Analyze data breaches and cyber insurance claims, conduct client security gap analyses, and advise CISOs on improving security controls. Work across cloud security, data protection, and compliance while partnering with product teams to codify security best practices into underwriting algorithms and risk management applications.
2-4 years of hands-on experience in security analysis, blue team/defensive security operations, and/or penetration testing/red team engagements
Deep understanding of the lifecycle of network threats, common attack vectors, and exploitation methods including TTPs
Strong knowledge of TCP/IP protocols, network analysis, and network/security applications including log and traffic analysis
Experience with vulnerability assessment and offensive security tools such as Nmap, Nessus, Burp Suite, Kali Linux, or Metasploit
Working knowledge of industry-standard security and risk frameworks such as NIST CSF, ISO 27001, HIPAA, PCI DSS
Clear, confident interpersonal communication skills with ability to translate technical concepts for non-technical audiences
Demonstrated ability to learn new technical concepts quickly and manage multiple tasks in a fast-paced environment
Bachelor's degree in Computer Science, Information Security, Engineering, or related field or equivalent practical experience
Review and analyze the security posture of insureds and prospective insureds quickly and efficiently
Evaluate customer security programs, technologies, controls, and business environments and recommend enhancements to reduce risk
Analyze root cause of cyber insurance claims and loss events and identify ways to detect and mitigate exposures
Triage security incidents and claims, understand root cause, and develop detection tradecraft informed by threat intelligence
Provide practical, prioritized recommendations to help customers manage information security risk and strengthen programs
Track emerging security practices, threat trends, and vulnerabilities and contribute insights to internal processes and products
Stay current on regulatory landscape and industry standards such as NIST, ISO, HIPAA, PCI and interpret implications
Collaborate cross-functionally with underwriting, claims, product, and engineering teams to translate security insights into scalable solutions
Remote-first organization with compensation reflecting cost of labor across Canadian geographic markets
Alberta, British Columbia and Ontario base salary ranges from $118,600/year up to $163,075/year
All other locations base salary ranges from $106,700/year up to $146,763/year
AI-assisted tools used to organize and review applications but human recruiting team makes all final hiring decisions
Status update on application provided within 45 days of final interview if interviewed
Posting is for an existing vacancy
184,000 – 356,500 USD
/ year
168,000 – 304,750 USD
/ year
124,000 – 195,500 USD
/ year
135,482 – 227,700 USD
/ year
184,000 – 356,500 USD
/ year