Are you looking for a role that will challenge you while helping protect critical systems, information, and operations? Can you see yourself playing a key role in strengthening cybersecurity within a highly regulated and mission-driven organization? Do you enjoy identifying risks, investigating security-related issues, and contributing to continuous improvement initiatives? If you answered yes, this may be the job for you-apply today! Our Chalk River location is seeking an
IT Security Analyst to support the delivery of CNL's Cyber Security Program through operational support, auditing, investigations, oversight, and continuous program improvement.
What will you be doing!- Leading the development, implementation, and ongoing operation of CNL's Cyber Security Program (based on NIST 800-53 and ISO27001).
- Coordinating and conducting audits of IT systems and infrastructure (hardware/software compliance, user accounts, application access, etc.), ensuring action items are identified, defined, and monitored for completion.
- Providing support to external auditors who are conducting audits and assessments against CNL systems and information.
- Participating and assisting in the design and execution of vulnerability assessments, penetration tests and security testing exercises.
- Monitoring the IT security toolset and enforcing IT security policies and procedures (e.g. password policy compliance, approval of external users, ensuring server configuration compliance, etc.)
- Providing 2nd level Operational Support in assisting our customers and supporting teams in the response, assessment and containment of security-related activities.
- Creating reports on activities such as Internet usage, Email usage, and Malware/Virus Alerts; may be engaged in highly sensitive investigations and audits.
- Researching emerging threats, products, services, protocols, and standards in support of CNL's Cyber Security Program (e.g. assess need for any security reconfigurations [minor to moderate]) and working with appropriate groups to implement changes to services (e.g. wireless, remote computing, encryption, etc.)
- Making formal and informal recommendations to IT Leadership on long-term direction of the Cyber Security tools, infrastructure and Program.
- Participating in resolving identified Cyber Security Incidents and accurately documenting and reporting the details of Cyber Security Incidents, including participation in an on-call rotation for IT Incident Response.
- Recommending hardware/software security patches and any other security measures required in the event of a security breach.
- Providing input to Cyber Security Requirements for new projects, ensuring adequate Cyber Security engagement throughout the life of the project
- Contributing to and reviewing project proposals and solutions, conducting risk assessments to ensure risk levels are managed, and compliance with Cyber Security Program, Privacy, and Protection of Information requirements
- Working collaboratively with other departments within CNL IT and our business partners (Security, HR, Legal, etc.) to deliver on CNL's APWB commitments and interacting with external agencies on IT security issues, (e.g AECL, TBS, PWGSC, RCMP, CSIS, etc.)
- Other duties as assigned by your manager.
What we are looking for:- Education
- Graduation from a 3-year college program from a recognized educational institution in Information Technology (focus on Network Technology and/or Security is desirable).
- Or graduation from an equivalent formal educational program and relevant IT experience.
- Experience
- 7 years of experience in an IT position, with demonstrated 5 years' experience related to IT security, auditing and compliance functions.
- Knowledge, Skills & Abilities
- Demonstrated knowledge and experience working with cybersecurity tools (ESG, NGFW, SIEM/SOAR, EDR, etc).
- Demonstrated capability to conduct security and compliance audits.
- Demonstrated knowledge of computer operating systems and networks (Windows/Linux/Cisco/wireless).
- Demonstrated knowledge of security concepts such as cyber-attacks and techniques, threat vectors, risk management, incident management, etc.
- Demonstrated investigative mindset with the ability to discover, identify, capture and document relevant information into a cohesive report.
- Consistently demonstrated analytical skills in security analysis and requirements to identify appropriate solutions.
- Self-motivated and demonstrates initiative when performing duties.
- Effective customer service orientation with ability to deal effectively with end users experiencing high levels of frustration.
- Relevant training and experience with the COBIT and ITIL frameworks are desirable.
- Relevant technical training, experience, and certification(s), such as CISSP, SSCP (ISC2) or CISM, CISA (ISACA) or equivalent, is highly desirable.
- Security Clearance Eligibility Required
- Level 2 Secret requires a minimum of 7 years of verifiable history in Canada, Australia, New Zealand, the United States, and/or the United Kingdom. CNL implements security screening in accordance with the Treasury Board of Canada Secretariat's "Standard on Security Screening" and the "Policy on Government Security."
Working Conditions:- Working schedule: Five (5) days per week, seven and a half (7.5) hours per day for a thirty-seven and a half (37.5) hour work week.
- May on occasion be required to work overtime or address high-stress situations with no advance warning (e.g. virus outbreak, malware infection or conduct investigations requiring immediate response).
Location: Fully RemoteThis position is offered on a
fully remote basis, allowing you to work from
home anywhere in Canada. You'll collaborate virtually with a dynamic team across CNL sites, helping to advance Canada's clean energy and environmental goals from your home office.
Please note: This is a
remote position supporting the Chalk River Laboratory, Ontario.
#LI-REMOTE