Information Security Analyst 3

Canada Life

Winnipeg

On-site

CAD 105,000 - 130,000

Full time

24 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Career development
Health & Wellness benefits
Time off and volunteer day
Pension and share options

Job summary

Canada Life seeks an Information Security Analyst III to partner with IT and business stakeholders, delivering risk-based security guidance across projects in Canada. You will conduct risk assessments, threat modeling, and security reviews, while advising on SAST/DAST/SCA, encryption, WAF, IDS/IPS, and DLP controls to safeguard confidential information.

You will collaborate with cross-functional teams, stay current on threats, and promote security awareness while enabling secure project

Qualifications

  • Post-secondary degree in Business, Technology, Cybersecurity, Computer Science, or related discipline.
  • Minimum of five (5) years of experience in Information Security/IT with risk management focus.
  • Professional security certifications such as CISSP, CCSP, CISM, CISA, CRISC preferred.
  • Strong knowledge of information security principles, risk management methodologies, and best practices.
  • Extensive experience performing security assessments and evaluating threats and controls.
  • Cloud security knowledge in Microsoft Azure and AWS.
  • Familiarity with NIST CSF 2.0, ISO 27001/27002, CIS, SOC 2, CSA, MITRE ATT&CK, OWASP Top 10.

Responsibilities

  • Provide information security consultation to business and IT stakeholders.
  • Identify, assess, and implement security controls across project lifecycles.
  • Assist in safeguarding confidential information and preventing data loss.
  • Conduct risk assessments including TRA, threat modeling, and security reviews.
  • Research threats and industry trends to mitigate organizational risk.
  • Document findings and remediation activities for stakeholders.
  • Review security reports and help prioritize remediation by risk.
  • Provide guidance on SAST/DAST/SCA/Penetration testing and related controls.

Skills

Information security
Risk management
Security assessments
Cloud security
Communication
Independent work
Threat modeling
Threat risk assessment
Regulatory compliance

Education

Post-secondary degree in Business/Technology/Cybersecurity/CS

Tools

SAST
DAST
SCA
Penetration Testing
IDS/IPS
WAF

Job description

Permanent Full Time

The Information Security Analyst III role is within the Project Security team, partnering with Information Technology and business stakeholders to identify, assess, and manage information security risks while ensuring compliance with organizational security policies, standards, and regulatory requirements. This role delivers security services across Canada Life projects, including security consultation, threat and risk assessments, threat modeling, and security control reviews to help ensure secure project delivery and effective risk management. Reporting to the Manager, Project Security, within the Information Security and Technology Risk (ISTR) group.

What You Will Do:
  • Provide information security consultation and advisory services to business and IT stakeholders.
  • Partner with project teams and technology stakeholders to identify, assess, and implement appropriate security controls throughout the project lifecycle.
  • Ensure the safeguarding and protection of Canada Life's confidential information by helping prevent unauthorized disclosure, modification, destruction, or misuse of information assets.
  • Conduct information security risk assessments, including Threat Modeling, Threat Risk Assessments (TRAs), security reviews, and other risk-based evaluations.
  • Research emerging threats, vulnerabilities, attack techniques, and industry trends, providing recommendations to mitigate organizational risk.
  • Develop and conduct security and risk assessments and document findings, recommendations, and remediation activities.
  • Review risk assessment and reports, identify security weaknesses, and assist stakeholders in prioritizing remediation activities based on risk.
  • Provide recommendations on findings from:
    • Static Application Security Testing (SAST)
    • Dynamic Application Security Testing (DAST)
    • Software Composition Analysis (SCA)
    • Penetration Testing
    • Infrastructure and Endpoint Vulnerability Assessments
  • Collaborate across Line of Business to solve complex security challenges and develop practical, risk-based solutions.
  • Maintain a customer-focused and delivery-oriented approach, driving positive outcomes in dynamic and ambiguous environments.
  • Work proactively with internal clients to understand business objectives and provide effective security guidance.
  • Promote continuous learning, knowledge sharing, and security awareness while positively influencing stakeholders and peers.
What You Will Bring:
  • Post-secondary degree in Business, Technology, Cybersecurity, Computer Science, or a related discipline, or an equivalent combination of education and experience.
  • Minimum of five (5) years or more of experience in Information Security and/or Information Technology, with significant experience in Information Security Risk Management.
  • Professional security certifications such as CISSP, CCSP, CISM, CISA, CRISC, or equivalent are preferred.
  • Strong knowledge of information security principles, risk management methodologies, security protocols, industry standards, and best practices.
  • Extensive experience performing security assessments and evaluating threat vectors, vulnerabilities, and compensating controls.
  • Strong technical background across multiple technology domains, including networking, servers, cloud computing, application development, enterprise architecture, and infrastructure.
  • Knowledge of security technologies and capabilities, including:
    • Threat Modeling and Threat Risk assessment
    • Encryption and key management
    • Network and Web Application Firewalls (WAF)
    • Intrusion Detection and Prevention Systems (IDS/IPS)
    • Advanced Malware Protection
    • Distributed Denial-of-Service (DDoS) protections
    • Data Loss Prevention (DLP)
    • Security Information and Event Management (SIEM)
  • Strong knowledge of cloud security principles and cloud platforms, particularly Microsoft Azure and AWS.
  • Working knowledge of cybersecurity frameworks, risk assessment methodologies, threat modeling frameworks, and security control standards, including NIST Cybersecurity Framework (CSF) 2.0, ISO 27001/27002, CIS, SOC 2, CSA, MITRE ATT&CK, OWASP Top 10, STRIDE, DREAD, and related industry standards and best practices.
  • Familiarity with IT audit, compliance, and security testing processes.
  • Knowledge of emerging AI technology including associated risks and controls.
  • Excellent communication, stakeholder management, presentation, negotiation, and consensus-building skills.
  • Demonstrated ability to work independently, think strategically, manage competing priorities, and deliver on commitments with minimal supervision.

