Description
Current work authorization for Canada is required for all openings.
You will be working on a Hybrid office schedule as part of Fidelity’s dynamic working arrangement.
At Fidelity, we’ve been helping Canadian investors build better financial futures for over 35 years. We offer individuals and institutions a range of trusted investment portfolios and services - and we’re constantly seeking to find new and better ways to help our clients. As a privately owned company, we boldly embrace innovation in all areas as we continue to grow our business into the future.
Working with us means you’ll be part of a diverse and dedicated group of people who make a real difference for our clients and communities every day. You’ll have a wide range of opportunities to grow and develop your career in an inclusive environment where you’ll feel valued and supported to be your best - both personally and professionally.
Business Overview :
The Information Security Analyst supports the risk mitigation efforts of the Information Security group primarily through the technical support of the procedures and policies established to safeguard information assets.
What You Will Do :
- Ensure the development life cycle complies with the information security policy requirements on secure coding and secure access controls.
- Tests for compliance with security policies and procedures. May assist in the creation, implementation, and / or management of security solutions.
- Ensure the information security policy requirements are communicated and taken into account by internal Infrastructure & development teams as well as third party vendors.
- Perform vulnerability analysis and issues management in pre-production and production applications & systems using standard application vulnerability scanning tools.
- Review and challenge any changes proposed to application controls including, but not limited to, data encryption, user security profiles / bands and entitlements as well as input, processing and output controls such as edit checks, control totals and data validation / integrity checks.
- Assist with assessment and integration of cloud vendors and SaaS from an Information Security requirements perspective.
- Review and update application security information and documentation in our asset registry.
- Conduct External Security Reviews on Fidelity vendors who have access to confidential information or perform critical functions.
- Assist in monitoring Fidelity’s Data Loss Prevention (DLP) tool and conduct investigations.
- Assist in conducting Security Training & Awareness.
- Provide assistance for Disaster Recovery (DR) team including support of DR tests.
The Expertise You Bring :
2-3 years of relevant experience in financial services industryBachelors in Information Technology, Computer Science or a related discipline or equivalent working experienceKnowledge of vulnerability assessments, secure code and infrastructure security reviews for internal and external facing (web) applicationsKnowledge of SDLC methodologies and tools. Development background is highly desirableKnowledge of secure access modeling, threat modeling, digital security methodologies and deployments, and security architectureUnderstanding of Cloud Security and capabilities of Amazon, Microsoft Azure etc.Understanding of industry audit standards, i.e. SSAE-16, FFIEC, and PCI-DSSStrong interpersonal skills like being a team player and effective collaborator with many different types of audiencesAbility to multitask and handle multiple projectsStrong presentation and written skillsNice to have :
Knowledge of Fortify, Veracode, Checkmarks, Appscan, ServiceNowCISSP and Cloud Security certificationSome of the ways we’ll help you feel valued and supported as part of our team :
Flexible working arrangements - 100% remote, hybrid, and in office optionsCompetitive total compensation, including company contributions to your group RRSP without a matching requirement from youComprehensive health benefits that start on your first day, with 100% employer-paid premiums, that include up to $5000 annually for mental health services and therapyParental leave top-up to 100% of your salary for a period of 25 weeksUp to $650 for home office equipmentGenerous time off policy, including 2 paid days annually to volunteer at a charity of your choiceDiversity and inclusion programs, including an active network of Employee Resource GroupsExtensive professional development opportunities, including access to over 11,000 training and development courses, tuition reimbursement, and monetary rewards for completing a required designationWe care a lot about fostering a compassionate, people-centric culture, and are proud to have been named one of Canada’s Top 100 employers for the last five years.