T

TRIUMF

Canada’s particle accelerator research facility

Cybersecurity Analyst 2

Full-TimeUpdated on 10/2/2026Deadline 10/24/26
CA$92.9k/yr
Senior
Bachelor's
Vancouver, BC, Canada
In Person
Canada Citizenship Required

About the job

Requirements
  • Strong communication skills, including the ability to explain complex technical attack scenarios, detection logic, and risk findings clearly to technical peers and non-technical stakeholders and leadership.
  • Strong analytical and adversarial thinking, approaching systems from an attacker's perspective and reasoning about how controls would hold up under realistic attack conditions.
  • Sound judgment when managing competing priorities, incomplete information, and technically complex or ambiguous risk decisions.
  • Discretion and professionalism in handling sensitive security, risk, and organizational information.
  • Ability to work collaboratively across IT, engineering, research groups, and leadership and influence security outcomes without direct authority.
  • Bachelor's degree in Cybersecurity, Information Technology, or Computer Science, or equivalent technical experience.
  • At least 5 years of hands-on cybersecurity experience, with depth in two or more of technical risk assessment, security architecture review, detection engineering, or identity security.
  • CISSP certification expected at this level, or active progress toward it.
  • Hands-on experience with technical security risk assessments, attack surface analysis, and threat modeling.
  • Hands-on experience reviewing security architecture for networks, cloud environments, applications, and enterprise systems.
  • Experience authoring SIEM detection content, correlation rules, behavioral analytics, and MITRE ATT&CK coverage mapping.
  • Experience with identity and access management security, including privileged access management, single sign-on, federation, zero-trust access design, and identity-based attack patterns.
  • Experience with data security concepts including data flow analysis, encryption standards, and sensitive data exposure risk.
  • Hands-on incident response across detection, triage, containment, eradication, recovery, and root cause investigation.
  • Technical depth in vulnerability management.
  • Cloud security architecture and risk experience across Azure, AWS, or Google Cloud Platform.
  • Windows, Linux, Active Directory, and enterprise network architecture fundamentals.
  • Mentoring or providing technical leadership to junior security staff.
  • Legal ability to work permanently in Canada as a Canadian citizen or permanent resident.
Responsibilities
  • Lead technical cybersecurity risk assessments of systems, applications, infrastructure, and projects.
  • Evaluate control effectiveness to determine whether existing safeguards would realistically detect or prevent an attack.
  • Evaluate third-party and vendor security posture before onboarding and on an ongoing basis.
  • Communicate risk findings with technical precision to technical stakeholders and in plain institutional-impact terms to non-technical stakeholders.
  • Contribute to risk reporting for governance and leadership forums as a secondary output of technical work.
  • Review the security design of proposed and existing systems, networks, applications, and cloud deployments.
  • Assess data flows and sensitive data exposure risks during architecture reviews and escalate findings to the appropriate owner.
  • Perform threat modeling to identify attack paths, trust-boundary weaknesses, and exploitable design flaws.
  • Provide secure design guidance to engineering and infrastructure teams throughout project lifecycles.
  • Participate in change-management processes to assess the security implications of infrastructure and application changes.
  • Own the development and lifecycle management of detection content across SIEM, EDR, and other detection platforms, including writing, testing, validating, and maintaining detection logic.
  • Map and maintain detection coverage against the MITRE ATT&CK framework, identify blind spots, and prioritize new detection development based on realistic organizational threat scenarios.
  • Translate threat intelligence, adversary tactics, techniques, and procedures, and post-incident findings into new detection use cases and build coverage where gaps exist.
  • Document detection logic, tuning rationale, and coverage decisions to support knowledge transfer and audit requirements.
  • Own the security architecture and risk posture of the organization's identity and access management environment, including authentication systems, privileged access management, single sign-on, federation, and directory services.
  • Evaluate IAM designs and configurations, assessing authentication strength, privilege scope, and susceptibility to identity-based attacks such as credential theft, lateral movement, and privilege escalation.
  • Lead or contribute to zero-trust identity initiatives, including least-privilege access design, conditional-access policy review, and multifactor-authentication coverage.
  • Identify and drive remediation of identity-architecture weaknesses surfaced through risk assessments, architecture reviews, or incident investigations.
  • Lead or provide senior technical support for complex or high-severity cybersecurity incident investigations.
  • Guide and mentor junior analysts through triage, containment, eradication, and recovery.
  • Lead post-incident reviews and root-cause analysis, identify architectural or detection weaknesses, and drive remediation.
  • Support the design and execution of incident-response tabletop exercises.
  • Provide senior technical oversight of vulnerability management, including validation of scan findings, prioritization based on exploitability and asset criticality, and guidance on remediation approaches.
  • Monitor threat-intelligence feeds and security advisories, evaluate relevance to the organization's architecture and risk posture, and determine prioritization and response.
  • Assess emerging vulnerabilities for real-world exploitability and business impact in context.
  • Identify systemic weaknesses and architectural patterns that produce repeated vulnerabilities and recommend structural remediation.
  • Contribute technical subject-matter expertise to the development and review of cybersecurity policies and standards.
  • Support audits, compliance assessments, and regulatory inquiries by providing technical evidence, documentation, and clear explanations of controls.
  • Identify opportunities to improve the organization's security posture through better architecture, tooling, detection, or process, and lead initiatives to address them.
  • Provide technical mentorship and coaching to junior and intermediate cybersecurity analysts, including guidance on assessment methodology, analytical approach, and communicating findings.
  • Review and validate the work of junior analysts on risk, detection, and vulnerability assessments.
  • Act as the team's primary subject-matter expert and escalation point for complex technical risk, detection, identity, and architecture questions.
Desired Qualifications
  • Familiarity with operational technology and industrial control system security concepts, including secure architecture and risk considerations for research or scientific environments.
  • Application security and secure software development lifecycle experience, including SAST and DAST tooling, dependency and software composition analysis, pipeline security, API security review, and hands-on secure coding guidance to development teams.
  • CCSP, OSCP, SABSA, SC-300, or GIAC certifications such as GCIH, GCIA, GDSA, or GPEN.

