Senior Risk & Compliance Specialist
LanceSoft Inc
Toronto
On-site
CAD 90,000 - 120,000
Full time
Boost your interview chances
Create a job specific, tailored resume for higher success rate.
Job summary
A leading company in information security is looking for a Risk/Compliance Specialist to improve governance and compliance frameworks. The candidate will contribute significantly by managing security projects and vendor risk assessments, alongside developing essential documentation and strategic processes to mitigate risks. Ideal for professionals with extensive experience in cybersecurity, this role promises to shape the organization's security landscape through collaboration and innovative solutions.
Qualifications
- 7+ years of experience in information security.
- Strong knowledge of industry standards and regulations such as PCI-DSS, NIST and ISO 27001.
- Proven experience with security governance and vendor risk assessments.
Responsibilities
- Leading security and vendor risk assessments for third-party vendors.
- Collaborate with teams to develop cybersecurity requirements.
- Develop governance artifacts and security controls within compliance programs.
Skills
Communication
Interpersonal Skills
Presentation
Cybersecurity Risk Management
Third-party Risk Management
Time Management
Tools
ServiceNow
OneTrust
Audit Board
Position: Risk/Compliance SpecialistLocation: Toronto, ON ()Duration: 133 Days Contract + Possible ExtensionExperience/skills required:- A minimum of seven (7+) years of experience in information security. Including working with large security projects
- Strong communication, interpersonal and presentation skills for engaging with diverse stakeholders
- Expertise in security governance, risk management, and compliance, including developing road maps, policies, standards, procedures and processes
- Proven experience in contractual security requirements and third-party risk management through RFP processes and vendor evaluations throughout procurement life cycle
- Ability to work in cross-functional teams, communicating complex technical information to all levels of the organization, including the leadership team
- Proficient in cybersecurity risk management and third-party risk management tools (e.g., ServiceNow, OneTrust, Audit Board).
- Experience with development of security processes, procedures and standards documentation
- Strong knowledge of industry standards and regulations such as PCI-DSS, NIST, ISO 27001 and the ability to ensure compliance
- Strong time management skills and the ability to prioritize project work and ongoing responsibilities
- Self-motivated with the ability to work independently in a fast-paced environment in a fast-paced environment
- Proficiency with standard Microsoft Office tools such as Word, Excel, PowerPoint, PowerBI and Visio
Must Have Requirements:- 7+ Leading security and vendor risk assessments, identifying risks and gaps, and developing mitigation strategies for third-party vendors.
- 7+ Collaborate with internal teams and vendors to develop cybersecurity requirements for new solutions
- 7+ Develop the security process, procedure, governance artifacts and security controls within the Cybersecurity Risk Management and Governance/Compliance Programs.
- 7+ years experience in contract negotiation with procurement and legal teams through RFP processes and vendor evaluations throughout procurement life cycle
- 7+ years experience knowledge of industry standards and regulations such as PCI-DSS, NIST, ISO 27001
- 7+ years experience with cybersecurity risk management and third-party risk management tools – ServiceNow and OneTrust
- 7+ years experience facilitating cybersecurity awareness training