Talent.com
Lumentum
Senior IT Security AnalystLumentum • Ottawa, Canada
Senior IT Security Analyst

Senior IT Security Analyst

Lumentum • Ottawa, Canada
5 days ago
Salary
CA$80,000.00 yearly
Job type
  • Full-time
Job description

It's fun to work in a company where people truly BELIEVE in what they're doing!


Lumentum Canada was awarded the 2022 National Capital Region’s Top Employers and the 2022 Career Directory Canada’s Best Employers for Recent Graduates .

Position Title: Senior IT Security Analyst

Employment Type: Full-time, Existing vacancy

Location: Ottawa (On-Site)

About Lumentum

At Lumentum, we’re building the tech behind the world’s fastest networks and most advanced systems. Our optical and photonic solutions power everything from AI and cloud computing to data centers, telecom, and advanced manufacturing.

We’re a global team of innovators working where light meets technology, solving big challenges that keep the world connected and moving forward. If shaping the future of connectivity excites you, you’ll fit right in.

Why You’ll Love This Role

At Lumentum, we are searching for Canada’s brightest young minds engineers and innovators who want to build the next generation of optical technology. If you are driven by curiosity, eager to solve real-world challenges, and excited about developing groundbreaking optical systems, this is your opportunity.

Join us in designing the future of optical cloud & networking technology our advanced photonic modules power the world’s voice and internet traffic, and we need your expertise to take them to the next level. This is not just another job; this is your chance to define & design what’s next in photonics.

What You’ll Be Doing

The postholder provides advanced technical security analysis, leads complex investigations, improves the maturity of security controls and advises stakeholders on cyber risk. The role combines hands-on security operations with control ownership, specialist guidance, assurance and continual improvement.

Role scope and level

  • Senior technical practitioner with authority to lead complex operational security work within agreed governance.
  • Responsible for risk-based recommendations, improvement of procedures and subject-matter advice for incidents, vulnerabilities, identity controls, data protection and security tooling.
  • Expected to coach colleagues, influence technical teams and translate threat, control and risk information into clear management updates.
  • Focuses on control maturity, assurance quality, repeatable processes and measurable reduction of cyber security risk.

Key responsibilities

1. Security operations leadership

  • Lead complex security investigations across endpoint, network, identity, email, cloud and application data sources.
  • Define triage criteria, alert handling standards, escalation paths and quality checks for security operations.
  • Review high-impact alerts and incidents, ensure proportional response and remove barriers to containment and remediation.
  • Develop and improve detection logic, playbooks, dashboards and operational procedures.

2. Incident response leadership

  • Coordinate response to significant cyber security incidents in line with the incident management process.
  • Lead technical analysis for malware, phishing, credential compromise, insider risk, data exposure, privilege misuse and suspicious network activity.
  • Ensure evidence handling, incident timelines, decisions, lessons learned and remediation actions are complete and auditable.
  • Produce post-incident reviews and track corrective actions through to closure.

3. Risk, governance and assurance

  • Translate technical findings into risk statements, control weaknesses and prioritised remediation plans.
  • Support risk assessment, risk acceptance, audit and assurance activity with clear evidence and professional judgement.
  • Advise on relevant information security legislation.
  • Contribute to security standards, control testing, supplier assurance and management reporting.

4. Data Loss Prevention and Multi-Factor Authentication control ownership

  • Own or act as technical lead for Data Loss Prevention (DLP) monitoring, rule tuning, alert quality, exception handling and escalation.
  • Own or act as technical lead for Multi-Factor Authentication (MFA) control performance, exception governance, break-glass account checks, privileged access enforcement and conditional access design.
  • Analyse Data Loss Prevention (DLP) and Multi-Factor Authentication (MFA) trends to identify control gaps, user behaviour issues, data handling risks and improvement opportunities.
  • Ensure control documentation, operating procedures and evidence packs are complete, current and aligned to policy.

