Information Security Analyst

Posted 21 hours ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Information Security Analyst strengthening GRC, risk management, and cybersecurity controls for EllisDon’s construction services. Supporting audits, vendor compliance, security awareness, and control remediation.

Responsibilities

  • Support identification, assessment, and tracking of IT/cyber risks
  • Maintain the enterprise risk register and remediation lifecycle
  • Perform risk assessments for systems, projects, and vendors
  • Support ongoing third-party compliance activities
  • Contribute to GRC program operations, including policies, standards, procedures, exception tracking, and evidence workflows
  • Support remediation of risks, control gaps, and audit findings across teams
  • Partner with IT Service Delivery, Operations, and DevOps to enable secure system and solution implementation
  • Support the security awareness program, including training, reporting, and threat simulations involving phishing, social engineering, and AI-driven attacks
  • Support compliance across SOC 2, NIST, ISO 27001, and CMMC / CPCSC / ITSP
  • Contribute to GRC initiatives involving risk maturity, audit readiness, vendor compliance, and standardization of security requirements

Requirements

  • 2–5 years of experience in Information Security, Cybersecurity, Governance, Risk & Compliance (GRC), IT Risk Management, or related disciplines
  • Experience performing security reviews, risk assessments, vendor evaluations, compliance activities, or governance functions
  • Strong security foundation with a risk-based approach to decision-making
  • Ability to evaluate security controls effectively
  • Ability to identify practical mitigation and recommend realistic, business-aligned improvements
  • Demonstrated interest in GRC and applying security concepts through a business-focused, risk-driven lens
  • Experience contributing to the development, implementation, or enhancement of security and GRC processes, programs, or initiatives
  • Ability to work independently while influencing technical and non-technical stakeholders
  • Strong analytical and critical thinking skills
  • Effective communication skills for articulating risks and recommendations to diverse audiences
  • Strong interpersonal, verbal, and written communication skills
  • Self-motivated with strong prioritization skills
  • Post-secondary education in IT, Cybersecurity, Information Security, or a related field, or equivalent experience
  • Industry certifications such as Security+, CISSP, CISA, CRISC, or similar are considered an asset
  • Working knowledge of NIST CSF, ISO 27001, SOC 2, CIS Controls, CMMC, CPCSC, or similar standards

Benefits

  • Continuous learning opportunities
  • Opportunity for growth
  • Competitive compensation package
  • Accommodation for applicants with disabilities during the recruitment process
  • Inclusive and respectful work environment

Job type

Full Time

Experience level

JuniorMid level

Salary

CA$66,000 - CA$80,000 per year

Degree requirement

No Education Requirement

Tech skills

Cyber Security

Location requirements

OnsiteLondonCanada

Report this job

Found something wrong with the page? Please let us know by submitting a report below.