Trillium Health Partners

Senior Advisor -CVH IT Common Services

Trillium Health Partners  •  Mississauga, CA (Onsite)  •  3 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Position: Sr. Cyber Security Analyst - AI Security & Microsoft 365 Security

Dept: Information Services/Cyber Defense and Identity Access Management

Posting ID: 8145

Status: Permanent Full-time

Role Level: PG11 ($48.85hr-$61.06hr)

Hours of work/Shift: Monday to Friday, 9.00 AM to 5.00 PM

Site: Credit Valley Hospital

Posted: August 26, 2026

Internal Deadline: September 2, 2026

Trillium Health Partners is one of Canada’s largest community-based teaching hospitals, serving the growing and diverse populations of Mississauga, West Toronto, and surrounding communities through the Credit Valley Hospital, the Mississauga Hospital, the Queensway Health Centre,the Reactivation care Centre (Church Site) and the new THP-UHN Reactivation Care Centre.Guided by our values of compassion, excellence, and courage, and through our strategic roadmap, Plan to 2030, we are creating a new kind of health care - defined not by illness, but by the health and well-being of people and communities.

Drive IT Excellence through Information Security

Bring your talents to Trillium Health Partners and Trillium HealthWorks and become an invaluable leading resource to our team ensuring the highest level of system performance, integrity and reliability. At THP, we are diligent in protecting our information assets. These assets are critical to the fulfillment of our mission. We strive to safeguard the confidentiality, integrity, and availability of our hospital and patient’s information.

The Senior Cybersecurity Analyst – AI Security & Microsoft 365 Security is a dedicated resource to Trillium HealthWorks and reporting to Cyber Defense and Identity Access Management team. The analyst will advance Trillium HealthWorks priorities by securing the organization's adoption and use of Artificial Intelligence (AI) technologies, AI-enabled applications, and Microsoft 365 cloud services. This role focuses on identifying, assessing, and mitigating cybersecurity risks associated with Generative AI, Agentic AI, Large Language Models (LLMs), Copilot technologies, AI-powered business applications, and evolving AI-driven cyber threats.

The successful candidate will work closely with business units, IT teams, cloud administrators, privacy stakeholders, and cybersecurity leadership to establish security controls, governance frameworks, monitoring capabilities, and threat detection strategies that protect enterprise data, identities, and systems.

Key responsibilities:

AI Security Governance & Risk Management

  • Develop, implement, and maintain security policies, standards, and governance frameworks for the secure adoption of AI technologies and AI-enabled business applications, designing future systems for Trillium HealthWorks.
  • Conduct security assessments and risk analyses of Generative & Agentic AI platforms, Large Language Models (LLMs), AI-powered SaaS applications, and internally developed AI solutions.
  • Evaluate AI vendors and third-party AI services to ensure compliance with organizational security, privacy, and regulatory requirements.
  • Collaborate with Legal, Privacy, Compliance, and Risk Management teams to address AI-related security, privacy, intellectual property, and data protection risks.
  • Define and implement controls for secure use of AI technologies, including data classification, data loss prevention (DLP), access control, and information protection.

AI Threat Detection & Protection

  • Research, analyze, and monitor emerging AI-driven cyber threats, attack techniques, and threat actor activities.
  • Assess & manage risks associated with:
    • Prompt injection attacks
    • Data poisoning
    • Model manipulation
    • Adversarial AI attacks
    • AI-generated phishing campaigns
    • Deepfake and synthetic media attacks
    • AI-assisted malware development
    • Credential theft and social engineering enhanced by AI
  • Develop detection and response use cases for AI-related threats within SIEM, XDR, and security monitoring platforms.
  • Collaborate with threat intelligence teams to identify indicators of compromise (IOCs) and emerging AI attack trends.
  • Recommend security controls and mitigation strategies to defend against AI-enabled attacks.

Security Operations & Incident Response

  • Monitor security alerts, events, and incidents related to AI platforms, Microsoft 365 environments, cloud services, and enterprise applications.
  • Investigate security incidents involving AI systems, Microsoft 365 services, user identities, and cloud resources.
  • Participate in incident response activities, root cause analysis, containment, eradication, and recovery efforts.
  • Develop incident response procedures and playbooks for AI-related security incidents.
  • Support vulnerability management and remediation activities across AI and cloud environments.
  • Participate in on-call rotation for Security Operation Support after hours.

Security Architecture & Control Validation

  • Assess AI and Microsoft cloud solutions against cybersecurity frameworks and industry best practices.
  • Conduct security reviews, threat modeling, and architecture assessments for AI deployments and cloud services.
  • Validate security controls through configuration reviews, testing, and continuous monitoring.
  • Support implementation of Zero Trust security principles across Microsoft 365 and AI environments.

Security Awareness & Training

  • Provide guidance and training to employees on the secure use of AI tools, Microsoft Copilot, and cloud collaboration services.
  • Develop awareness materials addressing AI-related risks including data leakage, prompt security, phishing, and deepfake threats.
  • Promote secure and responsible AI usage across the organization.

Microsoft 365 Security

  • Secure Microsoft 365 services including:
    • Microsoft Entra ID (Azure AD)
    • Microsoft Defender for Endpoint
    • Microsoft Purview
    • Microsoft Intune
    • Microsoft Teams
    • Exchange Online
    • SharePoint Online
    • OneDrive for Business
    • Microsoft Copilot
  • Implement and maintain security controls including:
    • Conditional Access
    • Multi-Factor Authentication (MFA)
    • Identity Protection
    • Privileged Identity Management (PIM)
    • Data Loss Prevention (DLP)
    • Information Protection and Sensitivity Labels
    • Insider Risk Management
    • Compliance and retention policies
  • Monitor Microsoft 365 security posture and recommend remediation actions to reduce risk.
  • Conduct security reviews of Microsoft Copilot deployments and AI-enabled M365 services.
  • Develop and apply Microsoft Copilot for Security to enable fast Cyber Security Incident detection, investigation and respond.

