Cybersecurity Analyst II

Posted 18 Days Ago
Be an Early Applicant
Vancouver, BC, CAN
In-Office
93K-93K Annually
Senior level
Aerospace • Healthtech • Biotech • Energy
The Role
Leads technical cybersecurity risk assessments, security architecture reviews, threat modeling, detection engineering, IAM security, incident response, vulnerability management, and threat intelligence. The role evaluates control effectiveness, develops SIEM and EDR detections, strengthens identity protections, supports complex investigations, and drives remediation. It also provides technical leadership, mentorship, governance support, audit assistance, and continuous security improvement across systems, infrastructure, applications, cloud environments, and research projects.
Summary Generated by Built In

Discover TRIUMF, Canada's particle accelerator centre. We are a publicly funded, not-for-profit research lab that is a hub for discovery and innovation.

Our mission is to serve as Canada’s particle accelerator centre.  We advance isotope science and technology, both fundamental and applied.  We collaborate across communities and disciplines, from nuclear and particle physics to the life and material sciences.  We discover and innovate, inspire and educate, creating knowledge and opportunity for all.

TRIUMF's diverse community of nearly 600 multidisciplinary researchers, engineers, technicians, tradespeople, staff, and students create a unique incubator for Canadian excellence, as well as a portal to premier global collaborations.  Fueling innovation and improving lives, we are committed to accelerating discovery and shaping a better world.


Are you a cybersecurity professional with 5+ years of hands-on experience in technical risk, security architecture, detection engineering, or identity security?


You could be a great fit if you bring:


  • Cybersecurity risk expertise: Lead technical security risk assessments across systems, applications, infrastructure, and projects, identifying vulnerabilities and evaluating whether security controls can effectively prevent or detect real-world attacks
  • Security architecture expertise: Review networks, cloud environments, applications, and enterprise systems to identify security weaknesses, assess data flows, perform threat modeling, and provide secure design guidance
  • Detection engineering: Develop, test, maintain, and improve SIEM, EDR, and other security detection content, while mapping detection coverage to the MITRE ATT&CK framework and addressing security gaps
  • Identity & access management: Assess and strengthen IAM environments, including MFA, SSO, privileged access management, federation, directory services, and zero-trust access controls
  • Incident response & investigation: Provide senior technical support during complex cybersecurity incidents, from detection and triage through containment, recovery, and root cause analysis
  • Vulnerability & threat intelligence: Evaluate vulnerabilities based on exploitability and asset criticality, monitor emerging threats, and translate threat intelligence into practical security improvements
  • Technical leadership & mentorship: Serve as a senior technical resource, providing guidance, coaching, and work review for junior and intermediate cybersecurity analysts

Why TRIUMF?


  • Work at Canada’s national particle accelerator centre and contribute to cybersecurity in a unique scientific research environment
  • Collaborate with a multidisciplinary community of researchers, engineers, technicians, IT professionals, and scientists
  • Grow your career through technical leadership, mentorship, continuous learning, and exposure to advanced research environments
  • Enjoy a comprehensive total rewards package, including employer-paid health and dental benefits, vision care, pension, disability benefits, wellness benefits, and generous time away

PRIMARY FUNCTION:

The Cybersecurity Analyst II applies deep technical expertise across a broad range of cybersecurity disciplines to evaluate and reduce risk across the organization's systems, infrastructure, and projects. The primary focus of the role is technical risk assessment and security architecture review, examining how systems are built, how they could be attacked, and whether controls in place would actually stop an adversary. In addition, the incumbent owns detection engineering and identity and access management security as core functions, ensuring the organization's defensive capabilities are built on sound design and continuously strengthened. The incumbent operates with minimal direction, exercises independent judgment on complex and ambiguous problems, and is trusted to make sound, technically grounded security decisions.


The ideal candidate thinks like an attacker and advises like a trusted advisor. They bring hands-on experience across threat modeling, attack surface analysis, detection content development, identity security architecture, and incident response, and can translate technical risk clearly and credibly to project teams, system owners, and leadership. This role also serves as a senior technical resource for the broader cybersecurity team, providing mentorship and guidance to junior analysts.


ORGANIZATIONAL RELATIONSHIPS:

The Cybersecurity Team is a group of the Information Systems and Technology Department (IS&T). The Cybersecurity Analyst II reports directly to the Group Leader, Cybersecurity, and interacts on a day-to-day basis with other members of IS&T and with a broad range of internal stakeholders, system owners, and research groups. This position works with colleagues across all areas of the Lab and in all job functions. External contacts include vendors, consultants, and support service providers.


RESPONSIBILITIES:

Technical Risk Assessment

  • Lead technical cybersecurity risk assessments of systems, applications, infrastructure, and projects.
  • Evaluate control effectiveness to determine whether existing safeguards would realistically detect or prevent an attack.
  • Evaluate third-party and vendor security posture prior to onboarding and on an ongoing basis.
  • Communicate risk findings with technical precision to technical stakeholders and in plain institutional impact terms to non-technical stakeholders.
  • Contribute to risk reporting for governance and leadership forums as a secondary output of technical work.

