Information Security Compliance Analyst

Canada Guaranty Mortgage Insurance Company

$90K — $110K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • College-level Diploma or University Degree in a relevant field.
  • 3 to 5 years of experience in information security compliance roles.
  • Familiarity with security compliance frameworks (CSAE 3416, SOC1, SOC2, ISO 27001:2022).
  • Experience managing GRC solutions like RSA Archer.
  • Strong analytical and problem-solving skills.

Responsibilities

  • Participate in planning and evidence collection for external audits.
  • Maintain security policies aligned with audit requirements.
  • Conduct technology infrastructure assessments and issue remediation.
  • Operate and maintain the Data Loss Prevention solution.
  • Support Third-Party Risk Management program operations.

Benefits

  • Recognized as one of the Best Workplaces™ in Canada, Financial Services & Insurance, and for Mental Wellness.
  • Offer a comprehensive total rewards package including health and dental coverage.
  • Provide flexible work options.
  • Promote a friendly, inclusive, and supportive workplace culture.
Full Job Description
About The Opportunity

The Information Security Compliance Analyst will play a critical role at Canada Guaranty. This individual will ensure Canada Guaranty meets security compliance requirements, ensuring new systems implemented are properly secured, third parties are meeting Canada Guaranty's information security expectations, and that any potential risks are raised to management in a timely manner. They will also play an important role in the design and maintenance of Canada Guaranty's GRC solution.

In this role, you will:
  • Participate in planning, scheduling, evidence collection, and preliminary analysis for all external audits.
  • Maintain information security policies and procedures, ensuring they remain aligned with audit and security requirements.
  • Perform assessments of technology infrastructure, including vulnerability and baseline compliance scanning, analysis, and issue remediation.
  • Operate the Data Loss Prevention solution, including designing, testing, and maintaining policies, performing data discovery scans, analyzing results, assessing real-time alerts, and providing coaching to business users or raising issues to management where appropriate.
  • Support the daily operations of the Third-Party Risk Management program, including maintaining the questionnaire inventory, coordinating assessments with third parties, and assisting internal relationship managers to ensure assessments are completed.
  • Perform Third-Party information security risk assessments, including analyzing questionnaire responses and reviewing supporting documentation, certifications, and independent audit reports. Raise identified issues to management in a timely manner.
  • Monitor implementation of outstanding issues including audit recommendations and Third-Party deficiencies to ensure they are remediated on schedule. Validate the effectiveness of their implementation.
  • Support the operation and maintenance of the GRC solution, including managing user access, implementing and testing application changes, and providing technical assistance to business users.
  • Contribute to the technology training and awareness program, including designing simulated phishing exercises, developing training campaigns, and administering training through the Learning Management System.
  • Assist with monthly reporting activities, including collecting metrics and generating formal dashboards and reports.


Essential Qualifications
  • College-level Diploma or University Degree in a related field.
  • 3 to 5 years progressive experience in similar roles.
  • Understanding and experience with security compliance frameworks including CSAE 3416, SOC1, SOC2, ISO 27001:2022.
  • Experience maintaining GRC solutions (i.e., RSA Archer) including user access permissioning and basic application development.
  • Demonstrated experience taking ownership of problems and working on projects involving multiple resources.
  • Understanding of audit process/methodology and business operations with the ability to align technology controls to business practices.
  • Experience with mock or real security breach discovery and management.
  • Strong verbal and written communication skills, including the ability to communicate and interact effectively with technical professionals as well as business users and non-technical experts.
  • High level of analytical and problem-solving skills, including the ability to follow problems through to resolution.
  • Equally able to work effectively and collaboratively as a team member, sharing information and ideas in a timely manner.
  • Ability to plan and manage time effectively, multi-task, prioritize and meet deadlines in a fast-paced, time sensitive environment.
  • Availability outside of business hours to help troubleshoot critical production issues and perform physical security audits as required.


What We Offer You

Canada Guaranty is proudly recognized by the Great Place to Work® Institute as one of the Best Workplaces™ in Canada - 100-999 Employees (2025, 2026). We are also honoured to be recognized as among the Best Workplaces™ in Financial Services & Insurance (2024, 2025, 2026), Best Workplaces™ in Ontario (2024, 2025), Best Workplaces™ for Mental Wellness (2025, 2026), Best Workplaces™ for Inclusion (2025), Best Workplaces™ for Women (2025, 2026), and Best Workplaces™ with the Most Trusted Executive Teams (2025, 2026). Join us and see why!

We offer a comprehensive total rewards package, including competitive compensation, company-matched retirement programs, health and dental coverage, flexible work options, and a friendly, inclusive, and supportive culture.

The salary range for this position ranges from $90,000 to $110,000. Offers are determined by a variety of factors, including job-related knowledge, skills, and experience, along with internal equity.

#LI-Hybrid

Similar Jobs

More Jobs at Canada Guaranty Mortgage Insurance Company

  • AI Engineer
    $115K — $135K *
    Toronto, ON M3C 0E3
    Information Technology
    In-Person

More Information Technology Jobs

Find similar Information Security Compliance Analyst jobs: