Specialist, IT Security Risk Management

3 weeks ago


Ottawa, Canada CMHC Full time

**Job Requisition ID**: 9921

**Position Status**: Permanent Full Time

**Position Type**:Hybrid

**Office Location**:Ottawa (ON); Calgary (AB); Montreal (QC); Toronto (ON)

**Travel Requirement**: Occasional

**Language Designation**: English Essential

**Language Skill Levels (Read/Write/Speak)**: ZZZ

About CMHC

At CMHC, the work you do and the work we do together matters. We come to work every day with a common purpose: to realize a future where everyone in Canada has a home that they can afford and meets their needs.

Our people are second to none. We lean in with courage, band together as a community and try new things to make a lasting impact on housing from coast to coast to coast.

Join us and be part of a team that's committed to making a real difference and be part of something meaningful.

What’s in it for you

We’ve got the purpose, the people and the perks you need for a fulfilling career. Here’s what you get when you’re a permanent employee:

- 5 weeks of vacation.
- Annual individual performance bonus.
- Defined benefit pension plan.
- Comprehensive group insurance plan to support your well-being from day one.
- Support in your personal and professional growth with training, mentorship and more - because when you thrive, we thrive.
- An inclusive workplace culture and environment with Employee Resource Groups and more.
- A hybrid work model that lets you balance working from home and nurturing in-person connections by coming into your region’s office at a minimum of 4 times a month.

About the role

Join the IT Security Team in the Specialist, IT Security Risk Management position. In this role, you will be responsible for supporting CMHC’s information technology risk, privacy, compliance and security programs. While working in conjunction with other professional colleagues and specialists, you will be acting as an expert advisor to management concerning IT security risks that involve and/or affect security, such as conducting security threats and risk assessments related to existing and new technologies. You will also be developing and implementing CMHC's security awareness program as well as its technology risk management policies, directives, procedures and guidelines.

**What you’ll do**:

- Develop and maintaining an IT security risk management framework to quickly identify and flag current and evolving threats to CMHC.
- Identify and assess the severity and potential impact of risks to IT Security and recommending a risk management strategy that optimizes the trade-offs between risk mitigation and business performance.
- Conduct security threat and risk analysis including information from any technical vulnerability assessment and penetration testing.
- Elaborate, characterize, assess and evaluate risks and making decisions dispassionately.
- Investigate, assess, track, resolve and report on mitigated actions and/or on suspected violations of policies and procedures in coordination with appropriate entities (e.g., Internal Audit team, Chief Risk Officer's delegates).
- Develop new or identify existing information security training, education and awareness activities appropriate for various audiences.
- Facilitate, guide and oversee audits and oversight activities concerning physical security and the security of information systems.
- Conduct research to stay abreast of security strategies, technologies and techniques that may have an impact on IT security at CMHC.

**What you should have**:

- A bachelor’s degree, preferably in Cyber Security, Computer Security, Information Systems Security, Computer Science or in a related field. An equivalent combination of related education and work experience may be considered.
- A minimum of five (5) years of increasing responsibilities and relevant work, experience/expertise in IT Security and/or in information security.
- Strong communication (written and verbal) and interpersonal skills, including the ability to negotiate, influence and challenge various audiences.
- An experience working in a highly regulated environment (such as a financial institution).
- An experience in overseeing the IT/network operations of a corporation.
- An experience in writing complex risk analysis/risk assessment reports for a variety of audiences (technical and non-technical).

**It would be great if you also had**:

- A professional designation, such as Certified in Risk and Information Systems Control (CRISC), Certified Information Systems Security Professional (CISSP), Certified in the Governance of Enterprise IT (CGEIT) or other relevant IT Security licence, designation, or certificate.
- Bilingualism (English and French).
- An experience and/or knowledge of recognized standards. E.g. NIST CSF, ISO 27001/27002, ITSG-33, etc.
- A knowledge of Canadian laws and Government of Canada regulatory requirements and standards. E.g. Treasury Board, Office of the Superintendent of Financial Institutes, etc.

**Posting closing date**: Note, the competition



  • Ottawa, Canada LeverageTek IT Solutions Full time

    Opportunity Details LeverageTek is actively seeking a Senior Information Security Specialist for an 11-month contract with its Ottawa-based customer. Work Location Remote. One month of onsite work. Security Requirement Must have a Government of Canada Enhanced Reliability Clearance. Key Tasks Conduct, document, and report on security risk assessments for...


  • Ottawa, Canada LeverageTek IT Solutions Full time

    Opportunity Details LeverageTek is actively seeking a Senior Information Security Specialist for an 11-month contract with its Ottawa-based customer. Work Location Remote. One month of onsite work. Security Requirement Must have a Government of Canada Enhanced Reliability Clearance. Key Tasks Conduct, document, and report on security risk assessments...


  • Ottawa, Canada LeverageTek IT Solutions Full time

    Opportunity Details LeverageTek is actively seeking a Senior Information Security Specialist for an 11-month contract with its Ottawa-based customer.Work Location Remote. One month of onsite work.Security Requirement Must have a Government of Canada Enhanced Reliability Clearance.Key Tasks Conduct, document, and report on security risk assessments for...


  • Ottawa, Canada LeverageTek IT Solutions Full time

    Opportunity DetailsLeverageTek is actively seeking a Senior Information Security Specialist for an 11-month contract with its Ottawa-based customer.Work Location Remote. One month of onsite work.Security Requirement Must have a Government of Canada Enhanced Reliability Clearance.Key Tasks Conduct, document, and report on security risk assessments for...


  • Ottawa, ON, Canada LRO Staffing Full time

    Security Specialist - Contract - 17319 Our government client is seeking a Security Specialist to support their division. Strengthen security awareness Review security controls and frameworks Establish Key Performance Indicators (KPIs) Provide a list of relevant documents to be reviewed Assess security governance Security...


