TC
Information Security Analyst 3 (Cybersecurity Incident Response) (Toronto, ON, CA)
The Canada Life Assurance Company
85.200–135.200 CA$ pro Jahr · Toronto, Ontario, CA
Canada Life has been writing insurance policies since 1847 - long enough to accumulate a sprawling attack surface across multiple continents. The company operates in Canada, the United Kingdom, the Isle of Man, Germany, and Ireland, spanning insurance, wealth management, and healthcare benefits. That means the data at stake isn't just financial: it's actuarial models, personal health records, benefits administration systems, and the regulatory obligations of at least five jurisdictions. For cybersecurity practitioners, the threat model here is dense and layered. Healthcare benefits processing pulls in protected health information under frameworks like PIPEDA and GDPR. Financial services operations face the usual fraud, credential-stuffing, and third-party risk vectors, compounded by legacy infrastructure that a 177-year-old institution accumulates organically. The perimeter isn't a single data center - it's a multinational web of policyholder portals, advisor platforms, claims systems, and benefits administration tooling. Security teams working across Canada Life's verticals are dealing with regulatory pressure from multiple directions simultaneously: Canadian OSFI guidelines, UK FCA expectations, and EU data protection mandates. The work involves securing environments where insurance underwriting, investment management, and healthcare claims processing all intersect - each with distinct data sensitivity profiles and compliance requirements.
Canada Life has been writing insurance policies since 1847 - long enough to accumulate a sprawling attack surface across multiple continents. The company operates in Canada, the United Kingdom, the Isle of Man, Germany, and Ireland, spanning insurance, wealth management, and healthcare benefits. That means the data at stake isn't just financial: it's actuarial models, personal health records, benefits administration systems, and the regulatory obligations of at least five jurisdictions.
For cybersecurity practitioners, the threat model here is dense and layered. Healthcare benefits processing pulls in protected health information under frameworks like PIPEDA and GDPR. Financial services operations face the usual fraud, credential-stuffing, and third-party risk vectors, compounded by legacy infrastructure that a 177-year-old institution accumulates organically. The perimeter isn't a single data center - it's a multinational web of policyholder portals, advisor platforms, claims systems, and benefits administration tooling.
Security teams working across Canada Life's verticals are dealing with regulatory pressure from multiple directions simultaneously: Canadian OSFI guidelines, UK FCA expectations, and EU data protection mandates. The work involves securing environments where insurance underwriting, investment management, and healthcare claims processing all intersect - each with distinct data sensitivity profiles and compliance requirements.