Senior Security Advisor

TechDoQuest

Markham

Hybrid

CAD 120,000 - 180,000

Full time

20 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

TechDoQuest in Markham, Ontario, is seeking a Senior Advisor for Security Advisory Services to lead and review ISRAs and TPISAs, overseeing cybersecurity risk management for internal solutions and projects.

You will guide risk identification, develop remediation plans, and communicate risk to executives, while ensuring alignment with client risk appetite and KRIs; a senior leadership role requiring 10+ years of experience and industry certifications.

Qualifications

  • 10+ years in cybersecurity risk assessments and vendor assessments.
  • Strong understanding of industry standards and risk concepts.
  • Ability to communicate complex issues to diverse audiences.
  • Experience with risk reporting and KRIs is a plus.
  • Post-secondary education in CS/IT Security or equivalent.

Responsibilities

  • Review ISRAs and TPISAs and manage cybersecurity risks.
  • Provide oversight on risk management processes and KRIs.
  • Identify gaps and develop remediation plans.
  • Lead risk reporting and communicate to stakeholders.
  • Manage pen test and business impact programs.

Skills

Cybersecurity risk assessments
Vendor assessments
Risk management
Leadership/communication
Stakeholder management
Ambiguity navigation

Education

Post-secondary in CS/IT Security
Cybersecurity designation preferred

Tools

Ariba
Archer (GRC)

Job description

Model: Hybrid (3 Days Onsite (Mon/ Tues/ Wed))
Job Type: Full time
Senior Advisor, Security Advisory Services

As Senior Advisor within the Security Advisory Services (SAS) team, this role will involve performing previews of Information Security Risk Assessments (ISRAs) deliverables for internal solutions and technology projects; and Third-Party Information Security Assessments (TPISA) deliverables

What you’ll do
  • You will review (and where required) conduct ISRAs, TPISAs, manage and mitigate cybersecurity risks and conduct and other consulting requests.
  • Provide oversight on assessments, risk identification and risk management processes, and tools for managing and reporting risks, and continuously improve the quality of services
  • Identify gaps in existing processes and technology and develop remediation plans to address risks
  • Assist in the development of cybersecurity risk reporting including the ongoing development and improvement of Key Risk Indicators (KRIs)
  • Provide oversight to ensure identified cybersecurity risks are mitigated and are effectively communicated to partners, and managed with risk-prioritized timelines aligned with client’s risk appetite
Other key responsibilities include
  • Provide senior management and executives with information security trends, the status of identified risks, and the effectiveness of work activities
  • Increase visibility of cybersecurity risks where and when appropriate with the respective collaborators when risk action plan target dates are not met
  • Manage the pen test and business impact assessment programs
  • Preparing for Internal Risks and Control Assessments
  • Help improve team processes to continuously increase efficiency and quality standards
What you’ll bring
  • Minimum 10 years of strong, progressive experience in all of cybersecurity risk assessments, vendor assessments, and continuous risk management.
  • Strong understanding of cybersecurity industry standards, principles and practices, as well as risk concepts. Understanding of application security design & architecture is an asset.
  • Proven management and leadership skills in communication, prioritization and developing talent
  • Demonstrated ability to communicate complex issues in a clear and concise manner to a wide range of audiences and stakeholders
  • Demonstrated ability to navigate through ambiguity and guide team through changes
  • Ability to understand complex processes and make sound judgement calls.
  • Ability to negotiate and influence others to achieve optimal results.
  • Knowledge of Ariba and Archer or other GRC management platforms.
  • Post-secondary education in Computer Science, Computer Engineering, IT Security, risk management, or comparable professional training.
  • Professional designation relating to cybersecurity or IT risk (e.g. CISSP, CISA, CISM, CCSP/CCSK, GIAC) preferred.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Cyber Security advisor
Sr. Cyber Security advisor

Key2Source INC • Markham

Hybrid
CAD 120,000 - 180,000
Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)
Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)

Charles River Associates • Toronto

On-site
CAD 110,000 - 170,000
Senior Manager, Cybersecurity & GRC
Senior Manager, Cybersecurity & GRC

Axiom Global Technologies • Mississauga

On-site
CAD 150,000 - 210,000
Manager, Cyber Security
Manager, Cyber Security

Clear Destination Inc. • Toronto

On-site
CAD 150,000 - 170,000
Senior Cyber Security Analyst - GRC
Senior Cyber Security Analyst - GRC

Metro Supply Chain • Mississauga

On-site
CAD 105,000 - 125,000
Security Risk Analyst
Security Risk Analyst

Acestack • Montreal

Hybrid
CAD 70,000 - 110,000
Senior Cybersecurity Specialist
Senior Cybersecurity Specialist

STACK IT Recruitment • Burlington

On-site
CAD 154,000 - 181,000
Paid vacation and personal days
Annual bonus
Cyber Security Architect
Cyber Security Architect

Resonaite • Mississauga

On-site
CAD 100,000 - 130,000
Senior Security Analyst, Third Party Risk
Senior Security Analyst, Third Party Risk

Insight Global • Vancouver

On-site
Senior Security Analyst
Senior Security Analyst

Mindlance • Toronto

On-site
CAD 90,000 - 120,000