Specialist, IT Security Risk Management

7 months ago


Ottawa, Canada CMHC Full time

**Job Requisition ID**: 9921

**Position Status**: Permanent Full Time

**Position Type**:Hybrid

**Office Location**:Ottawa (ON); Calgary (AB); Montreal (QC); Toronto (ON)

**Travel Requirement**: Occasional

**Language Designation**: English Essential

**Language Skill Levels (Read/Write/Speak)**: ZZZ

About CMHC

At CMHC, the work you do and the work we do together matters. We come to work every day with a common purpose: to realize a future where everyone in Canada has a home that they can afford and meets their needs.

Our people are second to none. We lean in with courage, band together as a community and try new things to make a lasting impact on housing from coast to coast to coast.

Join us and be part of a team that's committed to making a real difference and be part of something meaningful.

What’s in it for you

We’ve got the purpose, the people and the perks you need for a fulfilling career. Here’s what you get when you’re a permanent employee:

- 5 weeks of vacation.
- Annual individual performance bonus.
- Defined benefit pension plan.
- Comprehensive group insurance plan to support your well-being from day one.
- Support in your personal and professional growth with training, mentorship and more - because when you thrive, we thrive.
- An inclusive workplace culture and environment with Employee Resource Groups and more.
- A hybrid work model that lets you balance working from home and nurturing in-person connections by coming into your region’s office at a minimum of 4 times a month.

About the role

Join the IT Security Team in the Specialist, IT Security Risk Management position. In this role, you will be responsible for supporting CMHC’s information technology risk, privacy, compliance and security programs. While working in conjunction with other professional colleagues and specialists, you will be acting as an expert advisor to management concerning IT security risks that involve and/or affect security, such as conducting security threats and risk assessments related to existing and new technologies. You will also be developing and implementing CMHC's security awareness program as well as its technology risk management policies, directives, procedures and guidelines.

**What you’ll do**:

- Develop and maintaining an IT security risk management framework to quickly identify and flag current and evolving threats to CMHC.
- Identify and assess the severity and potential impact of risks to IT Security and recommending a risk management strategy that optimizes the trade-offs between risk mitigation and business performance.
- Conduct security threat and risk analysis including information from any technical vulnerability assessment and penetration testing.
- Elaborate, characterize, assess and evaluate risks and making decisions dispassionately.
- Investigate, assess, track, resolve and report on mitigated actions and/or on suspected violations of policies and procedures in coordination with appropriate entities (e.g., Internal Audit team, Chief Risk Officer's delegates).
- Develop new or identify existing information security training, education and awareness activities appropriate for various audiences.
- Facilitate, guide and oversee audits and oversight activities concerning physical security and the security of information systems.
- Conduct research to stay abreast of security strategies, technologies and techniques that may have an impact on IT security at CMHC.

**What you should have**:

- A bachelor’s degree, preferably in Cyber Security, Computer Security, Information Systems Security, Computer Science or in a related field. An equivalent combination of related education and work experience may be considered.
- A minimum of five (5) years of increasing responsibilities and relevant work, experience/expertise in IT Security and/or in information security.
- Strong communication (written and verbal) and interpersonal skills, including the ability to negotiate, influence and challenge various audiences.
- An experience working in a highly regulated environment (such as a financial institution).
- An experience in overseeing the IT/network operations of a corporation.
- An experience in writing complex risk analysis/risk assessment reports for a variety of audiences (technical and non-technical).

**It would be great if you also had**:

- A professional designation, such as Certified in Risk and Information Systems Control (CRISC), Certified Information Systems Security Professional (CISSP), Certified in the Governance of Enterprise IT (CGEIT) or other relevant IT Security licence, designation, or certificate.
- Bilingualism (English and French).
- An experience and/or knowledge of recognized standards. E.g. NIST CSF, ISO 27001/27002, ITSG-33, etc.
- A knowledge of Canadian laws and Government of Canada regulatory requirements and standards. E.g. Treasury Board, Office of the Superintendent of Financial Institutes, etc.

