EllisDon Corporation Logo

EllisDon Corporation

Information Security Analyst

Posted 7 Days Ago
Be an Early Applicant
In-Office
Mississauga, ON, CAN
Mid level
In-Office
Mississauga, ON, CAN
Mid level
Supports cybersecurity governance, risk, and compliance activities, including risk assessments, enterprise risk tracking, vendor evaluations, control remediation, audit readiness, security policies, evidence workflows, and awareness training. Partners with technical teams to implement secure solutions and supports compliance with SOC 2, NIST, ISO 27001, CMMC, CPCSC, and ITSP standards.
The summary above was generated by AI

Connect with us LinkedIn, Instagram, Facebook, Twitter.


Thinking about a change?


We recognize that the construction industry is changing at a rapid pace and we continually strive to be at the forefront. Our core values empower people to deliver great careers to one another and develop creative solutions for complex problems on some of the most exciting projects. It doesn’t matter what your expertise and craft is – there are no boundaries. We are a group of professionals with a variety of expertise within pre-construction, construction, and post-construction. To learn more, check out our Cradle to Grave services and hear from our team directly about what a career at EllisDon could look like for you. As you can see, we are a diverse bunch.


Above all, we are a group of individuals with unique experiences and at EllisDon, we choose to celebrate the strength in our differences, every day. EllisDon’s commitment to Inclusive Diversity is to work together to create an environment where every employee feels safe to be their true and authentic self. Ultimately, EllisDon’s purpose is to provide people with similar values the opportunity to achieve to their full potential; to deliver that opportunity for great careers to one another; and to contribute meaningfully to the community we share with others.


In case you’re curious, here’s what the industry thinks of us and some of the impacts we've made to the communities we work in and our latest Impact Report, highlighting how we're putting our values into practice in areas such as the climate & environment, inclusive diversity, indigenous relations, and health and safety.


This role is ideal for a cybersecurity professional looking to expand into GRC or a GRC practitioner who enjoys building and improving security processes, programs, and controls in a growing environment.

You as an Information Security Analyst will:

  • Support identification, assessment, and tracking of IT/cyber risks; maintain the enterprise risk register and remediation lifecycle
  • Perform risk assessments for systems, projects, and vendors; support ongoing third-party compliance activities
  • Contribute to GRC program operations (policies, standards, procedures, exception tracking, evidence workflows)
  • Support remediation of risks, control gaps, and audit findings across teams
  • Partner with IT (Service Delivery, Operations, DevOps) to enable secure system and solution implementation
  • Support security awareness program, including training, reporting, and modern threat simulations (phishing, social engineering, AI-driven attacks)
  • Support compliance across SOC 2, NIST, ISO 27001, and CMMC / CPCSC / ITSP, ensuring consistent control implementation
  • Contribute to key GRC initiatives, including risk maturity, audit readiness, vendor compliance, and standardization of security requirements across the organization 
     

This is the right role for you, if you have:

  • 2–5 years of experience in Information Security, Cybersecurity, Governance, Risk & Compliance (GRC), IT Risk Management, or related disciplines.
  • Experience performing assessments including security reviews, risk assessments, vendor evaluations, compliance activities, or governance functions.
  • Strong security foundation with a risk‑based approach to decision‑making and the ability to evaluate security controls effectively.
  • Ability to identify practical mitigation by assessing control gaps and recommending realistic, business‑aligned improvements.
  • Demonstrated interest in GRC and applying security concepts through a business‑focused, risk‑driven lens; interest in developing expertise across multiple GRC disciplines.
  • Experience contributing to program maturity including the development, implementation, or enhancement of security and GRC processes, programs, or initiatives.
  • Ability to work independently while influencing stakeholders across technical and non‑technical teams.
  • Strong analytical and critical thinking skills with the ability to evaluate controls, identify gaps, and propose actionable improvements.
  • Effective communication skills with the ability to articulate risks and recommendations to diverse audiences.
  • Strong interpersonal, verbal, and written communication skills.
  • Self‑motivated with strong prioritization skills and the ability to drive initiatives forward.
  • Post‑secondary education in IT, Cybersecurity, Information Security, or a related field, or equivalent experience.
  • Industry certifications such as Security+, CISSP, CISA, CRISC, or similar are considered an asset.
  • Working knowledge of security frameworks such as NIST CSF, ISO 27001, SOC 2, CIS Controls, CMMC, CPCSC, or similar standards.
  • The salary range for this role is $66,000 - $80,000.

