Information Security Analyst

 

Description:

As part of our Information Security team, you will lead or play a key role in high-profile investigations and contributing to develop and implement response plans for diverse security incidents. Your work will directly contribute to minimizing risks, safeguarding sensitive information, and enhancing the overall cybersecurity posture of our organization.

What You Will Do

Cybersecurity Incident Response
 

  • Perform the end-to-end security incident response process, including preparation, detection, analysis, containment, eradication, recovery, and post-incident review.
  • Act as a point of contact and coordinator during security incidents, managing incident communications and escalating as needed.
  • Establish and maintain incident response playbooks, procedures, and runbooks aligned with industry frameworks (NIST, ISO 27035, SANS, etc.).
  • Coordinate with the Security Operations Center (SOC) team, Threat Intelligence, and Vulnerability Management to proactively detect and respond to potential threats.
  • Document, classify, and report security incidents in accordance with established procedures, and and lead root cause analysis (RCA) activities to identify lessons learned and improvement opportunities.
  • Participate in tabletop exercises and simulations to assess and improve the organization’s incident response readiness.
     

Cybersecurity Investigations and Threat Analysis
 

  • Conduct security investigations to determine the cause, scope, and impact of security breaches.
  • Perform evidence gathering to support investigations, ensuring chain of custody and compliance with legal and regulatory standards.
  • Work with the Threat Intelligence team to analyze and respond to advanced persistent threats (APTs), malware outbreaks, ransomware incidents, and other cyberattacks.
  • Stay informed of emerging threats, vulnerabilities, and adversary tactics, techniques, and procedures (TTPs), and apply threat intelligence to incident investigations, response activities, and continuous improvement efforts.
     

Collaboration and Stakeholder Engagement
 

  • Act as a liaison between the Cybersecurity Incident Response Team (CSIRT) and business units, IT, Legal, Compliance, Risk, and external vendors.
  • Assist with internal audit, governance, and risk management teams to ensure alignment with corporate security policies and regulatory requirements.
  • Communicate effectively with senior leadership during high-severity incidents, providing regular updates on impact, response activities, and mitigation plans.
  • Contribute to the business continuity and disaster recovery teams to ensure seamless integration of incident response with overall organizational resilience.
     

Process Development and Maturity
 

  • Contribute to enhance and refine the incident response framework to align with evolving threats, business objectives, and regulatory landscapes.
  • Help develop and maintain comprehensive incident response policies, standards, and guidelines that address the needs of the business while aligning with global best practices.
  • Contribute to key performance indicators (KPIs) and metrics to measure the effectiveness and efficiency of the incident response program.
  • Lead initiatives to automate and optimize incident response activities through the integration of SOAR (Security Orchestration, Automation, and Response) platforms and other tools.
     

Mentorship and Technical Leadership
 

  • Serve as a senior technical resource and subject matter expert for the incident response team.
  • Mentor and provide guidance to junior analysts on investigative methodologies, response techniques, and cybersecurity best practices.
  • Review investigation findings and provide quality assurance for incident documentation and reporting.
  • Contribute to a culture of continuous learning, knowledge sharing, and operational excellence.
     

What You Will Bring
 

  • Bachelor's degree in computer science, Cybersecurity, Information Technology, or a related field, or equivalent practical experience.
  • 5+ years of cybersecurity experience, including at least 3 years of incident response, threat detection, digital forensics, or security operations.
  • Hands-on experience investigating and responding to cybersecurity incidents in enterprise environments.
  • Strong understanding of the incident response lifecycle and industry frameworks such as NIST 800-61, MITRE ATT&CK, and ISO 27035.
  • Experience working with SIEM, EDR/XDR, identity protection, email security, and cloud security technologies.
  • Knowledge of Windows, Linux, Active Directory, Microsoft 365, Azure, and cloud security concepts.
  • Experience performing forensic analysis, log analysis, and threat investigation activities.
  • Strong analytical, problem-solving, and decision-making skills.
  • Ability to effectively manage multiple investigations and priorities simultaneously.

Organization Canada Life
Industry IT / Telecom / Software Jobs
Occupational Category Information Security Analyst
Job Location Toronto,Canada
Shift Type Morning
Job Type Full Time
Gender No Preference
Career Level Experienced Professional
Experience 5 Years
Posted at 2026-08-05 4:30 pm
Expires on 2026-09-19