5. Vulnerability, threat and configuration management

  • Lead vulnerability prioritisation using exploitability, asset criticality, exposure and business impact.
  • Challenge and support remediation plans for high-risk vulnerabilities, insecure configurations and unsupported systems.
  • Develop recurring reporting on vulnerability trends, control gaps and remediation performance.
  • Use threat intelligence to improve detection, hardening and risk prioritisation.

6. Security architecture and technical assurance

  • Review proposed changes, projects and new services for security risks and control requirements.
  • Advise on secure design for identity, endpoint, network, cloud, logging, data protection and resilience controls.
  • Validate that logging, monitoring, access control, encryption, backup and recovery requirements are included in project delivery.
  • Recommend improvements to security tooling and integration, including automation where proportionate.

7. Metrics, reporting and continual improvement

  • Produce clear management information on incidents, vulnerabilities, Data Loss Prevention (DLP), Multi-Factor Authentication (MFA), control exceptions, detection coverage and remediation performance.
  • Define Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) for security operations and control assurance.
  • Identify process inefficiencies, repeat incidents and control weaknesses, then lead improvement actions.
  • Maintain a forward view of emerging threats, technology changes and relevant good practice.

8. Leadership, coaching and stakeholder management

  • Coach colleagues on investigation quality, evidence standards, tooling, communication and risk-based decision-making.
  • Provide clear guidance to infrastructure, application, cloud, data protection, service desk and business teams.
  • Present security findings, risks and recommendations to technical and non-technical stakeholders.
  • Promote a constructive security culture focused on proportionate risk management and business enablement.

What We’re Looking For

Education:

  • Relevant professional certification is desirable, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA) or equivalent.
  • A degree, apprenticeship or professional training in cyber security, information security, computer science or a related discipline is desirable but not essential where equivalent experience can be demonstrated.

Experience:
The ideal candidate will have:

  • Typically, five or more years in cyber security operations, incident response, security engineering, assurance, infrastructure security or a comparable environment, or equivalent demonstrable experience.
  • Experience leading complex investigations, coordinating stakeholders, improving controls and presenting risk-based recommendations.

Skills:

Essential technical skills

  • Advanced security investigation using Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), endpoint protection, identity, email, web, network and cloud data.
  • Strong Data Loss Prevention (DLP) policy design, tuning, investigation and exception management.
  • Strong Multi-Factor Authentication (MFA) implementation, exception governance, conditional access and privileged access control.
  • Vulnerability management, secure configuration assessment and remediation prioritisation.
  • Incident command, evidence handling, root cause analysis and post-incident review.
  • Security architecture assurance for identity, endpoint, network, cloud, application and data protection controls.
  • Detection engineering and automation using scripts, queries or workflow tools where appropriate.
  • Understanding of control frameworks and standards, including the National Cyber Security Centre (NCSC) Cyber Assessment Framework (CAF), National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF), Center for Internet Security (CIS) Critical Security Controls and International Organization for Standardization and International Electrotechnical Commission (ISO/IEC) 27001.

Essential knowledge

  • Cyber security risk governance, control design and assurance principles.
  • Advanced incident response, including evidence preservation, decision logging, containment strategy and recovery planning.
  • Threat-informed defence, including common attack tactics, techniques, procedures and defensive control mapping.
  • Identity and access control principles, including privileged access, conditional access, authentication assurance and access recertification.
  • Data handling, information classification, privacy considerations and insider risk indicators.
  • Secure architecture principles for cloud, endpoint, network, application, logging and resilience controls.

Behavioural skills

  • Sound judgement, professional integrity and commitment to confidentiality.
  • Ability to prioritise under pressure and make proportionate, risk-based recommendations.
  • Strong written and verbal communication with the ability to explain complex issues clearly.
  • Constructive leadership style that develops capability and supports collaboration across technical and business teams.
  • Commitment to continual improvement and practical security outcomes.

