systems security analyst

BC Pension CorporationVictoria, Canada
Full TimeOn-siteMidFrom CA$88,693 / YearLimited info disclosed
35 views0 applications

Description

Security Analyst Threat PreventionClassification:Information Systems R24Salary Range:$88,693.54 to $101,037.75 per annum (Includes 9.9% market adjustment)Reports to:Team Lead, IT SecurityUnion/Excluded:BCGEUSecurity Screening:RequiredJob Type:Regular full timeAdditional Info:An eligibility list to fill future vacancies may be established. Testing may be required. Lesser qualified applicants may be appointed at a lower level. This temporary opportunity may be extended or made regular. We are seeking a Security Analyst to join our Threat Prevention team in VICTORIA, British Columbia, Canada. As a Security Analyst, you will work closely with business and technology stakeholders to ensure security requirements are embedded into systems, processes, and projects across the organization. You are responsible for protecting the confidentiality, integrity, and availability of corporate information systems by identifying, assessing, and mitigating cybersecurity risks. You will focus on investigating security incidents, threats, exposures and implementing security controls to mitigate risk; conducting Threat and Risk Assessments (TRAs); and developing, maintaining, and enhancing security policies, and standards.Hybrid Work Model This position is located in our Victoria, BC office. You will have the flexibility to work part of the time on-campus and part of the time off-campus. The requirement for on-campus presence is a minimum of 40% of your schedule in a month.Additional requirements are determined by the role functions and operational needs of each business area. Responsibilities Supports threat, risk, and cost?benefit analyses of systems, processes, and information?sharing agreements to inform information security priorities and management decisions. Researches, investigates, and analyzes security incidents, threats, and vulnerabilities, recommending and implementing appropriate risk?reducing controls. Contributes to the development and continuous improvement of corporate security policies, procedures, standards, and initiatives by identifying gaps in existing baselines and supporting the development of appropriate security controls and remediation strategies. Supports security best practices into business processes, projects, and system designs. Develops and maintains processes and procedures to support the delivery of security operations, including threat and risk assessments, incident response, control implementation, and ongoing security monitoring across all systems. Ensures security requirements for new and enhanced systems are aligned with established security architecture, operational processes, and procedures. Maintains awareness of emerging technologies, cybersecurity threats, and industry best practices through ongoing research and professional development, and provides informed recommendations on emerging risks and technology solutions Represents the Cybersecurity team on projects, working groups, and task forces to ensure security standards are integrated; sensitive information is protected, and security awareness is promoted. Collaborates with IT, security, and development teams to remediate identified security issues and support the ongoing security of systems and networks. Monitors and investigates events from various tools such as IPS and Zero Trust SSE. QualificationsMust have A degree or diploma in computer science or a related field. An equivalent combination of education, training and experience may be considered. Security certification such as MS-SC200, GIAC Certified Incident Handler (GCIH), or currently obtaining a similar security certification. A minimum of three years of recent, related experience that includes the following: Monitoring, identifying, and assessing security risks from both business and technical perspectives. Working with security platforms, operational controls, and detection and response processes in modern, cloud?enabled environments. Supporting security investigations and inciden