Intermediate Cyber Security Analyst

Jsi
Jsi

Marketing & Communications, IT

Canada · Ottawa, ON, Canada · Can Giuoc, Long An, Vietnam

Posted on Oct 3, 2026

As a Cyber Security Analyst, you will provide frontline monitoring, triage, and escalation support for JSI's cyber security program. This is an early-career individual contributor role with no team leadership responsibilities, designed to build toward more senior security work under the guidance of senior team members.

You will report to the Senior Manager, IT/IS/Cyber Security Operations for people management, and take technical direction, task prioritization, and day-to-day operational guidance from the Cyber Team Lead and Senior Cyber Security Analysts. This role follows established playbooks and escalation procedures, building toward greater independence and judgment over time.

Role Summary

As an Intermediate Cyber Security Analyst, you will take on hands-on ownership across JSI's cyber security program, working independently on security monitoring, vulnerability and patch management, incident response, and information security governance, risk, and compliance (GRC). This is an individual contributor role with no formal team leadership responsibilities, positioned between the Cyber Security Analyst and Senior Cyber Security Analyst roles.

You will report to the Senior Manager, IT/IS/Cyber Security Operations for people management, and take technical direction, task prioritization, and day-to-day operational guidance from the Cyber Team Lead. You will work closely with Senior Cyber Security Analysts, providing mentorship and quality review to more junior analysts, while continuing to build toward senior-level ownership of incident response and GRC program work.

Role Purpose

The purpose of this role is to provide dependable, increasingly independent execution across JSI's security operations and GRC activities, closing the gap between first-line monitoring/triage and senior, program-level ownership. The position takes on routine execution of vulnerability scanning and reporting, handles standard (non-P1/P2) incident response activities with reduced oversight, and takes on day-to-day evidence collection, policy drafting, and third-party vendor compliance tracking in support of JSI's GRC program.

This role also supports the Cyber Team by triaging and resolving more complex Service Desk escalations, providing day-to-day guidance to Cyber Security Analysts, and contributing proactively to process and tooling improvements, while continuing to build toward full senior-level program ownership.

Key Responsibilities

Security Monitoring and Vulnerability Management

  • Monitor and investigate alerts across security tools (e.g., CrowdStrike, SIEM platforms, Tenable Nessus, Qualys), independently triaging and classifying most alerts without close supervision
  • Execute recurring vulnerability scans and produce reporting independently, escalating complex or high-risk findings to the Senior Analyst or Cyber Team Lead
  • Track outstanding vulnerability remediation status and follow up with asset owners against SLA
  • Support patch deployment validation in coordination with the ITS team
  • Support internal and external penetration testing activities, including scoping logistics and remediation follow-up

Incident Response

  • Lead triage, containment, and documentation for standard (non-P1/P2) security incidents, escalating P1/P2 incidents to the Senior Cyber Security Analyst or Cyber Team Lead per defined escalation procedures
  • Conduct data gathering, log review, and initial forensic analysis to support investigations
  • Contribute to post-incident documentation, root cause analysis, and lessons-learned reviews
  • Support the maintenance of incident response playbooks and escalation procedures, flagging gaps or improvement opportunities

GRC and Compliance

  • Coordinate evidence collection and day-to-day Vanta updates in support of ISO 27001, UK Cyber Essentials, and EU CRA compliance activities
  • Draft policy and procedure documentation for review by the Cyber Team Lead
  • Track third-party vendor compliance checklists and follow up on outstanding items, escalating non-responses
  • Support audit cycles and compliance assessments by preparing documentation and coordinating evidence requests across teams

Operational Excellence and Service Delivery

  • Handle escalated and more complex security-related Service Desk tickets referred by Cyber Security Analysts
  • Provide day-to-day guidance and quality review to Cyber Security Analysts on triage decisions and documentation
  • Identify and flag recurring or high-impact ticket trends to the Cyber Team Lead to support process or tooling improvements

Stakeholder Engagement and Collaboration

  • Collaborate with the ITS and IS teams to align security measures with infrastructure, application, and business system changes
  • Support user security awareness efforts, including phishing report triage and basic staff guidance
  • Communicate security findings and recommendations clearly to both technical and non-technical stakeholders
  • Take technical direction, task prioritization, and day-to-day operational guidance from the Cyber Team Lead

Required Education and Experience

  • Bachelor's degree, college diploma, or equivalent experience in Computer Science, Information Technology, or a related field
  • 4 to 6 years of progressive experience in IT security, cyber security, or a related technical role
  • Solid understanding of networking concepts, firewalls, and intrusion detection/prevention systems
  • Hands-on experience with vulnerability management and endpoint protection platforms (e.g., CrowdStrike)
  • Experience with, or meaningful exposure to, GRC and compliance management tooling (e.g., Vanta)
  • Working familiarity with ITIL/ITSM-aligned incident, problem, and change management practices

Additional Requirements

  • Strong analytical and problem-solving skills, with sound judgment on when to escalate
  • Ability to work independently on standard tasks while recognizing the limits of own authority
  • Good written and verbal communication skills across technical and business audiences
  • Willingness to work rotating shifts or provide on-call coverage if required
  • Ability to attain and maintain required security clearance

Desirable Skills

  • Working toward or holding an intermediate certification (e.g., CISSP, CompTIA Security+, GSEC) is a plus
  • Experience with SIEM/SOAR tooling and alert-tuning
  • Basic scripting skills (e.g., PowerShell, Python) to support automation of routine tasks
  • Familiarity with common compliance frameworks (e.g., NIST, ISO 27001)
  • Experience working in hybrid environments combining on-premises infrastructure, Microsoft 365, Azure, and SaaS platforms

Mindset and Growth

  • Demonstrates increasing independence and sound judgment in day-to-day decision-making
  • Strong sense of ownership and accountability for the quality of own work and work reviewed for others
  • Proactive in identifying risks, inefficiencies, and improvement opportunities
  • Comfortable mentoring more junior analysts while continuing to build toward senior-level scope

This role description is not intended to be an exhaustive list of responsibilities. Duties may evolve over time and may be adjusted to meet organizational needs. The successful candidate may also be required to perform other related duties as assigned.

The successful candidate will be required to complete a background check prior to employment

About JSI

JSI is built on purpose, that of making a difference in the world.

Founded in 1979, this privately-owned technology company is the North American leader in designing and developing acquisition, collection and analysis solutions for law enforcement and intelligence communities.

With 4Sight – JSI’s single, unified, product suite – customers can combine any number of disparate data sources into a highly intuitive, visually-focused platform. The result? JSI’s customers spend less time working with data and more time seeing patterns, understanding trends, and gaining perspective (and making the world a safer place).

With over 400 employees and a strong, growing global presence in Canada, the U.S., Australia, and Germany, JSI is not only the dominant player in its industry, it is also known for its fun, high-performing, purpose-driven corporate culture.

In accordance with the Accessibility for Ontarians with Disabilities Act (AODA), JSI will provide accommodation-accessible formats, and communication supports for the interview process upon request.

Our hiring process does not use artificial intelligence (AI) tools for screening, assessing, or selecting applicants. All applications are reviewed and evaluated by our HR team.