Information Security Analyst (Toronto)

Information Security Analyst (Toronto)

03 Oct
|
IS3 Solutions
|
Toronto

03 Oct

IS3 Solutions

Toronto

Location: Toronto, Canada or

Mt Laurel, NJ

3 days onsite

Senior Information Security Analyst – Agentic AI Identity Governance

Role Summary: The Senior Information Security Analyst – Agentic AI Identity Governance will lead the design, implementation, and oversight of identity governance controls for autonomous and semi-autonomous AI agents operating across enterprise systems. This role focuses on ensuring that agentic AI systems are governed as non-human identities with clearly defined ownership, least-privilege access, auditable actions, lifecycle controls, and human accountability.

Key Responsibilities

- Establish and maintain identity governance standards for agentic AI systems, including registration, classification, ownership, entitlement management, and lifecycle governance for AI agents.
- Define access control models for AI agents based on least privilege, segregation of duties, just-in-time access, delegated authority, and policy-based authorization.
- Partner with Cybersecurity, IAM, AI Engineering, Risk, Privacy, Compliance, and Legal teams to ensure AI agents operate within approved enterprise guardrails.
- Develop governance processes for agent onboarding, approval, credential issuance, privilege assignment, access review, suspension, decommissioning, and emergency revocation.
- Assess risks associated with autonomous agent actions, tool use, memory, decision-making, system-to-system access, and privileged operations.
- Implement monitoring and audit requirements to ensure AI agent activity is observable, attributable, reviewable, and traceable to accountable business owners.
- Support the development of policies for human-in-the-loop oversight, accountability boundaries, escalation procedures, and exception handling.
- Conduct periodic access certifications, control testing, gap assessments, and maturity reviews for agentic AI identity governance capabilities.




- Contribute to threat modelling for AI agents, including identity misuse, privilege escalation, credential compromise, unauthorized tool invocation, data exposure, and autonomous policy violations.
- Prepare executive-ready reporting on control effectiveness, residual risk, remediation progress, and compliance posture related to agentic AI identities.

Required Qualifications
- 5+ years of experience in information security, identity and access management, security governance, risk management, or related cybersecurity roles.
- Strong understanding of identity governance and administration, privileged access management, access lifecycle management, authentication, authorization, and access certification processes.
- Experience designing or operating controls for non-human identities, service accounts, machine identities, APIs, bots, automation platforms, or AI-enabled systems.
- Knowledge of Zero Trust principles, least-privilege access, policy-based access control, and enterprise security architecture.
- Experience with risk assessment, control design, audit readiness, regulatory compliance, and security documentation.
- Ability to translate emerging technology risks into practical governance requirements, operating procedures, and executive-level communications.
- Excellent stakeholder management, analytical thinking, problem-solving, and written communication skills.

Preferred Qualifications
- Experience with AI governance, model risk management, responsible AI, data governance, or emerging technology risk programs.




- Familiarity with agentic AI concepts such as autonomous planning, tool invocation, memory, delegated authority, and multi-agent workflows.
- Hands-on experience with IAM platforms, IGA tooling, PAM solutions, SIEM/SOAR platforms, API security, cloud identity platforms, or security monitoring tools.
- Relevant certifications such as CISSP, CISM, CISA, CCSP, CRISC, Security+, or identity-focused certifications.
- Experience in highly regulated environments such as financial services, healthcare, government, or critical infrastructure. Technical and Governance Skills
- Identity governance for human, privileged, service, machine, and AI-agent identities
- Role-based, attribute-based, and policy-based access control models
- Privileged access management and just-in-time access patterns
- Security logging, auditability, identity analytics, and access anomaly detection
- AI agent risk assessment, control mapping, and governance framework development
- Security policy development, standard operating procedures, and control evidence management
- Cross-functional collaboration with AI engineering, enterprise architecture, cybersecurity operations, compliance, and risk teams

Success Measures
- AI agents are inventoried, classified, assigned accountable owners, and governed through approved lifecycle processes.
- Agentic AI access is provisioned according to least privilege, reviewed regularly, and revoked promptly when no longer required.
- High-risk AI agent actions are observable, logged, auditable, and mapped to accountable human oversight.
- Control gaps, policy exceptions, and residual risks are documented, prioritized, and remediated within agreed timelines.
- Stakeholders have transparent, actionable reporting on Agentic AI identity governance posture, risks, and remediation progress.

📌 Information Security Analyst (Toronto)
🏢 IS3 Solutions
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: information security analyst (toronto) / toronto