Cybersecurity Risk Analyst

3 months ago


Montreal Quebec GF, CA Produits forestiers Résolu Full time

Resolute Forest Products, founded more than two centuries ago, is a global leader in the forest products industry. Through the years, it has built more than 20 predecessor companies and supported hundreds of communities.

The company owns or operates some 40 facilities, as well as power generation assets, in the United States and Canada. Our 6,600+ employees work hard to produce quality market pulp, tissue, wood products and papers that are marketed in over 60 countries.

Resolute offers a rewarding and safe work environment with opportunities and challenges that will help grow your skills.

The location in Montreal, (Quebec, Canada), is seeking talent to fill the position of Cybersecurity Risk Analyst. This job is full-time permanent.

By supporting the Manager of IT Compliance & Governance Security team, he/she will contribute the to IT risk management practice at Paper Excellence Group by maintaining and improving the IT risk management framework, manage IT exceptions and perform 3rd party vendor risk assessments. The resource will also participate to Business and IT projects and work with IT operation teams to assess risks and provide risk mitigation recommendations.

IT/Security Risk Assessment Framework
• Maintain and improve an IT/Security Risk Assessment Framework
• Document IT security risk, mitigating controls and present them to risk owner for decision taking.
• Coordinate with IT compliance team to ensure compensating controls have been put in place.
• Maintain the IT risk register through out IT risks lifecycle.
• Perform Privacy Impact Assessments (PIA).


3rd party vendors security assessment
• Maintain and improve 3rd party vendors assessment methodology.
• Perform 3rd party and cloud vendor security posture assessment, document the assessment and present the results to business owners.
• Review 3rd party contracts for IT security and data privacy related clauses and work in collaboration with IT Procurement and Legal teams.
• Maintain the Cloud vendor register.
• Provide vendor selection services for cybersecurity aspects to help business units select a vendor as part of RFP process.


IT Exception Handling Process
• Manage and maintain the IT Exception Handling Process.
• Document IT Exceptions, validate the needs from exception requestors and owner, seek exception approval from Cybersecurity management.
• Document risk assessment as needed.
• Maintain the IT Exceptions register and follow-up on approved exceptions.

Project advisory
• Provide project advisory services to Business and IT projects on IT risk matters to ensure risk management activities during project’s lifecycle. Occasionally provide support to project security advisory team to document project security requirements and controls to implement.


Risk management KPI and KRI
• Produce and report IT risk management KPI and KRI on a monthly basis.


Required Qualifications/Professional Experiences
• Bachelor degree or 5 years of professional experience in Cybersecurity;
• Minimum of 8 years’ experience of security governance, risk and compliance (GRC);
• Holds security related certifications such as CISSP, CISM, CSSP or similar an considered an asset;

Preferred Qualifications/Professional Experiences/Years of Experience:
• Practical experience with implementing and/or working with IT Risk management frameworks;
• Practical experience with performing IT Risk assessment during projects and as part of security operations;
• Practical experience with security controls and risk mitigation measures implementation.
• Practical experience by assessing 3rd party vendor risks and reviewing security and IT controls related assurances documentation provided by 3rd parties (e.g., ISO 27001 certifications, SSAE-16/18, SOC1, SOC2, etc);
• Practical experience with managing an IT exception handling process;
• Hands-on experience and good knowledge in topics such as: identity and access management, network security, Cloud security, cryptography, web security, next generation security solutions and operating system security; and
• Experience with project life cycles, particularly security risk analysis, solutions design and broad systems integration.

Critical Competencies (Leadership, Technical, Innovation and Work Complexity):
• Great organizational and analytical skills;
• Able to vulgarize, ease in expressing ideas, influence others, challenge ideas and be convincing;
• Excellent interpersonal skills to be able to interact at all levels;
• Ability to influence and engage with senior management;
• Ability to quickly adapt to changing priorities and demands;
• Worked in a decentralized environment (both technical and processes);
• Experience in an information security (application and/or infrastructure) role in an enterprise environment;
• Structured and autonomous person;
• You have the ability to work well on a collaborative team and influence others without direct authority;
• Excellent written (documentation) and verbal communication skills (English & French).

