Information Security Analyst

EllisDon Corporation

Mississauga

Hybrid

CAD 66,000 - 80,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

EllisDon Corporation in Mississauga seeks an Information Security Analyst to help manage IT risk, governance, and compliance within a growing construction services firm. You will perform risk assessments, track remediation, and partner with IT teams to strengthen security controls and awareness programs.

The role supports SOC 2, NIST, ISO 27001, and CMMC/CPCSC practices, with a salary range of CAD 66,000–80,000.

Qualifications

  • 2–5 years in Information Security, GRC or related disciplines.
  • Experience with risk assessments, security reviews, vendor evaluations.
  • Strong risk-based decision making and control evaluation.
  • Ability to identify practical mitigations and business-aligned improvements.
  • Interest in developing expertise across multiple GRC disciplines.
  • Experience building security programs and improving GRC processes.
  • Ability to work independently and influence stakeholders.
  • Excellent written and verbal communication.
  • Post-secondary IT/Cybersecurity education or equivalent.
  • Industry certs like Security+, CISSP, CISA, CRISC are assets.
  • Knowledge of NIST CSF, ISO 27001, SOC 2, CIS Controls, CMMC, CPCSC.

Responsibilities

  • Support identification, assessment, and tracking of IT/cyber risks; maintain the enterprise risk register and remediation lifecycle.
  • Perform risk assessments for systems, projects, and vendors; support ongoing third-party compliance activities.
  • Contribute to GRC program operations (policies, standards, procedures, exception tracking, evidence workflows).
  • Support remediation of risks, control gaps, and audit findings across teams.
  • Partner with IT (Service Delivery, Operations, DevOps) to enable secure system and solution implementation.
  • Support security awareness program, including training, reporting, and modern threat simulations (phishing, social engineering, AI-driven attacks).
  • Support compliance across SOC 2, NIST, ISO 27001, and CMMC / CPCSC / ITSP, ensuring consistent control implementation.
  • Contribute to key GRC initiatives, including risk maturity, audit readiness, vendor compliance, and standardization of security requirements across the organization.

Skills

Information Security
GRC
Risk assessment
Vendor evaluations
Security controls
Communication

Education

IT/Cybersecurity degree

Tools

NIST CSF
ISO 27001
SOC 2
CIS Controls
CMMC
CPCSC

Job description

Connect with us LinkedIn, Instagram, Facebook, Twitter. Thinking about a change? We recognize that the construction industry is changing at a rapid pace and we continually strive to be at the forefront. Our core values empower people to deliver great careers to one another and develop creative solutions for complex problems on some of the most exciting projects. It doesn’t matter what your expertise and craft is – there are no boundaries. We are a group of professionals with a variety of expertise within pre-construction, construction, and post-construction. To learn more, check out our Cradle to Grave services and hear from our team directly about what a career at EllisDon could look like for you. As you can see, we are a diverse bunch. Above all, we are a group of individuals with unique experiences and at EllisDon, we choose to celebrate the strength in our differences, every day. EllisDon’s commitment to Inclusive Diversity is to work together to create an environment where every employee feels safe to be their true and authentic self. Ultimately, EllisDon’s purpose is to provide people with similar values the opportunity to achieve to their full potential; to deliver that opportunity for great careers to one another; and to contribute meaningfully to the community we share with others. In case you’re curious, here’s what the industry thinks of us and some of the impacts we've made to the communities we work in and our latest Impact Report, highlighting how we're putting our values into practice in areas such as the climate & environment, inclusive diversity, indigenous relations, and health and safety.

This role is ideal for a cybersecurity professional looking to expand into GRC or a GRC practitioner who enjoys building and improving security processes, programs, and controls in a growing environment.

