702,361open jobs
41,480companies
101,376added this week
Browse all
Salary
$70k – $120k per year
Location
Remote/Hybrid (York, United Kingdom)
Seniority
Middle · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
CI Financial is an independent wealth and asset management company operating in Canada and the United States. It offers investment funds and portfolio management through CI Global Asset Management alongside wealth advisory services, including its US wealth business Corient. The company traces its history to 1965, is headquartered in Toronto, Ontario, and agreed in 2024 to be taken private by Mubadala Capital.

At CI, we see a great place to work as one that is a safe place for everyone to have a voice, where people are empowered to take ownership over meaningful work, where there is an opportunity to grow through stretching themselves, where they can work on innovative products and projects, and where employees are supported and engaged in doing so.

The Security Analyst II (Senior Security Specialist) is a senior hands-on security professional responsible for identifying, assessing, and remediating enterprise security risk. The role leads complex operational security activities across detection and response, vulnerability management, application security, cloud and infrastructure security, security technology, governance, and advisory services. The incumbent works independently, coordinates cross-functional remediation, communicates risk to technical and business stakeholders, and contributes to the continuous improvement of CI’s cybersecurity program.

Key Responsibilities

Security Engineering and Technology

  • Deploy, integrate, configure and enhance security solutions in accordance with approved architecture, change management and operating procedures.
  • Monitor security platforms for appropriate operation, data quality, coverage, performance and control effectiveness.
  • Lead technical troubleshooting and coordinate with internal teams and vendors to resolve security technology issues.
  • Evaluate security capabilities and recommend enhancements that measurably reduce risk, improve detection or increase operational efficiency.
  • Develop scripts, queries, automation or repeatable workflows to improve analysis, reporting and response.

Application and Cloud Security

  • Lead application security scanning activities across SAST, DAST, IaC, SAC, API testing and support teams in interpreting findings and selecting remediation approaches.
  • Partner with application owners and developers to embed security requirements into delivery processes and resolve material findings.
  • Provide security guidance through the system development lifecycle, including architecture design review, threat modelling, secure design and security testing.
  • Review cloud applications, configurations, identity controls, data flows and logging to identify security risk and required safeguards.

Security Monitoring, Threat Hunting and Incident Response

  • Investigate and triage complex security alerts and suspected compromises; determine scope, impact and required containment actions.
  • Lead or coordinate incident response activities, including investigation, containment, eradication, recovery, evidence preservation, documentation and lessons learned.
  • Improve detection coverage by identifying telemetry gaps, refining use cases and validating alert effectiveness.
  • Perform proactive threat hunting using endpoints, network, identity, cloud and SIEM telemetry to identify advanced or previously undetected threats.
  • Analyse threat intelligence and security advisories to determine relevance to CI and recommend defensive actions.
  • Participate in the after-hours on-call rotation and support high-severity incidents as required.

Vulnerability and Exposure Management

  • Lead infrastructure vulnerability management activities, including scan coverage, validation, prioritisation, exception handling, remediation tracking and reporting.
  • Partner with infrastructure, application and platform teams to drive risk-based remediation of vulnerabilities and security misconfigurations.
  • Assess exploitability, asset criticality, threat intelligence and business impact to establish remediation priorities.
  • Monitor emerging and actively exploited vulnerabilities, coordinate rapid exposure assessment and recommend compensating controls where immediate remediation is not possible.
  • Identify recurring control gaps and recommend sustainable process or technology improvements.

Security Risk Advisory and Governance

  • Advise business and technology projects on security requirements, control design, risk treatment and compliance with CI policies and standards.
  • Conduct structured security and threat risk assessments; document findings, risk rationale, mitigation recommendations and residual risk.
  • Assess new technologies and services for security risk and document clear, actionable requirements.
  • Maintain clear risk records and track agreed remediation actions to closure or formally approved acceptance.
  • Contribute to security policies, standards, baselines, procedures, playbooks and control documentation.
  • Support audits, regulatory reviews, client due diligence and security assessments by providing accurate control evidence and subject-matter expertise.
  • Present security findings and recommendations in language appropriate for technical teams, business leaders and executive stakeholders.
  • Recommend risk treatment and control improvements; formal business, risk acceptance and production-change approvals remain subject to CI governance

Leadership and Collaboration

  • Lead defined workstreams and coordinate activities across Security, Infrastructure, Application, Cloud, Architecture, Risk, Privacy, Legal and vendor teams.
  • Provide technical guidance, peer review and knowledge transfer to analysts and technology partners.
  • Exercise sound judgement, escalate material risk promptly and maintain clear ownership through to resolution.
  • Stay current on emerging threats, attack techniques, security technologies, regulatory expectations and industry practices.
  • Perform other related duties as assigned.

Qualifications

Experience

  • Five or more years of progressive, hands-on experience in information security, cybersecurity operations, security engineering, risk assessment or a related discipline.
  • Demonstrated experience leading complex security investigations or incident response activities.
  • Demonstrated experience with vulnerability management and remediation across enterprise infrastructure.
  • Experience with application security testing and remediation, including SAST and DAST.
  • Experience advising technology or business initiatives on security architecture, controls and risk treatment.
  • Experience producing clear security assessments, risk records, technical documentation and executive-ready communications.