Qualifications

Successful candidates will have demonstrated extensive experience in information security.

  • The ideal candidates will, at minimum, have 5 years of work experience in information security working in a regulated industry, preferably health care with responsibility in cloud security, identity security, security operations, or risk management.
  • Be familiar with government and industry regulations that involve information security.
  • A university degree in Information Security, Computer Science, Information Technology or related discipline is required.
  • Certified Information Systems Security Professional (CISSP) or equivalent industry certification is an advantage.
  • Hands-on experience securing Microsoft M365 and Microsoft Security Technologies
  • Experience assessing cybersecurity risks associated with cloud services, SaaS platforms, and emerging technologies.
  • Experience with AI security, Generative AI governance, or AI risk management is highly desirable.
  • Strong knowledge of:
    • Microsoft 365 Security and Compliance capabilities
    • Microsoft Entra ID (Azure AD)
    • Microsoft Defender Security Suite
    • Microsoft Purview
    • Microsoft Intune
    • Conditional Access and Identity Security
    • Data Loss Prevention (DLP)
    • SIEM and XDR technologies
    • Cloud security principles and Zero Trust architecture
  • Understanding of:
    • Generative AI platforms and LLM technologies
    • AI security risks and threat models
    • AI governance frameworks
    • Secure AI implementation practices
    • Threat intelligence and cyber threat analysis
  • Familiarity with scripting and automation tools such as PowerShell, Python, or similar technologies.
  • Microsoft Certified: Cybersecurity Architect Expert
  • Microsoft Certified: Security Operations Analyst Associate
  • Microsoft Certified: Identity and Access Administrator Associate
  • CISSP (Certified Information Systems Security Professional)
  • CCSP (Certified Cloud Security Professional)
  • AI security or cloud security certifications are considered an asset
  • NIST Cybersecurity Framework (CSF)
  • NIST AI Risk Management Framework (AI RMF)
  • ISO 27001
  • ISO 42001
  • CIS Critical Security Controls
  • Zero Trust Security Principles
  • MITRE ATT&CK Framework
  • Microsoft Secure Future Initiative (SFI) principles
  • Privacy and data protection regulations
  • Secure adoption and governance of AI technologies across the enterprise.
  • Reduced risk of data leakage and unauthorized access within Microsoft 365 and AI platforms.
  • Effective detection and response to AI-enabled cyber threats.
  • Improved Microsoft Secure Score and cloud security posture.
  • Compliance with organizational, regulatory, and industry security requirements.
  • Increased employee awareness and secure use of AI-enabled business applications.

Certifications (Preferred)

To pursue this career opportunity, please visit our website: www.trilliumhealthpartners.ca

Trillium Health Partners’ (THP) is an equal opportunity employer who values the importance of antiracism work and is committed to integrating antiracism, diversity, equity and inclusion best practices throughout THP operations, policies and culture. Therefore, we ask that even if you do not see yourself fully reflected in every job requirement listed on this posting, we still encourage you to reach out and apply. Research has shown that candidates from underrepresented groups often only apply when they feel 100% qualified. We encourage all applicants who are members of groups that have been marginalized on any grounds enumerated under the Ontario Human Rights Code based on race, gender identity or expression, sex, sexual orientation, disability, political belief, religion, marital or family status, age, and/or status as a First Nations, Métis or Inuk/Inuit person to consider this opportunity.

In accordance with the Accessibility for Ontarians with Disabilities Act, 2005 and the Ontario Human Rights Code Trillium Health Partners will provide accommodations throughout the recruitment and selection process to applicants with disabilities. If selected to participate in the recruitment and selection process, please inform Human Resources of the nature of any accommodation(s) that you may require in respect of any materials or processes used to ensure your equal participation.

All personal information is collected under the authority of the Freedom of Information and Protection of Privacy Act.

Trillium Health Partners is identified under the French Language Services Act.

We thank all those who apply but only those selected for further consideration will be contacted.

Our organization may use automated tools, including artificial intelligence (AI) or algorithm-assisted systems, to support the initial review of applications. These tools are used only to assist our recruiters and hiring managers; all hiring decisions include meaningful human involvement and final review.

Trillium Health Partners

About Trillium Health Partners

Trillium Health Partners is a leading hospital with an outstanding record of performance, fiscal responsibility and quality patient care. The hospital encompasses three main sites – Credit Valley Hospital, Mississauga Hospital and Queensway Health Centre – offering the full range of acute care hospital services, as well as a variety of community-based, specialized programs.

Our intention is to achieve the highest quality of care that is easily accessible for our community, at the lowest cost. We are committed to creating an exceptional experience for everyone who walks through our doors.

As our diverse community continues to grow and age, and as more people are living with chronic diseases, we’re taking into account the inevitable changes on the horizon. We know that to continue to deliver exceptional patient care, we must think and act differently, and take a new and innovative approach to the delivery of health care. We envision a new kind of health care for a healthier community – an inter-connected system of care that is organized around the patient, both inside the hospital and beyond its walls. Through partnership, working in a coordinated way across the system, we can meet the needs of our patients and continue to provide outstanding, sustainable quality patient care.

As partners in creating a new kind of health care, we are Better Together.

Industry
Healthcare & Social Services
Company Size
5,001-10,000 employees
Headquarters
Mississauga, CA
Year Founded
2011
Social Media