Information Security Analyst conducting audits and managing IT security risks for EllisDon. Supporting compliance activities and contributing to GRC program initiatives.
Responsibilities
Conduct IT audits, collect and validate evidence to support GRC program and audit readiness
Support identification, assessment, and tracking of IT/cyber risks; maintain the enterprise risk register and remediation lifecycle
Perform risk assessments for systems, projects, and vendors; support ongoing third-party compliance activities
Contribute to GRC program operations (policies, standards, procedures, exception tracking, evidence workflows)
Support remediation of risks, control gaps, and audit findings across teams
Partner with IT (Service Delivery, Operations, DevOps) to enable secure system and solution implementation
Support security awareness program, including training, reporting, and modern threat simulations (phishing, social engineering, AI-driven attacks)
Support compliance across SOC 2, NIST, ISO 27001, and CMMC / CPCSC / ITSP, ensuring consistent control implementation
Contribute to key GRC initiatives, including risk maturity, audit readiness, vendor compliance, and standardization of security requirements across the organization
Requirements
Strong interpersonal, oral, and written communication skills
Post-secondary education in IT, Information/Cyber Security, or relevant experience
Experience in Information/Cyber Security, GRC, or Risk Management
Hands-on experience supporting risk assessments, audits, compliance, or vendor reviews
Strong analytical and technical problem-solving skills
Ability to work independently, self-start, and quickly learn new tools and systems
Industry certifications (e.g., CISSP, CEH, CISA, Security+) considered an asset
Working knowledge of NIST Cybersecurity Frameworks
Familiarity with industry standards (CIS, SOC2 Type II, ISO) and CMMC / CPCSC or similar frameworks
IT Security Analyst II coordinating cybersecurity monitoring, MSP oversight, audits, and incident follow - up. Supporting Veristat’s global life - sciences services and regulated technology environments.
Security Analyst protecting GitLab’s DevSecOps platform through vulnerability triage and CVE operations. Coordinating researchers, customers, and internal teams on secure software response.
SIEM/SOAR cybersecurity analyst monitoring threats, building alerts, and measuring controls. Supporting Wepoint’s digital transformation work for businesses and public sector organizations.
SIEM/SOAR information security analyst supporting Wepoint’s digital transformation services. Developing cybersecurity monitoring cases, alerts, dashboards, and security - control documentation.
Security Analyst II protecting Intact’s insurance operations through incident response and SIEM monitoring. Supporting security platforms, incident resolution, dashboards, and IT security initiatives.
Lead AI risk analyst securing CBC/Radio - Canada’s public - service media technology. Designing enterprise AI governance, risk assessments and adversarial testing across the AI lifecycle.