Senior Information Security Analyst

Haventree Bank

Toronto

On-site

CAD 110,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Professional development

Job summary

Haventree Bank, headquartered in Toronto, seeks a Senior Information Security Analyst to advance security operations, threat detection, and incident response across cloud, endpoints, and identity ecosystems. You will design detection use cases, coordinate with MSSPs, and lead phishing simulations while shaping the bank's risk posture.

You will also develop training programs, oversee vulnerability management, and report security metrics to leadership, supporting regulatory expectations and data

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • 5+ years of information security, security operations, threat detection or related roles.
  • Hands-on experience investigating security events across multiple domains.
  • Proven ability to develop, tune, and validate detections in SIEM/EDR/XDR.
  • Strong knowledge of cloud and SaaS security, including Microsoft 365 and Azure.

Responsibilities

  • Monitor, investigate, and respond to security alerts and incidents across cloud, endpoint, identity, email, and network.
  • Act as escalation point for complex investigations; analyze attack patterns and business impact.
  • Collaborate with MSSP and internal teams for detection and response alignment.
  • Perform proactive threat hunting to identify undetected activity.
  • Develop and tune detection use cases aligned to MITRE ATT&CK.
  • Support security platforms (SIEM, EDR/XDR, CNAPP, identity).
  • Coordinate vulnerability management including remediation tracking and reporting.
  • Design phishing simulations and analyze results for leadership reports.
  • Deliver security awareness training and measure program effectiveness.
  • Conduct security reviews for systems, projects, and vendors.
  • Expand data protection efforts including data classification and DLP.
  • Develop operational metrics, runbooks, and improve security visibility.

Skills

Security operations
Threat detection
Incident response
Threat hunting
MITRE ATT&CK
Cloud security
IAM concepts
Scripting (PowerShell/Python)
Documentation & reporting

Education

Bachelor's degree in Computer Science, Information Security, or related field

Tools

SIEM
EDR/XDR
CNAPP
Azure
Microsoft 365 security
Sentinel/Defender/Entra ID

Job description

Haventree Bank is a private Canadian Schedule 1 bank specializing in alternative mortgage programs and insured GIC deposits. We help hardworking Canadians from coast-to-coast achieve homeownership by offering flexible mortgage solutions. Our insured GIC deposits offer competitive rates and are available through a variety of wealth management platforms.

About Haventree Bank

Headquartered in Toronto, Ontario, Haventree Bank (Haventree) is a mission‑driven alternative mortgage lender. The name Haventree is representative of the bank’s mission to help its customers find a place of refuge and to lay down new roots for the future. Haventree exists to be a catalyst of financial security and upward mobility for Canadians who are underserved by the traditional financial system.

Position Summary

Reporting to the Director, Information Security, the Senior Information Security Analyst plays a key role in advancing the Bank's security operations and strengthening its ability to detect, respond to, and mitigate evolving threats. This role combines hands‑on technical execution with broader contributions to the Bank's security programs and overall risk posture.

Major Duties & Responsibilities
  • Monitor, investigate, and coordinate response to security alerts and incidents across cloud, endpoint, identity, email, and network environments
  • Act as an escalation point for complex investigations, analyzing attack patterns, scope, and potential business impact
  • Collaborate with MSSP and internal teams to ensure effective detection, response, and operational alignment
  • Perform proactive threat hunting to identify suspicious or malicious activity not detected through standard alerting
  • Develop, tune, and maintain detection use cases aligned to attacker tactics and frameworks such as MITRE ATT&CK
  • Support and enhance the effectiveness of security platforms (e.g., SIEM, EDR/XDR, CNAPP, and identity)
  • Coordinate vulnerability management activities, including prioritization, remediation tracking, and risk reporting
  • Design and execute comprehensive phishing simulation campaigns to assess organizational security awareness. Analyze campaign results and create detailed reports for management and board presentations.
  • Manage and deliver security awareness training programs for employees, focusing on regulatory compliance, social engineering threats, and secure handling of financial data. Track completion rates and assess program effectiveness.
  • Conduct security reviews for systems, projects, and vendors to ensure alignment with security requirements and regulatory expectations
  • Expand and mature data protection initiatives, including alignment with data classification and DLP controls
  • Develop and maintain operational metrics, reporting, and runbooks to improve visibility, consistency, and response effectiveness
  • Stay up to date on information security trends and industry best practice approaches
Degrees, Diplomas & Certifications
  • Bachelor’s degree in Computer Science, Information Security, or a related field
Relevant Industry Certifications (Asset)
  • CompTIA Security+ or CySA+
  • GIAC (e.g., GCIH, GCIA)
  • Microsoft Certified: Azure Security Engineer Associate (or equivalent M365 security certifications)
  • Certified Cloud Security Professional (CCSP) or similar cloud-focused certification
Years and Range of Experience Required
  • 5+ years of progressive experience in information security, security operations, threat detection, incident response, or related cybersecurity roles
  • Hands‑on background investigating security events and incidents across multiple security domains
  • Proven ability to develop, tune, and validate detections in SIEM, EDR/XDR, or related security platforms
  • Strong working knowledge of cloud and SaaS security, including Microsoft 365 and Azure (Sentinel, Defender, Entra ID); exposure to AWS or GCP is considered an asset
  • Practical understanding of identity and access management (IAM) concepts, including user access reviews, privileged access management, or identity governance platforms
  • Demonstrated involvement in vulnerability management programs, security assessments, and operational security reporting
  • Familiarity with threat intelligence concepts, indicators of compromise (IOCs), and threat landscape monitoring
  • Proficiency in scripting (e.g., PowerShell, KQL, Python) for automation, detection development, or log analysis is considered an asset
  • Background working with MSSPs, managed detection and response providers, or external security partners is considered an asset
  • Exposure to regulated industries (e.g., financial services, banking) is considered an asset

Haventree Bank embraces equal opportunity, diversity, and inclusion. Please let us know if you require any accommodations during the recruitment and selection process by contacting accessibility@haventreebank.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Fraud Risk Management
Manager, Fraud Risk Management

Haventree Bank • Toronto

On-site
CAD 80,000 - 100,000
Senior Manager Operational Risk Management
Senior Manager Operational Risk Management

Haventree Bank • Toronto

On-site
CAD 110,000 - 150,000
Senior Software Engineer – Full Stack
Senior Software Engineer – Full Stack

Haventree Bank • Toronto

On-site
CAD 90,000 - 120,000
Accountant
Accountant

Haventree Bank • Toronto

On-site
CAD 70,000 - 90,000
Client Accounts Specialist
Client Accounts Specialist

Haventree Bank • Calgary

On-site
CAD 45,000 - 60,000
Technical Lead
Technical Lead

Haventree Bank • Toronto

On-site
CAD 120,000 - 180,000
Client Accounts Specialist
Client Accounts Specialist

Haventree Bank • Calgary

On-site
CAD 45,000 - 60,000
Technical Lead
Technical Lead

Haventree Bank • Calgary

On-site
CAD 100,000 - 130,000
Senior Cloud Security Engineer, Information Security
Senior Cloud Security Engineer, Information Security

Peoples Group • Calgary

Hybrid
CAD 140,000 - 190,000
Hybrid work environment
Profit sharing
RRSP matching
+2
Senior Cloud Security Engineer, Information Security
Senior Cloud Security Engineer, Information Security

Peoples Group • Toronto

Hybrid
CAD 140,000 - 180,000