48 Safety Data jobs in Canada
Information Security Specialist
Posted today
Job Viewed
Job Description
Work Location:
Toronto, Ontario, Canada
Hours
37.5
Line Of Business
Technology Solutions
Pay Details
$91,200 - $136,800 CAD
TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
Job Description
Job Summary:
The Senior Information security analyst is responsible for identifying, assessing, prioritizing, and coordinating responses to security vulnerabilities within the organization's systems, applications, and networks. This role requires a deep understanding of vulnerability management, risk assessment, and cross-functional collaboration to ensure timely remediation and alignment with organizational security objectives.
Key Responsibilities
Vulnerability Management and Triage:
- Oversee the end-to-end vulnerability triage process, including identification, assessment, prioritization, and tracking.
- Develop and maintain a triage framework that balances risk levels, exploitability, and business impact.
- Analyze vulnerability reports from various sources (e.g., scanners, penetration tests, threat intelligence) to determine criticality.
- Ensure vulnerabilities are accurately classified and assigned to the appropriate teams for remediation.
Collaboration And Coordination
- Work closely with system owners, application teams, DevOps, and IT infrastructure to drive vulnerability remediation.
- Act as a liaison between technical teams and business stakeholders to communicate risk and remediation priorities effectively.
- Collaborate with threat intelligence teams to assess the real-world impact of vulnerabilities.
Risk Assessment And Prioritization
- Develop and maintain a risk-based approach to prioritize vulnerabilities based on business context, likelihood of exploitation, and potential impact.
- Establish timelines for remediation based on severity and compliance requirements.
Process Improvement
- Implement and optimize workflows for vulnerability triage and reporting.
- Continuously review and refine vulnerability management policies, processes, and tools.
- Stay updated on evolving industry best practices and emerging threats
Reporting And Metrics
- Define and track key performance indicators (KPIs) for vulnerability management, such as mean time to remediate (MTTR) and vulnerability closure rates.
- Create regular reports on vulnerability status and risk posture for executive leadership and technical teams.
Leadership And Team Management
- Manage and mentor the vulnerability triage team, ensuring high performance and professional growth.
- Provide training and guidance to enhance the team's technical expertise and analytical skills.
- Foster a culture of security awareness and proactive risk management across the organization.
Container Security
- Provide technical expertise and oversight for container scanning, container vulnerability prioritization, and remediation.
- Be a lead contributor to enterprise-level initiatives pertaining to container security and risk remediation.
- Effectively communicate critical vulnerabilities, their impacts, associated risk, and remediation priorities to cross-functional leadership teams.
- Help build and enforce technology controls, along with container security standards to ensure best practices are followed, when building and deploying application containers.
- Influence behavior to reduce risk and foster a strong technology risk management culture throughout the bank.
Qualifications
Education: Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience).
Experience
- 5+ years of experience in vulnerability management, security operations, or related fields.
- 2+ years of experience in a leadership or management role
Technical Skills
- Expertise in vulnerability scanning tools (e.g., Qualys, Nessus, Rapid7).
- Knowledge of CVSS (Common Vulnerability Scoring System) and threat modeling.
- Strong understanding of operating systems, cloud platforms, networks, and application security.
- Familiarity with compliance frameworks (e.g., ISO 27001, NIST, PCI-DSS).
- Soft Skills:
- Strong analytical and problem-solving skills.
- Excellent verbal and written communication skills, with the ability to present technical information to non-technical audiences.
- Proven ability to manage multiple priorities and work under tight deadlines.
Preferred Qualifications
- Certifications such as CISSP, CISM, CEH, or GIAC.
- Experience with threat intelligence platforms and integration.
- Familiarity with automation tools and scripting languages (e.g., Python, PowerShell).
Who We Are
TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities and colleagues.
TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you've got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we're here to support you towards your goals. As an organization, we keep growing – and so will you.
Our Total Rewards Package
Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical, and mental well-being goals. Total Rewards at TD includes a base salary, variable compensation, and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off, banking benefits and discounts, career development, and reward and recognition programs. Learn more
Additional Information
We're delighted that you're considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we're committed to providing the support our colleagues need to thrive both at work and at home.
Please be advised that this job opportunity is subject to provincial regulation for employment purposes. It is imperative to acknowledge that each province or territory within the jurisdiction of Canada may have its own set of regulations, requirements.