**Posting closing date**: Note, the competition



  • Ottawa, Ontario, Canada Amazon Full time

    Job Summary:We are seeking a highly skilled Security and Risk Management Specialist to join our team at Amazon. In this role, you will be responsible for ensuring the protection of people and assets across our sites, adhering to GSO guidelines and policies.Main Responsibilities:Perform thorough risk assessments of our sites and operation models, identifying...


  • Ottawa, Ontario, Canada Communications Security Establishment (CSE Full time

    Job DescriptionWe are seeking a skilled Software Security Specialist to join our team at the Communications Security Establishment (CSE). This is a challenging role that requires strong technical expertise in software development and security.Key Responsibilities:Design, develop, and maintain secure software applicationsCollaborate with cross-functional...

  • Specialist, IT Risk

    4 weeks ago


    Ottawa, Canada CMHC Full time

    **Job Requisition ID**: 10613 **Position Status**: Permanent Full Time **Position Type**:Hybrid **Office Location**:Ottawa (ON); Montreal (QC); Toronto (ON) **Travel Requirement**: Travel not required **Language Designation**: English Essential **Language Skill Levels (Read/Write/Speak)**: ZZZ **Security Requirement**: Secret **Salary**: Our salaries...

  • Security Risk Analyst

    6 months ago


    Ottawa, Canada Bank of Canada Full time

    **Security Risk Analyst** **Take a central role** The Bank of Canada has a vision to be a leading central bank—dynamic, engaged and trusted—committed to a better Canada. No other employer in the country offers you the unique opportunity to work at the very center of Canada’s economy, in an organization with significant impact on the economic and...


  • Ottawa, Ontario, Canada ADGA Group Full time

    Job OverviewWe are seeking a highly experienced Cybersecurity Risk Management Specialist to join our team at ADGA Group.About the RoleThis is a challenging opportunity for a senior cybersecurity professional to assist in the development of a project charter, project plan, and security policy instruments. The ideal candidate will have a minimum of 10 years of...


  • Ottawa, Ontario, Canada CDA-AMC Full time

    Overview">CDA-AMC, a pan-Canadian health organization, is seeking an experienced IT Risk Management Analyst to join its team. As the Senior IT Risk Management Analyst, you will play a key role in identifying, assessing, and mitigating risks to our information systems and data.">Salary">The estimated annual salary for this position ranges from $97,000 to...


  • Ottawa, Canada Bank of Canada Full time

    **Principal Risk Management Specialist** **Take a central role** The Bank of Canada has a vision to be “a leading central bank—dynamic, engaged and trusted—committed to a better Canada.” No other employer in the country offers you the unique opportunity to work at the very center of Canada’s economy, in a diverse and inclusive organization with...


  • Ottawa, Ontario, Canada Maplesoft Group Full time

    About the RoleMaplesoft Group is currently seeking an experienced Cybersecurity Threat and Risk Management Specialist to join our team.Job DescriptionThe successful candidate will be responsible for reviewing, analyzing, and applying Federal, Provincial, or Territorial IT Security policies, System IT Security Certification & Accreditation processes, IT...

  • Risk Specialist

    4 months ago


    Ottawa, Canada Work in Ottawa Full time

    **Tech companies are hiring in Ottawa!** If you’re looking for your next opportunity in tech, Work in Ottawa can help you build a thriving career in the fast-growing technology industry in Canada’s capital. As an initiative of the city’s economic development agency, Invest Ottawa, Work in Ottawa helps tech firms fill open positions quickly so they can...


  • Ottawa, Canada The Federal Bridge Corporation Limited Full time

    The Manager, Corporate Security, Risk and Compliance reports to the Chief Corporate Services Officer and examines and continually assesses the Corporation’s security and risk requirements and is responsible for the FBCL corporate security plan. The incumbent provides advice on corporate risk and is responsible for compliance...

