Municipality of Port Hope

Cybersecurity Analyst - Closing October 14, 2026

Port Hope, Ontario · Posted today

Opens municipalityofporthope.applytojob.com

Get a version of your resume written for this job.

Salary
Not listed
Job type
Full-time
Work mode
Not specified
Source
Jazzhr (employer's hiring system)

Skills mentioned

Cybersecurity

About the role

Port Hope is a uniquely attractive place to work, highlighted by the potential future development of the world's largest nuclear plant, which promises cutting-edge infrastructure and economic stability. This potential diversification into nuclear energy complements the area's strong economic base in agriculture and manufacturing, securing a stable job market. Employees will engage with advanced technology and industry experts, enhancing professional development. The community's warmth promotes work-life balance, supported by cultural festivals and heritage sites. Proximity to Toronto/GTA provides urban access, while the area's natural beauty invites outdoor recreation. High-quality education and healthcare, low crime rates, and a commitment to environmental sustainability make Port Hope an exceptional place to live and work, fostering both professional and personal growth.

The Cybersecurity Analyst serves as the primary technical resource for identifying, assessing, and reducing cybersecurity risks across the Municipality’s information, systems, and technology services. This includes monitoring and investigating security alerts and incidents, coordinating and participating in vulnerability remediation, supporting the implementation of security controls, and contributing to secure technology planning and operational improvements. The role works collaboratively with I.T. staff, municipal departments, and service providers to strengthen the confidentiality, integrity, availability, and resilience of municipal technology services. 

Benefits and Perks
  • Employer paid Group Health, Dental and Life Insurance after three months of employment
  • OMERS Pension Plan from the date of hire
  • Professional Development and Skill Based Training Opportunities
  • Alternate Work Arrangements
  • Wellness, Social and Staff Ambassador Committees
  • Employee and Family Assistance Plan
  • Perks and Savings Partnerships
Compensation
Approximately $86,805 per annum
Non Union Compensation study under review

