Posting Title: Information Security Analyst
Department: Enterprise Enablement
Full/Part Time: Full Time
Job Type: Permanent
Location: Vancouver
Work Arrangement: Hybrid
Salary Range: $73,182.00 - $107,310.00
Close Date: August 19, 2026
SUMMARY The Information Security Analyst supports protection of BCFSA's data and services by monitoring security events, investigating and responding to cybersecurity threats, conducting investigations, supporting incident response and vulnerability management activities, improving security controls, and providing practical security guidance across the organization in accordance with established policies, standards, and procedures.
ACCOUNTABILITIES- Monitor security events and alerts using enterprise security tools, including SIEM, SOAR, XDR, EDR, and cloud security platforms.
- Investigate and respond to cybersecurity incidents, security alerts, and suspicious activities, including security-related escalations.
- Conduct threat analysis and threat hunting activities to identify potential threats, indicators of compromise, and opportunities to improve detection capabilities.
- Coordinate incident response activities with internal technology teams, managed security service providers, and external partners.
- Document investigations, findings, actions taken, and lessons learned to support continuous improvement of security operations.
- Stay current with emerging threats, vulnerabilities, security technologies and best practices.
- Contribute to BCFSA's security awareness program and knowledge-sharing initiatives.
- Validate identified vulnerabilities and work with other technology teams to prioritize remediation, including patch management.
- Supports information technology Threat and Risk Assessments.
- Contribute to business continuity, disaster recovery, and incident response planning.
- Maintain up-to-date baselines for the secure configuration and operations of all in-place devices.
- Monitor all in-place security solutions for efficient and appropriate operations.
- Investigate problematic activity and manage security related escalations.
- Participate in the creation/updating of enterprise security documents (policies, standards, baselines, guidelines, and procedures).
- Participate in the planning and design of the enterprise Incident Response Plans, Business Continuity Plan and Disaster Recovery Plan.
- Acts as subject matter expert providing expert digital security guidance to internal stakeholders in accordance with established policies, standards, and procedures.
JOB REQUIREMENTS - Experience with security operations tools and platforms such as SIEM, SOAR, XDR, EDR, cloud security, identity protection, vulnerability management, and firewall or security gateway technologies.
- Knowledge of Zero Trust security concepts and common security control frameworks.
- Knowledge of security and privacy issues and how they relate to business requirements, public sector operations, and privacy regulations.
- Ability to analyze security events, assess risk, document findings, and recommend practical remediation actions.
- Knowledge of Freedom of Information and Protection of Privacy services.
- Knowledge of change management processes and project management methodologies.
- Experience establishing and maintaining effective working relationships with a variety of organizations.
- Ability to exercise judgement, initiative, and discretion.
- Ability to clearly and concisely communicate complex information.
EDUCATION - College diploma or university degree in the field of computer science and/or 3 years' equivalent work experience.
CERTIFICATIONS - One or more related certifications such as CompTIA CySA+, GIAC Security Essentials (GSEC), GIAC Certified Incident Handler (GCIH), Microsoft Certified: Security Operations Analyst Associate (SC-200), or Certified Ethical Hacker (CEH).
PROVISOSCandidates must be eligible to work in Canada and living in British Columbia or intent to settle in the province.
Internal candidates are kindly requested to use their BCFSA email address when applying for this position. This will help us identify and streamline the internal application process.