You as an Information Security Analyst will:
  • Support identification, assessment, and tracking of IT/cyber risks; maintain the enterprise risk register and remediation lifecycle
  • Perform risk assessments for systems, projects, and vendors; support ongoing third-party compliance activities
  • Contribute to GRC program operations (policies, standards, procedures, exception tracking, evidence workflows)
  • Support remediation of risks, control gaps, and audit findings across teams
  • Partner with IT (Service Delivery, Operations, DevOps) to enable secure system and solution implementation
  • Support security awareness program, including training, reporting, and modern threat simulations (phishing, social engineering, AI-driven attacks)
  • Support compliance across SOC 2, NIST, ISO 27001, and CMMC / CPCSC / ITSP, ensuring consistent control implementation
  • Contribute to key GRC initiatives, including risk maturity, audit readiness, vendor compliance, and standardization of security requirements across the organization
This is the right role for you, if you have:
  • 2–5 years of experience in Information Security, Cybersecurity, Governance, Risk & Compliance (GRC), IT Risk Management, or related disciplines.
  • Experience performing assessments including security reviews, risk assessments, vendor evaluations, compliance activities, or governance functions.
  • Strong security foundation with a risk‑based approach to decision‑making and the ability to evaluate security controls effectively.
  • Ability to identify practical mitigation by assessing control gaps and recommending realistic, business‑aligned improvements.
  • Demonstrated interest in GRC and applying security concepts through a business‑focused, risk‑driven lens; interest in developing expertise across multiple GRC disciplines.
  • Experience contributing to program maturity including the development, implementation, or enhancement of security and GRC processes, programs, or initiatives.
  • Ability to work independently while influencing stakeholders across technical and non‑technical teams.
  • Strong analytical and critical thinking skills with the ability to evaluate controls, identify gaps, and propose actionable improvements.
  • Effective communication skills with the ability to articulate risks and recommendations to diverse audiences.
  • Strong interpersonal, verbal, and written communication skills.
  • Self‑motivated with strong prioritization skills and the ability to drive initiatives forward.
  • Post‑secondary education in IT, Cybersecurity, Information Security, or a related field, or equivalent experience.
  • Industry certifications such as Security+, CISSP, CISA, CRISC, or similar are considered an asset.
  • Working knowledge of security frameworks such as NIST CSF, ISO 27001, SOC 2, CIS Controls, CMMC, CPCSC, or similar standards.

The salary range for this role is $66,000 - $80,000.

EllisDon is proud to provide this unique career opportunity that provides continuous learning, opportunity for growth, and a competitive compensation package within an environment that is committed to inclusion and respects diversity. Go ahead and be yourself. We'll pay you for it!

We are an equal opportunity employer. We welcome people of any age, culture, subculture, gender identity or expression, sexual orientation, nationality, ethnicity, race, size, mental or physical status, veteran status, religion, language, political opinion, working-style preference, family status, education, and socio-economic status. The EllisDon core values of Integrity and Mutual Respect welcomes everyone, at work and in the community, and our value of Mutual Accountability, means that we all have a role to play. As an EllisDon employee, this will ultimately be your commitment to Inclusive Diversity. Accommodation for Applicants with disabilities will be made during the recruitment process when requested. We are committed to providing a positive candidate experience and ensuring timely updates are provided to all candidates.

EllisDon uses AI tools to assist in screening and assessing applicants for this position. Our people are at the heart of everything we do. From our employees to clients, subcontractors, partners, and our considerable network of contacts, building strong, resilient relationships is the key to our success. We build on great relationships We pride ourselves on being great people to work with. Guided by our shared values of trust, complete openness, and mutual respect and accountability, we’ve built a construction services company known for our people and integrity. We exist to provide great careers to one another With us you can expect to continually evolve your career, benefitting from mentorship at every level and working collaboratively with other teams to expand your knowledge and experience. Values-based leadership. EllisDon’s culture and approach to business is a reflection of our core values and principles: freedom, trust, complete openness, mutual accountability, entrepreneurial enthusiasm, integrity and mutual respect.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst - Secure Projects
Information Security Analyst - Secure Projects

EllisDon Corporation • Canada

On-site
CAD 80,000 - 100,000
Information Security Analyst - Secure Projects
Information Security Analyst - Secure Projects

J EllisDon Corporation • Mississauga

On-site
CAD 80,000 - 100,000
Competitive compensation package
Inclusive diversity and equal-opportun
Career learning and growth
Secure Infrastructure Analyst
Secure Infrastructure Analyst

J EllisDon Corporation • Mississauga

On-site
CAD 100,000 - 130,000
Secure Infrastructure Analyst
Secure Infrastructure Analyst

EllisDon Corporation • Mississauga

Hybrid
CAD 100,000 - 130,000
Information Security Analyst - Secure Projects
Information Security Analyst - Secure Projects

EllisDon • Calgary

On-site
CAD 80,000 - 100,000
Secure Infrastructure Analyst
Secure Infrastructure Analyst

EllisDon • Mississauga

On-site
CAD 100,000 - 130,000
Secure Infrastructure Analyst
Secure Infrastructure Analyst

Socket.dev • Mississauga

On-site
CAD 100,000 - 130,000
Information Security Analyst - Secure Projects
Information Security Analyst - Secure Projects

EllisDon • Mississauga

On-site
CAD 80,000 - 100,000
Sr. DevSecOps Analyst
Sr. DevSecOps Analyst

EllisDon • Mississauga

On-site
CAD 110,000 - 160,000
Sr. DevSecOps Analyst
Sr. DevSecOps Analyst

EllisDon Corporation • Mississauga

Hybrid
CAD 110,000 - 160,000
Equal opportunity employer
AI screening tools used in recruiting
Mentorship and career growth