Measures of success

  • Complex incidents are led effectively, with clear decisions, defensible evidence and timely corrective actions.
  • Security controls are improved through tuning, process enhancement, automation and measurable risk reduction.
  • Data Loss Prevention (DLP) and Multi-Factor Authentication (MFA) control performance is visible, governed and aligned to policy.
  • High-risk vulnerabilities and configuration weaknesses are prioritised and remediated using a risk-based approach.
  • Management reporting is clear, accurate and useful for decision-making.
  • Colleagues and stakeholders receive credible guidance that improves security capability and confidence.

Perks You’ll Love

  • Flexible time off
  • Health and wellness benefits (physical and mental)
  • Tuition reimbursement and career growth support
  • A workplace built for you: free gym, games room, prayer room
  • Subsidized meals, free coffee/tea
  • Employee stock options and incentive plans
  • A collaborative, innovative, and inclusive culture

Salary Range: $80,000 - $115,000 CAD (flexible).

Final compensation will be determined based on factors such as experience, skills, and qualifications. In line with our commitment to being a great place to work, Lumentum offers competitive total rewards which may include annual bonus, equity, and comprehensive health and welfare benefits.

Join a Team That’s Shaping the Future

At Lumentum, we’re more than just a workplace—we’re a launchpad for creativity and innovation. We’re committed to celebrating your unique talents and helping you grow. Our guiding principles—Innovate, Engage, Deliver, Excel, and Win—aren’t just words; they’re the heart of what we do.

Let’s Build a Brighter Future Together!

We’re committed to building an inclusive workplace where everyone feels valued and empowered. We welcome applicants from all backgrounds and provide accommodations for individuals with disabilities throughout the hiring process. Your uniqueness makes us stronger, sparks creativity, and drives our success.

Join us—your future starts here!

Create a job alert for this search

Senior IT Security Analyst • Ottawa, Canada

Similar jobs

Cyber Security Analyst

Searidge TechnologiesOttawa, ON, CA
Temporary

Fixed-Term Contract (6-months).Searidge Technologies is a global leader in the Air Traffic Control space, boldly forging new paths bringing innovative technology, such as Artificial Intelligence (A... Show more

 • Promoted

Principal Security Analyst - Remote

CyderesOttawa, ON, CA
Remote
Full-time

Be among the first 25 applicants.Cyderes (Cyber Defense and Response) is a pure-play, full life-cycle cybersecurity services provider with award-winning managed security services, identity and acce... Show more

 • Promoted

Senior Security Engineer Focused on Detection and Response Frameworks

1PasswordOttawa, ON, CA
Full-time

Join as a Senior Security Engineer to strengthen detection and incident response frameworks.Lead initiatives that optimize security measures and enhance organizational resilience in a remote enviro... Show more

 • Promoted

IT Security Risk Analyst

Onico SolutionsOttawa, ON, CA
Permanent

The IT Security Risk Analyst supports the Information Security Risk Management and Governance programs.They work with technology and business stakeholders to identify Information Security risks, co... Show more

 • Promoted

IT Security Threat & Risk Assessment (TRA) Analyst

ADGA GroupOttawa, ON, CA
Full-time

IT Security Threat & Risk Assessment (TRA) Analyst.Senior role on the Strategic Radio Capability project (Option Analysis and Definition phases) supporting radio frequency communications systems.AD... Show more

 • Promoted

Cyber Security Analyst

Brookfield RenewableGatineau, QC, CA
Full-time

Get AI-powered advice on this job and more exclusive features.Direct message the job poster from Brookfield Renewable.Talent Acquisition Coordinator, Brookfield Renewable | MBA | B.Brookfield Renew... Show more

 • Promoted

Senior Security Engineer Enhancing Product Integrity and Safety

AffirmOttawa, ON, CA
Full-time

Become a pivotal force in product security as a Senior Product Security Engineer.Engage in cross-functional collaboration to improve the security of innovative financial products in a remote role.T... Show more

