Analyst, Business Information Security (BIS), Deloitte Global Technology (Toront

🏢 Deloitte · all Deloitte jobs
📍 Canada
💰 CAD 69,000 - 114,000 / annual
📅 Posted 2026-08-30 · via Himalayas
🏷 Business-Information-Security,Cybersecurity-Analyst,Application-Security,Infosec,Security-Governance,Information-Security-Analyst,Cybersecurity-Risk-And-Compliance-Analyst
Apply on original site ↗

Job Type: Permanent
Work Model: Remote
Reference code: 134786
Primary Location: Toronto, ON
All Available Locations: Toronto, ON; Calgary, AB; Halifax, NS; Kitchener, ON; Ottawa, ON

Our Purpose

At Deloitte , our Purpose is to make an impact that matters. We exist to inspire and help our people, organizations, communities, and countries to thrive by building a better future. Our work underpins a prosperous society where people can find meaning and opportunity. It builds consumer and business confidence, empowers organizations to find imaginative ways of deploying capital, enables fair, trusted, and functioning social and economic institutions, and allows our friends, families, and communities to enjoy the quality of life that comes with a sustainable future. And as the largest 100% Canadian-owned and operated professional services firm in our country, we are proud to work alongside our clients to make a positive impact for all Canadians.

By living our Purpose, we will make an impact that matters.

- Have many careers in one Firm.

- Enjoy flexible, proactive, and practical benefits that foster a culture of well-being and connectedness.

- Learn from deep subject matter experts through mentoring and on the job coaching

Deloitte Global is the engine of the Deloitte network. Our professionals reach across disciplines and borders to develop and lead global initiatives. We deliver strategic programs and services that unite our organization.

What will your typical day look like?

As an Analyst within the Business Information Security area, you’ll work closely with both technical and non-technical stakeholders within an assigned line of business or technology enablement area providing the best possible support across a range of cybersecurity, risk, and risk mitigation disciplines. Along with having knowledge of industry-accepted best practices, the Analyst is expected to ensure that all applications and systems aligned to their line of business adhere to internal cybersecurity policies, standards, escalating any non-compliance up to the associated Business Information Security Officer (BISO). Successful candidates should showcase the capability to effectively influence and cultivate robust relationships with diverse stakeholders.

This role is responsible for overseeing the security posture and continual compliance of their assigned business/technology area’s applications by ensuring security is embedded from the start and that all associated development security procedures are followed, with appropriate security evaluations and testing process completed. Responsibilities will span from briefing teams on new cybersecurity priorities, to discussing risks and vulnerabilities (e.g., penetration testing, code scanning, etc., infrastructure patch/configuration, end of life software, TLS configurations, etc.), and controls compliance (e.g., service account compliance, firewall rule base compliance, key and certificate management, security agent health, etc.).

Responsibilities include:

-
- Understand their assigned global line of business, gain familiarity with priorities and become an advocate for them within cybersecurity.

- Work with multiple parties within their assigned service lines and the organization to help effect change and improve cybersecurity health/hygiene.

- Oversee the implementation of application security controls to ensure teams remain compliant with Deloitte cybersecurity standards.

- Process any risk-based matters / exceptions in accordance with Deloitte Technology’s strict policies and procedures.

- Support the Secure Systems Development Lifecycle (SSDLC), including functional and non-functional cybersecurity requirements.

- Strive for process improvement and automation; help development and operations team build automation for repeatable Cyber related vulnerability management activities.

- Maintain awareness of evolving application security threats and inform development, business, and risk sta

← All remote jobs

Similar for you