We are seeking a senior IT Security Analyst for a permanent full time position. This is a hybrid position requiring 3 days onsite weekly in the Greater London Ontario area.
Key Responsibilities include:
- Carry out information technology security plans and policies
- Guide and advise business units, technology solution delivery, other technology teams and partners on information technology security best practices.
- Identify and assess technology system security requirements at time of procurement, development and implementation of technology projects, identifying risks and implementing controls to mitigate operational risk at launch.
- Recommend, design, develop, test and implement information technology security platforms, tools and controls for on premise and cloud based solutions
- Lead and execute risk treatment remediation plans and tasks
- Lead incident response, including steps to minimize the impact, identifying how a breach happened, the extent of the damage and lessons learned
- Maintain information technology security platforms, tools and controls
- Participate in information technology security control assessments and audits for on premise and cloud based solutions
- Participate in audits of partners, vendors, others in the supply chain and employees focused on determining it they are working within the framework of established policies
- Monitoring regulatory PCI, PIPEDA, internal policy and other compliance
- Support the information technology security awareness training program
- Develop and maintain incident response play books and standard operation procedures
Technical:
- Experience with common information security tools and platforms.
- Experience with information security standards including NIST, CIS, OWASP and CSA.
- Experience with PCI, PIPEDA, CASL and PHIPA standards and regulations.
Strong understanding of information security infrastructure and controls including:
- Iaas, PaaS, SaaS security controls and best practices
- SIEM
- EDR
- EPP
- XDR
- SWG
- CASB
- DLP
- Firewall
- WAF
- IDPS
- Microsegmentation
- VPN
- MFA
- AD, AAD, Windows Conditional Access
- Windows and Linux servers
- Networking protocols
- Virtual environments
Education and Experience:
- Degree or diploma in Information Technology Security or Computer Science
- Minimum of 5 experience developing and implementing technology security standards, controls and best practices
- CISSP or CISM or similar designation is an asset
- CCSP or similar cloud security certification(s) is an asset
Please apply today!