Security Analyst
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
Proud to be 100% Canadian-owned, Northland Properties' are recognized as one of the most trusted names in hotels, restaurants, resorts, sports, construction, and asset management. Our well-known and loved brands have been bringing people together to celebrate unforgettable experiences across Canada, the US, Ireland, and the UK for over 50 years. As Canada's fastest-growing hospitality group, we believe the foundation of our continued success is our people and their ability to take great care of our guests.
EMPLOYER: Northland Properties Corporation (NPC)
LOCATION: Support Centre, Vancouver, BC
EMPLOYMENT TYPE: Full Time
COMPENSATION RANGE: $60,000 - 80,000
BENEFITS: Health/Dental/Vision, RRSP, Paid Time Off, Employee Perks.
Position Overview The Security Analyst helps protect the Company's technology environment, systems and information across Canada by monitoring security activity, investigating threats, supporting incident response and maintaining cybersecurity controls across corporate offices and operating locations.
Key Responsibilities Monitor security alerts and suspicious activity across endpoints, networks, cloud services, identity platforms and business applications.
Triage and investigate cybersecurity incidents; escape significant threats and support containment, recovery, documentation and lessons learned.
Administer and monitor security technologies, including endpoint detection and response, email security, vulnerability management, firewalls, multi-factor authentication and identity access controls.
Monitor Microsoft 365 and Azure security environments, including Entra ID, Microsoft Defender, Conditional Access, logging and alerting.
Perform vulnerability reviews and track remediation of critical patches, security updates and configuration issues.
Review user access, privileged accounts and security groups, including requirements for onboarding, role changes and departures.
Coordinate cybersecurity activities with internal IT teams, operating locations and managed service providers across Canada.
Support security assessments for new applications, vendors and technology changes.
Participate in phishing simulations, cybersecurity awareness initiatives and employee education.
Prepare reports on incidents, vulnerabilities, trends and risks, and maintain related procedures, technical documentation and system inventories.
Support business continuity, disaster recovery and cybersecurity incident response exercises.
Stay current on cybersecurity threats and recommend practical improvements.
Provide after-hours support during significant cybersecurity incidents when required.
Qualifications And Experience Post-secondary education in cybersecurity, information technology, computer science or a related field, or an equivalent combination of education and practical experience.
Two to four years of experience in cybersecurity, IT security, systems administration, infrastructure or a related technical role.
Hands-on experience monitoring and investigating security alerts and incidents using security monitoring, endpoint detection, ticketing and vulnerability management tools.
Working knowledge of Windows, Microsoft 365, Azure, Entra ID, networking fundamentals, identity and access management, endpoint security and vulnerability management.
Understanding of established cybersecurity practices and frameworks, such as the NIST Cybersecurity Framework, CIS Controls and incident response lifecycle principles.
Experience supporting a geographically distributed, multi-site or 24-hour operating environment—particularly hospitality, retail or restaurants—is an asset.
Certifications such as Security+, CySA+, SC-200, SSCP or equivalent are assets.
Ability to handle confidential information with discretion, travel occasionally within Canada and provide after-hours support when required.
Capabilities Analyzes security information methodically, exercises sound judgment and escalates issues appropriately.
Communicates technical information clearly to technical and non-technical audiences.
Maintains strong attention to detail and stays organized during competing priorities and security incidents.
Builds effective relationships with IT teams, business partners and external service providers.
Balances cybersecurity requirements with operational needs and recommends practical, risk-based solutions.
Takes ownership of assigned issues through resolution and continuously improves security processes and controls.
Measures of Success Security alerts and incidents are reviewed, investigated, documented, escalated and resolved within established timelines.
Vulnerabilities and security gaps have clear remediation actions, owners and timelines.
User access and security controls are consistently reviewed and maintained.
IT teams and business partners receive timely, clear information d