  • Ottawa, Canada Myticas Consulting Full time

    Myticas Consulting's direct client is looking for a Security Specialist for a 3-year HYBRID contract in Ottawa. **The Consultant should have the following qualifications and skills**: - University degree or college diploma in computer science, information technology, cyber security or risk management - A minimum of seven (7) years of demonstrated...


  • Ottawa, Canada LeverageTek IT Solutions Full time

    Opportunity DetailsLeverageTek is actively seeking a Senior Information Security Specialist for an 11-month contract with its Ottawa-based customer. Work LocationRemote. One month of onsite work. Security RequirementMust have a Government of Canada Enhanced Reliability Clearance. Key TasksConduct, document, and report on security risk assessments for...


  • Ottawa, ON, Canada LeverageTek IT Solutions Full time

    Opportunity DetailsLeverageTek is actively seeking a Senior Information Security Specialist for an 11-month contract with its Ottawa-based customer. Work LocationRemote. One month of onsite work. Security RequirementMust have a Government of Canada Enhanced Reliability Clearance. Key TasksConduct, document, and report on security risk assessments for...


  • Ottawa, ON, Canada LeverageTek IT Solutions Full time

    Opportunity DetailsLeverageTek is actively seeking a Senior Information Security Specialist for an 11-month contract with its Ottawa-based customer. Work LocationRemote. One month of onsite work. Security RequirementMust have a Government of Canada Enhanced Reliability Clearance. Key TasksConduct, document, and report on security risk assessments for...


  • Ottawa, Canada Transportation Security Administration Full time

    Summary Securing Travel, Protecting People - At the Transportation Security Administration, you will serve in a high-stakes environment to safeguard the American way of life. In cities across the country, you would secure airports, seaports, railroads, highways, and/or public transit systems, thus protecting America's transportation infrastructure...


  • Ottawa, ON, Canada LeverageTek IT Solutions Full time

    Opportunity Details LeverageTek is actively seeking a Senior Information Security Specialist for an 11-month contract with its Ottawa-based customer. Work Location Remote. One month of onsite work. Security Requirement Must have a Government of Canada Enhanced Reliability Clearance. Key Tasks Conduct, document, and report on security risk...


  • Ottawa, Canada Bank of Canada Full time

    **Principal Risk Management Specialist** **Take a central role** The Bank of Canada has a vision to be “a leading central bank—dynamic, engaged and trusted—committed to a better Canada.” No other employer in the country offers you the unique opportunity to work at the very center of Canada’s economy, in a diverse and inclusive organization with...


  • Greater Ottawa Metropolitan Area, Canada LeverageTek IT Solutions Full time

    Opportunity DetailsLeverageTek is actively seeking a Senior Information Security Specialist for an 11-month contract with its Ottawa-based customer. Work LocationRemote. One month of onsite work. Security RequirementMust have a Government of Canada Enhanced Reliability Clearance. Key TasksConduct, document, and report on security risk assessments for...


  • Greater Ottawa Metropolitan Area, Canada LeverageTek IT Solutions Full time

    Opportunity Details LeverageTek is actively seeking a Senior Information Security Specialist for an 11-month contract with its Ottawa-based customer. Work Location Remote. One month of onsite work. Security Requirement Must have a Government of Canada Enhanced Reliability Clearance. Key Tasks Conduct, document, and report on security risk...


  • Greater Ottawa Metropolitan Area, Canada LeverageTek IT Solutions Full time

    Opportunity DetailsLeverageTek is actively seeking a Senior Information Security Specialist for an 11-month contract with its Ottawa-based customer. Work LocationRemote. One month of onsite work. Security RequirementMust have a Government of Canada Enhanced Reliability Clearance. Key TasksConduct, document, and report on security risk assessments for...


  • Ottawa, Canada TEEMA Full time

    Job Title: Senior Security Specialist Job ID: 68290 Location: Nepean, Ontario Overview: Our client in Ottawa, ON is looking for a Senior Security Specialist resource for a 12-month contract to start (with an extension option of an additional 12 month). The position will have a flexible schedule for remote / onsite work but due to regularly required...


  • Ottawa, Canada TEEMA Full time

    Job Title: Senior Security Specialist Job ID: 68290 Location: Nepean, Ontario Overview: Our client in Ottawa, ON is looking for a Senior Security Specialist resource for a 12-month contract to start (with an extension option of an additional 12 month). The position will have a flexible schedule for remote / onsite work but due to regularly required...


  • Ottawa, Canada TEEMA Full time

    Job Title: Senior Security Specialist Job ID: 68290 Location: Nepean, Ontario Overview: Our client in Ottawa, ON is looking for a Senior Security Specialist resource for a 12-month contract to start (with an extension option of an additional 12 month). The position will have a flexible schedule for remote / onsite work but due to regularly required...


  • Ottawa, ON, Canada Brainhunter Full time

    Cyber Security Analysis and Reporting Specialist (#61769) Mindwire Systems is seeking the services of a Cyber Security Analysis and Reporting Specialist for one of our Valued Clients. Tasks and Services: Deliver detailed and executive level briefing materials tailored to different audiences (e.g. PowerPoint), illustrating the Bank's Cybersecurity metrics...


  • Ottawa, ON, Canada TEEMA Full time

    Job Title: Senior Security Specialist Job ID: 68290 Location:  Nepean, Ontario Overview: Our client in Ottawa, ON is looking for a Senior Security Specialist resource for a 12-month contract to start (with an extension option of an additional 12 month). The position will have a flexible schedule for remote / onsite work but due to regularly required...