Security Governance, Risk and Compliance specialist at Tecsys managing risk frameworks and vendor relations. Develops security strategies and collaborates across teams to improve security maturity.
Responsibilities
Support continuous security risk management framework.
Collaborate with technical teams for the development, implementation and monitoring of required corrective action plans relating to security compliance issues or audit deficiencies.
Collaborate with stakeholders to define processes, automate and continuously monitor information security controls, exceptions, risks, testing and evidence gathering.
Develop reporting metrics and dashboards.
Help identify cyber risks and solve various governance gaps and process inefficiencies.
Develop, execute and actively partake in internal and external security and compliance assessment initiatives such as SOC 2, PCI-DSS, NIST, FedRAMP.
Review and optimize vendor risk management program.
Monitor existing controls and conduct periodic audits and reviews to ensure their efficiency and operating effectiveness, and to identify and report on potential issues.
Collaborate with internal IT and business teams to identify cyber risks and prioritize security compliance-related improvements.
As security subject matter expert, support IT and cyber teams on the implementation of controls to meet security and privacy compliance requirements and best practices.
Support the development, review, update and optimization of security documentation.
Requirements
Bachelor’s degree in information systems or equivalent experience
Minimum 3 years of cumulated hands-on experience
Experience in the development and implementation of governance, risk and compliance strategy and security control framework.
Experience in risk assessments and cyber risk management methodology/processes.
Broad knowledge of defense in depth security concepts and best practices through practical experience.
Proven experience conducting security audits such as SOC2 or PCI DSS.
Experience with cybersecurity frameworks such as NIST, CIS.
Good knowledge of business continuity process and planning.
Familiarity with IP networking fundamentals and internet protocols.
Familiarity with Linux, Mac, and Windows operating systems, mobile devices, and the IT application landscape.
Proven experience with governing the security of public cloud platforms such as AWS and Azure.
Ability to work with minimal supervision.
Strong ability to define problems, collect and analyze data, establish facts and draw valid conclusions.
Positive attitude and agile mindset.
Motivated, team, and customer oriented.
Not afraid to fail.
Excellent interpersonal skills.
Ability to plan and deliver on commitment.
Strong proficiency in both written and verbal English communication essential for effective correspondence with clients, suppliers, business partners, and colleagues beyond the province of Quebec.
Job title
Security Governance, Risk and Compliance Specialist
Director of Security and Compliance safeguarding digital assets and data with a focus on cybersecurity and compliance. Leading risk management, stakeholder engagement, and team leadership initiatives.
Information Security Risk & Compliance Analyst supporting the maintenance of ISO 27001 standards. Contributing to risk assessments and compliance across AAB’s Business Protection Team.
Information Security Risk & Compliance Analyst at AAB managing compliance with ISO 27001, supporting enterprise risk assessments and enhancing information security systems.
Information Security Risk & Compliance Analyst at AAB focusing on ISO 27001 compliance and information security management. Collaborating across teams to ensure robust risk and compliance frameworks.
Security Principal at Optiv designing AI security solutions for clients, leveraging advanced security services and technologies. Driving pipeline generation and maintaining strong client relationships as a trusted advisor.
Cloud Security Architect supporting federal customer projects focused on architecture and security solutions. Conducting risk assessments and defining security requirements within a cloud environment.
Information Security Specialist responsible for enhancing cybersecurity posture through incident management and compliance. Collaborating with cross - functional teams to monitor threats and implement security measures.
Senior Lead Info Security Architect leading and collaborating on cybersecurity solutions at TIAA. Responsible for secure design and implementation of cloud security strategies and practices.
Part Time Security Officer providing protection for Collector's personnel and assets at trade shows across North America while reporting to Security Shows & Transportation Manager.
Enterprise Security Architect at PBCN GmbH designing and implementing security architectures. Collaborating with teams to ensure application security and conducting risk assessments.