Information Security Analyst
foresters · Toronto · Canada · On-site
Pay: CAD 59,000 – 84,700 a year
Posted Sep 9, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Career Opportunity
Role Title
Information Security Analyst
Purpose of role
Information Security Analyst is a hands-on role that requires to work with all business units and other risk functions to identify security requirements by using methods that may include risk and business impact assessments. The person in this position is responsible of defining security configuration and operations standards for systems and applications, by conducting assessments and reviews of systems, networks and applications.
Job Description
Key Responsibilities
Monitor systems, network and applications for security risks.
Work with information security team to plan and enforce security requirements
Report to management concerning residual risk, vulnerabilities and other security exposures, including misuse of information assets and noncompliance.
Participate, Investigate, support and document cybersecurity incidents and breaches.
Administer security tools to protect systems, networks and applications. This includes firewalls, Intrusion detections and prevention systems, security gateways etc.
Assess security requirements and controls during the application development and acquisition process as defined in company’s security policies and standards.
Perform vulnerability assessments and tests to uncover flaws and help technical teams to remediate identified vulnerabilities to maintain high security standards.
Provide support to ongoing external and internal audits and audit remediation on information technology, including generating technical recommendations
Develop and maintain security processes and procedures, and support service-level agreements (SLAs) to ensure that security controls are managed and maintained Create, manage and maintain user security awareness program
Participate in user access provisioning and de provisioning activities to verify security controls are adhered
Conduct security research in keeping abreast of latest security threat landscape and stay abreast with the current information technology trends
Develop positive working relationships with various teams involved in security and privacy matters
Key Qualifications
5 years of related work experience
Strong hands-on experience with tools such as: IDS/IPS, Metasploit, Nexpose, Nmap, Nessus, Wireshark, L0phtCrack, John the Ripper etc.
In-depth knowledge and understanding of information risk concepts and principles, as a means of relating business needs to security controls
Experience with common information security management frameworks, such as International Organization for Standardization (ISO) 27001, NIST Cybersecurity Framework. PCI DSS etc.
Experience with penetration tests and techniques is preferred
Proficiency in performing risk, business impact, control and vulnerability assessments
Experience in developing, documenting and maintaining security policies, processes, procedures and standards
Proficiency in network infrastructure, including routers,…