Expert, Information Security Third Party Risk Management

Found in: Adzuna CA C2 - 1 week ago


Toronto ON MC, Toronto, Canada Canadian National Railway Full time
At CN, we work together to move our company-and North America-forward. Be part of our Information & Technology (I&T) team, a critical piece of the engine that keeps us in motion. From enterprise architecture to operational technology, our teams use the agile methodology to automate and digitize our railroad ensuring our operations run optimally and safely and our employees can focus on value-added tasks. You will be able to develop your skills and career in our close-knit, safety-focused culture working together as ONE TEAM. The careers we offer are meaningful because the work we do matters. Join us

Job Summary

The purpose of this role is to maintain and grow an industry leading Information Security Third Party Risk Management (TPRM) practice to support the mission of empowering the business by building resilience against evolving cyber threats. This will include program governance, policy and guideline development, risk assessments, information protection contract clauses, continuous monitoring, compliance assessments, regulatory compliance assurance, due diligence and selection processes, technology and tool development and maintenance, cloud transformation, and stakeholder awareness and communication.

This role oversees the development and operations of the third-party security function within CN's Chief Information Security Office (CISO). It interfaces with a variety of senior stakeholders within I&T and the business in order to develop and influence the required changes for the management of third-party security risks originating from suppliers, customers, subsidiaries, and cloud-based technology tools and platforms, to a level that is manageable and aligned to CN's business risk tolerance. They are a senior resource with an understanding of how to apply deep technical knowledge while coordinating activities between multiple internal groups and third-party organizations to enable business objectives by ultimately managing risk to a level that is acceptable for the organization.

Main Responsibilities

Practice Development and Planning

• Align third party information security with organizational business goals

• Oversee a broad range of Information Security activities related to third party suppliers, solutions, subsidiaries and customers, including large outsourcing initiatives (e.g. I&T infrastructure and help desk managed services)

• Develop and maintain a set of policies & guidelines specific to protecting CN's assets where they are accessed or managed by third parties

• Create and maintain a TPRM practice, including a framework for evaluating and managing third party risk

• Ensure information security requirements are integrated with procurement processes

• Proactively monitor emerging trends and evolving threat landscapes to identify innovative ideas that would position CN to be an industry leader

Operation and Execution

• Identify, assess, and report critical and high risks involving third parties

• Manage and escalate incidents such as a material control weaknesses and security breaches and working with the Security Operations Centre (SOC) as required

• Report critical non-compliances and high risks to the appropriate business stakeholders

• Write and negotiate contractual terms internally and with external partners and suppliers to ensure CN's business goals are met relating to information security

• Ensure CN's Information Security policies & guidelines related to third parties meet regulatory requirements for security and privacy protection (e.g. TSA directives, CCSPA requirements, privacy bills, etc.)

• Enhance existing processes through innovation and continuous improvement

• Subject Matter Expertise

• Drive action across various internal and external stakeholders by communicating technical and process requirements

• Provide leadership and expertise on matters relating to third party information security to various internal stakeholders, including I&T, Procurement, Internal Audit, Legal, Facilities Management, and Insurance teams

• Discover and bring to light innovation opportunities and influence other groups to support and implement changes that will generate business value

• Mentor resources, provide knowledge transfer, and delegate support tasks

Organizational Impact

Decision Making & Impacts

The Expert, Information Security Third Party Risk Management implements the governance, risk, and compliance capabilities required to bring Information Security risks involving third party suppliers, solutions, subsidiaries, and customers to acceptable levels required to enable to enable the organization to achieve its business objectives.

To achieve this they conduct strategic planning, create and maintain processes and tools, and coordinate activities between various internal teams and external organizations.

Level of Interaction/Influence

The Expert, Information Security Third Party Risk Management influences and drives action among various areas within the organization, including Legal, Procurement, Internal Audit, Facilities Management, Insurance, and different areas within I&T. They also drive action within external subsidiaries, suppliers, and customers.

