Information Security Analyst 3 (Cybersecurity Incident Response)

Canada Life

$85K — $135K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in computer science, Cybersecurity, Information Technology, or related field, or equivalent experience.
  • 5+ years of cybersecurity experience, including a minimum of 3 years in incident response or threat detection.
  • Hands-on experience in investigating and responding to cybersecurity incidents in enterprise environments.
  • Strong knowledge of incident response lifecycle and frameworks like NIST 800-61 and MITRE ATT&CK.
  • Experience with SIEM, EDR/XDR, and cloud security technologies.
  • Ability to perform forensic log and threat investigation analysis.
  • Strong analytical, problem-solving, and decision-making skills.

Responsibilities

  • Perform the full spectrum of the security incident response process from detection to post-incident review.
  • Coordinate incident communications and manage escalations during security incidents.
  • Develop and maintain incident response playbooks and procedures aligned with industry standards.
  • Work with various teams to proactively identify and respond to threats.
  • Document security incidents and lead root cause analysis efforts.
  • Participate in exercises to improve the organization's incident response capabilities.
  • Serve as a technical mentor, providing guidance to junior analysts on effective response techniques.

Benefits

  • Comprehensive health, vision, and dental benefits.
  • 401(k) plan with company match.
  • Generous paid time off policy including holidays and volunteer time.
  • Flexible work arrangements and remote work options.
  • Continuous learning and professional development opportunities.
Full Job Description
Permanent Full Time

We are seeking an experienced Senior Analyst in Cybersecurity Incident Response (CSIRT) to play a key role in detecting, investigating, and coordinating the response to cybersecurity incidents across the organization. This role is critical to protecting our business, data, and clients by ensuring rapid, effective, and efficient responses to cybersecurity incidents and threats. The ideal candidate will have deep expertise in the incident response lifecycle, strong technical skills, and the ability to collaborate across various departments and stakeholders.

As part of our Information Security team, you will lead or play a key role in high-profile investigations and contributing to develop and implement response plans for diverse security incidents. Your work will directly contribute to minimizing risks, safeguarding sensitive information, and enhancing the overall cybersecurity posture of our organization.

What you will do

Cybersecurity Incident Response
  • Perform the end-to-end security incident response process, including preparation, detection, analysis, containment, eradication, recovery, and post-incident review.
  • Act as a point of contact and coordinator during security incidents, managing incident communications and escalating as needed.
  • Establish and maintain incident response playbooks, procedures, and runbooks aligned with industry frameworks (NIST, ISO 27035, SANS, etc.).
  • Coordinate with the Security Operations Center (SOC) team, Threat Intelligence, and Vulnerability Management to proactively detect and respond to potential threats.
  • Document, classify, and report security incidents in accordance with established procedures, and and lead root cause analysis (RCA) activities to identify lessons learned and improvement opportunities.
  • Participate in tabletop exercises and simulations to assess and improve the organization's incident response readiness.


Cybersecurity Investigations and Threat Analysis
  • Conduct security investigations to determine the cause, scope, and impact of security breaches.
  • Perform evidence gathering to support investigations, ensuring chain of custody and compliance with legal and regulatory standards.
  • Work with the Threat Intelligence team to analyze and respond to advanced persistent threats (APTs), malware outbreaks, ransomware incidents, and other cyberattacks.
  • Stay informed of emerging threats, vulnerabilities, and adversary tactics, techniques, and procedures (TTPs), and apply threat intelligence to incident investigations, response activities, and continuous improvement efforts.


Collaboration and Stakeholder Engagement
  • Act as a liaison between the Cybersecurity Incident Response Team (CSIRT) and business units, IT, Legal, Compliance, Risk, and external vendors.
  • Assist with internal audit, governance, and risk management teams to ensure alignment with corporate security policies and regulatory requirements.
  • Communicate effectively with senior leadership during high-severity incidents, providing regular updates on impact, response activities, and mitigation plans.
  • Contribute to the business continuity and disaster recovery teams to ensure seamless integration of incident response with overall organizational resilience.


Process Development and Maturity
  • Contribute to enhance and refine the incident response framework to align with evolving threats, business objectives, and regulatory landscapes.
  • Help develop and maintain comprehensive incident response policies, standards, and guidelines that address the needs of the business while aligning with global best practices.
  • Contribute to key performance indicators (KPIs) and metrics to measure the effectiveness and efficiency of the incident response program.
  • Lead initiatives to automate and optimize incident response activities through the integration of SOAR (Security Orchestration, Automation, and Response) platforms and other tools.


Mentorship and Technical Leadership
  • Serve as a senior technical resource and subject matter expert for the incident response team.
  • Mentor and provide guidance to junior analysts on investigative methodologies, response techniques, and cybersecurity best practices.
  • Review investigation findings and provide quality assurance for incident documentation and reporting.
  • Contribute to a culture of continuous learning, knowledge sharing, and operational excellence.


What you will bring
  • Bachelor's degree in computer science, Cybersecurity, Information Technology, or a related field, or equivalent practical experience.
  • 5+ years of cybersecurity experience, including at least 3 years of incident response, threat detection, digital forensics, or security operations.
  • Hands-on experience investigating and responding to cybersecurity incidents in enterprise environments.
  • Strong understanding of the incident response lifecycle and industry frameworks such as NIST 800-61, MITRE ATT&CK, and ISO 27035.
  • Experience working with SIEM, EDR/XDR, identity protection, email security, and cloud security technologies.
  • Knowledge of Windows, Linux, Active Directory, Microsoft 365, Azure, and cloud security concepts.
  • Experience performing forensic analysis, log analysis, and threat investigation activities.
  • Strong analytical, problem-solving, and decision-making skills.
  • Ability to effectively manage multiple investigations and priorities simultaneously.


Preferred Qualifications
  • GCIH, GCFA, GCIA, CISSP, CISM, or equivalent are highly desirable.
  • Experience in the insurance or financial services sector is a strong asset.
  • Familiarity with privacy regulations (GDPR, PIPEDA, CCPA) and industry compliance requirements.
  • Experience with SOAR platforms, threat hunting methodologies, and leveraging AI technologies to develop or enhance security operations workflows and automations.
  • Experience preparing and delivering incident briefings and executive-level communications during cybersecurity incidents.


Key Competencies
  • Critical thinking and problem-solving under pressure.
  • Excellent communication skills with the ability to explain technical concepts to non-technical audiences.
  • Strong collaboration and interpersonal skills to work effectively across teams and business units.
  • Detail-oriented with a high level of integrity and professionalism.


The base salary for this position is between $85,200.00 - $135,200.00 annually. This represents base salary only and does not represent other variable compensation components of our total compensation ( i.e. annual bonus, commission etc). If you are selected to move forward in our recruitment process, your recruiter will be able to discuss additional details of our total rewards program with you.

Career opportunities will be open a minimum of 5 business days from the date of posting, closing dates will vary depending on the search activity. All applications received will be reviewed on a rolling basis.

Requisition ID: 6592

Category: Digital Technology

Location:

Similar Jobs

More Jobs at Canada Life

More Information Technology Jobs

Find similar Information Security Analyst 3 (Cybersecurity Incident Response) jobs: