Goverance, Risk
1 week ago
The Information Technology Governance, Risk and Compliance Analyst is responsible for assessing and prioritizing risks for cyber security and data protection across the organization while helping Teknion meet its compliance obligations. The incumbent supports the risk mitigation efforts through conducting risk assessments, establishing and maintaining governance and compliance standards, creating, communicating, and enforcing information security/confidentiality policies and processes and providing recommendations on risk treatment strategies.
The incumbent executes and administers security solutions/systems consistent with regulations and established frameworks and may lead relevant implementation projects and is also responsible for promoting cybersecurity awareness throughout the company.
You will be leveraging a security and compliance automation platform (Drata) that continuously monitors and collects evidence of the company’s security controls while streamlining workflows to ensure audit readiness. The Drata platform also provides a Trust Centre (manage and publish Teknion’s security posture), Vendor Risk Management (identify and monitor vendor risk) and Audit Hub (create a centralized audit communication center). Additional tools / solutions may be utilized over time.
Governance
- Develop, implement, enhance and communicate security governance framework including policies, standards and procedures across the organization;
- Define and operationalize data classification standards to classify and label data and files and define security controls baseline for classified data;
- Collaborate with Information Technology and the business to ensure that appropriate controls are designed & operating effectively following the corporate policies. Conduct periodic internal audits / self assessments where applicable;
- Monitors activities impacted by regulatory requirements related to the organization’s governance and any location specific laws and implements changes to compliance processes due to these new or amended regulations;
- Must be trustworthy in keeping sensitive data confidential.
**Risk**
- Responsible for conducting comprehensive security risk assessments of new and existing information systems, networks and infrastructure, and third parties to identify potential risks & vulnerabilities;
- Responsible for managing and monitoring Teknion’s risk register to ensure risks are actioned in a timely manner when required.
- Present Governance, Risk and Compliance metrics to the Cyber Risk team and business leaders to ensure they are aware of risks and corresponding obligations (e.g., treatment plans, controls, processes, etc.);
- Recommend controls to mitigate / treat security and data protection risks identified through the risk assessment process and communicate risk findings that are clear and actionable to relevant stakeholders.
**Compliance**
- Evaluate and benchmark Teknion’s cybersecurity capabilities in line with NIST and ISO frameworks, develop plans to prioritize actions and investments required to improve capabilities to best practices;
- Utilizes established internal controls and audits systems (Drata) to identify, detect and correct noncompliance;
- Accomplish & eventually spearhead a team to perform the necessary analysis to deliver all the required evidence to support compliance audits;
- Provide support during certifications & assessments conducted by third parties;
- Design and document technical, administrative, and physical controls to ensure the business demonstrates compliance, ensuring that Teknion meets both the requirements and intent of its compliance obligations;
- Monitors activities impacted by regulatory requirements related to the organization’s governance and any location specific laws and implements changes to compliance processes due to these new or amended regulations;
- Assists with training initiatives that inform stakeholders about compliance requirements.
Other skills that would be an asset for future career opportunities:
- Ability to think analytically, define problems and frame solutions.
- Soft skills, including facilitation, diplomacy, and conflict resolution.
- Analytical, communication and negotiation skills, and attention to detail.
- Effective in a cross functional team environment & can work independently with mínimal supervision.
- A degree of creativity, critical thinking and latitude.
**Qualifications/Educational Requirements**
- University degree in Computer Science, Information Security, Cybersecurity, or a related field as well as experience with Cybersecurity risk management, technology risk, or the equivalent combination of education and experience.
- 2+ years of relevant experience in Cybersecurity and Governance, Risk and Compliance
- Experience with security frameworks such as NIST 800-53, NIST CSF, NIST 800-171, CMMC, ISO 27001 and the creation of applicable policies, standards and procedures
- Experience with Privacy Laws and Regulations su
-
Associate Director, Portfolio Services
4 months ago
Toronto, Canada BGIS Full time**Who We Are** SUMMARY The **Assistant Portfolio Director, **reporting to Portfolio Managing Director is responsible for the management of assigned real estate portfolios on a client account including ownership for overall client relationship, understanding client strategy, managing and overseeing client operating budget and BGIS profit and loss, account...