Senior Information Security Specialist, Governance and Compliance

Be among the first applicants.
Canadian Tire Corporation
Old Toronto
CAD 80,000 - 100,000
Be among the first applicants.
4 days ago
Job description

What you’ll do

Reporting to the AVP, Cyber Governance Risk and Compliance, the Senior Information Security Specialist, Governance and Compliance will lead the charge in maintaining cyber security policies and standards, responding to regulator and auditor inquiries, and providing an advisory function to the business surrounding cyber security governance.

  • Provide senior level advisory services to cybersecurity, technology teams, and business team members, as required.
  • Maintain cyber security policies and standards.
  • Respond to external inquiries regarding cyber security (e.g. ESG, regulators, etc.).
  • Analyze and assess cyber security related business scenarios and prepare/present position papers providing risk-based recommendations to assist the leadership team in making informed decisions.
  • Oversee and provide guidance on the cyber security configuration compliance management program for both on-prem and cloud environments.
  • Oversee and provide guidance on the cyber security vulnerability, configuration & patch remediation management programs.
  • Oversee and provide guidance on the Cloud security compliance management program.
  • Design and perform annual reviews of configuration benchmarks for teams to follow for new and existing systems.
  • Manage the cyber security policy exemption management processes by assessing policy exception requests, maintaining the exception workflows, and updating and keeping current the exception database.
  • Keep current with ongoing trends and changes within the cyber security community.

What you bring

  • University degree preferably in an IT related discipline.
  • CISSP, and/or CISM, and/or CISA, and/or CRISC designations would be an asset.
  • 8-10+ years experience in information security, and/or IT Audit/Compliance, and/or external audit.
  • Strong understanding of IT, cloud and cyber security concepts and best practices.
  • Understands cyber security risks and control frameworks including NIST CSF, CIS, COBIT 5, and ISO 270001.
  • Experience with security assessment tools such as Tripwire, Nexpose, MS Defender, McAfee EPO, Kenna, etc.
  • Understanding of Agile concepts and practices.
  • Ability to communicate and influence effectively at all levels from technical staff to company leadership team.
  • Proven ability to weigh business needs with information security priorities and make sound risk-based judgement calls.
  • Experienced with analyzing and assessing cyber security related business scenarios, performing risk assessments, and preparing position papers outlining sound, risk-based recommendations.
  • Experienced with analyzing and assessing cyber security policy exception requests and providing risk-based recommendations.
  • Experience overseeing cyber security configuration compliance programs.
  • Experience overseeing cyber security vulnerability & patch management programs.
  • Experience overseeing Cloud security compliance management programs.
  • Experience with developing security baselines based on industry accepted CIS benchmark, MS Azure security benchmark, PCI DSS benchmark, etc., and conduct regular reviews to update existing custom baselines.
  • Experience with Microsoft Azure Portal/Security Center to monitor and manage vulnerabilities, security policy compliance and all outstanding Microsoft recommendations.
  • Familiar with KQL (Kusto query language) to develop scripts to query Microsoft Azure policy database to report compliance status.
  • Technical knowledge including Linux, Windows, AIX, databases, network and security appliances and firewalls/IDS/IPS, web and cloud-based applications, secure coding practices, and cloud security.
  • Highly proficient with MS Office suite of products.
Get a free, confidential resume review.
Select file or drag and drop it
Avatar
Free online coaching
Improve your chances of getting that interview invitation!
Be the first to explore new Senior Information Security Specialist, Governance and Compliance jobs in Old Toronto