Provide information security expertise for government IT projects: perform on‑premise and cloud security assessments, identify risks and vulnerabilities, conduct privacy impact assessments, define security requirements, develop enterprise security documentation, support vulnerability testing and disaster recovery planning, and advise project teams on security and compliance aligned with NIST.
This is a remote position.
Overview
This is a remote consulting opportunity supporting a government client.
Subcontractor Opportunity: This is not an employee position. The successful consultant must be incorporated and able to provide services through their corporation.
Role Summary
The Security Analyst provides specialized expertise in information security, supporting enterprise initiatives by ensuring that IT projects are designed, assessed, and implemented in accordance with security and privacy requirements.
The role is responsible for conducting security assessments, defining security requirements, and developing documentation that supports secure, compliant, and resilient solutions aligned with industry standards.
Key Responsibilities
- Capture and assess current-state security solutions to establish baselines for new IT projects
- Conduct on-premise and cloud-based security assessments for proposed systems and initiatives
- Identify security risks, vulnerabilities, and gaps in system design and implementation
- Conduct privacy impact assessments for new IT projects in collaboration with business units
- Ensure alignment with relevant privacy legislation and regulatory requirements
- Apply industry standards such as NIST to assess and guide security practices
- Lead security requirements gathering activities for IT projects in collaboration with business analysts
- Develop and maintain enterprise security documentation including policies, standards, baselines, guidelines, and procedures
- Lead or support vulnerability assessments, penetration testing, and security audits for IT projects
- Participate in planning and design of business continuity and disaster recovery strategies
- Collaborate with project teams, IT operations, and business stakeholders to provide security guidance
- Conduct research into emerging security threats, tools, and technologies
Key Deliverables
- Security assessment reports and risk analyses
- Privacy impact assessments and compliance documentation
- Security requirements and control frameworks for IT projects
- Enterprise security policies, standards, and guidelines
- Vulnerability assessment and penetration testing results
- Business continuity and disaster recovery security inputs
- Security documentation maintained within the enterprise repository
Requirements
Qualifications
Education and Certifications
- Bachelor’s degree in Computer Science, Information Technology, or a related field preferred
- Certifications related to information security such as CISSP, CISM, or equivalent considered an asset
- Certifications aligned with NIST or security frameworks considered an asset
- Training or certification in privacy and compliance disciplines considered an asset
Experience
- Extensive experience with industry security solutions, particularly Microsoft security technologies
- Experience conducting on-premise and cloud security assessments for IT projects
- Experience developing security documentation for enterprise environments
- Experience performing privacy impact assessments
- Strong understanding of networking protocols including IP and TCP/IP
- Experience gathering and defining IT security requirements for projects
- Excellent analytical, problem-solving, and documentation skills
- Strong communication skills, both written and verbal
- Ability to manage priorities and deliver in high-pressure environments
Similar Jobs
7 Days Ago
Easy Apply
Easy Apply
Cloud • Security • Software • Cybersecurity • Automation
Triage bug bounty and vulnerability management reports, validate findings, assess severity, identify duplicates, and coordinate remediation through closure. Collaborate with PSIRT, engineering, legal, communications, customer success, and security teams. Support CVE assignments as a CNA representative, communicate with researchers and customers, maintain accurate records, monitor operational metrics, and improve vulnerability-handling procedures, runbooks, and documentation.
Top Skills:
APIsBugcrowdCi/CdCveCvssCweHackeroneOwasp Top 10Web Applications
Information Technology • Professional Services • Software • Consulting
Investigates and qualifies escalated SOC alerts involving phishing, account compromise, malware, and lateral movement. Correlates events across security platforms, enriches investigations with logs, indicators of compromise, and threat intelligence, determines severity and impact, and recommends or initiates mitigation and escalation actions. Documents findings, analyzes endpoint and network artifacts, coaches Level 1 analysts, improves detection rules and playbooks, and uses approved automation and AI tools.
Top Skills:
CypressEdrJIRAPlaywrightSIEMXdrXray
Hardware • Security • Software • Cybersecurity
Supports information security compliance programs, regulatory and framework assessments, risk mitigation, audit preparation, remediation tracking, policy maintenance, and security program improvements. The role coordinates evidence collection, manages risk exceptions and registers, monitors international regulations, supports penetration testing reviews, and maintains incident response and business continuity documentation. It also partners with Legal, auditors, stakeholders, and security leads to strengthen the organization’s security posture and compliance roadmap.
Top Skills:
Ai ToolsCcpa/CpraCloud SecurityEu Cyber Resilience ActEu Radio Equipment DirectiveGdprGrc PlatformsHipaaIso 27001Nis2Nist CsfPci DssPenetration TestingSoc 2Threat Modeling
What you need to know about the Ottawa Tech Scene
The capital city of Canada and the nation's fourth-largest urban area, Ottawa has proven a rapidly growing global tech hub. With over 1,800 tech companies, many of which are leaders in their sectors, the city's tech talent now makes up more than 13 percent of its total workforce. This growth is driven not only by the big players like UL Solutions and Dropbox, but also by a thriving startup ecosystem, as new businesses emerge to follow in the footsteps of those that came before them.



