Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Senior Security Analyst protecting Trillium Health Partners’ healthcare systems through cyber defense, identity management, and Microsoft 365 security. Supporting incident response, risk management, and secure AI adoption.

Responsibilities

  • Identify and report information security risks, threats, vulnerabilities, and breaches and recommend remediation opportunities
  • Develop, implement, and maintain information security governance, policies, procedures, and controls
  • Support information security strategic and operating plans
  • Implement best-practice security architecture procedures across application development, operations, and infrastructure
  • Support continuous delivery of day-to-day information security and privacy operations
  • Ensure 7x24 monitoring and security incident response capability
  • Lead or commission forensic analysis on security incidents
  • Lead vulnerability assessments, penetration tests, risk assessments, and security and privacy audits
  • Develop materials and promote information security awareness across the organization
  • Ensure projects and programs incorporate appropriate information security considerations
  • Determine minimum security requirements for applications and systems
  • Monitor security industry trends, emerging threats, attacks, and threat vectors
  • Evaluate new technologies and make security impact recommendations
  • Lead technical implementations of security-related systems
  • Administer, monitor, and improve Microsoft 365 security capabilities
  • Perform security monitoring, triage, investigation, threat hunting, detection engineering, and incident response
  • Support secure adoption and governance of AI, automation, and AI-enabled productivity or development tools
  • Review and validate IT controls and assess related deficiencies
  • Maintain current documentation and materials
  • Manage vendor relationships
  • Collaborate with technical teams, business stakeholders, clinical partners, vendors, and leaders to reduce organizational risk and enable secure technology adoption
  • Report to the Manager, Cyber Defense & Identity Access Management

Requirements

  • 3+ years of Information Security experience with expertise in client/server, network or application security engineering
  • Direct working experience performing IT security and risk assessments and audits
  • Hands-on experience with Microsoft 365 security and identity platforms, including Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Intune, Conditional Access, multi-factor authentication, data loss prevention, audit logging, and secure configuration management
  • Experience evaluating security risks associated with cloud services, SaaS platforms, automation, artificial intelligence, generative AI tools, and enterprise data or identity integrations
  • Working knowledge of NIST CSF and ISO 2700 standards
  • Working knowledge of COBIT or PCI auditing frameworks
  • Experience interpreting industry and regulatory requirements and authoring supporting controls
  • Strong business and technical acumen
  • Excellent written and verbal communication skills
  • Identity and access management experience with Active Directory, NTFS permissions, LDAP, and SSO solutions
  • Experience developing and maturing information security governance frameworks
  • Experience performing application penetration testing
  • Application and database security experience, including code reviews
  • Network and security engineering experience, including log and network traffic capture analysis
  • Strong understanding of network protocols such as IP and TCP/IP
  • Familiarity with Windows, Linux, and UNIX operating systems
  • Familiarity with application development processes and application architectures
  • Familiarity with encryption concepts
  • Experience with system hardening procedures for Windows, Linux, and UNIX platforms
  • Security operations experience with firewalls, IDS/IPS, SIEM, and endpoint protection platforms
  • Experience with Microsoft security and compliance portals and related tools
  • Ability to use KQL, advanced hunting, analytics rules, dashboards, automation playbooks, and incident workflows
  • Working knowledge of AI security, responsible AI governance, generative AI data protection, secure prompt/output handling, and AI vendor risk review
  • Familiarity with .NET web application development and client-side applications for mobile platforms
  • Familiarity with Oracle and MS SQL database technologies
  • Experience with Business Continuity Plans and Disaster Recovery Plans
  • Familiarity with ITIL and TOGAF concepts
  • Undergraduate degree in Information Management, Computer Science, Engineering, technology, or a related field
  • Ability to communicate with internal/external customers, vendors, and management
  • Ability to work independently, prioritize competing priorities, meet deadlines, and work under pressure

Benefits

  • Permanent full-time employment
  • Hybrid work arrangement
  • After-hours on-call work required
  • Accommodation throughout the recruitment and selection process for applicants with disabilities
  • Equal opportunity employer committed to antiracism, diversity, equity and inclusion

Job title

Job type

Full Time

Experience level

Senior

Salary

CA$38 - CA$48 per hour

Degree requirement

Bachelor's Degree

Tech skills

CloudFirewallsLinuxOracleSQLTCP/IPUnix.NET

Location requirements

HybridMississaugaCanada

Report this job

Found something wrong with the page? Please let us know by submitting a report below.