Senior Analyst - Cyber Threat Modeling and Risk

EQ Bank · Toronto

Join a Challenger

Being a traditional bank just isn’t our thing, so we challenge ourselves to get creative in providing innovative banking solutions for Canadians.

How do we get there? With a talented team of inquisitive and agile challengers that break through the status quo. So, if you’re passionate about redefining the future of banking—while having fun—this could be your next big opportunity.

Our company continues to grow, and today we serve more than 800,000 customers across Canada through Equitable Bank, Canada's Challenger Bank™, and have been around for more than 50 years. Equitable Bank's wholly-owned subsidiary, Concentra Bank, supports credit unions across Canada that serve more than six million members. Together we have over $142 billion in combined assets under management and administration, with a clear mandate to drive change in Canadian banking to enrich people's lives. Our customers have named our EQ Bank digital platform (eqbank.ca) one of the top banks in Canada on the Forbes World's Best Banks list since 2021. 

The Work
 
The Senior Analyst - Cyber Threat Modeling and Risk supports the Threat Modeling and Risk Assessment program by assisting with the identification, assessment, and tracking of cyber security risks across technology. The role works under the guidance of senior team members to help ensure appropriate security controls are identified early in the design lifecycle, enabling secure and resilient technology solutions while supporting business growth. 

The Core Responsibilities!

  • Provide security advisory support to technology and business teams under supervision.
  • Help conduct threat modeling and security assessments for applications and infrastructure.
  • Review solution designs with senior analysts and SMEs to identify threats, attack paths, and risks.
  • Document outputs like data flow and architecture diagrams, along with basic threat scenarios.
  • Assist in tracking and addressing design flaws and security findings from threat modeling.
  • Support onboarding of security services (e.g., MFA, logging, vulnerability scanning) guided by senior team members.
  • Keep accurate records in risk tracking repositories.
  • Aid continuous improvement of threat modeling processes, templates, and documentation.
  • Build foundational knowledge of the organization’s enterprise security frameworks, policies, and standards.
  • Review solution designs for risk and threat assessment.
  • Record risks, threat scenarios, and control gaps in tracking tools.
  • Track remediation actions and assist risk discussions with stakeholders.
  • Build knowledge of cyber security controls and their technology applications.
  • Let's Talk About You!

  • A college diploma or university degree in Computer Science, Information Technology, Cyber Security, or a related discipline is required.
  • 2–3 years of experience in information security, IT risk, or technology roles is preferred.
  • Foundational understanding of threat modeling concepts or methodologies; practical experience is an asset.
  • Basic understanding of application security principles and common vulnerabilities (e.g., OWASP Top 10).
  • Exposure to cloud and hybrid environments is an asset.
  • Ability to support IT security risk assessments and document findings clearly.
  • Familiarity with security diagrams and documentation such as data flow diagrams and architecture diagrams.
  • Understanding of APIs, CI/CD pipelines, or secure software development practices is an asset.
  • Strong communication, documentation, and collaboration skills. 
  • Interest in pursuing security certifications (e.g., Security+, CCSP, CISSP in future) is an asset.
  • Apply →