Information Security Analyst strengthening GRC, risk management, and cybersecurity controls for EllisDon’s construction services. Supporting audits, vendor compliance, security awareness, and control remediation.
Responsibilities
Support identification, assessment, and tracking of IT/cyber risks
Maintain the enterprise risk register and remediation lifecycle
Perform risk assessments for systems, projects, and vendors
Support ongoing third-party compliance activities
Contribute to GRC program operations, including policies, standards, procedures, exception tracking, and evidence workflows
Support remediation of risks, control gaps, and audit findings across teams
Partner with IT Service Delivery, Operations, and DevOps to enable secure system and solution implementation
Support the security awareness program, including training, reporting, and threat simulations involving phishing, social engineering, and AI-driven attacks
Support compliance across SOC 2, NIST, ISO 27001, and CMMC / CPCSC / ITSP
Contribute to GRC initiatives involving risk maturity, audit readiness, vendor compliance, and standardization of security requirements
Requirements
2–5 years of experience in Information Security, Cybersecurity, Governance, Risk & Compliance (GRC), IT Risk Management, or related disciplines
Cyber Security Co - op analyzing threats, data, and intelligence for RBC, Canada’s largest bank. Supporting detection, threat hunting, reporting, and security knowledge management.
Own AI governance and security strategy at the Alberta Energy Regulator, defining decision rights and the AI Register. Partner with security and data governance teams to ensure safe, secure AI use across a multi - vendor estate.
Analyste en sécurité des produits chez Alithya, intégrant la sécurité de l’information aux projets technologiques. Évaluation des risques, recommandations et suivi des mesures de sécurité.
Intermediate SOC Analyst monitoring and responding to security incidents for Long View, a North American IT provider. Managing SIEM tools, cloud environments, escalations, and 24x7 operations.
Azure AD Security Analyst leading identity and access management for Intact, a Canadian insurer. Integrating Azure AD, supporting IAM architecture, automation, privileged access, and major incidents.
Analyste sécurité informatique chez Beneva, compagnie d’assurance et de services financiers. Intégration des contrôles IAM, analyse des exigences de sécurité et accompagnement des équipes applicatives.