  • Specialist, IT Risk

    3 weeks ago


    Ottawa, Canada Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) Full time

    Job Requisition ID: 10613Position Status: Permanent Full TimePosition Type: HybridOffice Location: Ottawa (ON); Montreal (QC); Toronto (ON)Travel Requirement: Travel not requiredLanguage Designation: English EssentialLanguage Skill Levels (Read/Write/Speak): ZZZSecurity Requirement: SecretSalary: Our salaries generally range from $ 83038.35 to $ 103797.93...


  • Ottawa, Ontario, Canada High Tech Genesis Full time

    Job DescriptionWe are seeking a highly experienced and skilled Chief Security Officer to join our team at High Tech Genesis. As the head of our security department, you will play a critical role in safeguarding our organization's assets, mitigating risks, and ensuring compliance with regulatory standards.Key Responsibilities:Develop and Implement...


  • Ottawa, Ontario, Canada MacEwen Petroleum Inc. Full time

    Company OverviewMacEwen Petroleum Inc. is a leading independent petroleum and convenience store company in Ontario and Quebec, with over 150 retail locations and 16 Divisional Offices.About the RoleWe are seeking an experienced Cyber Security Risk Manager to join our team. This role will be responsible for monitoring, detecting, and responding to security...


  • Ottawa, Ontario, Canada Carleton University Full time

    Carleton University Insurance and Risk ManagerAbout the Opportunity:We are seeking an experienced Risk Management Specialist to join our team at Carleton University. This is a key role that requires strong risk management skills, excellent analytical abilities, and a passion for ensuring the university's assets are protected.Key Responsibilities:Procurement...


  • Ottawa, Canada acre security Full time

    Acre security is a leading provider of digital and physical security solutions for businesses worldwide. As a Senior Agile Project Manager, you will play a crucial role in shaping the future of security innovation.Role OverviewWe are seeking an experienced Senior Agile Project Manager to oversee the end-to-end delivery of Access management systems, from...


  • Ottawa, Canada David Joseph & Company Full time

    Our government client has a requirement for specialist professional servicesin the field of IT Security Vulnerability Analysis to assist their Information Protection.The enterprise information security program addresses these challenges through a range ofprograms and services, some of which require enhancement to further fulfill organizational needs.The IT...

  • Specialist, IT Risk

    6 months ago


    Ottawa, Canada CMHC Full time

    **Job Requisition ID**: 10191 **Position Status**: Permanent Full Time **Position Type**:Hybrid **Office Location**:Ottawa (ON); Montreal (QC); Toronto (ON) **Travel Requirement**: Travel not required **Language Designation**: English Essential **Language Skill Levels (Read/Write/Speak)**: ZZZ **Salary**: Our salaries generally range from $ 83038.35...


  • Ottawa, Ontario, Canada Alterna Sa Full time

    **Job Summary**We are seeking a skilled Financial Risk Management Specialist to join our team at Alterna Savings. In this role, you will be responsible for managing daily transactions and analyzing risks related to money laundering and terrorist financing.Main Responsibilities:Complete all FINTRAC transaction reporting accurately and on time.Analyze reports...

  • Security Supervisor

    6 months ago


    Ottawa, Canada AlfaDefence Security inc. Full time

    **About Us**: AlfaDefence Security is a leading provider of professional security services, dedicated to safeguarding our clients' assets and ensuring peace of mind. With a commitment to excellence and integrity, we deliver tailored security solutions to meet the unique needs of businesses and individuals. We are currently seeking a dynamic and experienced...


  • Greater Ottawa Metropolitan Area, Canada OXARO Inc. Full time

    OXARO Inc. Seeks Cyber Security ExpertWe are seeking a seasoned Senior Project Manager to lead our Land Cyber Security Risk Management Process in Ottawa, Canada.About the RoleThe successful candidate will oversee cyber security initiatives, manage projects and workshops, provide high-level briefings to stakeholders, develop and document policies, coordinate...