Senior cybersecurity analyst securing AI technologies and Microsoft 365 services for Trillium Health Partners’ community hospitals. Managing governance, threat detection, incident response, and cloud security controls.
Responsibilities
Develop and maintain security policies, standards, and governance frameworks for secure AI adoption and AI-enabled business applications
Conduct security assessments and risk analyses of Generative AI, Agentic AI, LLM, SaaS, and internally developed AI solutions
Evaluate AI vendors and third-party AI services for security, privacy, and regulatory compliance
Define and implement data classification, DLP, access control, and information protection controls
Research and monitor AI-driven cyber threats, attack techniques, and threat actor activity
Develop AI-threat detection and response use cases in SIEM, XDR, and security monitoring platforms
Monitor and investigate security alerts and incidents involving AI platforms, Microsoft 365, cloud services, applications, identities, and cloud resources
Participate in incident response, root cause analysis, containment, eradication, recovery, vulnerability management, and remediation
Participate in after-hours Security Operation Support on-call rotation
Conduct threat modeling, security reviews, architecture assessments, configuration reviews, testing, and continuous control monitoring
Support Zero Trust implementation across Microsoft 365 and AI environments
Provide employee guidance and training on secure AI tools, Microsoft Copilot, and cloud collaboration services
Secure Microsoft 365 services including Entra ID, Defender for Endpoint, Purview, Intune, Teams, Exchange Online, SharePoint Online, OneDrive, and Copilot
Implement and maintain Conditional Access, MFA, Identity Protection, PIM, DLP, sensitivity labels, Insider Risk Management, compliance, and retention policies
Monitor Microsoft 365 security posture and recommend remediation actions
Conduct security reviews of Microsoft Copilot and AI-enabled Microsoft 365 services
Apply Microsoft Copilot for Security to enable faster cybersecurity incident detection, investigation, and response
Requirements
Minimum 5 years of work experience in information security in a regulated industry, preferably health care
Experience in cloud security, identity security, security operations, or risk management
Familiarity with government and industry information security regulations
University degree in Information Security, Computer Science, Information Technology, or a related discipline
Hands-on experience securing Microsoft 365 and Microsoft Security technologies
Experience assessing cybersecurity risks associated with cloud services, SaaS platforms, and emerging technologies
Strong knowledge of Microsoft 365 Security and Compliance capabilities, Microsoft Entra ID, Microsoft Defender Security Suite, Microsoft Purview, Microsoft Intune, Conditional Access, Identity Security, DLP, SIEM, XDR, cloud security principles, and Zero Trust architecture
Understanding of Generative AI platforms, LLM technologies, AI security risks and threat models, AI governance frameworks, secure AI implementation practices, threat intelligence, and cyber threat analysis
Familiarity with PowerShell, Python, or similar scripting and automation tools
Knowledge of NIST CSF, NIST AI RMF, ISO 27001, ISO 42001, CIS Critical Security Controls, Zero Trust principles, MITRE ATT&CK, Microsoft Secure Future Initiative principles, and privacy/data protection regulations
CISSP or equivalent industry certification is an advantage; listed Microsoft, CISSP, CCSP, AI security, and cloud security certifications are preferred or assets
Benefits
Permanent full-time employment
Monday to Friday, 9:00 AM to 5:00 PM
Equal opportunity employer
Accommodations throughout the recruitment and selection process
Antiracism, diversity, equity and inclusion practices
Data Advisor advancing GMF’s Canadian municipal sustainability funding through dashboards, data systems, and program evaluation. Supporting risk monitoring, information systems, and continuous improvement.
Turnaround and recovery advisor managing distressed loans, bad debt and guarantees for Desjardins. Developing recovery strategies, analyzing data and advising clients and partners.
Wealth Management Advisor guiding Desjardins members and business owners on investments, loans, and insurance. Building client relationships and integrated financial strategies.
Wealth Management Advisor helping Desjardins members and business owners achieve financial goals. Recommending integrated investment, lending, and insurance strategies.
Wealth Management Advisor helping Desjardins members and clients with financial planning, investments, financing, and insurance. Managing relationships and developing integrated strategies.
Senior business advisor developing strategic client partnerships and growth initiatives for Desjardins. Advising members, clients, and stakeholders while driving retention, profitability, and sales - service development.
Warranty advisor managing registrations, pricing, reconciliations, and customer support for Finning Canada’s equipment operations. Partnering with sales teams and Caterpillar across Alberta, British Columbia, and Saskatchewan.