Connect with us LinkedIn, Instagram, Facebook, Twitter.
Thinking about a change?
We recognize that the construction industry is changing at a rapid pace and we continually strive to be at the forefront. Our core
values empower people to deliver great careers to one another and develop creative solutions for complex problems on some of the most exciting projects. It doesn’t matter what your expertise and craft is – there are no boundaries. We are a group of professionals with a variety of expertise within pre-construction, construction, and post-construction. To learn more, check out our
Cradle to Grave services and hear from
our team directly about what a career at EllisDon could look like for you. As you can see, we are a diverse bunch.
Above all, we are a group of individuals with unique experiences and at EllisDon, we choose to celebrate the strength in our differences, every day. EllisDon’s commitment to Inclusive Diversity is to work together to create an environment where every employee feels safe to be their true and authentic self. Ultimately, EllisDon’s purpose is to provide people with similar values the opportunity to achieve to their full potential; to deliver that opportunity for great careers to one another; and to contribute meaningfully to the community we share with others.
In case you’re curious, here’s what the industry thinks of us and some of the
impacts we've made to the communities we work in and our latest
Impact Report, highlighting how we're putting our values into practice in areas such as the climate & environment, inclusive diversity, indigenous relations, and health and safety.
This role is ideal for a cybersecurity professional looking to expand into GRC or a GRC practitioner who enjoys building and improving security processes, programs, and controls in a growing environment.
You As An Information Security Analyst Will
- Support identification, assessment, and tracking of IT/cyber risks; maintain the enterprise risk register and remediation lifecycle
- Perform risk assessments for systems, projects, and vendors; support ongoing third-party compliance activities
- Contribute to GRC program operations (policies, standards, procedures, exception tracking, evidence workflows)
- Support remediation of risks, control gaps, and audit findings across teams
- Partner with IT (Service Delivery, Operations, DevOps) to enable secure system and solution implementation
- Support security awareness program, including training, reporting, and modern threat simulations (phishing, social engineering, AI-driven attacks)
- Support compliance across SOC 2, NIST, ISO 27001, and CMMC / CPCSC / ITSP, ensuring consistent control implementation
- Contribute to key GRC initiatives, including risk maturity, audit readiness, vendor compliance, and standardization of security requirements across the organization
This is the right role for you, if you have:
- 2–5 years of experience in Information Security, Cybersecurity, Governance, Risk & Compliance (GRC), IT Risk Management, or related disciplines.
- Experience performing assessments including security reviews, risk assessments, vendor evaluations, compliance activities, or governance functions.
- Strong security foundation with a risk‑based approach to decision‑making and the ability to evaluate security controls effectively.
- Ability to identify practical mitigation by assessing control gaps and recommending realistic, business‑aligned improvements.
- Demonstrated interest in GRC and applying security concepts through a business‑focused, risk‑driven lens; interest in developing expertise across multiple GRC disciplines.
- Experience contributing to program maturity including the development, implementation, or enhancement of security and GRC processes, programs, or initiatives.
- Ability to work independently while influencing stakeholders across technical and non‑technical teams.
- Strong analytical and critical thinking skills with the ability to evaluate controls, identify gaps, and propose actionable improvements.
- Effective communication skills with the ability to articulate risks and recommendations to diverse audiences.
- Strong interpersonal, verbal, and written communication skills.
- Self‑motivated with strong prioritization skills and the ability to drive initiatives forward.
- Post‑secondary education in IT, Cybersecurity, Information Security, or a related field, or equivalent experience.
- Industry certifications such as Security+, CISSP, CISA, CRISC, or similar are considered an asset.
- Working knowledge of security frameworks such as NIST CSF, ISO 27001, SOC 2, CIS Controls, CMMC, CPCSC, or similar standards.
- The salary range for this role is $66,000 - $80,000.
EllisDon is proud to provide this unique career opportunity that provides continuous learning, opportunity for growth, and a competitive compensation package within an environment that is committed to inclusion and respects diversity.
Go ahead and be yourself. We'll pay you for it!
We are an equal opportunity employer. We welcome people of any age, culture, subculture, gender identity or expression, sexual orientation, nationality, ethnicity, race, size, mental or physical status, veteran status, religion, language, political opinion, working-style preference, family status, education, and socio-economic status. The EllisDon core values of
Integrity and Mutual Respect welcomes
everyone, at work and in the community, and our value of
Mutual Accountability, means that we all have a role to play. As an EllisDon employee, this will ultimately be
your commitment to Inclusive Diversity.
Accommodation for Applicants with disabilities will be made during the recruitment process when requested.
We are committed to providing a positive candidate experience and ensuring timely updates are provided to all candidates. If you haven’t already, be sure to create a profile on our Careers page to remain up to date on the status of your application and learn about new career opportunities as they arise.
EllisDon uses AI tools to assist in screening and assessing applicants for this position.