8/26/26
Apply now
- Start applying with LinkedIn
- Apply Now
Start
- Please wait...
Job Type: Permanent
Work Model: Remote
Reference code: 134786
Primary Location: Toronto, ON
All Available Locations: Toronto, ON; Calgary, AB; Halifax, NS; Kitchener, ON; Ottawa, ON
What will your typical day look like?As an Analyst within the Business Information Security area, you'll work closely with both technical and non-technical stakeholders within an assigned line of business or technology enablement area providing the best possible support across a range of cybersecurity, risk, and risk mitigation disciplines. Along with having knowledge of industry-accepted best practices, the Analyst is expected to ensure that all applications and systems aligned to their line of business adhere to internal cybersecurity policies, standards, escalating any non-compliance up to the associated Business Information Security Officer (BISO). Successful candidates should showcase the capability to effectively influence and cultivate robust relationships with diverse stakeholders.
This role is responsible for overseeing the security posture and continual compliance of their assigned business/technology area's applications by ensuring security is embedded from the start and that all associated development security procedures are followed, with appropriate security evaluations and testing process completed. Responsibilities will span from briefing teams on new cybersecurity priorities, to discussing risks and vulnerabilities (e.g., penetration testing, code scanning, etc., infrastructure patch/configuration, end of life software, TLS configurations, etc.), and controls compliance (e.g., service account compliance, firewall rule base compliance, key and certificate management, security agent health, etc.).
Responsibilities include:
- Understand their assigned global line of business, gain familiarity with priorities and become an advocate for them within cybersecurity.
- Work with multiple parties within their assigned service lines and the organization to help effect change and improve cybersecurity health/hygiene.
- Oversee the implementation of application security controls to ensure teams remain compliant with Deloitte cybersecurity standards.
- Process any risk-based matters / exceptions in accordance with Deloitte Technology's strict policies and procedures.
- Support the Secure Systems Development Lifecycle (SSDLC), including functional and non-functional cybersecurity requirements.
- Strive for process improvement and automation; help development and operations team build automation for repeatable Cyber related vulnerability management activities.
- Maintain awareness of evolving application security threats and inform development, business, and risk stakeholders.
- Provide application-specific security subject matter expertise to assigned customers.
- Evaluate the likelihood and impact of application vulnerabilities; develop and drive mitigation approaches.
- Lead, coach, and mentor project teams to incorporate security into enterprise and client-facing applications.
About the teamDeloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in "what is" but rather "what can be" to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.
Enough about us, let's talk about youRequired:- At least 3 years of related experience, including cybersecurity and/or risk management experience in organizations of a similar scale or client-service experience in the field.
- Demonstrated ability to work with multiple teams, business units within a large organization to effect change.
- Exceptional verbal and written communication skills. Must be able to interact effectively with professionals at all levels and communicate recommendations with diplomacy and tact.
- Experience with cloud security principles and functions.
- Solid capabilities across multiple security domains such as identity and access management (IAM), public-key encryption, security information and event management (SIEM), incident response, threat & vulnerability management
Preferred:- Familiarity with SOC 2 principles; experience in application security to meet SOC 2 requirements
- Experience in a fast-moving workplace, covering diverse areas such as software development, security architecture, application security risks and vulnerabilities
- Proven organizational skills, and understanding / experience of cybersecurity policies and procedures, ideally within a governance risk and compliance function
- Experience with Agile practices, SCRUM, Microsoft SDL, and STRIDE
Total RewardsThe salary range for this position is $69,000 - $114,000, and individuals may be eligible to participate in our bonus program. Deloitte is fair and competitive when it comes to the salaries of our people. We regularly benchmark across a variety of positions, industries, sectors, targets, and levels. Our approach is grounded on recognizing people's unique strengths and contributions and rewarding the value that they deliver.
Our Total Rewards Package extends well beyond traditional compensation and benefit programs and is designed to recognize employee contributions, encourage personal wellness, and support firm growth. Along with a competitive base salary and variable pay opportunities, we offer a wide array of initiatives that differentiate us as a people-first organization. On top of our regular paid vacation days, some examples include: $4,000 per year for mental health support benefits, a $1,300 flexible benefit spending account, firm-wide closures known as "Deloitte Days", dedicated days of for learning (known as Development and Innovation Days), flexible work arrangements and a hybrid work structure.