Senior Information Security Analyst
Lifemark Health GroupSalary Range: $80,000.00 To $100,000.00 Annually This is a hybrid position (4 days per week in office from 1 of our office locations below and 1 day remote). You can be based out of our Brampton or North York location. Brampton Location: 1 President's Choice Circle, Brampton, ON L6Y 5S5 (near Highway 407 and Mississauga Road) North York Location: 243 Consumers Rd, North York, ON M2J 4W8 (near Highway 401 and Highway 404) Lifemark Health Group (LHG) is a market leader in customized healthcare solutions. With over 20 years of service excellence, LHG is one of the largest, most trusted, and most comprehensive providers in Canada. As a national healthcare company, LHG employs over 5,000 highly trained clinicians, medical experts and team members in almost 400 locations coast-to-coast and continues to grow both organically as well as through acquisitions. With that growth, is a vision to be the most innovative healthcare providers in community rehabilitation, workplace health and wellness and medical assessment services. Lifemark was acquired by Loblaw Companies on May 10, 2022. Lifemark Health Group is seeking a Senior Information Security Analyst for a permanent, full-time role on our Security Team. In this position, you will monitor and respond to security threats across our systems, analyze security events, and help implement improvements. You will facilitate phishing awareness campaigns to strengthen organizational security posture, update security policies and playbooks to reflect evolving best practices and collaborate effectively with teams throughout the Lifemark network and its affiliates to ensure our information security practices support business goals. You will proactively identify risks through regular assessments, participate in incident response activities, and stay up to date with emerging technologies and threats to drive continuous improvement. About You: You are a seasoned information security professional with a passion for safeguarding technology and data. You bring strong technical expertise, extensive hands-on experience, and a commitment to continuous learning in the ever-evolving field of cybersecurity. Thriving in fast-paced environments, you excel at managing multiple priorities while maintaining attention to detail and high standards. Your collaborative approach allows you to work effectively across diverse teams, translating complex technical concepts into practical business solutions. Above all, you are dedicated to advancing Lifemark’s security posture and supporting its mission through proactive problem-solving and innovation. Impact we're looking for you to make: The role requires an in-depth understanding of Information Security practices as well as a good understanding of Microsoft products (such as Windows, Outlook/Exchange/O365), vulnerability management, anti-virus, identity & access management, network operations (proxy servers, DNS, firewalls, WAN/LAN switches), databases and exposure to DLP systems (such as Proofpoint and Palo Alto). Involvement in the implementation of new security solutions, including participation in the creation and maintenance of policies, standards, baselines, guidelines, and procedures Conduct vulnerability audits and assessments and participate in investigations, design, and execution of vulnerability assessments Monitor computer networks and systems for security issues, penetration tests, and security audits; document any security issues or breaches in line with Lifemark’s information security policies, procedures, and guidelines Respond to security alerts and work with the appropriate teams to investigate, triage, and resolve issues Maintain documentation of support processes and infrastructure Support incident and problem management, escalation, and resolution activities Implement and test changes in accordance with Change Management procedures Maintain a commitment to keeping current on the latest technologies, threats, and best practices through training courses and industry events Manage Helpdesk Tier II/III requests pertaining to information security Maintain relevant baselines and operational configurations, and review logs for the secure configuration and operation of server, compute, and network devices Participate in the planning and design of enterprise security architecture, Business Continuity Plan (BCP), and Disaster Recovery (DR) plan Provide input toward RFPs and security due diligence documents Participate in client security audits, evidence collection, and tracking of remediation items Own and track cybersecurity remediation activities aligned with the NIST Cybersecurity Framework, including control-gap validation, evidence collection, action owners, target dates, risk acceptance, and reporting of overdue items Conduct periodic access and configuration reviews covering privileged accounts, non-human identities, break-glass accounts, firewall rules, cloud service access, and other high-risk controls; document evidence and follow remediation to closure Perform security reviews