Information Security Analyst

EllisDonMississauga, ON
CA$66,000 - CA$80,000

About The Position

This role is ideal for a cybersecurity professional looking to expand into GRC or a GRC practitioner who enjoys building and improving security processes, programs, and controls in a growing environment. EllisDon is proud to provide this unique career opportunity that provides continuous learning, opportunity for growth, and a competitive compensation package within an environment that is committed to inclusion and respects diversity. We are an equal opportunity employer. We welcome people of any age, culture, subculture, gender identity or expression, sexual orientation, nationality, ethnicity, race, size, mental or physical status, veteran status, religion, language, political opinion, working-style preference, family status, education, and socio-economic status. The EllisDon core values of Integrity and Mutual Respect welcomes everyone, at work and in the community, and our value of Mutual Accountability, means that we all have a role to play. As an EllisDon employee, this will ultimately be your commitment to Inclusive Diversity. Accommodation for Applicants with disabilities will be made during the recruitment process when requested. We are committed to providing a positive candidate experience and ensuring timely updates are provided to all candidates. If you haven’t already, be sure to create a profile on our Careers page to remain up to date on the status of your application and learn about new career opportunities as they arise. EllisDon uses AI tools to assist in screening and assessing applicants for this position.

Requirements

  • 2–5 years of experience in Information Security, Cybersecurity, Governance, Risk & Compliance (GRC), IT Risk Management, or related disciplines.
  • Experience performing assessments including security reviews, risk assessments, vendor evaluations, compliance activities, or governance functions.
  • Strong security foundation with a risk‑based approach to decision‑making and the ability to evaluate security controls effectively.
  • Ability to identify practical mitigation by assessing control gaps and recommending realistic, business‑aligned improvements.
  • Demonstrated interest in GRC and applying security concepts through a business‑focused, risk‑driven lens; interest in developing expertise across multiple GRC disciplines.
  • Experience contributing to program maturity including the development, implementation, or enhancement of security and GRC processes, programs, or initiatives.
  • Ability to work independently while influencing stakeholders across technical and non‑technical teams.
  • Strong analytical and critical thinking skills with the ability to evaluate controls, identify gaps, and propose actionable improvements.
  • Effective communication skills with the ability to articulate risks and recommendations to diverse audiences.
  • Strong interpersonal, verbal, and written communication skills.
  • Self‑motivated with strong prioritization skills and the ability to drive initiatives forward.
  • Post‑secondary education in IT, Cybersecurity, Information Security, or a related field, or equivalent experience.
  • Working knowledge of security frameworks such as NIST CSF, ISO 27001, SOC 2, CIS Controls, CMMC, CPCSC, or similar standards.

Nice To Haves

  • Industry certifications such as Security+, CISSP, CISA, CRISC, or similar are considered an asset.

Responsibilities

  • Support identification, assessment, and tracking of IT/cyber risks; maintain the enterprise risk register and remediation lifecycle
  • Perform risk assessments for systems, projects, and vendors; support ongoing third-party compliance activities
  • Contribute to GRC program operations (policies, standards, procedures, exception tracking, evidence workflows)
  • Support remediation of risks, control gaps, and audit findings across teams
  • Partner with IT (Service Delivery, Operations, DevOps) to enable secure system and solution implementation
  • Support security awareness program, including training, reporting, and modern threat simulations (phishing, social engineering, AI-driven attacks)
  • Support compliance across SOC 2, NIST, ISO 27001, and CMMC / CPCSC / ITSP, ensuring consistent control implementation
  • Contribute to key GRC initiatives, including risk maturity, audit readiness, vendor compliance, and standardization of security requirements across the organization

Benefits

  • continuous learning
  • opportunity for growth
  • competitive compensation package
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service