Technical Knowledge

  • Security monitoring and incident response using endpoint detection and response, SIEM and network security telemetry; experience with platforms such as CrowdStrike, ExtraHop, Darktrace and Splunk is an asset.
  • Vulnerability assessment and remediation using platforms such as Qualys or Tenable.
  • Application security SAST,DAST,SCA, IaC and API testing using platforms such as Checkmarx , Veracod, Snyk.
  • Cloud security concepts and controls in Microsoft Azure and Amazon Web Services (AWS).
  • Identity and access management, including SSO, MFA, Microsoft Entra ID, Okta, Duo and privileged access management solutions such as CyberArk, One Identity Safeguard, BeyondTrust.
  • Network security concepts, including TCP/IP, OSI, segmentation, NAC, 802.1X, ISE, SSE and Zero Trust.
  • CIS Security standards for hardening of Windows workstations, MACs, Mobile phones, Windows Server and Linux environments.
  • Security frameworks and methods such as NIST Cybersecurity Framework, NIST Risk Management Framework, ISO/IEC 27001, MITRE ATT&CK and recognized threat-modelling approaches.
  • Scripting, query languages or automation using PowerShell, Python, shell or equivalent technologies.

Education and Certifications

  • Post secondary education in information security or equivalent and relevant work experience.
  • CISSP or comparable industry certification.
  • AWS Certified Security - Specialty, or equivalent cloud security credential is an asset.

Working Conditions

  • Professional office and hybrid work environment, in accordance with CI workplace requirements.
  • After-hours work and participation in an on-call rotation may be required.
  • Work may involve time-sensitive response to security incidents and coordination across multiple teams and service providers.

This opportunity is for an existing vacancy with the company. The anticipated base salary range for this position is $69,500 to $119,500. Exact salary depends on several factors such as experience, skills, education, and budget. Salary range may vary based on geographic location. In addition to base salary, this position is eligible for participation in a bonus program. In addition, The Company offers a variety of benefits to eligible employees, including health insurance coverage, wellness programs, life and disability insurance, retirement savings plans, paid leave programs, education-related programs, paid holidays and vacation time, and many others. Many of these benefits are subsidized or fully paid for by the company.

CI Financial is an independent company offering global wealth management and asset management advisory services through diverse financial services firms. Since 1965, we have consistently anticipated and responded to the changing needs of investors. We are driven by a commitment to provide individuals and institutions with the highest-quality investments and advice. Our commitment to the highest levels of performance means that whatever their position, CI employees must be comfortable in a fast-paced environment that will stretch them to tap into their highest potential. Employees with a healthy dose of ambition, a desire to commit to a curious mindset for continuous learning, and a willingness to go the extra mile thrive at CI.

A Supportive Environment for Success

We offer an in-office environment, competitive benefits, and a supportive workplace to help our employees thrive both personally and professionally.

WHAT WE OFFER

  • Modern HQ location within walking distance from Union Station
  • Training Reimbursement
  • Paid Professional Designations
  • Employee Savings Plan (ESP)
  • Corporate Discount Program
  • Enhanced group benefits
  • Parental Leave Top-up program
  • Paid time off for Volunteering

We are focused on building a diverse and inclusive workforce. If you are excited about this role and are not confident you meet all the qualification requirements, we encourage you to apply to investigate the opportunity further.

Please submit your resume in confidence by clicking “Apply”. Only qualified candidates selected for an interview will be contacted. CI Financial Corp. and all of our affiliates (“CI”) are committed to fair and accessible employment practices and provide reasonable accommodations for persons with disabilities. If you require accommodations in order to apply for any job opportunities, require this posting in an additional format, or require accommodation at any stage of the recruitment process please contact us at [email protected],or call 416-364-1145 ext. 4747.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
702,361 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
York
$85k – $161k per year (Estimated) • Equity • Remote • 5+ years exp
Python
JavaScript
PHP
Ruby
PowerShell
Bash
YARA
DevOps
Splunk
Azure
Linux
Windows
VPN
Cybersecurity
Snort
Suricata
YARA
Velociraptor
osquery
Eric Zimmerman Tools
SIEM
Apply
$142k – $180k per year • Equity • Remote/Hybrid • Full-Time • Bachelor's Degree • Burlington
Python
C++
C++
Conan
CMake
AI/ML
Machine Learning
DevOps
CI/CD
Git
GitHub
GitLab
Linux
Robotics
ROS
Path Planning
Management
Confluence
Jira
Agile
Apply
$79k – $135k per year (Estimated) • Remote/Hybrid • Internship • PhD • San Francisco
Python
SQL
AI/ML
LLM
Recommender Systems
Machine Learning
Design
Figma
Apply
Network Engineer 1 hour ago
In office • Athens
Python
DevOps
Ansible
VPN
BGP
OSPF
Management
ITIL
Apply
$150k – $187k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree
Python
SQL
AI/ML
Machine Learning
Apply
$43k – $71k per year • In office • Full-Time • 2+ years exp • York
Apply
$60k – $75k per year • In office • Full-Time • 1+ year exp • Canada
Management
Outlook
Microsoft Office
Apply
$43k – $71k per year • In office • Full-Time • 2+ years exp • York
Management
Microsoft Office
Apply
$43k – $71k per year • In office • Full-Time • 1+ year exp • York
Management
Outlook
Apply
$85k – $100k per year • In office • Full-Time • York
Apply
$75k – $159k per year (Estimated) • In office • Full-Time • York
Apply
$29k – $54k per year (Estimated) • In office • 2+ years exp • High School Diploma • York
Analytics
Microsoft Excel
Management
Outlook
Apply
$35k – $73k per year (Estimated) • In office • 3+ years exp • High School Diploma • York
Apply
$22k – $34k per year • In office • Full-Time • York
Apply
Sales Assistant 1 day ago
$26k – $34k per year • In office • Full-Time • York
Apply
See all jobs
This is one of many
702,361 more open roles from verified company boards, updated every day.