 • Promoted

Senior IT Security Design Specialist

Adga-Groupottawa, on, Canada
Full-time

Compensation: CAD 110 - CAD 120 - hourly.ADGA Group is a Canadian‑owned defence and security company that provides integrated, mission‑critical technical solutions to Government and industry, speci... Show more

 • Promoted

Senior IT and security Administrator – Malware Protection Specialist

act digitalOttawa, ON, CA
Full-time

Senior IT and security Administrator – Malware Protection Specialist.ALTER SOLUTIONS is a consulting and technology expertise company founded in 2006.Our mission is to support our clients with thei... Show more

 • Promoted

Senior IT Compliance & Audit Lead — Remote

P2POttawa, ON, CA
Remote
Full-time

A leading crypto firm is seeking a senior IT audit professional.This fully remote role emphasizes managing SOC examinations and establishing audit rigor.Ideal candidates will have over 5 years of e... Show more

 • Promoted

Senior IT Security Computer Support Specialist

49 SolutionsOttawa, ON, CA
Full-time

Senior IT Security Computer Support Specialist.Department of National Defence (DND).Secret (minimum), Top Secret preferred.Senior IT Security Technical Support Specialists.These resources will prov... Show more

 • Promoted

Remote IT Security Risk Analyst: Governance & Risk

Onico SolutionsOttawa, ON, CA
Remote
Permanent

A leading IT security firm in Richmond Hill is looking for an IT Security Risk Analyst to support their Information Security Risk Management programs.The role requires expertise in risk assessments... Show more

 • Promoted

Cyber Security Analyst

ArsenaultOttawa, ON, CA
Full-time

The Cybersecurity Analyst supports the risk mitigation efforts of our clients' Cyber Defense Operations (CDO) under the Information Security and Technology Risk group in order to safeguard and prot... Show more

 • Promoted

IT Security Analyst

Farm Boy Inc.Ottawa, ON, CA
Full-time

At Farm Boy, it is our mission to create a fun, fresh experience for all! Whether you are a team member or a customer, Farm Boy is passionate about creating a unique fresh food shopping experience ... Show more

 • Promoted

IT & Security Professional at Senstar

SenstarOttawa, ON, CA
Full-time

Advance your career with Senstar as an IT & Security Professional, where you will ensure IT operations security in a hybrid work setting.As an integral part of Senstar, you will handle the daily op... Show more

 • Promoted

IT & Security Specialist

Senstar CorporationOttawa, ON, CA
Full-time

Senstar is a global leader in advanced perimeter intrusion detection and video management solutions.For over 40 years, we have protected critical infrastructure, national borders, and high‑value as... Show more

 • Promoted

Manager, Security & IT

KnakOttawa, ON, CA
Full-time

The Role: Team Lead, Security & Compliance.As Team Lead, Security & Compliance at Knak, you’ll lead the programs that keep our platform, customers, and company secure.This is a hands‑on leadership ... Show more

 • Promoted

Senior Analyst, Security Compliance

P2POttawa, ON, CA
Full-time

Our Krakenites are a world-class team with crypto conviction, united by our desire to discover and unlock the potential of crypto and blockchain technology.Kraken is a mission-focused company roote... Show more

 • Promoted

Senior IT Security TRA Analyst — Ottawa Focused Risk

ADGA GroupOttawa
Full-time

A Canadian defence and security technology firm is seeking a Senior IT Security Threat & Risk Assessment (TRA) Analyst in Ottawa.Responsibilities include reviewing IT Security policies, conducting ... Show more

 • Promoted

Remote Information Risk & Security Analyst

DexianOttawa, ON, CA
Remote
Full-time

A leading IT services firm is seeking an Information Control Testing Specialist to manage information risk and ensure compliance with security policies.You will work on global initiatives, conduct ... Show more