1

Infrastructure Security Analyst Jobs in Ontario (NOW HIRING)

... and Infrastructure-as-Code security * Applied knowledge of common vulnerabilities, threats ... Strong analytical, troubleshooting, communication and organizational skills * Ability to ...

We are seeking a senior security/threat analyst with expertise in threat modeling who has the ... Develop Security Patterns for application and infrastructure. Review the developed security pattern ...

The Analyst - Managed Security Services provides first-level technical client support and upholds ... Understanding of IT infrastructure and Information Systems design, including hardware, software and ...

next page

Showing results 1-20

Infrastructure Security Analyst information

See Ontario salary details

$11

$55

$90

How much do infrastructure security analyst jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for infrastructure security analyst in Ontario is $55.22, according to ZipRecruiter salary data. Most workers in this role earn between $47.84 and $63.46 per hour, depending on experience, location, and employer.

What does an infrastructure security analyst do?

An Infrastructure Security Analyst is responsible for protecting an organization’s IT infrastructure from cyber threats and vulnerabilities. They monitor networks, servers, and systems for suspicious activity, conduct risk assessments, and implement security measures such as firewalls and encryption. These professionals also respond to security incidents, ensure compliance with security policies, and help design strategies to prevent future breaches. Their work is crucial in maintaining the confidentiality, integrity, and availability of company data and services.

What are the key skills and qualifications needed to thrive as an infrastructure security analyst?

To excel as an Infrastructure Security Analyst, you need a solid background in network security, risk assessment, and incident response, typically supported by a degree in information technology or cybersecurity and relevant certifications like CompTIA Security+ or CISSP. Familiarity with security information and event management (SIEM) tools, firewalls, intrusion detection systems, and vulnerability scanners is crucial. Strong analytical thinking, attention to detail, and effective communication skills help analysts identify threats and collaborate with IT teams. These skills and qualities are vital for proactively protecting organizational assets and ensuring robust defense against evolving cyber threats.

What are the most common challenges infrastructure security analysts face when balancing security requirements with business operations?

Infrastructure Security Analysts often encounter the challenge of implementing robust security controls without disrupting essential business processes. They must strike a balance between enforcing strict security measures, such as access controls and monitoring, while ensuring that employees can efficiently perform their duties. Collaboration with IT, operations, and business teams is crucial to understand workflow needs and to design solutions that mitigate risks without causing unnecessary friction. Effective communication and a proactive approach to understanding evolving business requirements help analysts address these challenges successfully.

What is the difference between Infrastructure Security Analyst vs Network Security Analyst?

AspectInfrastructure Security AnalystNetwork Security Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, CCNA Security
Work EnvironmentFocus on securing entire IT infrastructure, including servers, cloud, and hardwareFocus on securing network devices, traffic, and network-specific vulnerabilities
Employer & Industry UsageUsed across industries to protect infrastructure assetsCommon in organizations with complex networks, such as ISPs and large enterprises
Comparison Search IntentHigh overlap in cybersecurity roles, often compared in job searchesRelated but more network-specific

While both roles focus on cybersecurity, the Infrastructure Security Analyst primarily safeguards the entire IT infrastructure, including servers and cloud systems. The Network Security Analyst concentrates on protecting network devices and traffic. Understanding these differences helps in choosing the right career path or job focus.

What are popular job titles related to Infrastructure Security Analyst jobs in Ontario?

For Infrastructure Security Analyst jobs in Ontario, the most frequently searched job titles are:

What job categories do people searching Infrastructure Security Analyst jobs in Ontario look for?

The top searched job categories for Infrastructure Security Analyst jobs in Ontario are:

Infographic showing various Infrastructure Security Analyst job openings in Ontario as of August 2026, with employment types broken down into 79% Full Time, 19% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $114,860 per year, or $55.2 per hour.

Senior Information Security Analyst

D2L

Kitchener, ON • Hybrid

Full-time

Re-posted 14 days ago


Job description

As Senior Information Security Analyst at D2L, you are a key influencer and contributor to the refinement and delivery of D2L's Information Security Program.  

How will I make an Impact?

  • Assist in refining and delivering D2L's Information Security Program with particular focus on endpoints, applications, and the underlying infrastructure.  
  • Perform regular application/infrastructure security scans, generate reports, and liaise with related stakeholders to work towards closing open issues.  
  • Liaise with operational teams on existing and emerging information security risks and provide subject matter expertise.  
  • Monitor/track information security risks and related artifacts throughout their lifecycle.  
  • Support the Information Security Continuous Monitoring Program(s) aligned with specific security compliance programs.  
  • Support the product sales cycle by completing security questionnaires from prospective clients.  
  • Collaborate with internal subject matter experts to collate, review, and submit periodic security questionnaires from D2L's client.  
  • Support internal D2L teams during security assessments/reviews/audits.  
  • Review independent third-party reports from vendors, suppliers and partners for adequacy and alignment with D2L's Information Security Program.  
  • Track identified gaps from third party assessments and follow up with stakeholders to close outstanding issues.  

What you'll bring to the role:

Competencies: 

  • Ability to think critically  
  • Ability to engage process owners and explain security controls associated with processes 
  • Ability to breakdown complex technical concepts to simple terms for various levels of stakeholders 
  • Ability to achieve outcomes with minimal supervision. 
  • Ability to learn fast and synthesize information from different domains and sources. 
  • Ability to work well with teams within a matrix structure and operational setting 

Skills 

  • Sound knowledge of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST) and Software Composition Analysis (SCA).  
  • Sound knowledge of public cloud infrastructure  
  • Practical knowledge of implementing security controls in public cloud deployments/workloads  
  • Practical knowledge of Governance Risk and Compliance (GRC) tools  
  • Practical knowledge of infrastructure and application security scanning tools  
  • Deep understanding of vulnerability management and penetration testing  
  • Acumen with Artificial Intelligence tools
  • Sound knowledge of risk management framework and standards 
  • Sound knowledge of Information Security frameworks and standards including ISO 27001, NIST 800-53 etc. 

Suggested Qualifications/Experience: 

  • You have previous hands-on experience implementing information security controls across a wide range of domains including Endpoint Security, Application Security, and Infrastructure Security.  
  • You have hands-on experience with public cloud services like Amazon Web Services (AWS), Azure etc.  
  • You have hands-on experience performing vulnerability assessments and penetration tests.  
  • You have demonstrable experience working with teams that have implemented security controls based on ISO 27001/NIST 800-53, CSAE 3416/SSAE18, SOC1/2/3.  
  • You have experience using enterprise-grade governance risk and compliance (GRC) tools.  
  • You have experience assessing security control implementations on large enterprise, web scale and serverless environments. 
  • You have experience engaging stakeholder in remediating security-related findings  
  • You have experience supporting an audit exercise by generating security-related evidence  

This position is to fill an existing vacancy


D2L operates in a hybrid work style, with expectation of 3 days per week in office.Â