North American construction and infrastructure development company delivering civil, transport, nuclear, utility and industrial projects.
Senior Analyst ensures security risk assessments, compliance with ISO 27001 and regulations.
5 days ago ago
Expert & Leadership (13+ years)
Full Time
Toronto, Ontario, Canada
Office Full-Time
Company Size
9,427 Employees
Service Specialisms
Construction services
Project Management
Engineering
Design
Technical Services
General Contractor
Property Development
Turnkey
Sector Specialisms
Nuclear
Civil
Industrial
Urban Transportation
Utility
Electrical Transmission and Distribution
Renewables
Pipeline Distribution
Role
Description
risk assessment
compliance framework
audit facilitation
security controls
policy development
kpi monitoring
Facilitate audits and risk reviews with internal/external auditors, clients, and business teams; ensure timely response and track remediation to closure.
Conduct comprehensive security risk assessments for new and existing services, applications, technologies, and vendors. Clearly document and communicate findings to relevant stakeholders.
Recommend and implement appropriate controls to address identified security risks and enhance organizational security.
Identify opportunities to improve processes for security risk identification and management.
Design, operate, and manage a compliance framework aligned with ISO 27001, including associated controls.
Prepare periodic reports and presentations for senior management, steering committees, and the board of directors.
Conduct monthly compliance reviews with security service providers to ensure adherence to SLAs and contractual requirements.
Ensure you and your family receive the services needed to support your mental, emotional, and physical well-being.
Provide backup support for other security team members as needed.
Collaborate with Internal Audit, Legal, Privacy, and other stakeholders to ensure IS policies and controls meet all regulatory and organizational requirements.
Develop and maintain information security governance documentation, including policies, standards, procedures, and guidelines.
Monitor the effectiveness of security controls through the design and implementation of KPIs and KRIs for reporting.
Assess security controls of vendors and third parties safeguarding company assets through contract and compliance reviews.
Provide expert consultative advice to Information Services (IS) and business units to support informed risk management decisions.
Requirements
cism
cisa
crisc
cissp
networking
compliance
Problem Solving: Proficient in applying logic and techniques to resolve complex issues; skilled in asking probing questions to achieve optimal outcomes.
Ability to adapt to evolving technical, regulatory, and compliance environments.
Minimum 8 years of experience in IT, with at least 5 years in information security/compliance or IT audit, and 3 years in security risk management.
Capacity to manage multiple priorities and meet tight deadlines.
Strong analytical and problem-solving skills.
Demonstrated results orientation, energy, and self-motivation.
Proven ability to work collaboratively within a team environment.
Professional certifications such as CISM, CISA, CRISC, or CISSP are considered assets.
Influencing: Ability to positively influence colleagues and gain genuine agreement.
Strong understanding of computer networking concepts, protocols, and IT security methodologies.
Adaptive Thinking: Effective change leadership and critical thinking skills; sound analysis and logical reasoning.
Bachelor's degree in Computer Science, Information Security, or a related field.
Business Acumen: Deep understanding of business operations, trends, and technologies impacting the organization.
Decision Making: Sound judgment and decision-making in complex, dynamic environments; innovative risk orientation.
In-depth knowledge of legal and regulatory compliance standards (e.g., GDPR, PCI-DSS, PHIPA, ISO 27001, NIST).
Stakeholder Management: Ability to influence with and without direct authority; high emotional intelligence and organizational awareness.
Excellent verbal and written communication skills.
Benefits
Information not given or found
Training + Development
Information not given or found
Interview process
Information not given or found
Visa Sponsorship
Information not given or found
Security clearance
Information not given or found
Company
Overview
C$9.7B Backlog
Record Project Orders
Signifies a substantial and growing pipeline of construction and infrastructure projects.
C$150M Investment
Utilities Expansion Fund
Strategic financial backing to bolster and expand utilities infrastructure development.
From humble beginnings in plumbing and gas fitting, the company has evolved into a leading infrastructure developer, with operations rooted in Hamilton since its founding in 1877.
Offers comprehensive construction services across civil infrastructure, urban transit, nuclear power, utilities, and industrial works.
Through its Concessions arm, the company specializes in private-public partnerships (P3) for global infrastructure development, emphasizing integrated delivery from planning to long-term operations.
Delivers iconic projects including the CN Tower, Vancouver SkyTrain, Montreal-Trudeau Airport, Gordie Howe Bridge, and major nuclear refurbishments.
Expanding into next-generation energy solutions with Canada’s largest battery storage initiative and leadership in small modular reactor development.
While maintaining a strong presence in Canada, the company also caters to North American markets and selectively engages in international concessions.
Demonstrates expertise in complex mega-projects through seamless integration of engineering, construction, financing, and operations.
Culture + Values
Safety First - Ensuring a safe, healthy work environment and fostering a 'zero injury' culture.
Trust and Candour - Conducting ourselves professionally, with candour, respect, and integrity.
Passion for Excellence - Being pace-setting and innovative, always striving to find a better way, and doing it right the first time - every time.
A People Focused, Learning Culture - Developing the best leaders and realizing the full potential of our people. Learning is core - we never stop trying to improve.
Results Oriented - Having a 'do whatever it takes' attitude. Empowered and entrepreneurial operations within a common framework of values, strategies, and key processes.
Environment + Sustainability
30% CO₂ Reduction
CO₂ Emissions Intensity Target
Aims to reduce CO₂ emissions intensity (Scopes 1 & 2) by 30% by 2030 compared to 2020 levels.
59% Revenue from Sustainability
Revenue Linked to Sustainability Projects
59% of 2024 revenue is tied to projects focused on climate change mitigation, energy transition, renewable energy, and water management.
78% Backlog Sustainability
Backlog Linked to Sustainability
78% of the company's backlog is connected to sustainability-related projects, highlighting a strong focus on environmental initiatives.
34% Early Target Achievement
Early Achievement of 2030 Target
Surpassed the 2030 target for Scope 1 & 2 emissions intensity reduction by achieving a 34% cumulative reduction by 2024, relative to revenue.
Net‑zero target for Scopes 1, 2 & 3 by 2050
20% cumulative Scope 1 & 2 GHG reduction by end of 2023 (vs 2020)
Projects include grid‑scale SMR, nuclear refurbishments, Oneida Energy Storage, Site C hydroelectric, Réseau express métropolitain, Surrey Langley SkyTrain
Approved science‑based near/long‑term emissions targets; SBTi‑verified net‑zero by 2050
Silver Certification from Progressive Aboriginal Relations; procured $127 M Indigenous goods/services in 2024
Inclusion & Diversity
$275M Procured
Indigenous Procurement
Significant investments in Indigenous goods and services were made in 2023 and 2024.
0.89 Injury Frequency
Safety Metrics
Improved workplace safety with a low Total Recordable Injury Frequency in 2023.
Inaugural Reconciliation Action Plan established
Silver Certification in Progressive Aboriginal Relations
Established three Indigenous‑led joint ventures
Expanded Aecon Women in Trades program (added nuclear cohort)
Inclusion stated as core value alongside Safety Always, Integrity and Accountability
Committed to inclusion through equitable opportunities, Equity, Diversity & Inclusion training, Women in Trades and Diversity in Trades programs, and Employee Resource Groups