What we are offering

  • Competitive salary and annual bonus
  • At least three weeks of vacation and three floating holidays a year from the first day of work, depending on your experience
  • Full range of group insurance from the first day of work
  • Telemedicine services
  • Defined-contribution pension plan with generous employer participation from the first day of work
  • Employee and family assistance program
  • Education assistance program
  • Health club reimbursement program
  • Hybrid workplace: in-person and remote work
  • Work environment based on respect, inclusion and diversity
  • Office accessible by public transit

Since January 1, 2022, we have occupied new state-of-the-art, open-concept, collaborative offices at 1010 De La Gauchetière Street West (Bonaventure metro station).

Resolute is firmly committed to placing greater emphasis on the principles of equity, diversity and inclusion to empower all employees to reach their full potential. We form a dynamic team whose diverse backgrounds and wealth of perspectives are one of the keys to our success. We offer an inclusive, rewarding and safe work environment with opportunities that will help grow your skills.

Four core values influence everything we do at Resolute and help ensure our continued growth and success:

  • Work safely
  • Be accountable
  • Ensure sustainability
  • Succeed together

Consult the Resolute Blog and follow us on LinkedIn, Instagram and Twitter to learn more about our company.

Resolute Forest Products is committed to the principles of employment equity.

#LI-Hybrid

20476
[[titleNOC]]
Information Technology



  • Montreal, Quebec, G4F, CA Canadian National Railway Full time

    Canadian National Railway Company (CN) is looking for a highly motivated person to fulfill a full-time (40h/week) Intern, Governance, Risk and Compliance position in Montreal, QC from May- Aug 2025. Job Summary The Intern, Governance, Risk and Compliance (GRC) is responsible to execute the activities supporting the GRC framework and processes. The incumbent...


  • Montreal, Quebec, G4F, CA Administration portuaire de Montréal Full time

    Reporting to the Treasury and Risk Manager, the incumbent is responsible for analyzing financial data and assessing risks to support strategic decision-making within the organization. This role involves developing financial models, conducting risk assessments and making recommendations to mitigate risks and optimize financial performance.Financial analysis,...


  • Montreal, Quebec, G4F, CA National Bank Full time

    As a Chief Advisor, Technology and Cyber Risk Management for Business Lines on the Technology, Cyber and Data Risk Management team at National Bank, you will act as a second line of defence specialist on information technology and cybersecurity. Your experience in several areas of technology (IT architecture, cloud, cyber) will help you to have a positive...


  • Montreal, Quebec, G4F, CA National Bank Full time

    As a Senior Advisor on the Technology, Cyber and Data Risk Management team at National Bank, you’ll act as a specialist in support of the implementation of the Bank’s risk management strategy. This role will enable you to have a positive impact on the organization by taking charge of risk governance for the 2nd line of defence.Your role Contribute to the...


  • Montreal, Quebec, G4F, CA National Bank Full time

    A career as an Identity and Senior Manager/Access Management (IAM) business owner with National Bank's Cybersecurity team means being responsible for the delivery of high value-added services for the organization. You will mobilize a multidisciplinary team of professionals who will collaborate with our internal partners. Thanks to your expertise in IAM...


  • Montreal, Quebec, G4F, CA National Bank Full time

    A career in cybersecurity at National Bank means participating in the transformation to have a direct and positive impact on the client. As an Business Information Security Officer (BISO) you will be responsible for aligning the information security strategy with the strategy and context of the business line that will be assigned to you.You will adapt the...


  • Montreal, Quebec, G4F, CA National Bank Full time

    A career as a Senior Cybersecurity Advisor at National Bank means acting as a cybersecurity expert and providing tactical and strategic guidance as well as advice to help business and technical teams achieve acceptable security risk postures. It is through your diplomacy, as well as your knowledge of governance processes, risk management and compliance that...


  • Montreal, Quebec, G4F, CA National Bank Full time

    As a Business Analyst in the Cybersecurity team at National Bank, you’ll liaise with business teams and delivery teams. You’ll work in Agile mode and will be part of a squad that manages and delivers business and technology projects for different sectors. In this role, you’ll have the opportunity to use your business analysis skills to help implement...