Colleague Development
If you're interested in a specific career path or are looking to build certain skills, we want to help you succeed. You'll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD – and we're committed to helping you identify opportunities that support your goals.
Training & Onboarding
We will provide training and onboarding sessions to ensure that you've got everything you need to succeed in your new role.
Interview Process
We'll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.
Accommodation
Your accessibility is important to us. Please let us know if you'd like accommodations (including accessible meeting rooms, captioning for virtual interviews, etc.) to help us remove barriers so that you can participate throughout the interview process.
We look forward to hearing from you
Language Requirement (Quebec Only)
Sans Objet
Information Security Officer
Posted 3 days ago
Job Viewed
Job Description
**Responsibilities:**
+ Perform security reviews on SaaS and PaaS products
+ Performing security assessment on Saas & Paas
+ Ability to engage in deep technical discussions with other Engineering groups, as well as ability to convey the same concepts and issues at an elevated level to senior leadership.
+ Ability to execute technical responsibilities, including, Design / Architecture reviews, Code / Configuration reviews and vulnerability assessment.
+ Develops security architecture, strategy, planning, and problem-solving solutions on an enterprise level.
+ Identify opportunities to automate and standardize information security controls and for the supported groups
+ Resolve any vulnerabilities or issues detected in an application or infrastructure
+ Analyze source code to mitigate identified weaknesses and vulnerabilities within the system
+ Review and validate automated testing results and prioritize actions that resolve issues based on overall risk
+ Scan and analyze applications with automated tools, and perform manual testing if necessary
+ Reduce risk by analyzing the root cause of issues, their impact, and required corrective actions
+ Direct the development and delivery of secure solutions by coordinating with business and technical contacts
+ Recommend security solutions according to Security Policy and Practices established by Citigroup.
+ Establish and maintain relationships with domain architects, project managers, and others within the technology development unit.
+ Maintains continuous awareness of business, technical, and infrastructure issues and acts as a sounding board or consultant to aid in the development of creative GCP security architecture solutions.
+ Interfaces with vendors to security assess their technology and to guide their product roadmap based on Citi's security requirements.
**Qualifications:**
+ 6-10 years of relevant experience as an ISO officer
+ Proficiency in application, architecture, information, and cyber security
+ Proficiency in one or more: GCP, AWS and Azure
+ Advanced proficiency with Microsoft Office tools and software
+ Consistently demonstrates clear and concise written and verbal communication
+ 5-10 years of experience in Application Security and/or Security Architecture
+ 5-10 years of experience Public & Private Cloud Security
**Education:**
+ Bachelor's degree/University degree in Information Security/Computer Science/Electrical, Mechanical Engineering /Information Technology or equivalent experience
+ Master's degree preferred
+ Professional certifications, such as CISSP and CSSLP, or willingness to obtain certification within 12-18 months of start date.
This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required
**About Citi**
Citi, the leading global bank, has approximately 200 million customer accounts and does business in more than 160 countries and jurisdictions. Citi provides consumers, corporations, governments, and institutions with a broad range of financial products and services, including consumer banking and credit, corporate and investment banking, securities brokerage, transaction services, and wealth management.
As a bank with a brain and a soul, Citi creates economic value that is systemically responsible and in our clients' best interests. As a financial institution that touches every region of the world and every sector that shapes your daily life, our Operations & Technology teams are charged with a mission that rivals any large tech company. Our technology solutions are the foundations of everything we do from keeping the bank safe, managing global resources, and providing the technical tools our workers need to be successful to designing our digital architecture and ensuring our platforms provide a first-class customer experience. We reimagine client and partner experiences to deliver excellence through secure, reliable, and efficient services.
Our commitment to diversity includes a workforce that represents the clients we serve from all walks of life, backgrounds, and origins. We foster an environment where the best people want to work. We value and demand respect for others, promote individuals based on merit, and ensure opportunities for personal development are widely available to all. Ideal candidates are innovators with well-rounded backgrounds who bring their authentic selves to work and complement our culture of delivering results with pride. If you are a problem solver who seeks passion in your work, come join us. We'll enable growth and progress together.
