General InformationPress space or enter keys to toggle section visibility
Job Location Date Published 10-Aug-2026
Department Information Technology
Employment Type Permanent
Working Arrangement Hybrid
Role Type Full-Time
Job DescriptionPress space or enter keys to toggle section visibility
Reporting to the IT Security Manager, the Data Security Analyst plays a key role in protecting the organization's sensitive information. The primary objective of this position is to improve data visibility, reduce exposure risks, detect suspicious behaviors, and support data governance practices across Pomerleau and its subsidiaries.
The successful candidate will monitor data-related activities, investigate security incidents, support access governance initiatives, and work closely with Security, Infrastructure, Identity, and Governance teams to maintain a secure and compliant environment.
This role offers the opportunity to make a direct impact on the organization's data security posture through strategic initiatives, monitoring, analysis, and continuous improvement efforts.
What you will do
• Monitor alerts and suspicious activities related to sensitive data.
• Analyze anomalous behavior, risky access patterns, and permission changes.
• Identify data exposure or exfiltration risks and recommend corrective actions.
• Participate in investigations involving security incidents, unauthorized access, and data loss events.
• Support data governance, classification, and access review initiatives.
• Produce reports, dashboards, and metrics related to the organization's data security posture.
• Assist with compliance requirements and audit activities.
• Continuously improve detection rules, alerts, and data security practices.
• Collaborate with IT, Security, Infrastructure, Identity, and Governance teams to strengthen security controls.
This role could be for you if you have
• Minimum of 5 years of experience in IT Security, Data Governance, or Security Operations.
• Experience working with data security and data governance platforms.
• Strong understanding of NTFS permissions, SharePoint, OneDrive, Active Directory, and Azure AD.
• Knowledge of Microsoft 365, SIEM environments, and incident response processes.
• Experience investigating data- or access-related security incidents.
• Strong analytical, problem-solving, and organizational skills.
• Excellent communication skills with the ability to explain technical concepts to non-technical audiences.
• Strong attention to detail, accountability, and ability to manage multiple priorities.
• Eligibility to obtain a Government of Canada Secret Security Clearance.
Assets
• Experience with Varonis or a similar data security platform.
• Degree in Information Technology, Cybersecurity, or a related field.
• Experience working in cloud environments (Azure, AWS, or GCP).
• Knowledge of ITIL practices.
• Security certifications (CISSP, CISM, CEH, Security+, etc.).
• Experience with SIEM technologies.
Benefits• RRSP with up to 5% employer matching
• Hybrid work model for corporate roles
• Employee stock ownership program
• Career growth through real development opportunities
• Transit pass reimbursement - get to work for free
• Minimum 4 weeks of vacation from day one