JobConnect

Senior Analyst, IT Common Services

Position: Senior Analyst (x1)

Dept: IT common Services

Posting ID: 8463

Status: Permanent Full-time

Role Level: PG 08 $38.26 -$47.82

Hours of work/Shift:

Site: Credit Valley Hospital

Posted:

Internal Deadline:

Trillium Health Partners is one of Canada’s largest community-based teaching hospitals, serving the growing and diverse populations of Mississauga, West Toronto, and surrounding communities through the Credit Valley Hospital, the Mississauga Hospital, the Queensway Health Centre, the Reactivation care Centre (Church Site) and the new THP-UHN Reactivation Care Centre. Guided by our values of compassion, excellence, and courage, and through our strategic roadmap,Plan to 2030, we are creating a new kind of health care - defined not by illness, but by the health and well-being of people and communities.

As an integral member of the Information Services division, the Senior Security Analyst reports to the Manager, Cyber Defense & Identity Access Management and supports the delivery, operation, and continuous improvement of THP’s information security program. The role provides hands-on expertise across cyber defense, identity and access management, cloud and Microsoft 365 security, incident response, vulnerability management, security governance, and emerging technology risk management.

The Senior Security Analyst will work closely with technical teams, business stakeholders, clinical partners, vendors, and leaders to reduce organizational risk while enabling secure adoption of technology. The role is responsible for supporting security architecture, operational monitoring, threat detection and response, secure configuration of Microsoft cloud services, responsible use of AI-enabled capabilities, and day-to-day security operations in a complex healthcare environment.

Duties and Responsibilities

This is not an exhaustive list, and the details are bound to change over time.

Security:

  • Identify and report on information security risks, threats, vulnerabilities and breaches and make recommendations on remediation opportunities to manage risks.
  • Develop, implement and maintain information security governance, policies, procedures and controls in coordination with Manager, Cyber Defense & Identity Access Management, and the Security Technical Lead, to ensure continuous improvement aligned with the changing risk landscape.
  • Assist and support the development and delivery of an Information Security strategic and operating plans.
  • Implement best practice procedures to ensure uniform security architecture throughout Application Development, Operations and Infrastructure.
  • Ensure the team develops and implements the information technology security architecture framework.
  • Ensuring the continuous delivery of day-to-day information security and privacy operations.
  • Ensure team can provide 7x24 monitoring and security incident response.
  • Leads or commissions forensic analysis on security incidents.
  • Ensure the security processes and procedures are followed at all times and escalations are performed in a timely manner.
  • Leads design and execution of vulnerability assessments, penetration tests, risk assessments, and security and privacy audits and ensures they are performed on regular intervals.
  • Develop materials and promote activities to foster information security awareness across the organization.
  • Ensures that projects, programs and other activities in IS are implemented with proper consideration given to information security.
  • Determines minimum security requirements for applications and systems based on policy, data sensitivity, exposure, and other factors.
  • Maintain current knowledge security industry trends and technologies
  • Evaluate new technologies including emerging concepts for security impact on the environment and makes appropriate recommendations.
  • Monitor internet for emerging threats of new attacks and threat vectors.
  • Leads technical implementations of security-related systems.
  • Administer, monitor, and continuously improve Microsoft 365 security capabilities, including Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Intune, Secure Score, and related security and compliance controls.
  • Perform security monitoring, triage, investigation, threat hunting, detection engineering, and incident response using Microsoft security tools, SIEM/SOAR capabilities, Kusto Query Language (KQL), endpoint telemetry, email security data, identity signals, cloud application data, and third-party security platforms.
  • Support the secure adoption and governance of artificial intelligence, automation, and AI-enabled productivity or development tools by assessing risks related to data protection, privacy, identity, access, model output, vendor controls, acceptable use, and compliance with responsible AI practices.
  • Understand current regulatory environment and related implications to security management compliance.
  • Effectively communicate with a wide range of technical and non-technical personnel.
  • Review and validate IT controls and assess the impact of any related IT deficiencies.
  • Ensure that all documentation and materials are regularly reviewed and up to date.
  • Vendor relationship management.
  • After hours on call work is required for this role.

Work Experience Requirements

  • 3+ years of Information Security experience with expertise in either client/server, network or application security engineering.
  • Direct working experience performing IT security and risk assessments and audits:
  • Hands-on experience with Microsoft 365 security and identity platforms, such as Microsoft Defender XDR, Microsoft Defender for Endpoint, Defender for Office 365, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Intune, Conditional Access, multi-factor authentication, data loss prevention, audit logging, and secure configuration management.
  • Experience evaluating security risks associated with cloud services, software-as-a-service platforms, automation, artificial intelligence, generative AI tools, and integrations with enterprise data or identity systems.
  • Working knowledge of information security frameworks such as the National Institute of Standards and Technology (NIST) Cyber Security Framework (CSF), and ISO 2700 standards.
  • Working knowledge of auditing frameworks such as COBIT or PCI.
  • Certified Information Systems Security Professional (CISSP) certification is an asset.
  • Health care experience an asset.
  • Experience interpreting industry and regulatory requirements and authoring supporting controls.
  • Strong business and technical acumen.
  • Excellent written and verbal communication skills.

