Information Security Analyst 3

Canada Life

Toronto

On-site

CAD 105,000 - 130,000

Full time

20 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Education reimbursement
Health benefits
Volunteer day
Pension plan
Employee discounts
ERGs and mentoring

Job summary

Canada Life in Toronto is seeking an Information Security Analyst III to partner with IT and business teams to identify, assess, and manage information security risks across projects. You will provide security consultation, conduct threat modeling and risk assessments, review controls, and guide remediation to protect confidential information.

Candidates should have 5+ years in information security, security certifications preferred (CISSP, CISM, CISA).

Qualifications

  • Minimum of five years in Information Security or Information Technology with strong risk management experience.
  • Professional security certifications such as CISSP, CCSP, CISM, CISA, CRISC are preferred.
  • Strong knowledge of security principles, standards, and best practices.
  • Experience with cloud security in Azure and AWS is required.

Responsibilities

  • Provide security consultation and advisory services to business and IT stakeholders.
  • Identify, assess, and implement security controls across project lifecycles.
  • Conduct risk assessments, threat modeling, TRAs, and security reviews.
  • Analyze findings from SAST/DAST/SCA, provide remediation guidance.
  • Collaborate with lines of business to deliver risk-based solutions.
  • Promote security awareness and effective stakeholder engagement.

Skills

Information security
Risk management
Threat modeling
Cloud security
Azure
AWS
NIST CSF
ISO 27001/27002
SIEM
Communication

Education

Bachelor's degree in a related field

Tools

SAST
DAST
SCA
Penetration Testing
IDS/IPS
WAF
SIEM tools

Job description

Permanent Full Time

The Information Security Analyst III role is within the Project Security team, partnering with Information Technology and business stakeholders to identify, assess, and manage information security risks while ensuring compliance with organizational security policies, standards, and regulatory requirements. This role delivers security services across Canada Life projects, including security consultation, threat and risk assessments, threat modeling, and security control reviews to help ensure secure project delivery and effective risk management. Reporting to the Manager, Project Security, within the Information Security and Technology Risk (ISTR) group.

What You Will Do:
  • Provide information security consultation and advisory services to business and IT stakeholders.
  • Partner with project teams and technology stakeholders to identify, assess, and implement appropriate security controls throughout the project lifecycle.
  • Ensure the safeguarding and protection of Canada Life's confidential information by helping prevent unauthorized disclosure, modification, destruction, or misuse of information assets.
  • Conduct information security risk assessments, including Threat Modeling, Threat Risk Assessments (TRAs), security reviews, and other risk-based evaluations.
  • Research emerging threats, vulnerabilities, attack techniques, and industry trends, providing recommendations to mitigate organizational risk.
  • Develop and conduct security and risk assessments and document findings, recommendations, and remediation activities.
  • Review risk assessment and reports, identify security weaknesses, and assist stakeholders in prioritizing remediation activities based on risk.
  • Provide recommendations on findings from:
    • Static Application Security Testing (SAST)
    • Dynamic Application Security Testing (DAST)
    • Software Composition Analysis (SCA)
    • Penetration Testing
    • Infrastructure and Endpoint Vulnerability Assessments
  • Collaborate across Line of Business to solve complex security challenges and develop practical, risk-based solutions.
  • Maintain a customer-focused and delivery-oriented approach, driving positive outcomes in dynamic and ambiguous environments.
  • Work proactively with internal clients to understand business objectives and provide effective security guidance.
  • Promote continuous learning, knowledge sharing, and security awareness while positively influencing stakeholders and peers.
What You Will Bring:
  • Post-secondary degree in Business, Technology, Cybersecurity, Computer Science, or a related discipline, or an equivalent combination of education and experience.
  • Minimum of five (5) years or more of experience in Information Security and/or Information Technology, with significant experience in Information Security Risk Management.
  • Professional security certifications such as CISSP, CCSP, CISM, CISA, CRISC, or equivalent are preferred.
  • Strong knowledge of information security principles, risk management methodologies, security protocols, industry standards, and best practices.
  • Extensive experience performing security assessments and evaluating threat vectors, vulnerabilities, and compensating controls.
  • Strong technical background across multiple technology domains, including networking, servers, cloud computing, application development, enterprise architecture, and infrastructure.
  • Knowledge of security technologies and capabilities, including:
    • Threat Modeling and Threat Risk assessment
    • Encryption and key management
    • Network and Web Application Firewalls (WAF)
    • Intrusion Detection and Prevention Systems (IDS/IPS)
    • Advanced Malware Protection
    • Distributed Denial-of-Service (DDoS) protections
    • Data Loss Prevention (DLP)
    • Security Information and Event Management (SIEM)
  • Strong knowledge of cloud security principles and cloud platforms, particularly Microsoft Azure and AWS.
  • Working knowledge of cybersecurity frameworks, risk assessment methodologies, threat modeling frameworks, and security control standards, including NIST Cybersecurity Framework (CSF) 2.0, ISO 27001/27002, CIS, SOC 2, CSA, MITRE ATT&CK, OWASP Top 10, STRIDE, DREAD, and related industry standards and best practices.
  • Familiarity with IT audit, compliance, and security testing processes.
  • Knowledge of emerging AI technology including associated risks and controls.
  • Excellent communication, stakeholder management, presentation, negotiation, and consensus-building skills.
  • Demonstrated ability to work independently, think strategically, manage competing priorities, and deliver on commitments with minimal supervision.