Security Architecture Review

  • Review the security design of proposed and existing systems, networks, applications, and cloud deployments.
  • Assess data flows and sensitive data exposure risks as part of architecture reviews, escalating findings to the appropriate owner.
  • Perform threat modeling to identify attack paths, trust boundary weaknesses, and exploitable design flaws.
  • Provide secure design guidance to engineering and infrastructure teams throughout project lifecycles.
  • Participate in change management processes to assess the security implications of infrastructure and application changes.

Detection Engineering

  • Own the development and lifecycle management of detection content across SIEM, EDR, and other detection platforms, including writing, testing, validating, and maintaining detection logic
  • Map and maintain detection coverage against the MITRE ATT&CK framework, identifying blind spots and prioritizing new detection development based on realistic threat scenarios for the organization.
  • Translate threat intelligence, adversary TTPs, and post-incident findings into new detection use cases, building coverage where gaps exist.
  • Document detection logic, tuning rationale, and coverage decisions to support team knowledge transfer and audit requirements.

Identity and Access Management Security

  • Own the security architecture and risk posture of the organization's identity and access management environment, including authentication systems, privileged access management, SSO, federation, and directory services.
  • Evaluate IAM designs and configurations, assessing authentication strength, privilege scope, and susceptibility to identity-based attacks such as credential theft, lateral movement, and privilege escalation.
  • Lead or contribute to zero trust identity initiatives, including least-privilege access design, conditional access policy review, and MFA coverage.
  • Identify and drive remediation of identity architecture weaknesses surfaced through risk assessments, architecture reviews, or incident investigations.

Incident Response and Security Operations

  • Lead or provide senior technical support for complex or high-severity cybersecurity incident investigations.
  • Guide and mentor junior analysts through triage, containment, eradication, and recovery.
  • Lead post-incident reviews and root cause analysis, identifying architectural or detection weaknesses and driving remediation.
  • Support the design and execution of incident response tabletop exercises.

Vulnerability Management and Threat Intelligence

  • Provide senior technical oversight of vulnerability management, including validation of scan findings, prioritization based on exploitability and asset criticality, and guidance on remediation approaches.
  • Monitor threat intelligence feeds and security advisories, evaluate relevance to the organization's architecture and risk posture, and determine prioritization and response.
  • Assess emerging vulnerabilities for real-world exploitability and business impact in context.
  • Identify systemic weaknesses and architectural patterns that produce repeated vulnerabilities and recommend structural remediation.

Governance and Continuous Improvement

  • Contribute technical subject-matter expertise to the development and review of cybersecurity policies and standards.
  • Support audits, compliance assessments, and regulatory inquiries by providing technical evidence, documentation, and clear explanation of controls.
  • Identify opportunities to improve the organization's security posture through better architecture, tooling, detection, or process, and lead initiatives to address them.

Leadership and Mentorship

  • Provide technical mentorship and coaching to junior and intermediate cybersecurity analysts, including guidance on assessment methodology, analytical approach, and communicating findings.
  • Review and validate the work of junior analysts on risk, detection, and vulnerability assessments.
  • Act as the team's primary subject-matter expert and escalation point for complex technical risk, detection, identity, and architecture questions.

General Duties

  • Perform other related duties and responsibilities as assigned, consistent with the scope and level of the position.

KNOWLEDGE AND SKILLS:

  • Must possess strong communication skills, including the ability to explain complex technical attack scenarios, detection logic, and risk findings clearly to both technical peers and non-technical stakeholders and leadership.
  • Must demonstrate strong analytical and adversarial thinking, approaching systems from an attacker's perspective and reasoning about how controls would hold up under realistic attack conditions.
  • Must demonstrate sound judgment when managing competing priorities, incomplete information, and technically complex or ambiguous risk decisions.
  • Must exercise discretion and professionalism in handling sensitive security, risk, and organizational information.
  • Must work collaboratively across IT, engineering, research groups, and leadership, and be effective at influencing security outcomes without direct authority.

Preferred Skills:

  • Familiarity with operational technology and industrial control system security concepts, including secure architecture and risk considerations for research or scientific environments.
  • Application security and secure SDLC: SAST and DAST tooling, dependency and software composition analysis, pipeline security, API security review, and providing hands-on secure coding guidance to development teams.

MINIMUM QUALIFICATIONS AND YEARS OF EXPERIENCE:

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent technical experience.
  • Minimum 5 years of hands-on cybersecurity experience, with demonstrated depth in two or more of: technical risk assessment, security architecture review, detection engineering, or identity security.
  • CISSP expected at this level, or in active progress. Additional relevant certifications are considered assets, including CCSP, OSCP, SABSA, SC-300 (Microsoft Identity and Access Administrator), or GIAC certifications such as GCIH, GCIA, GDSA, or GPEN.
  • Substantial hands-on experience in several of the following areas:
    • Technical security risk assessments, attack surface analysis, and threat modeling.
    • Security architecture review of networks, cloud environments, applications, and enterprise systems.
    • Detection engineering: authoring SIEM detection content, correlation rules, behavioral analytics, and MITRE ATT&CK coverage mapping.
    • Identity and access management security: PAM, SSO, federation, zero trust access design, and identity-based attack patterns.
    • Data security concepts including data flow analysis, encryption standards, and sensitive data exposure risk.
    • Hands-on incident response across all phases, including detection, triage, containment, eradication, recovery, and root cause investigation.
    • Vulnerability management with technical depth.
    • Cloud security architecture and risk across Azure, AWS, or GCP.
    • Windows, Linux, Active Directory, and enterprise network architecture fundamentals.
    • Mentoring or providing technical leadership to junior security staff.

