Information Security Analyst 3

Description: 

 

Permanent Full Time 

-

 

 

 

The Information Security Analyst III role is within the Project Security team, partnering with Information Technology and business stakeholders to identify, assess, and manage information security risks while ensuring compliance with organizational security policies, standards, and regulatory requirements. This role delivers security services across Canada Life projects, including security consultation, threat and risk assessments, threat modeling, and security control reviews to help ensure secure project delivery and effective risk management. Reporting to the Manager, Project Security, within the Information Security and Technology Risk (ISTR) group.

 

 

What You Will Do:

 

  • Provide information security consultation and advisory services to business and IT stakeholders.
  • Partner with project teams and technology stakeholders to identify, assess, and implement appropriate security controls throughout the project lifecycle.
  • Ensure the safeguarding and protection of Canada Life's confidential information by helping prevent unauthorized disclosure, modification, destruction, or misuse of information assets.
  • Conduct information security risk assessments, including Threat Modeling, Threat Risk Assessments (TRAs), security reviews, and other risk-based evaluations.
  • Research emerging threats, vulnerabilities, attack techniques, and industry trends, providing recommendations to mitigate organizational risk.
  • Develop and conduct security and risk assessments and document findings, recommendations, and remediation activities.
  • Review risk assessment and reports, identify security weaknesses, and assist stakeholders in prioritizing remediation activities based on risk.
  • Provide recommendations on findings from:
    • Static Application Security Testing (SAST)
    • Dynamic Application Security Testing (DAST)
    • Software Composition Analysis (SCA)
    • Penetration Testing
    • Infrastructure and Endpoint Vulnerability Assessments
  • Collaborate across Line of Business to solve complex security challenges and develop practical, risk-based solutions.
  • Maintain a customer-focused and delivery-oriented approach, driving positive outcomes in dynamic and ambiguous environments.
  • Work proactively with internal clients to understand business objectives and provide effective security guidance.
  • Promote continuous learning, knowledge sharing, and security awareness while positively influencing stakeholders and peers.

 

 

What You Will Bring:

 

  • Post-secondary degree in Business, Technology, Cybersecurity, Computer Science, or a related discipline, or an equivalent combination of education and experience.
  • Minimum of five (5) years or more of experience in Information Security and/or Information Technology, with significant experience in Information Security Risk Management.
  • Professional security certifications such as CISSP, CCSP, CISM, CISA, CRISC, or equivalent are preferred.
  • Strong knowledge of information security principles, risk management methodologies, security protocols, industry standards, and best practices.
  • Extensive experience performing security assessments and evaluating threat vectors, vulnerabilities, and compensating controls.
  • Strong technical background across multiple technology domains, including networking, servers, cloud computing, application development, enterprise architecture, and infrastructure.
  • knowledge of security technologies and capabilities, including:
    • Threat Modeling and Threat Risk assessment
    • Encryption and key management
    • Network and Web Application Firewalls (WAF)
    • Intrusion Detection and Prevention Systems (IDS/IPS)
    • Advanced Malware Protection
    • Distributed Denial-of-Service (DDoS) protections
    • Data Loss Prevention (DLP)
    • Security Information and Event Management (SIEM)
  • Strong knowledge of cloud security principles and cloud platforms, particularly Microsoft Azure and AWS.
  • Working knowledge of cybersecurity frameworks, risk assessment methodologies, threat modeling frameworks, and security control standards, including NIST Cybersecurity Framework (CSF) 2.0,  ISO 27001/27002, CIS, SOC 2, CSA, MITRE ATT&CK, OWASP Top 10, STRIDE, DREAD, and related industry standards and best practices.
  • Familiarity with IT audit, compliance, and security testing processes.
  • Knowledge of emerging AI technology including associated risks and controls.
  • Excellent communication, stakeholder management, presentation, negotiation, and consensus-building skills.
  • Demonstrated ability to work independently, think strategically, manage competing priorities, and deliver on commitments with minimal supervision.

 

 

-

The base salary for this position is between $105,000 - $130,000 annually. This represents base salary only and does not represent other variable compensation components of our total compensation ( i.e. annual bonus, commission etc). If you are selected to move forward in our recruitment process, your recruiter will be able to discuss additional details of our total rewards program with you.

Career opportunities will be open a minimum of 5 business days from the date of posting, closing dates will vary depending on the search activity. All applications received will be reviewed on a rolling basis.

Grow with Canada Life 

We’re united by a shared purpose: to improve the financial, physical and mental well-being of Canadians. Our company is trusted by 1 in 3 Canadians and contributes to the strength of communities across the country.  

We’re looking for people who live our values everyday: we step up, we do the right thing, and we deliver – for our customers, communities and each other. Are you someone who always strives to do the right thing, who steps up for themselves and others, and who delivers with impact? Then we want to hear from you! 

What we offer:  

We’re committed to supporting our employees through every stage of their career. Here’s what you can expect as a full-time or part-time permanent team member: 

  • Career Development: Opportunities for career advancement, access to industry-leading learning programs and up to $2,000 annually towards education reimbursement. 
  • Health & Wellness: Flexible health and dental benefits, plus a $5,000 mental health benefit to support your well-being. 
  • Time Off: In addition to regular vacation and personal days, we support community involvement with a volunteer day.  
  • Financial Security: Company-matching pension plan, share ownership program and additional investment options. 
  • Rewards and Recognition: Employee recognition programs, service milestone celebrations, employee discounts and more!  
  • Emphasis on Community: We provide a workplace where employees feel connected and supported through Employee Resource Groups (ERGs), mentorship programs, social clubs and events.  

Learn more about Canada Life.  

We’re committed to removing barriers and ensuring equal access to employment. Applicants requiring reasonable accommodation during the application process may contact  talentacquisitioncanada@canadalife.com. All information provided will be handled in accordance with applicable laws and Canada Life policies.  

Canada Lifewould like to thank all applicants, however only those who qualify for an interview will be contacted

#LI-Hybrid 

Requisition ID:  6912
Category:  Digital Technology
Location: 

Toronto, ON, CA Winnipeg, MB, CA

Date:  Sep 3, 2026

If you are not finding suitable opportunities now, please click below to join our talent community!