Provide information security expertise for government IT projects: perform on‑premise and cloud security assessments, identify risks and vulnerabilities, conduct privacy impact assessments, define security requirements, develop enterprise security documentation, support vulnerability testing and disaster recovery planning, and advise project teams on security and compliance aligned with NIST.
This is a remote position.
Overview
This is a remote consulting opportunity supporting a government client.
Subcontractor Opportunity: This is not an employee position. The successful consultant must be incorporated and able to provide services through their corporation.
Role Summary
The Security Analyst provides specialized expertise in information security, supporting enterprise initiatives by ensuring that IT projects are designed, assessed, and implemented in accordance with security and privacy requirements.
The role is responsible for conducting security assessments, defining security requirements, and developing documentation that supports secure, compliant, and resilient solutions aligned with industry standards.
Key Responsibilities
- Capture and assess current-state security solutions to establish baselines for new IT projects
- Conduct on-premise and cloud-based security assessments for proposed systems and initiatives
- Identify security risks, vulnerabilities, and gaps in system design and implementation
- Conduct privacy impact assessments for new IT projects in collaboration with business units
- Ensure alignment with relevant privacy legislation and regulatory requirements
- Apply industry standards such as NIST to assess and guide security practices
- Lead security requirements gathering activities for IT projects in collaboration with business analysts
- Develop and maintain enterprise security documentation including policies, standards, baselines, guidelines, and procedures
- Lead or support vulnerability assessments, penetration testing, and security audits for IT projects
- Participate in planning and design of business continuity and disaster recovery strategies
- Collaborate with project teams, IT operations, and business stakeholders to provide security guidance
- Conduct research into emerging security threats, tools, and technologies
Key Deliverables
- Security assessment reports and risk analyses
- Privacy impact assessments and compliance documentation
- Security requirements and control frameworks for IT projects
- Enterprise security policies, standards, and guidelines
- Vulnerability assessment and penetration testing results
- Business continuity and disaster recovery security inputs
- Security documentation maintained within the enterprise repository
Requirements
Qualifications
Education and Certifications
- Bachelor’s degree in Computer Science, Information Technology, or a related field preferred
- Certifications related to information security such as CISSP, CISM, or equivalent considered an asset
- Certifications aligned with NIST or security frameworks considered an asset
- Training or certification in privacy and compliance disciplines considered an asset
Experience
- Extensive experience with industry security solutions, particularly Microsoft security technologies
- Experience conducting on-premise and cloud security assessments for IT projects
- Experience developing security documentation for enterprise environments
- Experience performing privacy impact assessments
- Strong understanding of networking protocols including IP and TCP/IP
- Experience gathering and defining IT security requirements for projects
- Excellent analytical, problem-solving, and documentation skills
- Strong communication skills, both written and verbal
- Ability to manage priorities and deliver in high-pressure environments
Similar Jobs
Insurance • Financial Services
Provide IAM (GIA) technical guidance to application teams, translate security and regulatory requirements into functional specifications, integrate and implement IAM controls (SailPoint IdentityIQ), analyze security issues, contribute to project planning and delivery, and produce documentation. Also provide executive administrative support to VP (calendar, travel and hotel bookings, expense reports, meeting coordination, committee minutes, event logistics) in a hybrid role.
Top Skills:
AgileAuthenticationAuthorizationMfaMicrosoft PowerpointMicrosoft WordSafeSailpoint IdentityiqSso
Security • Software • Cybersecurity
Validate, reproduce, and triage vulnerability reports for web and mobile applications; assess severity and impact using CVSS and security frameworks; communicate findings and remediation to customers and researchers; leverage automation/AI workflows; collaborate cross-functionally and improve triage processes. Weekend shifts required occasionally.
Top Skills:
Burp SuiteCvssOwasp Top 10
Productivity • Software • Conversational AI
Lead and improve daily operations of Twilios Security Risk program: maintain risk registers and KRIs, perform qualitative and quantitative risk analyses, build dashboards and predictive models, coordinate remediation with engineering, support audits, and drive automation and AI-enabled risk tooling to scale program impact.
Top Skills:
Ai Risk Management Framework (Ai Rmf)CosoEnterprise AiGrc ToolingIso 31000Nist Risk Management Framework (Nist Rmf)Risk Modeling Tools
What you need to know about the Calgary Tech Scene
Employees can spend up to one-third of their life at work, so choosing the right company is crucial, not just for the job itself but for the company culture as well. While startups often offer dynamic culture and growth opportunities, large corporations provide benefits like career development and networking, especially appealing to recent graduates. Fortunately, Calgary stands out as a hub for both, recognized as one of Startup Genome's Top 100 Emerging Ecosystems, while also playing host to a number of multinational enterprises. In Calgary, job seekers can find a wide range of opportunities.



_0.png)