---
**Job Family Group:**
Technology
---
**Job Family:**
Information Security
---
**Time Type:**
Full time
---
**Primary Location Full Time Salary Range:**
$120,800.00 - $170,800.00
---
**Most Relevant Skills**
Please see the requirements listed above.
---
**Other Relevant Skills**
For complementary skills, please see above and/or contact the recruiter.
---
_Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law._
_If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review_ _Accessibility at Citi ( _._
_View Citi's_ _EEO Policy Statement ( _and the_ _Know Your Rights ( _poster._
Citi is an equal opportunity and affirmative action employer.
Minority/Female/Veteran/Individuals with Disabilities/Sexual Orientation/Gender Identity.
Information Security Specialist
Posted 10 days ago
Job Viewed
Job Description
Toronto, Ontario, Canada
**Hours:**
37.5
**Line of Business:**
Technology Solutions
**Pay Details:**
$91,200 - $136,800 CAD
TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
**Job Description:**
**Responsibilities:**
+ Provide consultation and advice to partners on a broad range Technology Controls / Information Security programs / policies / standards and incidents for own specialized area
+ Conduct project consulting on assessment of risk, definition of required controls, appropriateness of implemented control procedures, vulnerability assessments and any other relevant areas
+ Lead or contribute to completion of risk and control design assessments for an application portfolio, articulate and document impact of control gaps to the business and the overall Bank, risk mitigation and remediation plans, remediation strategy document as applicable
+ Contribute to the definition, development, and oversight of a global security management strategy and framework
+ Ensure technology, processes, and governance are in place to monitor, detect, prevent, and react to both current and emerging technology / security threats against TDBG's business
+ Develop on-going Technology Risk reporting, monitoring key trends and defining metrics to regularly measure control effectiveness for own area
+ Work proactively with technology partners / stakeholders and service/platform owners to ensure all technology security components are integrated into the bank's overall Enterprise Architecture, and any control gaps are addressed.
+ Consult on Regulatory compliance requirements, reporting and questions
+ Provide support and consulting in preparation for Audits and in composing management responses and appropriate remediation activities
+ Participate in computer security incident responses relevant to business (or enterprise wide) and represent respective function and Enterprise position to the business, and business needs to incident response team
+ Continuously enhance knowledge / expertise in own area
+ Keep current on emerging trends / developments and grow knowledge of the business, analytical tools and techniques
+ Prioritize and manage own workload to deliver quality results and meet assigned timelines
+ Support a positive work environment that promotes service to the business, quality, innovation and teamwork and ensure timely communication of issues/ points of interest
+ Identify and recommend opportunities to enhance productivity, effectiveness and operational efficiency
+ Establish effective relationships across multiple business and technology partners, program and project managers
+ Participate in knowledge transfer within the team and business units
**Requirements:**
+ 7+ years of relevant experience
+ Expert knowledge of IT security and risk disciplines and practices
+ Advanced knowledge of of organization, technology controls / security/ risk issues
+ Experience as a lead expert resource in technology controls and information security
+ Strong presentation skills and ability to work with stakeholders at all different levels
+ University degree
+ Information security certification / accreditation an asset
#LI-TECH
**Who We Are:**
TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities and colleagues.
TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you've got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we're here to support you towards your goals. As an organization, we keep growing - and so will you.
**Our Total Rewards Package**
Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical, and mental well-being goals. Total Rewards at TD includes a base salary, variable compensation, and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off, banking benefits and discounts, career development, and reward and recognition programs. Learn more ( Information:**
We're delighted that you're considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we're committed to providing the support our colleagues need to thrive both at work and at home.
Please be advised that this job opportunity is subject to provincial regulation for employment purposes. It is imperative to acknowledge that each province or territory within the jurisdiction of Canada may have its own set of regulations, requirements.
**Colleague Development**
If you're interested in a specific career path or are looking to build certain skills, we want to help you succeed. You'll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD - and we're committed to helping you identify opportunities that support your goals.
**Training & Onboarding**
We will provide training and onboarding sessions to ensure that you've got everything you need to succeed in your new role.
**Interview Process**
We'll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.
**Accommodation**
Your accessibility is important to us. Please let us know if you'd like accommodations (including accessible meeting rooms, captioning for virtual interviews, etc.) to help us remove barriers so that you can participate throughout the interview process.
We look forward to hearing from you!
