Job Type: PermanentWork Model: HybridReference code: 135049Primary Location: Toronto, ONAll Available Locations: Toronto, ON; Calgary, AB; Halifax, NS; Ottawa, ON
Our Purpose
At Deloitte, our Purpose is to make an impact that matters. We exist to inspire and help our people, organizations, communities, and countries to thrive by building a better future. Our work underpins a prosperous society where people can find meaning and opportunity.
It builds consumer and business confidence, empowers organizations to find imaginative ways of deploying capital, enables fair, trusted, and functioning social and economic institutions, and allows our friends, families, and communities to enjoy the quality of life that comes with a sustainable future. And as the largest 100% Canadian-owned and operated professional services firm in our country, we are proud to work alongside our clients to make a positive impact for all Canadians.
By living our Purpose, we will make an impact that matters.
- Have many careers in one Firm.
- Enjoy flexible, proactive, and practical advantages that foster a culture of well-being and connectedness.
- Learn from deep subject matter experts through mentoring and on the job coaching
Deloitte Global is the engine of the Deloitte network. Our professionals reach across disciplines and borders to develop and lead global initiatives. We deliver strategic programs and services that unite our organization. What will your typical day look like?
Work you'll do
As a member of the Cybersecurity team, you will play a key role in identifying emerging threats, reducing organizational risk, and advancing security capabilities across Deloitte's technology landscape. This position combines strategic risk management with hands-on operational execution, offering opportunities to influence security practices, drive remediation efforts, and support the adoption of secure technologies and processes.
Key Responsibilities
Strategic
- Identify security exposures that exist or may pose potential threats to Deloitte’s networks or systems.
- Notify leadership of potential or existing threats and lead the development of risk-mitigating strategies of assigned items.
- Identify areas for improvement including systems integration, current technology, and automation and lead the design and implementation of solutions.
- Monitor security blogs, articles, and reports and remain current on related laws, regulations, and industry standards to keep up-to-date on the latest security risks, threats, and technology trends, and where relevant notify leadership to incorporate information into processes, procedures, and audit preparedness activities.
Operational
- Maintain the operation of the vulnerability management tool, ensuring the tool and supporting processes are working effectively to identify and report vulnerabilities in Deloitte systems.
- Operate security controls and processes to identify vulnerability and risk for Deloitte technology systems and users, reporting and remediating items.
- Track progress for the remediation of identified risks and vulnerabilities and provide appropriate reporting to leadership, intervening and escalating where necessary to ensure agreed priorities and timescales are met.
- Identify non-compliances to global standards, lead work with GTI and GDAS colleagues to remediate and implement treatment plans.
- Identify the need for, track, report on, and implement security-related Continual Service Improvement Plans to ensure control gaps and risks are remediated within agreed timescales.
- Monitor ServiceNow queues and ensure requests are handled within specified SLEs.
- Provide Cybersecurity SME support to Deloitte Technology colleagues and processes relating to vulnerability management, compliance to security controls, Active Directory policy, privileged access, cloud security, M365 security, network security,
cyber security incidents, and change management.
About The Team Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global setting, we operate not in what is but rather what can be to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.
Qualifications
Enough about us, let’s talk about you
Required
- Bachelor’s degree in computer science, cybersecurity, other technology-related fields, or equivalent education-related experience
- 4+ years combined experience in cybersecurity and / or solution design in an information security context
- Proven track record and experience of developing and driving security requirements across a broad spectrum of infrastructure and end user computing technologies
- Proven track record and experience of operating a vulnerability management tool and process in an enterprise environment (Qualys)
- Proven track record supporting external research findings such as BitSight
- Relevant technical certification preferred (CISSP-ISSEP, CEH, CCNP Security, GSEC)
- Strong interpersonal and collaborative skills, with ability to communicate strategic information security topics, policies, and standards as well as risk-related concepts to technical and nontechnical audiences at various hierarchical levels
- Ability to communicate effectively in written and verbal formats with a variety of stakeholders.
- Knowledge of business management principles, cybersecurity engineering, and secure solution design, with the ability to develop and document security hardening standards and practices.
- Experience working in cross-functional environments and consulting with technical and business stakeholders to evaluate requirements, solve problems, and support security-related outcomes.
