Information Security Consultant
Skills
About the role
Job number:
J0826-0426
Job title:
Information Security Consultant
Job Type:
Contract
Vacancy Type:
New
Location:
Toronto, Ontario, Canada
Number of positions:
1
Contract Duration :
1 year
Date posted:
August 25, 2026
Closing date:
September 8, 2026
Compensation:
$92,846.00 - $109,231.00/year
Who we are
We are an organization comprised of industry thought leaders who are passionate about health data and want to make a difference in the health care field. We are an independent, not-for-profit organization and together with our partners we provide essential information on Canada's health systems, enabling decisions that lead to healthier Canadians. As a valued member of the CIHI team, you and your work will have a pivotal role in the evolution of Canada's health care systems.
CIHI is recognized as an eceptional place to work that embraces diversity, respect, integrity, collaboration and innovation.
At CIHI, we recognize what matters to our employees. Some of the benefits of working at CIHI include
HOOPP Pension Plan (Defined Benefits Pension)
Retirement Planning Program
Generous vacation days for permanent and long-term contracts
Work-life balance
Career Planning Program
Learning and Professional Development Program
Fle ible benefits program from your first day on the job for permanent and long-term contracts
Why is this role important?
The Information Security Consultant is responsible for the effective design, configuration, management, monitoring, and protection of CIHI’s security infrastructure, including cloud environments, firewalls, and Security Information and Event Management (SIEM) solutions. The role enforces CIHI’s information security policies, procedures, and standards while maintaining compliance with industry, regulatory, and contractual requirements and managing risk. The Consultant ensures that security controls and infrastructure meet or eceed CIHI’s information security management requirements and continue to evolve in response to industry and regulatory changes.
What you'll do
1. Lead the planning, design, and implementation of CIHI’s security environment.
2. Oversee the secure deployment of cloud services provided by AWS, Azure, and other vendors, incorporating required security controls and monitoring solutions.
3. Design, configure, and manage security controls and policies in AWS and Microsoft Azure, ensuring protection for cloud-based infrastructure and applications.
4. Upgrade, configure, and maintain security systems and software, including firewalls, IDS/IPS, SIEM, web gateways, VPN solutions, and endpoint security software.
5. Plan and lead IT security projects for deploying, integrating, and enhancing security solutions in accordance with CIHI processes and industry best practices.
6. Participate and respond to security incidents as per CIHI’s security incident protocols, and lead the creation of incident playbooks and incident response tabletop eercises.
7. Monitor and asses risk, resolve security incidents (breaches, vulnerabilities, malware), and provide recommendations for improvements to eisting configurations, enhancements, or new security solutions for cloud and on-premises architectures.
8. Remain current on evolving security threats and proactively implement mitigation solutions.
9. Lead periodic vulnerability assessments, penetration testing, and internal audits to ensure staff preparedness and regulatory compliance.
10. Provide consulting on CIHI’s security systems, architecture, and industry best practices.
11. Define evaluation benchmarks to appraise, test, and select new security software and hardware technologies.
12. Assist with the development, implementation, and maintenance of CIHI’s IT security policies and procedures.
13. Lead the development of training material to facilitate information security awareness within the organization.
14. Liaise with members of the Privacy and Legal team and program areas as appropriate.
15. Provide guidance and instruction to junior team members.
What you'll bring to the table
Undergraduate degree in Computer Science program or related discipline, or equivalent combination of education and related eperience.
AWS Certified Security Specialist or Palo Alto PCNSE certification or equivalent security certification.
Minimum 5 years of relevant eperience as a security administrator.
Eperience in security for various cloud service models like IaaS, PaaS, SaaS, for AWS and Microsoft Azure, including the implementation of security best practices and compliance.
Eperience in creating alerts, reports, and dashboards using SIEM solutions.
Epertise in the design of networks, IP Addressing and IP protocols such as TCP/IP, DNS, DHCP, HTTP, TLS, SSH, 802.1, and IPsec.
Proficient in designing and managing enterprise security solutions such as firewall HA clusters, intrusion prevention systems, SIEM solutions, Web Gateways, Web Application Firewalls, Cloud Security Posture Management solutions, multi-factor VPN authentication, and application sandboing.
Proven ability to design, configure and manage security controls and policies in AWS and Azure.
Demonstrated knowledge of forensic tools (Wireshark), techniques, and methodology.
Strong understanding of security in the OS platforms and technologies including MS Windows, Linu, virtualization, containerization, mobile devices, and cloud services.
Proficient understanding of tiered Web applications operating on Windows/Linu
environment using Apache/IIS web servers and MS SQL/Oracle/MySQL databases.
Knowledge of NIST Cybersecurity framework and ISO 27001:2022.
Ability to conduct research into security issues and products, as required.
Strong interpersonal, communication skills, organizational skills and attention to detail.
Ability to effectively prioritize and eecute tasks with minimal supervision.
Eperience working in a team-oriented, collaborative environment.
Additional Requirements
Primary locations: Toronto or Ottawa.
Ability to work fleible hours to maintain systems and participate in on-call rotation.
Lifting of moderately heavy objects, such as servers and network appliances.
Occasional travel may be required.
Must comply with all CIHI workplace policies, including privacy and confidentiality.
Fluency in English is required, bilingualism in both official languages is an asset.
To find out more about this role and other eciting opportunities visit our website at www.cihi.ca and check out our 'Careers' section.
We thank all those who apply, however, only candidates selected for an interview will be contacted.
At CIHI we are committed to fostering an inclusive, barrier-free and accessible environment. Part of this commitment includes arranging accommodations to ensure an equitable opportunity to participate in the recruitment and selection process. If you require an accommodation, we will work with you to meet your needs.
Please note the CIHI Recruiting Team uses to communicate with applicants. Please make sure your profile has an updated address that is checked regularly, including the junk/spam mail folder, as we send time sensitive s (i.e. testing and interview bookings).
Data Privacy and Record Retention Notice
In accordance with Ontario’s legislation, CIHI is required to retain copies of this job posting and all associated application materials for a minimum of three (3) years from the date the posting is removed from public view.
By submitting your application, you acknowledge that your personal information and application data will be stored securely in our systems for this mandatory retention period to ensure compliance with provincial employment standards.
Are you interested in this job?
Compensation
This Security Engineer role pays $93k-$109k/yr. Within typical range for security engineer roles in Canada.
Questions about this role
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.