**Language Requirement (Quebec only):**
Sans Objet
Federal law prohibits job discrimination based on race, color, sex, sexual orientation, gender identity, national origin, religion, age, equal pay, disability and genetic information.
Information Security Specialist
Posted 10 days ago
Job Viewed
Job Description
Toronto, Ontario, Canada
**Hours:**
37.5
**Line of Business:**
Technology Solutions
**Pay Details:**
$91,200 - $136,800 CAD
TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
**Job Description:**
**Responsibilities:**
+ Provide consultation and advice to partners on a broad range Technology Controls / Information Security programs / policies / standards and incidents for own specialized area
+ Conduct project consulting on assessment of risk, definition of required controls, appropriateness of implemented control procedures, vulnerability assessments and any other relevant areas
+ Lead or contribute to completion of risk and control design assessments for an application portfolio, articulate and document impact of control gaps to the business and the overall Bank, risk mitigation and remediation plans, remediation strategy document as applicable
+ Contribute to the definition, development, and oversight of a global security management strategy and framework
+ Ensure technology, processes, and governance are in place to monitor, detect, prevent, and react to both current and emerging technology / security threats against TDBG's business
+ Develop on-going Technology Risk reporting, monitoring key trends and defining metrics to regularly measure control effectiveness for own area
+ Work proactively with technology partners / stakeholders and service/platform owners to ensure all technology security components are integrated into the bank's overall Enterprise Architecture, and any control gaps are addressed.
+ Consult on Regulatory compliance requirements, reporting and questions
+ Provide support and consulting in preparation for Audits and in composing management responses and appropriate remediation activities
+ Participate in computer security incident responses relevant to business (or enterprise wide) and represent respective function and Enterprise position to the business, and business needs to incident response team
+ Continuously enhance knowledge / expertise in own area
+ Keep current on emerging trends / developments and grow knowledge of the business, analytical tools and techniques
+ Prioritize and manage own workload to deliver quality results and meet assigned timelines
+ Support a positive work environment that promotes service to the business, quality, innovation and teamwork and ensure timely communication of issues/ points of interest
+ Identify and recommend opportunities to enhance productivity, effectiveness and operational efficiency
+ Establish effective relationships across multiple business and technology partners, program and project managers
+ Participate in knowledge transfer within the team and business units
**Requirements:**
+ 7+ years of relevant experience
+ Expert knowledge of IT security and risk disciplines and practices
+ Advanced knowledge of of organization, technology controls / security/ risk issues
+ Experience as a lead expert resource in technology controls and information security
+ Strong presentation skills and ability to work with stakeholders at all different levels
+ University degree
+ Information security certification / accreditation an asset
#LI-TECH
**Who We Are:**
TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities and colleagues.
TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you've got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we're here to support you towards your goals. As an organization, we keep growing - and so will you.
**Our Total Rewards Package**
Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical, and mental well-being goals. Total Rewards at TD includes a base salary, variable compensation, and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off, banking benefits and discounts, career development, and reward and recognition programs. Learn more ( Information:**
We're delighted that you're considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we're committed to providing the support our colleagues need to thrive both at work and at home.
Please be advised that this job opportunity is subject to provincial regulation for employment purposes. It is imperative to acknowledge that each province or territory within the jurisdiction of Canada may have its own set of regulations, requirements.
**Colleague Development**
If you're interested in a specific career path or are looking to build certain skills, we want to help you succeed. You'll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD - and we're committed to helping you identify opportunities that support your goals.
**Training & Onboarding**
We will provide training and onboarding sessions to ensure that you've got everything you need to succeed in your new role.
**Interview Process**
We'll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.
**Accommodation**
Your accessibility is important to us. Please let us know if you'd like accommodations (including accessible meeting rooms, captioning for virtual interviews, etc.) to help us remove barriers so that you can participate throughout the interview process.
We look forward to hearing from you!
**Language Requirement (Quebec only):**
Sans Objet
Federal law prohibits job discrimination based on race, color, sex, sexual orientation, gender identity, national origin, religion, age, equal pay, disability and genetic information.
Information Security Engineer
Posted 14 days ago
Job Viewed
Job Description
**What You'll be Doing:**
Do you have a passion for information security and auditing? Looking for an opportunity to apply your Palo Alto firewall expertise in a dynamic and remote environment? In this role, you'll be responsible for auditing firewall changes, threat intelligence, and ensuring compliance with security policies. You'll collaborate with IT teams, analyze logs, and deliver recommendations aligned with business and technical objectives.