This would include incorporating Information Security requirements into procurement processes, ensuring I&T asset inventory systems include relevant data, influencing behaviours of Solution Architects to identify and mitigate high risks, negotiating contractual terms with Legal and Facilities Management, providing expertise to Internal Audit and Insurance teams, issuing Cybersecurity Policies and conducting compliance monitoring activities on subsidiaries, influencing external agencies and service providers to better align to CN's needs, working with customers on Information Security requirements and posture, and many other interactions with various internal and external stakeholders.

Requirements

Education/Certification/Designation

• B.S. degree in Computer Science, Information Systems or other related field, or equivalent work experience

Skills/Knowledge

• Broad skillset and depth of expertise in technical areas of information security and how they impact business objectives

• Demonstrated capability to understand the security implications of complex business operations and how they are linked to technological solutions that provide practical risk mitigation and business enablement

• Good knowledge of existing and emerging technologies and architecture principles involved in complex information and technology systems

• Significant and proven experience in applying a structured approach to problem resolution

• Sufficient knowledge on matters relating to third party information security

• Excellent written and verbal communication skills as well as business acumen

• Detail-oriented self-starter with a high level of commitment and personal motivation

• Knack for prioritizing tasks and working in a fast-paced environment

• Able to learn quickly to keep pace with rapidly evolving technology and cybersecurity environments

• Able to lead initiatives to completion with minimal management oversight

• Able to communicate in a clear, concise manner

• Experience with contract and supplier negotiations

• Able to multi-task and work effectively across multiple organizational units

• Security assessment experience

• Strong understanding of security frameworks including NIST CSF, NIST SP 800-53, and ISO-270001

• Strong understanding of regulatory requirements including SOX, PIPEDA, HIPAA and TSA

• Deep understanding of security threat landscape

• Ability to translate complex technical topics into simple business language for business audiences

• Experience developing and delivering executive level presentations

• Relationship management skills

• Experience dealing with third parties

• Strong process orientation

• Recognized security certifications (e.g. CISSP, CISM, CRISC, CISA)

Specific skills per speciality

Experience

• Minimum 5 years experience in Information Security

• 10+ years of I&T experience or 5+ years in a similar role

• 10-15 years overall work experience

• Assets

• Knowledge of railway systems

• Good understanding of Cloud Computing

• Understanding of both IT and OT systems

Working Conditions

Occasional business travel (Canada and US) in accordance with CN policy

This position is posted as a grade LEVEL 7. For internal candidates, note that the grade level of the position may adjust based on the employee's experience.

About CN

CN is a world-class transportation leader and trade-enabler. Essential to the economy, to the customers, and to the communities it serves, CN safely transports more than 300 million tons of natural resources, manufactured products, and finished goods throughout North America every year. As the only railroad connecting Canada's Eastern and Western coasts with the Southern tip of the U.S. through a 19,500 mile rail network, CN and its affiliates have been contributing to community prosperity and sustainable trade since 1919. CN is committed to programs supporting social responsibility and environmental stewardship. At CN, we work as ONE TEAM, focused on safety, sustainability and our customers, providing operational and supply chain excellence to deliver results.

For internal candidates, note that the grade level of the position will depend on the employee's experience.
. click apply for full job details
  • Risk Manager

    Found in: Adzuna CA C2 - 3 days ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada L&T Technology Services Full time

    Title – Risk ManagerJob ID – 477643Location - Toronto, CanadaExperience – 8+ yearsJob Description:Minimum 8+ years of experience as a Risk Manager or similar role.Must have experience in either: Safran OR ArmConstruction / Civil Engineering domain is mandatory.Previous have experience or vast understanding of Project Controls (estimate/cost and...