  • Montreal, Quebec, G4F, CA S.i. Systems Full time

    Job ID: 52862# of positions: 1Start Date: Dec 2nd Duration: 12 months Extension possible: YesConversion Possible: YesInterview Process: 1 Teams + 1 with other team members also virtual or in person Work Location: 1350 Rene-Levesque Blvd Corporate MTL ( 3 days in office Tuesday to Thursday ) DescriptionApply specialized skills and fundamental data science...

  • Analyst, Insurance

    3 days ago


    Montreal, Quebec, G4F, CA Canadian National Railway Full time

    At CN, everyday brings new and exciting challenges. You can expect an interesting environment where you’re part of making sure our business is running optimally and safely―helping keep the economy on track. We provide the kind of paid training and opportunities that long-term careers are built on and we recognize hard workers who strive to make a...


  • Montreal, Quebec, G4F, CA Canadian National Railway Full time

    Canadian National Railway Company (CN) is looking for a highly motivated person to fulfill a full-time (40h/week) Intern, Operational Technology Security Architecture position in Montreal, QC from May- Aug 2025. Job Summary The Intern, Operational Technology (OT) Security Architecture is responsible for executing activities that support the Chief Information...


  • Montreal, Quebec, G4F, CA Produits forestiers Résolu Full time

    Resolute Forest Products, founded more than two centuries ago, is a global leader in the forest products industry. Through the years, it has built more than 20 predecessor companies and supported hundreds of communities. The company owns or operates some 40 facilities, as well as power generation assets, in the United States and Canada. Our 6,600+...


  • Montreal, Quebec, G4F, CA Canadian National Railway Full time

    At CN, we work together to move our company-and North America-forward. Be part of our Information & Technology (I&T) team, a critical piece of the engine that keeps us in motion. From enterprise architecture to operational technology, our teams use the agile methodology to automate and digitize our railroad ensuring our operations run optimally and safely...


  • Montreal, Quebec, G4F, CA BRP Full time

    We are looking for an internal control analyst SOX, finance who will have the opportunity to discover, acquire and apply skills and knowledge concerning the accounting cycle and financial reporting activities of a publicly traded company. You will work with different global finance teams to improve the quality of financial information. YOUR FIRST-YEAR...


  • Montreal, Quebec, G4F, CA S.i. Systems Full time

    Our Public sector client is seeking a Sr Business Analyst to provide Business Process re-engineering in support of the maintenance of their internal platform. The resources may also be asked to assist with the onboarding of new projects that require production environment support. The resource will also be asked to assist with putting together a training...

  • Treasury Analyst

    3 months ago


    Montreal, Quebec, G4F, CA BRP Full time

    We’re looking for an analyst to join our treasury department and be at the heart of the corporate treasury function (cash management, risk management, financing, etc.), assisting our team with various ad hoc and strategic analyses. You'll have the chance to work for a dynamic, publicly-traded company with top-quality brands and great projects in the...


  • Montreal, Quebec, G4F, CA National Bank Full time

    As an analyst on the National Bank Operations team, you’ll contribute to delivering a superior client experience by supporting colleagues, partners and/or clients with our products, systems, and processes. If you are passionate about data and you enjoy working in synergy with people, we can use your expertise, discipline, empowerment, and ability to...

  • ERP Business Analyst

    3 months ago


    Montreal, Quebec, G4F, CA Commsoft Technologies - Fidelio Full time

    You are passionate about technology and business processes? You want to be part of a growing company that cares about the well-being and development of its employees? The Business Analyst position is perfect for you! Our mission At Fidelio, we support small and medium-sized businesses in their growth so that they can become more competitive. How? By helping...

  • Product Owner

    1 week ago


    Montreal, Quebec, G4F, CA National Bank Full time

    A career as a PO Lead Product in the Privacy Protection (PRP) and Artificial Intelligence (AI) Strategic Transformation Program. You will be required to act as a manager of cross-cutting projects relating to the management of access to personal information (GARP); or the evolution of the framework for the development, acquisition and use of AI as well as...


  • Montreal, Quebec, G4F, CA National Bank Full time

    A career as a senior analyst in the Insurance team at National Bank means understanding the business context and the impact of projects on processes. You are guarantor of the success of business deliveries and therefore of the growth of the sector. Your job: Contribute and/or handle as a team the delivery of business initiatives Identify business needs,...