You'll report to the Information Security Manager. We're looking for a detail-oriented professional to act as one, as you will encourage and motivate your team to resolve issues, accomplish goals and influence security posture.
**During a Typical Day, You'll:**
+ Serve as the administrator and auditor for:
+ Firewall Changes - conduct post-implementation reviews to ensure compliance and effectiveness
+ Discovery Tool (Census) - monitor alerts for new TTEC-related transactions and assess their security implications.
+ Conduct regular audits and reviews of firewall rules to ensure alignment with security policies and best practices.
+ Analyze firewall logs for anomalies, troubleshooting, and incident response.
+ Collaborate with IT teams to communicate findings and deliver actionable recommendations.
+ Maintain documentation of audit findings, remediation actions, and compliance reports.
+ Stay current with Palo Alto firewall updates, features, and security trends.
**What You Bring to the Role:**
+ Proven experience auditing and administering Palo Alto Firewalls.
+ Strong understanding of firewall principles, rule sets, and traffic flow.
+ Proficiency in analyzing firewall logs and troubleshooting network issues.
+ Solid networking knowledge, including Internet protocols such as TCP/IP, HTTP, HTTPS, SSL, FTP, Telnet, SSH, etc.
+ Excellent communication and interpersonal skills, with the ability to convey technical concepts to non-technical stakeholders.
+ Strong ethics, integrity, and attention to detail.
+ Ability to work independently and collaboratively in a remote environment.
+ Strong organizational skills and ability to manage multiple priorities.
**What You Can Expect:**
+ Supportive of your career and professional development
+ An inclusive culture and community minded organization where giving back is encouraged
+ A global team of curious lifelong learners guided by our company values
+ Ask us about our paid time off (PTO) and wellness and healthcare benefits
And yes. a great compensation package and performance bonus opportunities, benefits you'd expect and maybe a few that would pleasantly surprise you (like tuition reimbursement)
**Compensation:**
The anticipated range is $70,000 - $85,000 CAD annually. Actual compensation offers to a candidate may vary based upon geographic location, work experience, education and/or skill levels.
**About TTEC**
Our business is about making customers happy. That's all we do. Since 1982, we've helped companies build engaged, pleased, profitable customer experiences powered by our combination of humanity and technology. On behalf of many of the world's leading iconic and hypergrowth brands, we talk, message, text, and video chat with millions of customers every day. These exceptional customer experiences start with you.
TTEC is proud to be an equal opportunity employer where all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. TTEC embraces and is committed to building a diverse and inclusive workforce that respects and empowers the cultures and perspectives within our global teams. We aim to reflect the communities we serve, by not only delivering amazing service and technology, but also humanity. We make it a point to make sure all our employees feel valued, belonging, and comfortable being their authentic selves at work. As a global company, we know diversity is our strength because it enables us to view things from different vantage points and for you to bring value to the table in your own unique way.
**Title:** _Information Security Engineer_
**Location:** _CAN-ON-London_
**Requisition ID:** _04775_
Information Security Analyst
Posted today
Job Viewed
Job Description
Job Description
Description
At ActiveState, we're dedicated to helping DevOps, InfoSec, and Development teams improve their security and get secure applications to market faster. We're the only solution that offers Intelligent Remediation, a process that helps organizations prioritize vulnerabilities, assess the impact of updates, and quickly get fixes into production.
We're looking for an Information Security Analyst to join our team. This is a great opportunity for a hands-on individual who is eager to learn and grow in the information security field. You'll play a crucial role in supporting our security program by assisting with the development, implementation, and maintenance of policies and controls that protect our systems and assets.
This is a unique opportunity to contribute to security research that will directly influence our products and help protect millions of developers worldwide.
You're focused on our customers —Developers and DevOps Engineers. You understand that your role is to help solve their problems.- You're passionate about open source and want to learn more about the communities that build the software we all rely on.
- You're a problem-solver. You enjoy finding the best approach to a challenge, thinking about customer issues, not just the technology itself.
- You're a great communicator. You can explain technical topics clearly and concisely to help others understand what needs to be done.