The base salary for this position is between $105,000 - $130,000 annually. This represents base salary only and does not represent other variable compensation components of our total compensation ( i.e. annual bonus, commission etc). If you are selected to move forward in our recruitment process, your recruiter will be able to discuss additional details of our total rewards program with you.

Career opportunities will be open a minimum of 5 business days from the date of posting, closing dates will vary depending on the search activity. All applications received will be reviewed on a rolling basis.

Grow with Canada Life

We’re united by a shared purpose: to improve the financial, physical and mental well-being of Canadians. Our company is trusted by 1 in 3 Canadians and contributes to the strength of communities across the country.

We’re looking for people who live our values everyday: we step up, we do the right thing, and we deliver – for our customers, communities and each other. Are you someone who always strives to do the right thing, who steps up for themselves and others, and who delivers with impact? Then we want to hear from you!

What we offer
  • Career Development: Opportunities for career advancement, access to industry-leading learning programs and up to$2,000 annually towards education reimbursement.
  • Health & Wellness:Flexible health and dental benefits, plus a $5,000 mental health benefit to support your well-being.
  • Time Off:In addition to regular vacation and personal days, we support community involvement with a volunteer day.
  • Financial Security:Company-matching pension plan,share ownership program and additionalinvestment options.
  • Rewards and Recognition: Employee recognition programs, service milestone celebrations, employee discounts and more!
  • Emphasis on Community: We provide a workplace where employees feel connected and supported through Employee Resource Groups (ERGs), mentorship programs, social clubs and events.

Learn more about Canada Life.

We’re committed to removing barriers and ensuring equal access to employment. Applicants requiring reasonable accommodation during the application process may contact talentacquisitioncanada@canadalife.com. All information provided will be handled in accordance with applicable laws and Canada Life policies.

Canada Life would like to thank all applicants, however only those who qualify for an interview will be contacted.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst 3
Information Security Analyst 3

Canada Life • Toronto

On-site
CAD 105,000 - 130,000
Education reimbursement
Health benefits
Volunteer day
+3
Consulting Infrastructure Specialist
Consulting Infrastructure Specialist

Canada Life • Toronto

On-site
CAD 120,000 - 170,000
Education reimbursement up to $2,000
Mental health benefit $5,000
Volunteer day
+2
Consulting Infrastructure Specialist
Consulting Infrastructure Specialist

Canada Life • Winnipeg

On-site
CAD 120,000 - 170,000
Health and dental benefits
Mental health benefit
Volunteer day
+2
ISEMC (SOC) Analyst
ISEMC (SOC) Analyst

Canada Life • Winnipeg

On-site
CAD 69,000 - 91,000
Data Analyst
Data Analyst

Canada Life • Winnipeg

Hybrid
CAD 66,000 - 110,000
Career Development
Health & Wellness
Time Off
+3
DAM Engineering Specialist
DAM Engineering Specialist

Canada Life • Toronto

On-site
CAD 85,000 - 135,000
Education reimbursement up to $2,000
Mental health benefit up to $5,000
Volunteer day
+2
DAM Engineering Specialist
DAM Engineering Specialist

Canada Life • London

On-site
CAD 85,000 - 135,000
Career Development
Health & Wellness
Time Off
+3
DAM Engineering Specialist
DAM Engineering Specialist

Canada Life • Winnipeg

On-site
CAD 85,000 - 135,000
Education reimbursement up to $2,000/​
Mental health benefit up to $5,000
Volunteer day
+2
Senior Analyst Strategy
Senior Analyst Strategy

Canada Life • Toronto

Hybrid
CAD 80,000 - 130,000
Career Development
Health & Wellness
Time Off
+3
Senior IT Business Systems Analyst
Senior IT Business Systems Analyst

Canada Life • London

On-site
CAD 90,000 - 115,000
Career development reimbursement
Health & Wellness benefits
Volunteer day
+1