# Governance and Compliance SpecialistMontrealHybridCybersecurity and Identity ManagementApplyWith over 30 years of recognized expertise, COFOMO is now a leading Canadian consulting firm specializing in digital and artificial intelligence. Supported by more than 3,000 experts, 10 Centers of Excellence, and 4 offices across the country, we are uniquely positioned to successfully guide our clients through their transformations. Both strategic and tactical, we help organizations across a wide range of industries thrive in today’s rapidly evolving world.## Our promiseHelp our clients succeed and maximize the impact of their transformation initiatives, turning them into powerful drivers of growth and innovation.## Job description**Here's a brief overview of the tasks and responsibilities you'll have :*** Design and evolve the security posture management framework in accordance with industry-recognized organizational guidance and frameworks;* Develop and maintain standards derived from the Security Posture Management Directive;* Analyze, document and draft requests for exceptions to security requirements and ensure their presentation to the appropriate decision-making bodies;* Prepare analyses, reports and executive presentations summarizing findings, risks, recommendations and required decisions;* Participate in the development, review and update of information security governance documents, including policies, directives, standards and other normative documents;* Review and update the library of security controls to ensure alignment with regulatory requirements, emerging risks, and applicable compliance frameworks;* Collaborate with technology, cybersecurity, risk management, compliance, project teams and vendors to support governance and information security objectives;* Contribute to the continuous improvement of information security processes, management frameworks and governance practices;* Participate in third-party risk assessments and make recommendations to reduce identified risks;* Implement a process for managing exceptions to the security requirements prescribed in governance documents;* Ensure that governance documents and the security control library are updated as needed;* Produce executive materials presenting findings, risks, recommendations and decisions to be made. **The profile we are looking for is as follows:*** Have a minimum of seven (7) years of experience in governance, risk management and compliance in information technology or cybersecurity;* Experience in a financial institution or a highly regulated environment;* Have experience in writing and maintaining security policies, guidelines and standards;* Master the drafting of waivers or exceptions to security or governance requirements;* Be familiar with one or more recognized frameworks such as NIST CSF, NIST SP 800-53, ISO 27001 or COBIT;* Demonstrate experience working with technical and business teams;* Hold a bachelor's degree or certificate in cybersecurity, information technology, computer engineering, information systems, business administration with a specialization in IT, audit, risk management or a related field;* Have CISA, CRISC, CGEIT or CISSP certification (an asset);* Master cybersecurity governance, risk management, and compliance principles;* Understand security posture management practices;* In-depth knowledge of cybersecurity frameworks and frameworks, including NIST CSF and NIST SP 800-53;* Understand concepts related to security controls, exception management, compliance, and auditing;* Knowledge of the regulatory context applicable to financial institutions (an asset);* Understand the cybersecurity issues associated with cloud environments (an asset);* Demonstrate an ability to popularize technical concepts to different audiences;* Formulate strategic recommendations based on risks and industry best practices;* Excellent analytical, synthetic, documentative, communicative and workshop facilitation skills;* Demonstrate autonomy in the realization of mandates and the production of deliverables.