- You have good judgment. You're learning to prioritize tasks and understand which problems need immediate attention and which can wait.
- You're a collaborator. You work well with others across different teams like Research, Product, and Engineering.
- You're enthusiastic about our mission and want to help our platform become a global success.
What You'll Do: The Mission
- Assist in managing the cross-functional InfoSec Squad to maintain and enhance compliance management and continually monitoring, assessing and strengthening ActiveState’s security posture.
- Collaborate with Product, Engineering, and Business teams to embed security into systems and processes, ensuring compliance with secure development frameworks and driving continuous security improvements.
- Assist in implementing and maintaining information security policies, standards and guidelines for data governance, privacy, and access controls and leading audits as required.
- Assist in the maintaining SOC 2 Type 2 compliance and achievement of additional certifications, ensuring alignment with evolving industry regulations and frameworks (e.g., ISO 27001, NIST, GDPR, HIPAA, PCI-DSS), while staying ahead of evolving standards, and continuously strengthening the overall security posture.
- Assist in risk assessments, vulnerability management, and incident response, including 24/7 monitoring, alert triage, initial investigations, and maintaining detailed records of these along with remediation efforts.
- Facilitate and support the execution of SAST, DAST, penetration testing, and other industry-leading security assessments to achieve organizational security objectives.
- Support the evaluation and management of third-party vendors to ensure they meet compliance and certification requirements.
- Coordinate and support security awareness and training programs to strengthen the security culture across the organization.
- Coordinate responding to security questionnaires with internal and external parties.
- Stay current with emerging threats, vulnerabilities, and security technologies.
- Contribute to security reporting and metrics to inform leadership decisions and drive continuous improvement efforts.
- Assist in configuring and maintaining security tools and systems, such as SIEM platforms and endpoint protection solutions, to ensure optimal performance and coverage.
- Perform daily review of CVEs and other vulnerability data related to our product offerings and produce the reports required for our teams to action them, including VEX documents, risk register, etc.
Qualifications & Experience
- Bachelor’s degree in Computer Science/Information Technology, or equivalent through specialized coursework and/or training.
- Recent graduate in relevant field up to 3 years experience or demonstrated knowledge of infosec frameworks and methodologies in information security, with a desire to learn about security research.
- Currently pursuing or have obtained a relevant security certification (e.g., CompTIA Security+, CEH)
- Basic understanding of the software development lifecycle (SDLC), including concepts like CI/CD pipelines.
- Familiarity with GDPR is a plus
- Experience with SOC II is a plus
- Knowledge of theory and principles within a professional IT discipline and basic cybersecurity practices (e.g. Familiarity with industry standards such as ITIL).
- A foundational understanding of IT and cloud environments.
- An eagerness to learn how to translate technical security risks into business impact.
- Interest in or some experience with scripting and programming (Python is a plus).
- Good written and verbal communication skills.
- A genuine passion for open-source software and a commitment to security.
- The ability to work independently and manage your time effectively.
What We Offer
- A competitive salary and comprehensive benefits.
- A remote-first culture with a focus on work-life balance and flexibility.
- The opportunity to work on a mission-driven product that has a meaningful impact on the global software ecosystem.
- A collaborative and innovative environment with a team of passionate and talented individuals.
Manager Information Security
Posted today
Job Viewed
Job Description
Job Description
Founded in 1974, CMiC today delivers comprehensive and advanced enterprise and field operations solutions, purpose-built for construction and capital projects companies. CMiC’s powerful software transforms how firms optimize productivity, minimize risk and drive growth by planning and managing all financials, projects, resources, and content assets - all from a single database platform.
In the past several years, the construction industry has experienced unprecedented changes driven by new technologies - including integration with multi-dimensional modeling, an explosion of cloud-based offerings and the demand for robust mobile capabilities. CMiC has kept pace by constantly upgrading and enhancing our advanced platform to reflect the changing needs of the industry, leading to significant growth as a company.
Job Overview/Position Summary
The Manager, Information Security will assist the Chief Information Security Officer (CISO) to develop and implement cybersecurity strategies that protect our organization's information assets and those of our customers’. This role requires a good understanding of cybersecurity principles, strong leadership skills, and the ability to collaborate across departments to achieve security goals
Primary Responsibilities:
- Assist in the development, implementation, and management of the organization's cybersecurity strategy.