- Knowledge of risk management processes (e.g., methods for assessing and mitigating risk), cybersecurity and privacy principles (relevant to confidentiality, integrity, availability, authentication, non-repudiation)
- Knowledge of systems testing, evaluation methods, and countermeasures for identified security risks
- Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth)
- Knowledge of network protocols, GWAN and WAN technologies and fundamental networking skills (TCP, IP, IDS/IPS, virtualization, etc.)
- Knowledge of common information security management frameworks, such as ISO/IEC 27001, COBIT, and NIST, including 800-53 and the NIST Cybersecurity Framework
- Experience in designing and validating security controls based on cybersecurity objectives
- Experience in discerning the protection needs (i.e., security controls) of information systems and networks
- Experience in conducting audits or reviews of technical systems
Preferred
- Professional security management certifications strongly desirable, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or other similar credentials
Total Rewards The salary range for this position is $69,000 - $114,000, and individuals may be eligible to participate in our bonus program. Deloitte is fair and competitive when it comes to the salaries of our people. We regularly benchmark across a variety of positions, industries, sectors, targets, and levels.
Our approach is grounded on recognizing people's unique strengths and contributions and rewarding the value that they deliver. Our Total Rewards Package extends well beyond traditional compensation and benefit programs and is designed to recognize employee contributions, encourage personal wellness, and support firm growth. Along with a competitive base salary and variable pay opportunities, we offer a wide array of initiatives that differentiate us as a people-first organization. On top of our regular paid vacation days, some examples include: $4,000 per year for mental health support benefits, a $1,300 flexible benefit spending account, firm-wide closures known as "Deloitte Days", dedicated days of for learning (known as Development and Innovation Days), flexible work arrangements and a hybrid work structure.
Our promise to our people: Deloitte is where potential comes to life.
Be yourself, and more.
We are a group of talented people who want to learn, gain experience, and develop skills. Wherever you are in your career, we want you to advance.
You Shape How We Make Impact.
Diverse perspectives and life experiences make us better. Whoever you are and wherever you’re from, we want you to feel like you belong here. We provide flexible working options to support you and how you can contribute.
Be the leader you want to be
Some guide teams, some change culture, some build essential expertise.
We offer opportunities and experiences that support your continuing growth as a leader.
Have as many careers as you want.
We are uniquely able to offer you new challenges and roles – and prepare you for them. We bring together people with unique experiences and talents, and we are the place to develop a lasting network of friends, peers, and mentors.
The next step is yours
At Deloitte, we are all about doing business inclusively – that starts with having diverse colleagues of all abilities. Deloitte encourages applications from all qualified candidates who represent the full diversity of communities across Canada. This includes, but is not limited to, people with disabilities, candidates from Indigenous communities, and candidates from the Black community in support of living our values, creating a culture of Diversity Equity and Inclusion and our commitment to our AccessAbility Action Plan, Reconciliation Action Plan and the BlackNorth Initiative.
We encourage you to connect with us at
[email protected] if you require an accommodation for the recruitment process (including alternate formats of materials, accessible meeting rooms or other accommodations) or
[email protected] for any questions relating to careers for Indigenous peoples at Deloitte (First Nations, Inuit, Métis).
When you apply, we will review your application using Deloitte's Global Talent Standards to ensure a consistent recruitment experience. Our recruitment advisors and hiring teams will utilize human screening combined with AI technology to help identify the skills and qualities that matter most to our business, while safeguarding your privacy and using AI responsibly.
Deloitte Canada has 20 offices with representation across most of the country. We acknowledge that Deloitte offices stand on traditional, treaty, and unceded territories in what is now known as Canada. We recognize that Indigenous Peoples have been the caretakers of this land since time immemorial, nurturing its resources and preserving its natural beauty.
We acknowledge this land is still home to many First Nations, Inuit, and Métis Peoples, who continue to maintain their deep connection to the land and its sacred teachings. We humbly acknowledge that we are all Treaty people, and we commit to fostering a relationship of respect, collaboration, and stewardship with Indigenous communities in our shared goal of reconciliation and environmental sustainability.
📌 Lead Cybersecurity Operations Analyst, Deloitte Global Technology (Toronto)
🏢 Deloitte
📍 Toronto