Information Security Analyst 3

Canada Life

$105K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Post-secondary degree in Business, Technology, Cybersecurity, Computer Science, or equivalent experience.
  • Minimum five years of experience in Information Security/Technology, focusing on Risk Management.
  • Professional security certifications preferred (CISSP, CCSP, CISM, CISA, CRISC).
  • Strong knowledge of information security principles and risk management methodologies.
  • Technical expertise in areas such as networking, cloud computing, and application development.
  • Familiarity with security technologies, including DLP and SIEM.
  • Knowledge of cybersecurity frameworks and emerging AI technology risks.

Responsibilities

  • Provide security consultation to business and IT stakeholders.
  • Collaborate with project teams to implement security controls during project lifecycles.
  • Safeguard confidential information against unauthorized access or misuse.
  • Conduct risk assessments and threat modeling evaluations.
  • Research emerging threats and provide risk mitigation recommendations.
  • Develop security assessment reports with findings and remediation plans.
  • Review assessments to identify security weaknesses and prioritize remediation.

Benefits

  • Promotes continuous learning and knowledge sharing.
  • A customer-focused and delivery-oriented work environment.
  • Opportunities for career growth within the organization.
  • Flexible work arrangements with a hybrid model.
Full Job Description
Permanent Full Time

The Information Security Analyst III role is within the Project Security team, partnering with Information Technology and business stakeholders to identify, assess, and manage information security risks while ensuring compliance with organizational security policies, standards, and regulatory requirements. This role delivers security services across Canada Life projects, including security consultation, threat and risk assessments, threat modeling, and security control reviews to help ensure secure project delivery and effective risk management. Reporting to the Manager, Project Security, within the Information Security and Technology Risk (ISTR) group.

What You Will Do:

  • Provide information security consultation and advisory services to business and IT stakeholders.
  • Partner with project teams and technology stakeholders to identify, assess, and implement appropriate security controls throughout the project lifecycle.
  • Ensure the safeguarding and protection of Canada Life's confidential information by helping prevent unauthorized disclosure, modification, destruction, or misuse of information assets.
  • Conduct information security risk assessments, including Threat Modeling, Threat Risk Assessments (TRAs), security reviews, and other risk-based evaluations.
  • Research emerging threats, vulnerabilities, attack techniques, and industry trends, providing recommendations to mitigate organizational risk.
  • Develop and conduct security and risk assessments and document findings, recommendations, and remediation activities.
  • Review risk assessment and reports, identify security weaknesses, and assist stakeholders in prioritizing remediation activities based on risk.
  • Provide recommendations on findings from:
    • Static Application Security Testing (SAST)
    • Dynamic Application Security Testing (DAST)
    • Software Composition Analysis (SCA)
    • Penetration Testing
    • Infrastructure and Endpoint Vulnerability Assessments
  • Collaborate across Line of Business to solve complex security challenges and develop practical, risk-based solutions.
  • Maintain a customer-focused and delivery-oriented approach, driving positive outcomes in dynamic and ambiguous environments.
  • Work proactively with internal clients to understand business objectives and provide effective security guidance.
  • Promote continuous learning, knowledge sharing, and security awareness while positively influencing stakeholders and peers.


What You Will Bring:

  • Post-secondary degree in Business, Technology, Cybersecurity, Computer Science, or a related discipline, or an equivalent combination of education and experience.
  • Minimum of five (5) years or more of experience in Information Security and/or Information Technology, with significant experience in Information Security Risk Management.
  • Professional security certifications such as CISSP, CCSP, CISM, CISA, CRISC, or equivalent are preferred.
  • Strong knowledge of information security principles, risk management methodologies, security protocols, industry standards, and best practices.
  • Extensive experience performing security assessments and evaluating threat vectors, vulnerabilities, and compensating controls.
  • Strong technical background across multiple technology domains, including networking, servers, cloud computing, application development, enterprise architecture, and infrastructure.
  • knowledge of security technologies and capabilities, including:
    • Threat Modeling and Threat Risk assessment
    • Encryption and key management
    • Network and Web Application Firewalls (WAF)
    • Intrusion Detection and Prevention Systems (IDS/IPS)
    • Advanced Malware Protection
    • Distributed Denial-of-Service (DDoS) protections
    • Data Loss Prevention (DLP)
    • Security Information and Event Management (SIEM)
  • Strong knowledge of cloud security principles and cloud platforms, particularly Microsoft Azure and AWS.
  • Working knowledge of cybersecurity frameworks, risk assessment methodologies, threat modeling frameworks, and security control standards, including NIST Cybersecurity Framework (CSF) 2.0, ISO 27001/27002, CIS, SOC 2, CSA, MITRE ATT&CK, OWASP Top 10, STRIDE, DREAD, and related industry standards and best practices.
  • Familiarity with IT audit, compliance, and security testing processes.
  • Knowledge of emerging AI technology including associated risks and controls.
  • Excellent communication, stakeholder management, presentation, negotiation, and consensus-building skills.
  • Demonstrated ability to work independently, think strategically, manage competing priorities, and deliver on commitments with minimal supervision.


The base salary for this position is between $105,000 - $130,000 annually. This represents base salary only and does not represent other variable compensation components of our total compensation ( i.e. annual bonus, commission etc). If you are selected to move forward in our recruitment process, your recruiter will be able to discuss additional details of our total rewards program with you.

Career opportunities will be open a minimum of 5 business days from the date of posting, closing dates will vary depending on the search activity. All applications received will be reviewed on a rolling basis.

#LI-Hybrid

Requisition ID: 6912

Category: Digital Technology

Location:

Similar Jobs

More Jobs at Canada Life

More Information Technology Jobs

Find similar Information Security Analyst 3 jobs: