Security Analyst II
Job in
Toronto, Ontario, C6A, Canada
Listed on 2026-09-24
Listing for:
CI Financial
Full Time
position Listed on 2026-09-24
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Job Description & How to Apply Below
At CI, we see a great place to work as one that is a safe place for everyone to have a voice, where people are empowered to take ownership over meaningful work, where there is an opportunity to grow through stretching themselves, where they can work on innovative products and projects, and where employees are supported and engaged in doing so.
Key Responsibilities Security Engineering and Technology- Deploy, integrate, configure and enhance security solutions in accordance with approved architecture, change management and operating procedures.
- Monitor security platforms for appropriate operation, data quality, coverage, performance and control effectiveness.
- Lead technical troubleshooting and coordinate with internal teams and vendors to resolve security technology issues.
- Evaluate security capabilities and recommend enhancements that measurably reduce risk, improve detection or increase operational efficiency.
- Develop scripts, queries, automation or repeatable workflows to improve analysis, reporting and response.
- Lead application security scanning activities across SAST, DAST, IaC, SAC, API testing and support teams in interpreting findings and selecting remediation approaches.
- Partner with application owners and developers to embed security requirements into delivery processes and resolve material findings.
- Provide security guidance through the system development lifecycle, including architecture design review, threat modelling, secure design and security testing.
- Review cloud applications, configurations, identity controls, data flows and logging to identify security risk and required safeguards.
- Investigate and triage complex security alerts and suspected compromises; determine scope, impact and required containment actions.
- Lead or coordinate incident response activities, including investigation, containment, eradication, recovery, evidence preservation, documentation and lessons learned.
- Improve detection coverage by identifying telemetry gaps, refining use cases and validating alert effectiveness.
- Perform proactive threat hunting using endpoints, network, identity, cloud and SIEM telemetry to identify advanced or previously undetected threats.
- Analyse threat intelligence and security advisories to determine relevance to CI and recommend defensive actions.
- Participate in the after-hours on-call rotation and support high-severity incidents as required.
- Lead infrastructure vulnerability management activities, including scan coverage, validation, prioritisation, exception handling, remediation tracking and reporting.
- Partner with infrastructure, application and platform teams to drive risk-based remediation of vulnerabilities and security misconfigurations.
- Assess exploitability, asset criticality, threat intelligence and business impact to establish remediation priorities.
- Monitor emerging and actively exploited vulnerabilities, coordinate rapid exposure assessment and recommend compensating controls where immediate remediation is not possible.
- Identify recurring control gaps and recommend sustainable process or technology improvements.
- Advise business and technology projects on security requirements, control design, risk treatment and compliance with CI policies and standards.
- Conduct structured security and threat risk assessments; document findings, risk rationale, mitigation recommendations and residual risk.
- Assess new technologies and services for security risk and document clear, actionable requirements.
- Maintain clear risk records and track agreed remediation actions to closure or formally approved acceptance.
- Contribute to security policies, standards, baselines, procedures, playbooks and control documentation.
- Support audits, regulatory reviews, client due diligence and security assessments by providing accurate control evidence and subject-matter expertise.
- Present security findings and recommendations in language appropriate for technical teams, business leaders and executive stakeholders.
- Recommend risk treatment and control improvements; formal business, risk acceptance and production-change approvals remain subject to CI governance
- Lead defined work streams and coordinate activities across Security, Infrastructure, Application, Cloud, Architecture, Risk, Privacy, Legal and vendor teams.
- Provide technical guidance, peer review and knowledge…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×