About the company

TRIUMF is Canada’s national particle accelerator centre in Vancouver, running a large accelerator complex for research in particle and nuclear physics. Researchers use its facilities to study fundamental matter and to develop practical technologies, including medical isotopes and materials science applications. It differentiates itself through nationwide university collaborations, a multidisciplinary team, and a direct path from basic discoveries to real-world benefits. Its goal is to advance science while building Canadian leadership in science and technology and training the next generation of scientists, engineers, and leaders.

Company Size

501-1,000

Company Stage

Grant

Total Funding

$293.2M

Headquarters

Vancouver, Canada

Founded

1968

Get referred to TRIUMF

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • BC’s $32 million cancer investment expands PET/CT capacity from 16,000 to 41,000 scans.
  • TRIUMF’s July 2026 benchmark strengthens grant leverage for advanced neutron and antimatter programs.
  • The 2025 CERN statement and 2026 summer-student pipeline reinforce TRIUMF’s talent and partnership moat.

What critics are saying

  • TRIUMF depends on public funding; the 2024 federal package and 2025 ministerial support dominate budgets.
  • Health Canada licensing and 2026 commissioning for the cyclotron can delay cancer-research revenue.
  • A failed nEDM or isotope program would weaken TRIUMF’s scientific relevance and funding case.

What makes TRIUMF unique

  • TRIUMF’s 2026 ultracold neutron source leads the world with 6.7×10⁵ neutrons per second.
  • Canada’s CERN partnership and TRIUMF-ATLAS work keep TRIUMF embedded in global physics networks.
  • TRIUMF’s UBC campus location anchors isotope science beside BC Cancer and Health Canada licensing.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

Wellness Program

Parental Leave

Paid Vacation

Growth & Insights and Company News

Headcount

6 month growth

↑ 13%

1 year growth

↑ 13%

2 year growth

↑ 13%
SNOLAB
May 21st, 2025
Former SNOLAB director elected Fellow of the Royal Society

Smith left SNOLAB in 2021 to take on the role of executive director and CEO of TRIUMF in Vancouver.

Government of British Columbia
Jan 30th, 2024
BC Gov News

The Province is investing $32 million to support this work through $21 million to BC Cancer for the new cyclotron and radiopharmacy laboratory and approximately $11 million to TRIUMF to advance research.