Compliance & Audit Manager, Information Security
4 days ago
The Opportunity: WSP is a global consulting firm assisting public and private clients to plan, develop, design, construct, operate and maintain thousands of critical infrastructure projects around the world.
WSP's Information Security Office (ISO) is responsible for the deployment and maintenance of the information security framework for both the IT organization and wider business community. This includes the Governance mechanisms, policies and processes, tools and technologies, and employee training required to protect WSP information and that of our clients.
We are currently seeking an experienced Information Security Compliance and Audit Manager to lead the design, optimization, and implementation of our compliance program based on ISO27K. Your primary responsibilities will include overseeing the entire internal audit ISO27K lifecycle, from planning and scoping to execution and reporting, with a strong emphasis on identifying and mitigating security risks. You will collaborate closely with cross-functional teams, including IT, compliance, and risk management, to drive continuous improvement and ensure alignment with best practices (e.g: ISO 27001, NIST). Effective communication skills are essential to convey audit findings, provide actionable recommendations, and influence stakeholders to prioritize information security initiatives.
If you have excellent communication skills, a strong understanding of Compliance, and a passion for driving continuous improvement, we encourage you to apply for this pivotal role.
We value and are committed to upholding a culture of inclusion and belonging
Our Flexible Work Policy – we recognize the importance of balance in our lives and encourage you to prioritize the balance in yours. We will support you on and off the job so you can be fully present in both your work and home lives.
Enhance the world around you - from the environment to the highways, to the buildings and the terrain, WSP is the fabric of Canada.
We offer attractive pay, flexible work options, a great corporate culture, comprehensive and employee-focused benefits including virtual healthcare and a wellness platform as well as great savings programs, and a clear vision for the future.
#Audit Execution & Reporting: Review audit evidence across IT systems and processes as part of the ISO27K internal audit lifecycle, assess compliance with ISO 27001 requirements, and issue structured audit reports that highlight findings, recommend corrective actions, and support continuous improvement.
Develop and Implement Audit Plans: Lead the development and implementation of comprehensive audit plans tailored to assess compliance with ISO27K and other best standards (i.e: NIST)
Execute Audits: Lead and conduct audits of IT systems, processes, and controls to evaluate adherence to ISO27K requirements, ensuring the effectiveness and adequacy of information security measures.
Provide Recommendations: Analyse audit findings and provide actionable recommendations to enhance information security posture, mitigate risks, and address any non-compliance with best standards ISO27K.
Collaborate with Stakeholders: Collaborate closely with global and regional IT teams, business units, and other stakeholders to communicate audit objectives, gather relevant information, and foster a culture of continuous improvement in information security practices.
Stay Current with Standards: Stay abreast of developments in information security best practices, industry standards, and regulatory requirements related to best standards (e.g: ISO 27001, NIST), and incorporate relevant updates into the audit program as needed.
Minimum of combined 5-year specialization in compliance, audit, or risk management activities.
Knowledge of, and experience with, current IT/Information Security/Governance frameworks (e.g., Knowledge of security technologies and best practices, pertinent regulation and legislation, risk management and operations with relation to systems, applications, network, and client setups.
Proficient with MS Office and GRC tools (e.g., Service-Now IRM).
Excellent interpersonal skills, including interfacing effectively with a broad range of people and roles, such as Regional Information Security Officers, Accounting/ Finance, Internal Audit, Financial Compliance, and other corporate functions.
and the ability to take initiative with minimal direction.
Possess strong time management to meet deadlines.
Accommodation of schedule for international conference calls.
Bachelor's degree in an IT, Computer Science/Engineering - or related field, or a similar level of training.
-
Montréal, QC, Canada WSP Full timeThe Opportunity: WSP is a global consulting firm assisting public and private clients to plan, develop, design, construct, operate and maintain thousands of critical infrastructure projects around the world. WSP's Information Security Office (ISO) is responsible for the deployment and maintenance of the information security framework for both the IT...
-
Information Security and Compliance Manager
1 week ago
Montréal, Canada WorkJam, Inc. Full time**WorkJam**’s mission? To provide the best Digital Workplace for frontline and hourly workers. Through our industry-leading Digital Frontline Workplace platform, we are positively impacting the lives of millions of frontline employees worldwide, enabling them to achieve breakthrough productivity levels at companies of all sizes._ _We’re proud of our...
-
Montréal, QC HZ A, Canada Jesta I.S. Full time $60,000 - $80,000 per yearCompany overviewJesta I.S. is a leading supplier of ERP software for the apparel, footwear, and soft-goods industries. Our global client base includes many recognizable brands and continues to grow. We are seeking a Security & Compliance Analyst to join our IT Operation team in Montreal.Position summaryWe're looking for someone with 2+ years working hands-on...
-
Information Security Governance Manager
3 days ago
Montréal, Canada Humanity Full timeCompany Description Jobs for Humanity is dedicated to building an inclusive and just employment ecosystem. Therefore, we have dedicated this job posting to individuals coming from the following communities: Refugee, Neurodivergent, Single Parent, Blind or Low Vision, Ethnic Minority, and the Previously Incarcerated. If you identify with any of the following...
-
Health Information Compliance Manager
7 days ago
Montréal, Canada Circle Medical Full time**ABOUT US** Circle Medical is the fastest-growing telemedicine provider in the US and has seen incredible growth of over 100% per year over the past three years. Circle Medical is a venture-backed Y-Combinator healthcare startup on a mission to bring quality, delightful primary care to everyone on the planet. Built by top-tier physicians, engineers, and...
-
SAP Security/compliance Specialist
2 weeks ago
Montréal, Canada Xideral Full time**Responsibilities**: 1. Compliance and Risk Management: Ensuring adherence to regulatory requirements (e.g., SOX, GDPR) and internal policies. Mitigating risks associated with access management, segregation of duties (SoD), and sensitive transactions. 2. Execution and Monitoring of Key Controls: Conducting periodic user access reviews, role audits, and...
-
Safety and Compliance Manager
2 weeks ago
Montréal, QC, Canada TST-CF Express Full time**About Us**: Founded in 1928, TST-CF Express provides LTL service within Canada from 23 locations and between Canada and the U.S. through its strategic partnership with Saia LTL Freight. **We are looking to hire Safety and Compliance Manager for Montreal (Hiring Immediately)** **Responsibilities**: - Accident Handling and Resolution - Contact person for...
-
Manager IT Security Governance Risk Compliance
2 weeks ago
Laval, QC HP P, Canada Sonepar Full time $120,000 - $180,000 per yearAbout Us:Sonepar Canada is an independent family-owned company with global market leadership in the business-to-business distribution of electrical, industrial and safety products and related solutions. In Canada, we are represented by 9 locally managed electrical and industrial distributors and have over 100+ locations with coverage in 8 provinces.We are a...
-
Regulatory Risk
4 weeks ago
Montréal, QC, Canada Broadsign Full timeSenior GRC/S Specialist - Information Security Assurance & Automation Broadsign is a growing software company with a mission to make buying, selling, and delivering out-of-home media easier than ever. Our software is operated by some of the most successful out-of-home businesses and powers impactful, compelling campaigns seen across the world. Come...
-
Regulatory Risk
4 weeks ago
Montréal, QC, Canada Broadsign Full timeSenior GRC/S Specialist - Information Security Assurance & Automation Broadsign is a growing software company with a mission to make buying, selling, and delivering out-of-home media easier than ever. Our software is operated by some of the most successful out-of-home businesses and powers impactful, compelling campaigns seen across the world. Come...