18th August, 2026Senior Analyst - IT Security About the Role We are looking for a Senior Analyst - IT Security with a strong focus on Governance, Risk, and Compliance (GRC). Reporting to the Cybersecurity Manager, you will support the organization's Information Security Management System, ISO 27001 certification, cybersecurity compliance initiatives, and information security risk management activities.
This is an opportunity for an experienced cybersecurity professional to work across technical, operational, and business teams while helping strengthen the organization's overall security posture.
What You'll Do - Support the development, implementation, and maintenance of the Information Security Management System (ISMS) in alignment with ISO 27001.
- Assist with internal and external ISO 27001 audits.
- Support gap assessments, compliance mapping, and strategic planning for the Canadian Program for Cybersecurity Certification (CPCSC).
- Maintain and support risk register and risk management activities.
- Conduct third-party risk assessments and report findings.
- Conduct solution risk assessments and recommend appropriate mitigation strategies.
- Act as a subject matter expert for cybersecurity policies and standards.
- Collaborate with cross-functional teams to promote security awareness and policy compliance.
- Support the collection and reporting of cybersecurity program metrics.
- Monitor compliance with regulatory requirements and industry standards.
- Support cybersecurity projects and initiatives.
- Assist with security awareness activities, including company-wide communications, presentations, and phishing campaigns.
- Work with stakeholders to drive security improvements and deliver outcomes.
What We're Looking For - 7+ years of cybersecurity experience, with a focus on Governance, Risk, and Compliance.
- Strong knowledge of security frameworks, standards, and best practices, including ISO 27001, NIST, and CIS.
- Experience with audit and compliance activities.
- Experience developing and implementing security policies and procedures.
- Technical understanding of security control implementation.
- Experience conducting risk assessments and developing mitigation strategies.
- Knowledge of international cybersecurity legislation and regulatory requirements.
- Excellent written and verbal communication skills.
- Ability to communicate complex technical concepts to non-technical stakeholders.
- Strong collaboration skills across multiple teams and departments.
- Ability to work independently and manage competing priorities.
- Comfortable working under pressure in a fast-paced, agile environment.
- Customer-focused and delivery-oriented approach.
Nice to Have - Experience supporting ISO 27001 certification programs.
- Experience with CPCSC readiness or cybersecurity certification programs.
- Experience conducting third-party risk assessments.
- Experience with security awareness programs and phishing campaigns.
Education & Certifications - Post-secondary degree, diploma, or certificate in Computer Science, Engineering, Computer Technology, or a related discipline.
- Industry-recognized cybersecurity certification such as CISSP, CISM, CISA, or equivalent is desired.
What Success Looks Like - You help maintain and strengthen the organization's security and compliance program.
- You identify and communicate information security risks clearly.
- You provide practical guidance that helps teams implement effective security controls.
- You build strong relationships with technical and non-technical stakeholders.
- You help turn compliance requirements into measurable security improvements.
Work Model - Employment type: Permanent
- Location: South East Calgary
- Work model: Hybrid