  • Project Manager

    Found in: Adzuna CA C2 - 3 days ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada ARS Global Emergency Management CA Full time

    ARS / Global Emergency Management is a proud leader in disaster mitigation and property restoration. With a commitment to quality and over 60 years of experience, we are dedicated to meeting the needs of insurers, agents, brokers, and most importantly, the policy holder. We serve property owners of all types with restoration services resulting from WATER,...

  • Admissions and Case Manager, Secure Treatment Program

    Found in: Adzuna CA C2 - 3 days ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada Youthdale Treatment Centres Full time

    JOB OPPORTUNITY - Admissions and Case Manager, Secure Treatment Program - Full-Time PermanentPosition SummaryThe Admissions and Case Manager will ensure that Youthdale values are reflected in the ongoing triage of services to identified need, transition, and continued recovery of the children, youth, and young adults. This role will over see the admission...

  • Environmental Risk Assessor

    Found in: Adzuna CA C2 - 3 days ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada ML6 Search + Talent Advisory Full time

    The Opportunity:Our client, a well known Canadian owned Environmental Consulting firm is currently seeking a Risk Assessor to join their dynamic team across the nation. The successful candidate will play a pivotal role in providing technical leadership for a variety of projects across Canada, encompassing screening-level to detailed quantitative risk...

  • Software Developer

    Found in: Adzuna CA C2 - 3 days ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada Dogico Information Inc. Full time

    Join Our Team as a Software Developer.At Dogico Information Inc., we take pride in our history of providing exceptional software and data management solutions tailored to our clients' unique needs. Our dedication to excellence has resulted in growth and success, and we are looking for a talented Senior Software Developer who wants to work with us on a...

  • Senior Project Manager

    Found in: Adzuna CA C2 - 3 days ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada The Mirillion Group Full time

    Senior project manager FraudROLE SUMMARYThis role is accountable for the oversight and project management of fraud mitigation and solutions for Our Client. The Senior Project Manager, Fraud will identify opportunities for fraud mitigation, and detection enhancements for all of payment systems and supporting services to ensure fraud risks are effectively...

  • Project Manager

    Found in: Adzuna CA C2 - 3 days ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada Matchtech North America Full time

    Project ManagerLocation: Toronto, Canada (other locations within Canada will be considered) - hybrid remote workingPermanent PositionThe RoleWe have an exciting opportunity for a Project Manager to join our North America team.The role is to work with our engineering and assurance teams to manage a wide range of projects, including budget management,...

  • Business Data Analyst

    Found in: Adzuna CA C2 - 3 days ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada Acunor Full time

    Role & Responsibilities Overview:Create, maintain BRD’s for identified data product, strategy initiativeProficient in data handling, manipulation using common tools – SQL, ExcelIdentify, prioritize and help deliver various data products within the organizationEmphasis on implementing data strategy initiatives for eg. merging internal data with third...

  • Project Manager

    Found in: Adzuna CA C2 - 3 days ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada Barnard Full time

    Who We AreBarnard Construction Company, Inc. is a heavy civil construction company based in Bozeman, Montana, with projects underway across North America. We are ranked by Engineering News-Record, (a leading construction industry periodical), as one of the USA’s Top 400 civil contractors. We specialize in dam construction and rehabilitation, power...

  • Manager, Operations

    Found in: Adzuna CA C2 - 3 days ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada Altis Recruitment Full time

    We are currently partnered with our client in the higher education industry to locate their Manager, Operations & Project Delivery.This is a fulltime permanent position located in East GTA with a hybrid working model (Tuesday & Thursday on site).The Manager, Operations & Project Delivery in the Office of Research & Innovation will be overseeing operational...

  • Privacy Impact Assessment

    Found in: Adzuna CA C2 - 3 days ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada AMISEQ Full time

    Privacy Impact Assessment (PIA) SpecialistToronto, ON - Hybrid role12 MonthsResponsibilities:Develop privacy impact assessments of the Ministry’s optimization of the provincial Immunization Repository and other provincial repositories and the COVaxON solution (this includes initiatives in support of immunization administration, and vaccine distribution and...