of new technologies, vendors, and material changes; document risks, minimum control requirements, and recommendations before implementation or renewal Maintain up-to-date knowledge of the IT security industry, including awareness of new or revised security solutions, improved security processes, and emerging attacks and threat vectors Recommend additional security solutions or enhancements to existing security solutions to improve overall enterprise security Participate in the deployment, integration, and configuration of new security solutions and enhancements to existing security solutions in accordance with standard operating procedures and enterprise security documentation Provide after-hours and on-call support when needed What we're looking for: Minimum five years of progressive, hands-on information security experience, including at least two years independently leading security investigations, remediation initiatives, or security control operations in a complex enterprise environment. Experience with network applications, firewall security, virtual private networking, and SIEM Experience with cloud hosting platforms (Microsoft Azure preferred) Knowledge of network and host IDS/IPS Strong familiarity with data classification concepts and processes Solid understanding of data loss and data protection processes Experience with a wide variety of technical solutions focused on data protection and cybersecurity Experience with Microsoft server and cloud infrastructure, such as Windows Server and Active Directory Experience with Microsoft 365 security and collaboration tools, including Exchange Online, Teams, SharePoint, OneDrive, Defender, Entra ID, and Purview Demonstrated experience applying the NIST Cybersecurity Framework and translating framework gaps into prioritized, measurable remediation plans; experience supporting SOC 2 - comparable assurance activities is an asset Experience assessing third-party, SaaS, and application security risks, including identity and access, data protection, logging, vulnerability management, resilience, and contractual security requirements Experience in healthcare, another regulated environment, or a large distributed organization is strongly preferred; working knowledge of PHIPA, PIPEDA, and protection of personal health information is an asset Excellent time management skills Strong written and verbal communication Work with different divisions understanding their IT Security needs Set clear expectations and define key performance indicators for self Work within a team environment providing insight when appropriate Superior organizational skills, attention to detail, and ability to prioritize and manage multiple tasks Ability to successfully interact with non-technical business contacts Ability to analyze and understand technical information Ability to effectively prioritize and execute tasks in a high-pressure environment Ability to conduct research into IT security issues and products as required Additional Qualifications: Associate degree in a related technical field or equivalent experience Network+, Security+, GISP, MCSA, CISSP with demonstrated knowledge of security frameworks or standards such as CIS top 20, NIST and ISO 27001 (certifications are assets) Understanding of remote management tools and techniques Extensive knowledge of Microsoft Windows operating systems and Office 365 An understanding of network topologies and protocols (including firewalls, routers, switches, access points) Experience with Microsoft Active Directory and PowerShell Scripting Some knowledge of Microsoft windows server platform Use of SAST/DAST tools such as Snyki.io, Fortify and Burp Suite Use of work item tracking software such as Azure DEVOPS, Zendesk, ServiceNow and JIRA Familiarity working with SQL databases schema, queries, entries, creation Must be able to participate in a defined after-hours incident escalation rotation and support urgent cyber events when required. Our Perks: Have access to a yearly education re-imbursement fund Receive 30% discount from Shopper Drug Mart purchases Contribute to an Employee Stock Ownership Plan (ESOP) with employer matching percentage Have paid vacation days as well as wellness days Have a choice to enroll in our Health & Dental Flex Life Benefits (or in lieu contribute to your RRSPs) Access to employee assistance program On-site gym, Basketball & Volleyball courts, Groceries delivered to work via PC Express, Dry-Cleaning services (1 Presidents Choice Circle Office) Inclusion Lifemark welcomes and encourage application from people with disabilities. Accomodations are available on request for candidates taking part in all aspects of the selection process. Lifemark promotes equal employment opportunities for all job applicants, including those self-identifying as a member of the following groups: Indigenous peoples, Newcomers to Canada, and Visible minorities. Accommodation Accommodations are available on request for all candidates taking part in any aspect of the recruitment and selection process. Email us at talent at lifemark.ca #LI-DNP