Creyos (formerly Cambridge Brain Sciences) is a leading growth-stage B2B SaaS Health Tech company. Our proprietary brain health tools, including digital cognitive assessments and mental health questionnaires, are used by healthcare practitioners treating mental health conditions, brain injuries, aging, and other patient populations throughout the world, as well as by leading researchers. To learn more about our organization, please visit .
You will be part of a team that includes not just your typical SaaS business functions (Sales, Marketing, Customer Success), but also engineers, psychologists, business leaders, and even a world-renowned neuroscientist. We are proud to say that you will be surrounded by some of the smartest, enthusiastic, hard working and dedicated people that you’ll ever meet (at least, that we’ve ever met!).
Whowe are looking for:
At Creyos, we understand that solving big challenges demands unwavering resilience and determination. We don’t stop until we achieve our goals. People who thrive at Creyos are driven, curious, hardworking, and enthusiastic about scaling a company - along with having a good sense of humor. If this resonates with you, we’d love to hear from you!
We are looking for a Cybersecurity Analyst to join our team to drive the implementation of compliance and information security initiatives, and ensure our business practices meet the requirements of industry standards. This role will support our team as our on-site cybersecurity point of contact for IT support, hardware asset management, and physical security.
This is an in-person role located at our Toronto office.
What you will be doing:As a Cybersecurity Analyst at Creyos, you will:
- - Perform vulnerability/risk assessments and control testing across applications, networks, and infrastructure to remediate vulnerabilities and support secure software deployments.
- - Lead initial triage, resolution, and escalation for security incidents and support requests while monitoring the latest advisories, alerts, and regulatory changes.
- - Drive physical and technical security assessments, lead audit evidence collection/inquiries, and deliver remediation reports to key stakeholders.
- - Develop, recommend, and maintain security policies, standard operating procedures (SOPs), and operational runbooks.
- - Administer end-to-end identity life cycles (provisioning, offboarding, and role-based access control) grounded in least-privilege principles.
- - Maintain complete oversight and lifecycle inventory of all hardware assets.
- - Deliver security-centric on-site IT support, including network hardening, hardware setup, account provisioning, and troubleshooting.
- - Mentor team members and drive internal knowledge sharing through technical presentations and documentation.
- - 1-3 years professional work experience in information security;
- - Working knowledge of collaboration tools such as JIRA and Confluence;
- - Understanding of core security concepts: least privilege, access control, incident handling, and asset lifecycle management;
- - Ability to configure, implement, and maintain security tools as well as the configuration of data sources for metric reporting/tracking;
- - Experience with security tools and methodologies for conducting vulnerability and application security assessments;
- - Ability to analyze IT solutions and technology infrastructure to identify and assess security vulnerabilities, threats, and risks;
- - Understanding of industrial frameworks such as NIST, SOC 2, or similar compliance frameworks;
- - Ownership mindset, comfortable being the accountable on-site cybersecurity resource;
- - Think analytically and synthesize technical information from various sources;
- - High level of…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).