoted to inspiring...


  • Toronto, Ontario, Canada Vretta Full time

    Vretta is looking for an Information Security Analyst to join our Systems and Security team. This position requires creative problem solving and sound technical ability to understand requirements, and support the maintenance of the cybersecurity standards and compliances.The Information Security Analyst should have the attitude and energy to contribute to an...


  • Toronto, Canada Mindlance Full time

    Information Security Analyst Location: Toronto, ON (Onsite) Duration: 6+ Months Responsibilities Execute IAM operational risk controls by identifying and reporting security risks in accordance with Client's Logical Access Security Standards (LASS). Providing operational support to internal employees at all levels of management for SailPoint (i.e., Access...


  • Toronto, Canada Mindlance Full time

    Information Security Analyst Location: Toronto, ON (Onsite) Duration: 6+ Months Responsibilities Execute IAM operational risk controls by identifying and reporting security risks in accordance with Client's Logical Access Security Standards (LASS). Providing operational support to internal employees at all levels of management for SailPoint (i.e., Access...


  • Toronto, Canada Wittington Full time

    **Location**: 22 St. Clair Avenue East, Toronto, Ontario, M4T 2S7 **About Us** Wittington Investments, Limited, a private Canadian company, is the holding company of the Weston group of companies, which includes George Weston Limited, Loblaw Companies Limited and Choice Properties REIT. George Weston Limited is a Canadian public company, founded in 1882....


  • Toronto, Canada Fidelity Investments Full time

    Job Description Current work authorization for Canada is required for all openings. You will be working on a Hybrid office schedule as part of Fidelity’s dynamic working arrangement. At Fidelity, we’ve been helping Canadian investors build better financial futures for over 35 years. We offer individuals and institutions a range of trusted investment...


  • Toronto, Canada Delpath Full time

    OverviewMBA | Connecting Talent to Opportunities | Hiring for Banking / Insurance / Finance / IT industriesLocationLocation Address: Downtown Toronto - Hybrid - onsite at least once a weekContractContract Duration: 5 monthsPossibility of extension & conversion to FTEPosition DetailsNumber of Positions: 1Schedule Hours: 9am-5pm Monday-Friday; standard 37.5...


  • Toronto, Canada Delpath Full time

    OverviewMBA | Connecting Talent to Opportunities | Hiring for Banking / Insurance / Finance / IT industriesLocationLocation Address: Downtown Toronto - Hybrid - onsite at least once a weekContractContract Duration: 5 monthsPossibility of extension & conversion to FTEPosition DetailsNumber of Positions: 1Schedule Hours: 9am-5pm Monday-Friday; standard 37.5...


  • Toronto, Canada Delpath Full time

    Overview MBA | Connecting Talent to Opportunities | Hiring for Banking / Insurance / Finance / IT industries Location Location Address: Downtown Toronto - Hybrid - onsite at least once a week Contract Contract Duration: 5 months Possibility of extension & conversion to FTE Position Details Number of Positions: 1 Schedule Hours: 9am-5pm Monday-Friday;...


  • Toronto, Canada Fidelity Investments Full time

    Job Description Current work authorization for Canada is required for all openings. You will be working on a Hybrid office schedule as part of Fidelity’s dynamic working arrangement. At Fidelity, we’ve been helping Canadian investors build better financial futures for over 35 years. We offer individuals and institutions a range of trusted investment...