The base salary for this position is between $105,000 - $130,000 annually. This represents base salary only and does not represent other variable compensation components of our total compensation ( i.e. annual bonus, commission etc). If you are selected to move forward in our recruitment process, your recruiter will be able to discuss additional details of our total rewards program with you.

Career opportunities will be open a minimum of 5 business days from the date of posting, closing dates will vary depending on the search activity. All applications received will be reviewed on a rolling basis.

Grow with Canada Life

We’re united by a shared purpose: to improve the financial, physical and mental well-being of Canadians. Our company is trusted by 1 in 3 Canadians and contributes to the strength of communities across the country.

We’re looking for people who live our values everyday: we step up, we do the right thing, and we deliver – for our customers, communities and each other. Are you someone who always strives to do the right thing, who steps up for themselves and others, and who delivers with impact? Then we want to hear from you!

What we offer
  • Career Development: Opportunities for career advancement, access to industry-leading learning programs and up to$2,000 annually towards education reimbursement.
  • Health & Wellness:Flexible health and dental benefits, plus a $5,000 mental health benefit to support your well-being.
  • Time Off:In addition to regular vacation and personal days, we support community involvement with a volunteer day.
  • Financial Security:Company-matching pension plan,share ownership program and additionalinvestment options.
  • Rewards and Recognition: Employee recognition programs, service milestone celebrations, employee discounts and more!
  • Emphasis on Community: We provide a workplace where employees feel connected and supported through Employee Resource Groups (ERGs), mentorship programs, social clubs and events.

Learn more about Canada Life.

We’re committed to removing barriers and ensuring equal access to employment. Applicants requiring reasonable accommodation during the application process may contact talentacquisitioncanada@canadalife.com. All information provided will be handled in accordance with applicable laws and Canada Life policies.

Canada Life would like to thank all applicants, however only those who qualify for an interview will be contacted.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst 3
Information Security Analyst 3

Canada Life • Winnipeg

On-site
CAD 105,000 - 130,000
Career development
Health & Wellness benefits
Time off and volunteer day
+1
Consulting Infrastructure Specialist
Consulting Infrastructure Specialist

Canada Life • Winnipeg

On-site
CAD 120,000 - 170,000
Health and dental benefits
Mental health benefit
Volunteer day
+2
Consulting Infrastructure Specialist
Consulting Infrastructure Specialist

Canada Life • Toronto

On-site
CAD 120,000 - 170,000
Education reimbursement up to $2,000
Mental health benefit $5,000
Volunteer day
+2
ISEMC (SOC) Analyst
ISEMC (SOC) Analyst

Canada Life • Winnipeg

On-site
CAD 69,000 - 91,000
Data Analyst
Data Analyst

Canada Life • Winnipeg

Hybrid
CAD 66,000 - 110,000
Career Development
Health & Wellness
Time Off
+3
DAM Engineering Specialist
DAM Engineering Specialist

Canada Life • London

On-site
CAD 85,000 - 135,000
Career Development
Health & Wellness
Time Off
+3
DAM Engineering Specialist
DAM Engineering Specialist

Canada Life • Toronto

On-site
CAD 85,000 - 135,000
Education reimbursement up to $2,000
Mental health benefit up to $5,000
Volunteer day
+2
DAM Engineering Specialist
DAM Engineering Specialist

Canada Life • Winnipeg

On-site
CAD 85,000 - 135,000
Education reimbursement up to $2,000/​
Mental health benefit up to $5,000
Volunteer day
+2
Senior Analyst Strategy
Senior Analyst Strategy

Canada Life • Toronto

Hybrid
CAD 80,000 - 130,000
Career Development
Health & Wellness
Time Off
+3
Senior IT Business Systems Analyst
Senior IT Business Systems Analyst

Canada Life • London

On-site
CAD 90,000 - 115,000
Career development reimbursement
Health & Wellness benefits
Volunteer day
+1