Senior Information Security Analyst, Third-Party Security and Data Breach Expert (T & I) (Telework/Hybrid)

CBC/Radio-Canada

Toronto

Hybrid

CAD 120,000 - 160,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

CBC/Radio-Canada is seeking a Senior Information Security Analyst, Third-Party Security and Data Breach Expert, to spearhead its TPRM program for external partners and vendors. You will oversee ongoing assessments to keep vendor risks within acceptable limits while ensuring regulatory and organizational compliance.

You will report risk posture to governance committees and advise on GRC across the organization. This hybrid role can be based in Montreal or Toronto.

Qualifications

  • 5+ years in IT risk governance and TPRM with at least 3 years in information security.
  • Strong knowledge of security standards and risk assessment methods.
  • Able to negotiate contractual security/privacy requirements with legal teams.
  • Excellent written and verbal communication for governance committees.
  • Bilingual English/French required.
  • Security certifications (CISSP/CISM/CISA) are a plus.

Responsibilities

  • Lead and oversee the organization-wide Third-Party Risk Management program.
  • Define risk classification frameworks and assessment questionnaires.
  • Evaluate security posture using SOC 2 Type II, ISO 27001, audits.
  • Develop remediation plans and work with vendors to close gaps.
  • Maintain third-party risk registers and report KPIs to leadership.

Skills

IT risk governance
Third-Party Risk
Information security
Vendor risk assessment
Regulatory compliance
GRC communication

Education

University degree in computer science/IT/InfoSec

Tools

ISO/IEC 27001
NIST SP 800-53
Cloud security

Job description

Position Title:

Senior Information Security Analyst, Third-Party Security and Data Breach Expert (T & I) (Telework/Hybrid)

Status of Employment:

Permanent

Position Language Requirement:

English, French

Language Skills:

English (Reading - C - Advanced), English (Speaking - C - Advanced), English (Writing - B - Intermediate), French (Reading - C - Advanced), French (Speaking - C - Advanced), French (Writing - B - Intermediate)

Work at CBC/Radio-Canada

At CBC/Radio-Canada, we create content that informs, entertains and connects Canadians on multiple platforms.
Do you think you have the ability and drive to keep up with this exciting, ever-changing industry? Whether it be in front of the camera, on air, online or behind the scenes, you would be joining a team that thrives on making connections and telling stories that are important to Canadians.

Unposting Date:

2026-09-25 11:59 PM

Behind the scenes, but ahead of the curve: help us develop the next-generation public service media organization.

Technology & Infrastructure (T&I) is the backbone and the future-forward arm of CBC/Radio-Canada. Our purpose is to constantly innovate to evolve and maintain the Corporation’s technology and infrastructure. We are the people that make stuff work. We make connections between media content, systems, people and places. We are the space in between.

A place with purpose. CBC/Radio-Canada has always been a highly regarded pioneer of media technology — not just in Canada but around the world. Today, we are transforming ourselves into a modern and agile public service media organization. Technology is the driving force, and we are the team making it happen.

This is a hybrid position with a mix of in-office and remote work. Work arrangements will be discussed with hiring managers per departmental guidelines.

Your Role

CBC/Radio-Canada is seeking a Senior Information Security Analyst, Third-Party Security and Data Breach Expert, to spearhead its Third-Party Risk Management (TPRM) program for external partners and vendors.

In this role, you will oversee and execute ongoing assessments of third-party technology risk to ensure vendor risks remain within acceptable tolerance thresholds while maintaining compliance with regulatory and organizational requirements. You will report the overall risk posture to information security governance and management committees. As a recognized subject matter expert, you will serve as a trusted adviser for governance, risk and compliance (GRC) across the organization.

This position can be based in Montreal or Toronto.

What’s in It for You

Challenges. We spend our days solving problems of all kinds. Media files are highly nuanced and incredibly complicated; updating, installing and supporting technologies that are organization-wide and that impact broadcasting content is a time-sensitive, complex technical feat. And that’s just the beginning. You’ll be working with leading-edge data management, cloud, IP broadcasting, AI, security and reliability technologies.