Applicants must be legally able to work in Canada on a permanent basis (Canadian Citizen or Permanent Resident).


Salary: $92,905.00 CAD plus our comprehensive employer-paid benefits plan


Position type:

PermanentTotal Rewards

At TRIUMF, we value our employees and are committed to providing a competitive total rewards package. We offer comprehensive benefits that promote the well-being and security of our staff and provide an excellent opportunity to grow your career in a high-profile national research facility, where you can make a difference.

Benefits Information:

  • TRIUMF paid dental, extended health, vision care, emergency travel assistance, Employee Assistance Program (EAP), Life Insurance, and supplementary Wellness Benefits.
  • Excellent Employee Pension Plan
  • Disability benefits, and optional additional Life insurance and Accidental Death & Dismemberment (AD&D)
  • Generous time away
  • Maternity and paternity leaves and top-ups
Application closing date:October 23, 2026

Apply now and be part of our extraordinary journey.

Learn more about the amazing research and work we do at TRIUMF.

https://www.discoverourlab.triumf.ca

http://www.rarestdrug.com

Equity, diversity, and inclusion are integral to excellence and enhance our ability to create knowledge and opportunity for all. Together, we are committed to building an inclusive culture that encourages, supports, and celebrates the voices of our employees, students, partners, and the people and communities we serve.

As an equal opportunity employer, committed to diversity, we encourage applications from members of groups that have been marginalised on any grounds enumerated under the B.C. Human Rights Code. All qualified applicants will receive consideration for employment.

Contact information:
Email: [email protected]
Phone: 604.222.1047
Fax: 604.222.3791
4004 Wesbrook Mall - Vancouver, BC - V6T 2A3

TRIUMF is located on the traditional, ancestral, and unceded territory of the xwməθkwəy̓əm (Musqueam) People, who for millennia have passed on their culture, history, and traditions from one generation to the next on this site.

Skills Required

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or equivalent technical experience
  • Minimum 5 years of hands-on cybersecurity experience
  • Demonstrated depth in at least two of technical risk assessment, security architecture review, detection engineering, or identity security
  • CISSP certification or active progress toward CISSP
  • Hands-on experience with technical security risk assessments, attack surface analysis, and threat modeling
  • Hands-on experience with security architecture review for networks, cloud environments, applications, and enterprise systems
  • Hands-on detection engineering experience, including SIEM detection content, correlation rules, behavioral analytics, and MITRE ATT&CK mapping
  • Hands-on identity and access management security experience, including PAM, SSO, federation, zero trust access design, and identity-based attack patterns
  • Knowledge of data security concepts, data flow analysis, encryption standards, and sensitive data exposure risk
  • Hands-on incident response experience across detection, triage, containment, eradication, recovery, and root cause investigation
  • Technical depth in vulnerability management
  • Cloud security architecture and risk experience across Azure, AWS, or GCP
  • Windows, Linux, Active Directory, and enterprise network architecture fundamentals
  • Experience mentoring or providing technical leadership to junior security staff
  • Legally able to work in Canada on a permanent basis as a Canadian citizen or Permanent Resident
  • CCSP, OSCP, SABSA, SC-300, GCIH, GCIA, GDSA, or GPEN certification
  • Operational technology and industrial control system security familiarity
  • Application security and secure SDLC experience, including SAST, DAST, dependency analysis, pipeline security, API security, and secure coding guidance
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Vancouver
Year Founded: 1968

What We Do

TRIUMF is Canada's particle accelerator centre, serving as a multidisciplinary research laboratory that advances isotope science, particle physics, and nuclear medicine to drive discovery and innovation.

Similar Jobs

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Assistant Store Manager I

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
Vancouver, BC, CAN
16000 Employees
28K-40K Hourly

Samsara Logo Samsara

Customer Success Manager

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
Canada
4000 Employees
99K-128K Annually

Square Logo Square

Head of Social - Square

eCommerce • Fintech • Hardware • Payments • Software • Financial Services
Remote or Hybrid
8 Locations
12000 Employees
153K-245K Annually

Samsara Logo Samsara

Senior Software Engineer

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
Canada
4000 Employees
143K-185K Annually

Similar Companies Hiring

Vitalize Thumbnail
Artificial Intelligence • Healthtech • Software
US
50 Employees
Ford Energy Thumbnail
Automotive • Software • Energy • Utilities • Manufacturing • Renewable Energy
US
55 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
70 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account