  • Quality Assurance Manager

    Found in: Adzuna CA C2 - 3 days ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada Actionstep Full time

    Actionstep is a pioneer in the development and sale of software-as-a-service (SaaS) products, specializing in the delivery of Legal Practice Management software. We are a fast growing, dynamic business with a global customer base and team. Headquartered in Auckland, New Zealand, with team members in the United Kingdom, United States, Canada and Australia, we...

  • Business Analyst

    Found in: Adzuna CA C2 - 3 days ago


    Toronto, ON, M5H 1W7, City of Toronto, Canada Intelliware Development Inc. Full time

    At Intelliware, you’ll have the opportunity to be part of a top-notch team and work on a wide range of complex custom software solutions. We have a collaborative team-based Agile environment where you’ll find learning opportunities and challenging work. Our project teams work closely with client subject matter experts, end users and technology teams to...

  • Medical Information Specialist

    Found in: Adzuna CA C2 - 3 days ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada Brunel Full time

    Bilingual Medical Information Specialist (renewable contract)Remote – Greater Toronto AreaIntroductionWe are hiring a Bilingual (French/English) Medical Information Specialist for our client based in the Greater Toronto Area. The Medical Information Specialist will contribute to ensuring evidence-based and accurate medical information of the company’s...

  • DevOps SRE Manager

    Found in: Adzuna CA C2 - 3 days ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada Actionstep Full time

    Actionstep is a pioneer in the development and sale of software-as-a-service (SaaS) products, specializing in the delivery of Legal Practice Management software. We are a fast growing, dynamic business with a global customer base and team. Headquartered in Auckland, New Zealand, with team members in the United Kingdom, United States, Canada and Australia, we...

  • Program Manager-Reference Data

    Found in: Adzuna CA C2 - 3 days ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada Davies - Consulting Division Full time

    Position Type : Contract (6-12months)Location : Toronto/GTAWork Environment : HybridRole overview:We are seeking a highly motivated and experienced Program Manager (Reference Data Lead) with technical subject matter expertise in Reference Data to join our team on contract basis.The Reference Data used within Treasury Services for a Global Custodian, and also...

  • Disability Leave Consultant

    Found in: Adzuna CA C2 - 3 days ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada HUB International Full time

    At HUB International , we are a team of entrepreneurs. We believe in empowering our clients, and we do so by protecting businesses and individuals in our local communities. We help businesses evaluate their risks and develop solutions tailored to their needs. We believe in empowering our employees. As a global firm, we offer employees resources in both...

  • Senior Program Manager

    Found in: Adzuna CA C2 - 3 days ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada The Mirillion Group Full time

    SENIOR TRANSFORMATION PROJECT/PROGRAM MANAGERWe are currently seeking a Senior Transformation/IT Project Manager for a highly visible long term assignment with one of our clients. This position is responsible for leading the enterprise transformation work related to people, process, and technology at the cutting edge of payments modernization initiatives....

  • ESG analyst and projects manager

    Found in: Adzuna CA C2 - 3 days ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada IGM Technology Full time

    IGM Technology is looking for an ESG consultant to lead ESG reporting implementation projects and be a subject matter expert on ESG data collection and reporting.The ESG consultant will collaborate with our customers’ executive leadership and marketing teams to implement ESG data collection and reporting software.ResponsibilitiesSupport the implementation...

  • Customer Service Manager with French

    Found in: Adzuna CA C2 - 3 days ago


    Toronto, ON, M5P 2N7, City of Toronto, Canada Asahi Canada Full time

    Company VisionAsahi Canada’s vision is to become an International Premium Beer powerhouse. We will achieve this by leveraging our strengths and existing success models, and by applying a challenger mind-set to everything we do. Asahi Canada's collection of premium beers each tell their own brand story and share a passion for craftsmanship, authenticity...