Search jobs > Toronto, ON > It security analyst

IT Senior Security Analyst

Alterna
Toronto, ON
$26,92-$40,53 an hour (estimated)
Full-time

Scope of Position

This role is key in the identification of risks and threats, protection of information and assets, detection and monitoring of events and anomalies, and response to and recovery from, cyber events.

The successful candidate will also play a key role in the implementation of new security solutions, maintenance of various security tools and technologies.

The IT Senior Security Analyst is expected to be fully aware of the enterprise's security goals and to actively work to support these goals.

Major Responsibilities

  • Participate in strategic and tactical planning for IT Security to drive standards and architecture elements of the security program
  • Maintain up-to-date baselines for the secure configuration and operations of all in-place devices, including Firewall, IPS, Application Control, web filtering, Messaging Gateway, SIEM, DLP, IAM and Endpoint Protection
  • Monitor server logs, firewall logs, intrusion detection logs, web filtering, and antiviral systems for security events or threats.

Investigate security breaches and other cyber security incidents

  • Perform tests and uncover network vulnerabilities and misconfiguration, track and monitor the remediation activities
  • Demonstrate expertise in the planning and design of enterprise security architecture and create and maintain inventory of security technology
  • Lead third party review of technology systems including the existing and upcoming cloud services
  • Perform risk and control design assessments of infrastructure and systems as well as cloud-based solutions. Recommend remedial actions, and work with system owners and business partners to develop plans and timelines to address risks
  • Develop and / or implementation of standards, policies, procedures, and security solutions
  • Recommend and implement improvements to security tools, configurations, processes and policies, and research additional security solutions or enhancements to improve overall security posture
  • Demonstrate expertise in the design and execution of vulnerability assessments, penetration tests and security audits
  • Help implement and enhance Threat Modelling capability with SDLC and application development efforts
  • Develop on-going technology risk reporting, monitoring key trends and defining metrics to measure control effectiveness
  • Conduct BIA's and DR planning. Ensure DR configurations are updated to reflect production environment
  • Stay up to date knowledge of security threats and new leading-edge technology

Qualifications

Education / Certifications / Experience

  • Post-secondary diploma or degree in the field of computer science
  • Minimum 5-7 years of practical experience and demonstrated ability to carry out the functions of the job
  • Relevant security certification such as CISSP, CCSP, Security+, CEH, CompTIA Security, etc.
  • Understanding of security standards and frameworks such as ISO27001, NIST and CIS, etc.
  • Strong knowledge of technical configurations from various operating systems and security solutions (Windows, Linux, VMware, IDS / IPSDLP, VCM, SIEM, WAF, VPNs, EPP, encryption, etc.)
  • Demonstrated experience in security architecture for both applications and infrastructure
  • Excellent problem-solving and analytical skills to identify and resolve security issues effectively
  • Strong understanding of cloud security concepts and experience securing cloud-based infrastructure is an asset
  • Proven project management and organizational skills, specifically managing multiple, concurrent projects

Competencies

  • Critical thinking skills
  • Detail oriented
  • Well developed troubleshooting,
  • Analytical and problem-solving skills
  • Ability to communicate effectively, both orally and in writing with a variety of audiences
  • Self motivated and directed
  • Team oriented and experience working within a collaborative environment

Work Conditions

  • Overtime may be required to meet project deadlines
  • On-Call on rotation

Working at Alterna

Alterna offers a fast-paced, impactful work experience in an organization that cares about doing good. For over 110 years, Alterna has been creating financial services that transform lives for the better, all while giving back to our community.

We are incredibly proud of our corporate culture, where everyone works together towards a common goal, the financial wellbeing of our members and customers.

This commitment has earned us several prestigious employer awards, including the National Capital Region's Top Employers award for seven years running.

  • Although we appreciate all applicants, preference will be given to candidates who most closely meet the qualifications, key skills, and competencies outlined above.
  • Alterna is compliant with the Ontarians with Disabilities Act. If you have a disability, please contact the recruiter to let us know how we can accommodate you
  • 30+ days ago
Related jobs
RBC - Royal Bank
Toronto, Ontario

As a Senior Cyber Security Analyst in the Identity Access Management (IAM) Team, you will work with the IAM Application Onboarding Team to integrate RBC applications onto IAM solutions ( Entra ID (Azure), Sailpoint IIQ, CyberArk, etc). Confidentiality, Cyber Security Management, Decision Making, Det...

Vidyard
Remote, Canada
Remote

The Senior Security Analyst will be a pivotal role on the IT & Security team, and will lend their experience and mentorship expertise in secure software development and secure Engineering practices to the rest of the team, navigating exciting and new technology, and leveling up Vidyard’s posture and...

Scotiabank
Toronto, Ontario

You take pride in managing a critical portfolio of vendors and managing strategic dependencies and complexities with a focus on optimizing costs, risks, and benefits. You enjoy scheduling regular validation and updates of key ITAM data structures, including entitlements, deployments, catalogues, arc...

Law Society of Ontario
Toronto, Ontario

We are committed to creating an accessible, barrier-free and inclusive workplace and are committed to continuing compliance with the Accessibility for Ontarians with Disabilities Act (AODA). The Senior IT Endpoint Analyst is responsible for taking a leading role in the research, planning, implementa...

S.i. Systems
Toronto, Ontario

Senior Business Analyst with PAM/IAM experience to improve solutions for enhanced security measures to adhere to PCI 4. Work with various stakeholders and technical teams to identify gaps on proposed solutions to enhance security, control deficiencies and compliance to audit and regulatory expectati...

Manulife
Toronto, Ontario

We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin,colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy...

Sterling Crane Canada
Remote, Canada
Remote

The Senior Manager, IT Infrastructure and Security - Global will play a critical role in ensuring the stability, security, and scalability of the infrastructure and security environment for the organization, while providing technical leadership, people management, and strategic guidance to a global ...

Intact Financial Corporation
Mississauga, Ontario

You have our commitment to support you in reaching your goals with tools, opportunities, and flexibility. Collaborate with Business Data teams, security, internal and external audit stakeholders. IT Business Analyst experienced in the SAS IFRS17 Solution and Insurance Financial Reporting. Insurance ...

TEEMA Group Solutions
Las Vegas, NV, CA

Familiarity with network security practices and protocols. Self-starter with strong information security principles. Capability to assess security threats effectively. Experience: 4 – 8 years in a relevant security analyst role. ...

RBC - Royal Bank
Toronto, Ontario

The IT Risk & Control Senior Analyst will perform risk-based testing activities that independently evaluate the design and effectiveness of controls and further assist with the enhancement and execution of the first line of defense Internal Control Testing and Monitoring for Architecture, Infrastruc...