As Lead Analyst, you will:

  • Drive the TPRM Program: Lead and oversee the organization-wide Third-Party Risk Management (TPRM) program, from process development through to operational implementation.
  • Define Assessment Methodologies and Standards: Design, maintain and update third-party risk classification frameworks (criticality, data sensitivity) and security assessment questionnaires aligned with industry standards (e.g., ISO 27001, NIST).
  • Assess Compliance and Security Posture: Evaluate the security posture and maturity of third parties by reviewing SOC 2 Type II reports, ISO 27001 certifications, penetration test results and regulatory compliance attestations (e.g., GDPR, Quebec’s Law 25).
  • Address Risks and Recommend Mitigation: Assess identified security gaps, formulate risk mitigation strategies or compensating controls, and establish binding remediation plans with vendors.
  • Define and validate complex contractual security requirements, including audit rights, incident notification SLAs (24- to 48-hour response windows), encryption standards and business continuity plans.
  • Negotiate Directly With Partners and Vendors: Engage directly with vendor security leaders during contracting phases to advocate for and enforce organizational security requirements.
  • Provide technical leadership during third-party security incidents or data breaches.
  • Manage Third-Party Risk Registers: Maintain an up-to-date mapping and complete inventory of all external partners and their corresponding risk levels.
  • Oversee Periodic Reassessments: Schedule and perform ongoing security evaluations based on vendor criticality (e.g., annual reviews for high-risk third parties).
  • Champion security best practices across internal teams to foster a security-first mindset from contract initiation.
  • Advance the TPRM Strategy: Continuously adapt assessment processes in response to emerging cyber threats and regulatory updates.
  • Produce Governance Dashboards and Metrics (KPIs/KRIs): Report third-party risk metrics to leadership (e.g., assessment completion rates, turnaround times, open risk findings).
  • Maintain broad knowledge of best practices and trends in information security.

What You Bring

  • University degree in computer science, IT or information security.
  • Minimum five years’ experience in IT risk governance and TPRM, including a minimum of three years focused on information security.
  • Extensive knowledge of security technology and risk assessment methodologies, policies and processes.
  • Proven ability to collaborate with legal teams to define and negotiate contractual security and privacy requirements (e.g., security schedules, audit rights, data breach notification timelines).
  • Excellent written and verbal communication skills, with a demonstrated ability to translate complex technical concepts for non-technical decision-makers (e.g., governance committees, business units, legal teams).
  • Excellent analytical, evaluative and problem-solving abilities.
  • Experience with compliance programs as well as their technical and security requirements.
  • Technical expertise across key domains:
    • Standards and Frameworks: Strong command of industry standards such as ISO/IEC 27001, 27002, 27005, NIST SP 800-53 / 800-161, COBIT and ITIL.
    • Cloud and Web Architecture Security: Solid understanding of web infrastructure security and cloud architecture models.
    • Network and Security Technologies: Thorough understanding of network security architecture (LAN/WAN, firewalls, IDS/IPS, DNS, web filtering) and cryptographic principles (encryption at rest and in transit).
    • Architecture and Data Security: Working knowledge of database architecture concepts and secure software development best practices.
    • Operational Resilience and Physical Security: Solid understanding of business continuity and disaster recovery planning (BCP/DRP), operational resilience and physical security controls.
  • Relevant professional security certifications a definite asset (e.g., CISSP, CRISC, CBCP, CISA, CISM or equivalent).
  • Bilingualism (English and French) essential.

Candidates may be subject to skills and knowledge testing.

We thank all applicants for their interest, but only candidates selected for an interview will be contacted.

As part of our recruitment process, candidates who advance to the next

step will be asked to complete a background check. This includes:

  • A mandatory Criminal record check.
  • Other background checks may be conducted based on the operational requirements of the position.