Skills and Knowledge

  • Identity and access management (I&AM) experience with Active Directory, NTFS permissions, LDAP, and Single Sign On (SSO) solutions.
  • Experience developing and maturing information security governance frameworks, such as NIST CSF
  • Experience performing Application penetration testing
  • Application and database security experience including code reviews.
  • Network and security engineering experience including log and network traffic capture analysis.
  • Strong understanding of network protocols (e.g. IP, TCP/IP) and other network administration protocols.
  • Familiarity with Windows, Linux, and UNIX based operating systems.
  • Familiarity and knowledge of application development processes and typical application architectures.
  • Familiarity and understanding of encryption concepts.
  • Experience with system hardening procedures for Windows, Linux and UNIX platforms.
  • Security operations experience with firewalls, IDS/IPS, SEIM and end-point protection platforms.
  • Experience with Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Microsoft Intune, Defender for Cloud Apps, Defender for Office 365, and related Microsoft security and compliance portals.
  • Ability to use Kusto Query Language (KQL), advanced hunting, analytics rules, dashboards, automation playbooks, and incident workflows to support threat detection, investigation, response, and reporting.
  • Working knowledge of AI security, responsible AI governance, data protection considerations for generative AI, secure prompt and output handling, vendor risk review for AI-enabled solutions, and controls required to protect sensitive healthcare information.
  • Familiarity with Web application development experience using .NET framework as well client side applications for all mobile platforms.
  • Familiarity with database technology including Oracle and MS SQL.
  • Experience in with Business Continuity Plans and Disaster Recovery Plans.
  • Familiarity with Information Technology Infrastructure Library (ITIL) concepts. Familiarity with architecture frameworks such as The Open Group Architecture Framework (TOGAF).
  • Demonstrated ability to understand the business side of information risk.
  • Strong analytical, research, writing, and communication skills.
  • Must have the ability to communicate with internal/external customers, vendors, management etc. in both formal and informal situations.
  • Ability to work with teams to achieve goals and meet deadlines in a fast-paced environment.
  • Works well under pressure and time constraints and can prioritize competing priorities appropriately.
  • Can work independently with minimal supervision and direction.

Education

  • Undergraduate degree in Information Management, Computer Science, Engineering, or emphasis in technology or related field
  • Masters degree or postgraduate diploma in information/computer science or a technology-related field preferred.

Additional Knowledge and Skills are as an asset:

  • Certified Information Systems Security Professional (CISSP)
  • Certified for Pentest
  • Certified for Proofpoint Email Security, Insider Threat
  • Microsoft Security Operation Analyst is an asset.
  • Microsoft Security, Compliance, and Identity certifications such as SC-200, SC-300, SC-400, AZ-500, MS-102, or equivalent practical experience are considered assets.
  • SIEM analysis
  • Wireshark, Malware analysis & Triage
  • Next Generation Firewall

To pursue this career opportunity, please visit our website:www.trilliumhealthpartners.ca

Trillium Health Partners’ (THP) is an equal opportunity employer who values the importance of antiracism work and is committed to integrating antiracism, diversity, equity and inclusion best practices throughout THP operations, policies and culture. Therefore, we ask that even if you do not see yourself fully reflected in every job requirement listed on this posting, we still encourage you to reach out and apply. Research has shown that candidates from underrepresented groups often only apply when they feel 100% qualified. We encourage all applicants who are members of groups that have been marginalized on any grounds enumerated under the Ontario Human Rights Code based on race, gender identity or expression, sex, sexual orientation, disability, political belief, religion, marital or family status, age, and/or status as a First Nations, Métis or Inuk/Inuit person to consider this opportunity.

In accordance with the Accessibility for Ontarians with Disabilities Act, 2005 and the Ontario Human Rights Code Trillium Health Partners will provide accommodations throughout the recruitment and selection process to applicants with disabilities. If selected to participate in the recruitment and selection process, please inform Human Resources of the nature of any accommodation(s) that you may require in respect of any materials or processes used to ensure your equal participation.

All personal information is collected under the authority of the Freedom of Information and Protection of Privacy Act.

Trillium Health Partners is identified under the French Language Services Act.

We thank all those who apply but only those selected for further consideration will be contacted.

Our organization may use automated tools, including artificial intelligence (AI) or algorithm-assisted systems, to support the initial review of applications. These tools are used only to assist our recruiters and hiring managers; all hiring decisions include meaningful human involvement and final review.

Skills

  • Cyber Defense
  • Identity and Access Management
  • Microsoft 365 Security
  • Incident Response
  • Vulnerability Management
  • Cloud Security
  • Security & Governance

Related jobs

Trillium Health PartnersApply for this job