Qualifications
  • Minimum 2 Year post-secondary education with a focus on cybersecurity.
  • Relevant cybersecurity certifications are preferred, such as CompTIA Security+, CompTIA CySA+, Microsoft Certified: Identity and Access Administrator Associate. Certified Information Systems Security Professional (CISSP) or similar is an asset.
  • Minimum of 3 years of experience in cybersecurity, security operations, or systems administration with substantial security responsibilities.
  • Demonstrated experience investigating and responding to security alerts or incidents, managed detection and response (MDR), endpoint detection and response (EDR), and identity.
  • Strong practical knowledge of Microsoft 365 security and identity capabilities, including Microsoft Defender, Entra ID, Intune, conditional access, multifactor authentication, role-based access control, audit logging, endpoint protection, and security/compliance controls.
  • Working knowledge of hybrid I.T. environments, including Windows servers and workstations, virtualization, Active Directory, networking, firewalls, VPNs, wireless networks, cloud services, mobile-device management, backup systems, and patch management.
  • Strong knowledge of vulnerability management, secure configuration, least privilege, privileged-access management, logging and monitoring, encryption, data protection, phishing and social-engineering risks, malware/ransomware response, and incident-response practices.
  • Knowledge of risk assessment, third-party and application security review, change management, security documentation, and the practical application of security controls in operational environments.
  • Understanding of the protection of personal information and confidential municipal information, and the importance of applying privacy-by-design and security-by-design principles.
  • Commitment to continuous education in Information Technology to stay current with emerging trends and technologies.
Responsibilities
  • Monitor and triage cybersecurity alerts and advisories; identify false positives and escalate or coordinate investigation and remediation of credible threats.
  • Coordinate and participate in vulnerability and patch management across municipal technology services; validate findings, prioritize risks, support remediation, verify completion, and track outstanding risks and exceptions.
  • Investigate suspected security incidents using logs, endpoint and identity data, user reports, and threat intelligence; document evidence, findings, timelines, and recommended actions.
  • Coordinate the technical response to cyber security incidents. Support containment, eradication, recovery, technical communications, and post-incident review activities.
  • Recommend, test, and support implementation of approved security controls and improvements through established change-management processes.
  • Assess and improve Microsoft 365 security, identity, endpoint, compliance, and information-protection controls, including Microsoft Defender, Entra ID, Intune, Conditional Access, MFA, privileged access, logging, retention, and data loss prevention.
  • Support the security of network, server, cloud, endpoint, backup, and monitoring environments through secure configuration, hardening, and hands-on vulnerability remediation in coordination with the I.T. team and applicable service providers.
  • Conduct security and privacy reviews for new or changed systems, vendors, integrations, and technology purchases; assess risks related to architecture, access, data handling, hosting, logging, encryption, vendor practices, and recovery requirements.
  • Participate in project planning, solution design, testing, go-live readiness, and post-implementation reviews to ensure security requirements and controls are identified early, appropriately implemented, and effectively maintained.
  • Support identity and access governance by reviewing privileged access, account lifecycle processes, role-based access, service accounts, MFA, external sharing, and access exceptions; identify gaps and coordinate corrective actions.
  • Analyze security logs, dashboards, service-health information, and metrics to identify trends, control weaknesses, recurring issues, and improvement opportunities.
  • Develop and maintain security standards, configuration baselines, procedures, checklists, and documentation; recommend updates to security policies and practices.
  • Support security awareness activities, including phishing simulations, targeted communications, end-user guidance, and role-appropriate training. Translate technical risks into clear, practical, actionable advice for municipal staff.
  • Maintain accurate records of security alerts, incidents, vulnerabilities, risks, remediation actions, exceptions, controls, and security assets.
  • Stay current on cybersecurity threats, vulnerabilities, tools, Microsoft security capabilities, and public-sector practices; recommend practical improvements aligned with municipal risk, capacity, service needs, and budget.
  • Provide cross-functional cybersecurity expertise and technical support to the I.T. team to strengthen the security, continuity, and resilience of municipal technology services.
  • Lead the development and maintenance of incident-response playbooks, escalation procedures, and contact lists for common cybersecurity scenarios.
  • Prepare incident summaries, post-incident reports, remediation plans, and periodic cybersecurity status reports for the Manager, Information Technology and other authorized stakeholders.
  • Maintain confidentiality and adhere to applicable municipal policies, procedures, legislative requirements, cyber security practices, standards of ethical conduct, and high standards of ethical behaviour, recognizing that personal actions may impact the public’s perception of the Municipality.
  • Perform other duties as assigned by the Manager, Information Technology or designate.
Skills and Abilities
  • Strong analytical, investigative, troubleshooting, and problem-solving skills, with the judgement to assess risk, prioritize competing events, and escalate appropriately.
  • Ability to translate technical cyber risks, controls, and recommendations into clear, practical language.
  • Ability to plan, document, and coordinate multiple security initiatives and incident activities while working effectively under tight timelines and shifting priorities.
  • Ability to work independently on assigned security operations and improvement work, while collaborating closely with the I.T. team and external service providers.
  • Strong judgement, organizational, analytical, and problem-solving skills.
  • Ability to multitask and work both independently and as a team.
  • Logical and efficient, with keen attention to detail.
  • Self-motivated and self-directed.
  • Excellent time management skills with the ability to prioritize effectively.
  • Ability to maintain confidentiality and handle sensitive information with discretion.
Other
  • Valid and satisfactory ‘G’ Driver’s license and access to own vehicle.
  • Valid and satisfactory Criminal Record and Judicial Matters Check.
  • Office environment with flexibility to work remotely.
  • Occasional travel to other municipal work locations.
  • Extended periods of concentration and work on computer screens.
  • Fast-paced working environment with constantly shifting priorities.
  • Must perform on-call duties as required.
Submit an Application
Please submit your cover letter and resume online at Careers - Municipality of Port Hope by October 14, 2026. Interviews may be scheduled in advance of the closing date. This position is currently vacant.

Recruitment Process

Job ID jz-municipalityofporthope-20260929121514_6djlwx2nysjh4160 · Original posting ↗