Enable job alerts via email!

Risk compliance Specialist 0153-1612

Dheya

Toronto

Hybrid

CAD 100,000 - 130,000

Full time

4 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading company is seeking a cybersecurity professional with extensive experience in risk management and compliance. This role involves conducting risk assessments, developing cybersecurity frameworks, and ensuring alignment with regulatory standards. Ideal candidates will have strong communication skills, leadership experience, and a solid background in managing third-party vendors and risk assessments.

Qualifications

  • 7+ years experience in information security, leading vendor risk assessments.
  • Proficiency in cybersecurity risk management tools and standards like PCI-DSS, NIST.
  • Strong communication skills for engaging diverse stakeholders.

Responsibilities

  • Lead security assessments, identifying gaps and developing mitigation strategies.
  • Develop and implement cybersecurity governance frameworks and policies.
  • Collaborate with internal teams for cybersecurity requirements on new solutions.

Skills

Risk Assessment
Regulatory Compliance
Communication Skills
Data Analysis
Project Management

Education

CISSP
CISM
CCSP
CISA

Tools

ServiceNow
OneTrust
Microsoft Office

Job description

Skills Required :

Risk Assessment Regulatory Compliance Knowledge Audit Management Data Analysis Experience with GRC Governance Risk Compliance tools CISSP CISM CCSP CISA designation PCIDSS NIST ISO 27001 knowledge ServiceNow OneTrust Communication Skills Project Management IT Security Principles

HM Note: This hybrid contract role is three (3) days in office. Candidates resume must include first and last name.

Description

Responsibilities:

Coordinate and perform risk assessments against a wide variety of inputs.

Analyzes data from various sources to identify remediation of risks. Interprets policies, legislation and standards to adequately provide advice for management and executives.

General Skills:

Experience interpreting requirements from those standards and translating them into actionable implementations

Strong understanding of internal control frameworks, control mappings, and scoping

Familiar with a broad range of technical concepts: logical access control, agile development process, secure coding principles, security architecture, information security, network security, and privacy Expertise in gap analysis, remediation, control design and risk assessments

Exceptional verbal and written communication skills

Experience with GRC (Governance, Risk, Compliance) tools is a plus

  • Lead security and vendor risk assessments, identifying risks and gaps, and developing mitigation strategies for third-party vendors.
  • Conduct detailed assessments of third-party vendors’ security domains, communicate findings, prepare regular reports and updates to management and stakeholders.
  • Develop and implement cybersecurity governance frameworks, policies, and procedures in collaboration with cross-functional teams.
  • Provide support for audit, compliance, and regulatory requests. Precise and thorough documentation and analysis are essential for effective security auditing and compliance efforts.
  • Collaborate with internal teams and vendors to develop cybersecurity requirements for new solutions, ensuring alignment with security policies and standards.
  • Work with other team members to develop and align with cybersecurity requirements for solutions as required
  • Work with project teams to recommend and implement security controls to address identified risks.
  • Work with Enterprise Architecture, Solution Delivery, Security and Operations teams as part of a large program/project team to ensure security solutions and meet security compliance and security policies and standards
  • Identify requirements for policies and standards, and work with relevant teams in creation, development, review and approval
  • Act as a cybersecurity resource for new and upcoming project-based detail work
  • Work with project teams to identify and recommend security controls to remediate security risks and issues
  • Ongoing compliance work related to regulatory requirements and/or compliance to Metrolinx standards
  • Develop the security process, procedure, governance artifacts and security controls within the Cybersecurity Risk Management and Governance/Compliance Programs.
  • Assist with security audits and threat/risk assessments to ensure compliance with security policies, standards and procedures, and work with business/technical/operational areas in taking corrective actions on any identified security exposures
  • Provide advice, risk assessment, recommendations and technical assistance in implementing security controls for projects
  • Communicate regularly with cybersecurity teams, internal stakeholders, project teams and representatives from various functional teams, including escalating any matters to senior team members that require additional analysis
  • Support the implementation of security principles, policies, and standards to align with industry best practices, ensuring security controls are integrated into system development, deployment, and operation
Experience/skills required:
  • A minimum of seven (7+) years of experience in information security. Including working with large security projects
  • Strong communication, interpersonal and presentation skills for engaging with diverse stakeholders
  • Expertise in security governance, risk management, and compliance, including developing road maps, policies, standards, procedures and processes
  • Proven experience in contractual security requirements and third-party risk management through RFP processes and vendor evaluations throughout procurement life cycle
  • Ability to work in cross-functional teams, communicating complex technical information to all levels of the organization, including the leadership team
  • Proficient in cybersecurity risk management and third-party risk management tools (e.g., ServiceNow, OneTrust, Audit Board).
  • Experience with development of security processes, procedures and standards documentation
  • Strong knowledge of industry standards and regulations such as PCI-DSS, NIST, ISO 27001 and the ability to ensure compliance
  • Strong time management skills and the ability to prioritize project work and ongoing responsibilities
  • Self-motivated with the ability to work independently in a fast-paced environment in a fast-paced environment
  • Proficiency with standard Microsoft Office tools such as Word, Excel, PowerPoint, PowerBI and Visio
Education:
  • A current security designation (CISSP, CISM, CCSP or CISA)
Must Haves:
  • 7+ Leading security and vendor risk assessments, identifying risks and gaps, and developing mitigation strategies for third-party vendors.
  • 7+ Collaborate with internal teams and vendors to develop cybersecurity requirements for new solutions
  • 7+ Develop the security process, procedure, governance artifacts and security controls within the Cybersecurity Risk Management and Governance/Compliance Programs.
  • 7+years experiencein contract negotiation with procurement and legal teams through RFP processes and vendor evaluations throughout procurement life cycle
  • 7+years experienceknowledge of industry standards and regulations such as PCI-DSS, NIST, ISO 27001
  • 7+years experiencewith cybersecurity risk management and third-party risk management tools – ServiceNow andOneTrust
  • 7+years experience facilitating cybersecurity awareness training
Didn't find the role you were looking for? Upload your resume now to get considered for future job opportunities at Foilcon.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Privacy and Compliance Lead

VetStrategy

Vaughan

Remote

CAD 120.000 - 150.000

6 days ago
Be an early applicant

Lead Compliance Specialist. GFT

RBC

Toronto

Hybrid

CAD 80.000 - 110.000

10 days ago

Governance and Compliance Specialist, eAML #87457

PCRecruiter - Recruitment Software & Applicant Tracking System

Toronto

Hybrid

CAD 80.000 - 120.000

9 days ago

PCI Compliance Specialist

Bell

Mississauga

Hybrid

CAD 90.000 - 130.000

14 days ago

Compliance Counsel

Norton Rose Fulbright

Ottawa

Remote

CAD 80.000 - 120.000

5 days ago
Be an early applicant

Manager, Business Risk and Reporting

RBC

Toronto

On-site

CAD 85.000 - 120.000

6 days ago
Be an early applicant

Senior Risk/Compliance Specialist

isgSearch

Old Toronto

Hybrid

CAD 100.000 - 125.000

30+ days ago

Chief Compliance Officer (CCO)

Agentis Capital

Toronto

Remote

CAD 80.000 - 120.000

30+ days ago

Compliance Specialist

IFG - International Financial Group

Toronto

Hybrid

CAD 125.000 - 140.000

24 days ago