EllisDon is proud to provide this unique career opportunity that provides continuous learning, opportunity for growth, and a competitive compensation package within an environment that is committed to inclusion and respects diversity.

Go ahead and be yourself. We'll pay you for it!

We are an equal opportunity employer. We welcome people of any age, culture, subculture, gender identity or expression, sexual orientation, nationality, ethnicity, race, size, mental or physical status, veteran status, religion, language, political opinion, working-style preference, family status, education, and socio-economic status. The EllisDon core values of Integrity and Mutual Respect welcomes everyone, at work and in the community, and our value of Mutual Accountability, means that we all have a role to play. As an EllisDon employee, this will ultimately be your commitment to Inclusive Diversity.

Accommodation for Applicants with disabilities will be made during the recruitment process when requested.

We are committed to providing a positive candidate experience and ensuring timely updates are provided to all candidates. If you haven’t already, be sure to create a profile on our Careers page to remain up to date on the status of your application and learn about new career opportunities as they arise.

EllisDon uses AI tools to assist in screening and assessing applicants for this position. 

Similar Jobs

5 Days Ago
Hybrid
Toronto, ON, CAN
Senior level
Senior level
Digital Media • Music • News + Entertainment
Oversee network security as a cybersecurity subject matter expert, including network assessments, secure configurations, vulnerability scanning, risk identification, compliance, and mitigation planning. Advise technical and business stakeholders, communicate security posture to management, develop security technology strategies, and coordinate multidisciplinary design and implementation projects. Ensure assigned initiatives are delivered effectively, on time, and within budget. The role requires occasional travel and includes a mandatory criminal record check.
Top Skills: Access Control ListsCloud SecurityCobitCybersecurityEncryptionFirewallsIds/IpsInformation SecurityInternet Filtering TechnologiesIp NetworksIso 27001Iso 27002Iso 27005ItilLanNdrNetwork SecurityNetwork SwitchesNistRoutersRouting ProtocolsSsl CertificatesVpnsVulnerability Scanning ToolsWanWeb Infrastructure Security
5 Days Ago
In-Office
Toronto, ON, CAN
Senior level
Senior level
Fintech • Insurance • Financial Services
Leads enterprise response to significant fraud, financial crime, insider risk, and fraud-related cybersecurity incidents. Coordinates containment, recovery, remediation, investigations, and closure while assessing customer, financial, regulatory, operational, and reputational impacts. Provides executive-level briefings and risk recommendations, collaborates across fraud, cybersecurity, technology, legal, compliance, and investigations teams, evaluates fraud controls, supports audits and regulatory reviews, and drives post-incident improvements. Participates in 24x7x365 follow-the-sun and on-call support.
7 Days Ago
In-Office
Toronto, ON, CAN
Senior level
Senior level
Fintech • Insurance • Financial Services
Supports enterprise vulnerability management governance and daily operations, including application security scanning, vulnerability data validation, remediation tracking, reporting, secure coding training, audit support, and process improvement. Partners with security, development, technology, risk, compliance, and business teams to resolve issues, maintain controls and documentation, communicate risks, and improve vulnerability management outcomes.
Top Skills: Application Security ScanningCommon Vulnerabilities And Exposures (Cves)Common Weakness Enumeration (Cwes)Patch ManagementQualys VmSecure Software DevelopmentServicenow Security OperationsSnykVeracodeVulnerability ManagementWiz

What you need to know about the Toronto Tech Scene

Although home to some of the biggest names in tech, including Google, Microsoft and Amazon, Toronto has established itself as one of the largest startup ecosystems in the world. And with over 2,000 startups — more than 30 percent of the country's total startups — Toronto continues to attract new businesses. Be it helping entrepreneurs manage their finances, simplifying business operations by automating payroll or assisting pharmaceutical companies in launching new drugs, the city's tech scene is just getting started.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account