- Monitor and analyze security threats, vulnerabilities, and incidents to identify risks and mitigate them effectively.
- Assist in the design and enforcement of security policies, standards, and procedures.
- Oversee implementation and evidence collection of the SOC 1 & 2 and ISO 27001 audits
- Collaborate with IT, legal, and other internal stakeholders to ensure alignment with security protocols and regulatory requirements.
- Provide technical and operational guidance in the development and implementation of information security programs.
- Manage security incidents and coordinate incident response efforts, including root cause analysis and remediation.
- Stay current with emerging security trends, technologies, and regulatory changes.
- Report on security metrics and provide updates to senior management and the Information and Privacy Governance Committee.
Other responsibilities
- Responsible for the development and maintenance of disaster recovery and business continuity plans and table top exercises.
- Responsible for regular security reviews and risk assessments to identify and address potential security weaknesses.
Requirements
Education and Experience:
- Bachelor's degree in Computer Science, Information Technology, or a related field.
- Certified Information Systems Security Professional (CISSP) or other relevant certifications.
- Minimum of 3 years of experience in information security management or a related role.
Skills and Competencies:
- A solid understanding of cybersecurity principles, network security, encryption, and vulnerability management
- Strong understanding of risk management framework and ability to identify, assess, and mitigate risks to the organization's information assets.
- Ability to develop and implement long-term security strategies that align with the organization's goals.
Preferred Qualifications (Optional)
- Strong knowledge of cybersecurity frameworks (e.g., NIST, ISO 27001, AICPA Trust Services Criteria) and regulatory requirements.
- Be a self-starter and take ownership of initiatives.
- Excellent analytical, problem-solving, and decision-making skills.
- Strong communication and interpersonal skills, with the ability to effectively communicate complex security concepts to non-technical stakeholders.
- Proven leadership abilities and experience in managing security team.
- Having IT Operational experience is a bonus.
Work Environment (Optional)
- CMiC has a hybrid work environment. Successful candidate is expected to be in the office one to two days a week.
Benefits
- Competitive benefits Package (including Health & Dental benefits)
- Paid vacation and personal days
- Townhall meetings where all employees are encouraged to participate in open discussions
- Located on York University’s campus, easily accessible by transit (TTC, GO, etc.), walking distance to shopping and restaurants
- Outdoor lunch space, including picnic tables
- An active Social Events Committee (past events include annual seasonal parties, pool and bowling tournaments, karaoke nights, Game nights, BBQs, and more)
- Health and Wellness focus including virtual yoga classes and wellness webinars
- RRSP Matching Program after 2 years of employment
- Experience in a rapidly growing, socially responsible corporation
CMiC is an Equal Opportunity Employer. In accordance with the Accessibility for Ontarians with Disabilities Act, 2005 and the Ontario Human Rights Code, CMiC will provide accommodation to applicants with disabilities throughout the recruitment, selection and/or assessment process. If selected to participate in the recruitment, selection and/or assessment process, please inform Human Resources staff of the nature of any accommodation(s) that you may require.
Be The First To Know
About the latest Safety data Jobs in Canada !
Information Security Engineer
Posted today
Job Viewed
Job Description
Duties and Responsibilities
As a Staff Information Security Engineer, you will be joining a diverse team of mixed background technologists. Your mandate as Staff Information Security Engineer is to provide secure and stable platform solutions that empower our organization to create the highest quality services for our customers. On a day to day basis, you’ll assist with triaging information security alerts, events, and investigations for potential security incidents by performing detailed analysis activities. You will take corrective actions if necessary and escalate as appropriate.
Qualifications
● Bachelor’s degree in computer science, systems analysis or a related study, or equivalent experience.
● CISSP (certified with Endorsement phase fully completed).
● 5+ years of demonstrable experience spanning at least four different CISSP domains.
● Experience working with Compliance programs like PCI-DSS or SOC2.
● Strong understanding of defense-in-depth strategies and implementation of technical controls across the entire organization, with ability to assess gaps and risks around computing systems and operations.
● Experience developing and adopting information security and governance standards, policies and procedures.
● Experience in conducting successful vulnerability assessments across various infrastructure tiers, including penetration testing, scanning and remediation activities.