CBC/Radio-Canada is committed to being a leader in reflecting our country's diversity. That’s because we can only create and tell the stories that connect Canadians, by having a workforce that mirrors the ever-changing makeup of our country. That’s why we, as an employer, value equal opportunity and nurture an inclusive workplace where our individual differences are not only recognized and valued, but also extend to and pervade all the services we provide as Canada’s public broadcaster. For more information, visit the Diversity and Inclusion section of our website. If you have accommodation needs at this stage of the recruitment process, please inform us as soon as possible by sending an e‑mail to recruitment@cbc.ca.
You are invited to consult and familiarize yourself with our Code of Conduct, which can be found on our corporate website. All employees must adhere to the Code as a condition of employment. We also invite you to take a look at our policy on conflicts of interest. In the event that you become an employee, it will be important to inform us, as quickly as possible, of any situation that, because of your hiring, constitutes or could appear to constitute a conflict of interest.

Primary Location:

1000, Rue Papineau, Montreal, Quebec, H2K 0C2

Number of Openings:

1

Work Schedule:

Full time

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Information Security Analyst, Third-Party Security and Data Breach Expert (T&I) (Telework/Hybrid)
Lead Information Security Analyst, Third-Party Security and Data Breach Expert (T&I) (Telework/Hybrid)

CBC/Radio-Canada • Montreal (administrative region)

Hybrid
CAD 110,000 - 150,000
Senior Information Security Analyst, Third-Party Security and Data Breach Expert (T & I) (Telework/Hybrid)
Senior Information Security Analyst, Third-Party Security and Data Breach Expert (T & I) (Telework/Hybrid)

Radio-Canada • Montreal (administrative region)

Hybrid
CAD 110,000 - 150,000
Senior Information Security Analyst, Third-Party Security and Data Breach Expert (T & I) (Telework/Hybrid)
Senior Information Security Analyst, Third-Party Security and Data Breach Expert (T & I) (Telework/Hybrid)

CBC/Radio-Canada • Montreal (administrative region)

Remote
CAD 100,000 - 130,000
Lead Information Security Analyst, Data Protection Specialist (T & I) (Telework/Hybrid)
Lead Information Security Analyst, Data Protection Specialist (T & I) (Telework/Hybrid)

Radio-Canada • Montreal (administrative region)

Hybrid
CAD 110,000 - 140,000
Lead Information Security Analyst, Vulnerability and External Attack Surface Management (T & I) (Telework/Hybrid)
Lead Information Security Analyst, Vulnerability and External Attack Surface Management (T & I) (Telework/Hybrid)

CBC/Radio-Canada • Toronto

Hybrid
CAD 120,000 - 170,000
Hybrid work model
Lead Information Security Analyst, Vulnerability and External Attack Surface Management (T & I) (Telework/Hybrid)
Lead Information Security Analyst, Vulnerability and External Attack Surface Management (T & I) (Telework/Hybrid)

Radio-Canada • Montreal (administrative region)

Hybrid
CAD 110,000 - 140,000
Lead Information Security Analyst, Continuous AI Risk Management Expert (T & I) (Telework/Hybrid)
Lead Information Security Analyst, Continuous AI Risk Management Expert (T & I) (Telework/Hybrid)

CBC/Radio-Canada • Toronto

Hybrid
CAD 110,000 - 160,000
Hybrid work model
Information Security Architect (T & I) (Telework/Hybrid)
Information Security Architect (T & I) (Telework/Hybrid)

Radio Canada • Montreal (administrative region)

Hybrid
CAD 120,000 - 160,000
Lead Information Security Analyst, Vulnerability and External Attack Surface Management (T & I) (Telework/Hybrid)
Lead Information Security Analyst, Vulnerability and External Attack Surface Management (T & I) (Telework/Hybrid)

CBC/Radio-Canada • Montreal (administrative region)

Hybrid
CAD 120,000 - 160,000
Lead Information Security Analyst, Data Protection Specialist (T & I) (Telework/Hybrid)
Lead Information Security Analyst, Data Protection Specialist (T & I) (Telework/Hybrid)

CBC/Radio-Canada • Montreal (administrative region)

Hybrid
CAD 120,000 - 160,000
Hybrid work model