Information security / analyst cyber analyst (Winnipeg)

Information security / analyst cyber analyst (Winnipeg)

15 Sep
|
Canada Life
|
Winnipeg

15 Sep

Canada Life

Winnipeg

Permanent Full Time The Information Security Analyst III role is within the Project Security team, partnering with Information Technology and business stakeholders to identify, assess, and manage information security risks while ensuring compliance with organizational security policies, standards, and regulatory requirements. This role delivers security services across Canada Life projects, including security consultation, threat and risk assessments, threat modeling, and security control reviews to help ensure secure project delivery and effective risk management. Reporting to the Manager, Project Security, within the Information Security and Technology Risk (ISTR) group.

Provide information security consultation and advisory services to business and IT stakeholders. Partner with project teams and technology stakeholders to identify, assess, and implement appropriate security controls throughout the project lifecycle. Ensure the safeguarding and protection of Canada Life's confidential information by helping prevent unauthorized disclosure, modification, destruction, or misuse of information assets.

Conduct information security risk assessments, including Threat Modeling, Threat Risk Assessments (TRAs), security reviews, and other risk-based evaluations. Research emerging threats, vulnerabilities, attack techniques, and industry trends, providing recommendations to mitigate organizational risk. Develop and conduct security and risk assessments and document findings, recommendations, and remediation activities.

Review risk assessment and reports, identify security weaknesses, and assist stakeholders in prioritizing remediation activities based on risk.

Static Application Security

Testing (SAST) Dynamic Application Security Testing (DAST) Software Composition Analysis (SCA) Collaborate across Line of Business to solve complex security challenges and develop practical, risk-based solutions.



Maintain a customer-focused and delivery-oriented approach, driving positive outcomes in dynamic and ambiguous environments. Work proactively with internal clients to understand business objectives and provide effective security guidance.

Promote continuous learning, knowledge sharing, and security awareness while positively influencing stakeholders and peers. Post-secondary degree in Business, Technology, Cybersecurity, Computer Science, or a related discipline, or an equivalent combination of education and experience. Minimum of five (5) years or more of experience in Information Security and/or Information Technology, with significant experience in Information Security Risk Management.

Professional security certifications such as CISSP, CCSP, CISM, CISA, CRISC, or equivalent are preferred. Strong knowledge of information security principles, risk management methodologies, security protocols, industry standards, and best practices. Extensive experience performing security assessments and evaluating threat vectors, vulnerabilities, and compensating controls.

Solid technical background across multiple technology domains, including networking, servers, cloud computing, application development, enterprise architecture, and infrastructure. Knowledge of security technologies and capabilities, including: Threat Modeling and Threat Risk assessment Network and Web Application Firewalls (WAF) Data Loss Prevention (DLP) Security Information and Event Management (SIEM)



Strong knowledge of cloud security principles and cloud platforms, particularly Microsoft Azure and AWS. Working knowledge of cybersecurity frameworks, risk assessment methodologies, threat modeling frameworks, and security control standards, including NIST Cybersecurity Framework (CSF) 2.0, ISO 27001/27002, CIS, SOC 2, CSA, MITRE ATT&CK;, OWASP Top 10, STRIDE, DREAD, and related industry standards and best practices.

Familiarity with IT audit, compliance, and security testing processes. Knowledge of emerging AI technology including associated risks and controls. Excellent communication, stakeholder management, presentation, negotiation, and consensus-building skills.

Demonstrated ability to work independently, think strategically, manage competing priorities, and deliver on commitments with minimal supervision. This represents base salary only and does not represent other variable compensation components of our total compensation ( i.e. annual bonus, commission etc). Our company is trusted by 1 in 3 Canadians and contributes to the strength of communities across the country.

We’re looking for people who live our values everyday: we step up, we do the right thing, and we deliver – for our customers, communities and each other. Versatile health and dental benefits, plus a $5,000 mental health benefit to support your well-being. Time Off:In addition to regular vacation and personal days, we support community involvement with a volunteer day.

Financial

Security:Company-matching pension plan,share ownership program and additionalinvestment options.

Emphasis on Community: We provide a workplace where employees feel connected and supported through Employee Resource Groups (ERGs), mentorship programs, social clubs and events. All information provided will be handled in accordance with applicable laws and Canada Life policies.

📌 Information security / analyst cyber analyst (Winnipeg)
🏢 Canada Life
📍 Winnipeg

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: information security / analyst cyber analyst (winnipeg) / winnipeg

Subscribe to this job alert:

Get the latest job offers by email for: information security / analyst cyber analyst (winnipeg) / winnipeg