● Experience in cloud native technologies, especially around Kubernetes, and cloud environments is a must. ● Strong understanding of networking concepts, protocols and architectures.
● Strong understanding of security concepts around PKI, TLS and encryption.
● Experience using network and security assessment tools – both at host and at network tier.
● Experience with IAM, SSO, RBAC, and other AuthN/AuthZ management technologies.
● Familiarity with CVE databases, vulnerability scoring systems (e.g., CVSS), and security industry standards such as ISO 27001 and NIST.
● Strong proficiency in Linux/Unix based operating systems, Python programming language and Shell scripting.
● Other industry standard certifications like CISA, CISM, CGRC and CRISC are a plus.
● Experience as a team lead is a plus.
Information Security Engineer
Posted today
Job Viewed
Job Description
Duties and Responsibilities
As a Staff Information Security Engineer, you will be joining a diverse team of mixed background technologists. Your mandate as Staff Information Security Engineer is to provide secure and stable platform solutions that empower our organization to create the highest quality services for our customers. On a day to day basis, you’ll assist with triaging information security alerts, events, and investigations for potential security incidents by performing detailed analysis activities. You will take corrective actions if necessary and escalate as appropriate.
Qualifications
● Bachelor’s degree in computer science, systems analysis or a related study, or equivalent experience.
● CISSP (certified with Endorsement phase fully completed).
● 5+ years of demonstrable experience spanning at least four different CISSP domains.
● Experience working with Compliance programs like PCI-DSS or SOC2.
● Strong understanding of defense-in-depth strategies and implementation of technical controls across the entire organization, with ability to assess gaps and risks around computing systems and operations.
● Experience developing and adopting information security and governance standards, policies and procedures.
● Experience in conducting successful vulnerability assessments across various infrastructure tiers, including penetration testing, scanning and remediation activities.
● Experience in cloud native technologies, especially around Kubernetes, and cloud environments is a must. ● Strong understanding of networking concepts, protocols and architectures.
● Strong understanding of security concepts around PKI, TLS and encryption.
● Experience using network and security assessment tools – both at host and at network tier.
● Experience with IAM, SSO, RBAC, and other AuthN/AuthZ management technologies.
● Familiarity with CVE databases, vulnerability scoring systems (e.g., CVSS), and security industry standards such as ISO 27001 and NIST.
● Strong proficiency in Linux/Unix based operating systems, Python programming language and Shell scripting.
● Other industry standard certifications like CISA, CISM, CGRC and CRISC are a plus.
● Experience as a team lead is a plus.
Information Security Engineer
Posted today
Job Viewed
Job Description
Duties and Responsibilities
As a Staff Information Security Engineer, you will be joining a diverse team of mixed background technologists. Your mandate as Staff Information Security Engineer is to provide secure and stable platform solutions that empower our organization to create the highest quality services for our customers. On a day to day basis, you’ll assist with triaging information security alerts, events, and investigations for potential security incidents by performing detailed analysis activities. You will take corrective actions if necessary and escalate as appropriate.
Qualifications
● Bachelor’s degree in computer science, systems analysis or a related study, or equivalent experience.
● CISSP (certified with Endorsement phase fully completed).
● 5+ years of demonstrable experience spanning at least four different CISSP domains.
● Experience working with Compliance programs like PCI-DSS or SOC2.
● Strong understanding of defense-in-depth strategies and implementation of technical controls across the entire organization, with ability to assess gaps and risks around computing systems and operations.
● Experience developing and adopting information security and governance standards, policies and procedures.
● Experience in conducting successful vulnerability assessments across various infrastructure tiers, including penetration testing, scanning and remediation activities.
● Experience in cloud native technologies, especially around Kubernetes, and cloud environments is a must. ● Strong understanding of networking concepts, protocols and architectures.
● Strong understanding of security concepts around PKI, TLS and encryption.
● Experience using network and security assessment tools – both at host and at network tier.
● Experience with IAM, SSO, RBAC, and other AuthN/AuthZ management technologies.
● Familiarity with CVE databases, vulnerability scoring systems (e.g., CVSS), and security industry standards such as ISO 27001 and NIST.
● Strong proficiency in Linux/Unix based operating systems, Python programming language and Shell scripting.
● Other industry standard certifications like CISA, CISM, CGRC and CRISC are a plus.
● Experience as a team lead is a plus.