Cybersecurity Risk Analyst

1 week ago


Montreal, Quebec, Canada Domtar Full time
About the Role

We are seeking a highly skilled Cybersecurity Risk Analyst to join our team at Domtar. As a key member of our IT Compliance & Governance Security team, you will play a critical role in maintaining and improving our IT risk management framework.

Key Responsibilities
  • Maintain and improve our IT/Security Risk Assessment Framework to ensure it remains effective and up-to-date.
  • Document IT security risk, mitigating controls, and present them to risk owners for decision-making.
  • Coordinate with the IT compliance team to ensure compensating controls have been put in place.
  • Maintain the IT risk register throughout the IT risks lifecycle, including performing Privacy Impact Assessments (PIA).
  • Develop and maintain 3rd party vendors assessment methodology to ensure it remains effective and compliant.
  • Perform 3rd party and cloud vendor security posture assessments, document the assessment, and present the results to business owners.
  • Review 3rd party contracts for IT security and data privacy related clauses and work in collaboration with IT Procurement and Legal teams.
  • Maintain the Cloud vendor register and provide vendor selection services for cybersecurity aspects to help business units select a vendor as part of the RFP process.
  • Manage and maintain the IT Exception Handling Process, including documenting IT Exceptions, validating the needs from exception requestors and owners, and seeking exception approval from Cybersecurity management.
  • Provide project advisory services to Business and IT projects on IT risk matters to ensure risk management activities during the project's lifecycle.
  • Produce and report IT risk management KPI and KRI on a monthly basis.
Requirements
  • Bachelor's degree or 5 years of professional experience in Cybersecurity.
  • Minimum of 8 years' experience in security governance, risk, and compliance (GRC).
  • Holds security-related certifications such as CISSP, CISM, CSSP, or similar considered an asset.
Preferred Qualifications
  • Practical experience with implementing and/or working with IT Risk management frameworks.
  • Practical experience with performing IT Risk assessments during projects and as part of security operations.
  • Practical experience with security controls and risk mitigation measures implementation.
  • Practical experience in assessing 3rd party vendor risks and reviewing security and IT controls related assurances documentation provided by 3rd parties.
  • Practical experience with managing an IT exception handling process.
  • Hands-on experience and good knowledge in topics such as identity and access management, network security, Cloud security, cryptography, web security, next-generation security solutions, and operating system security.
  • Experience with project life cycles, particularly security risk analysis, solutions design, and broad systems integration.
Critical Competencies
  • Great organizational and analytical skills.
  • Able to communicate effectively, influence others, challenge ideas, and be convincing.
  • Excellent interpersonal skills to interact at all levels.
  • Ability to influence and engage with senior management.
  • Ability to quickly adapt to changing priorities and demands.
  • Experience in a decentralized environment (both technical and processes).
  • Experience in an information security (application and/or infrastructure) role in an enterprise environment.
  • Structured and autonomous person.
  • Ability to work well on a collaborative team and influence others without direct authority.
  • Excellent written (documentation) and verbal communication skills (English & French) a strong asset.


  • Montreal, Quebec, Canada Produits forestiers Résolu Full time

    Job Title: Cybersecurity Risk AnalystResolute Forest Products is seeking a highly skilled Cybersecurity Risk Analyst to join our team. As a key member of our IT Compliance & Governance Security team, you will play a critical role in maintaining and improving our IT risk management framework.Key Responsibilities:Maintain and improve the IT/Security Risk...


  • Montreal, Quebec, Canada Produits forestiers Résolu Full time

    Job Title: Cybersecurity Risk AnalystResolute Forest Products is seeking a highly skilled Cybersecurity Risk Analyst to join our team. As a key member of our IT Compliance & Governance Security team, you will play a critical role in maintaining and improving our IT risk management framework.Key Responsibilities:Maintain and improve the IT/Security Risk...


  • Montreal, Quebec, Canada Produits forestiers Résolu Full time

    Job Title: Cybersecurity Risk AnalystResolute Forest Products is seeking a highly skilled Cybersecurity Risk Analyst to join our team. As a key member of our IT Compliance & Governance Security team, you will play a critical role in maintaining and improving our IT risk management framework.Key Responsibilities:Maintain and improve the IT/Security Risk...


  • Montreal, Quebec, Canada Produits forestiers Résolu Full time

    Job Title: Cybersecurity Risk AnalystResolute Forest Products is seeking a highly skilled Cybersecurity Risk Analyst to join our team. As a key member of our IT Compliance & Governance Security team, you will play a critical role in maintaining and improving our IT risk management framework.Key Responsibilities:Maintain and improve the IT/Security Risk...


  • Montreal, Quebec, Canada Domtar Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Risk Analyst to join our team at Domtar. As a key member of our IT Compliance & Governance Security team, you will play a critical role in maintaining and improving our IT risk management framework.Key ResponsibilitiesMaintain and improve our IT/Security Risk Assessment FrameworkDocument IT security...


  • Montreal, Quebec, Canada Domtar Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Risk Analyst to join our team at Domtar. As a key member of our IT Compliance & Governance Security team, you will play a critical role in maintaining and improving our IT risk management framework.Key ResponsibilitiesMaintain and improve our IT/Security Risk Assessment FrameworkDocument IT security...

  • Cybersecurity Analyst

    2 weeks ago


    Montreal, Quebec, Canada Intelcom Full time

    About IntelcomIntelcom is a leading provider of last-mile connectivity solutions in the e-commerce sector. Our teams across Canada and our network of independent contractors work together to drive our daily operations.Our VisionWe aim to stay ahead in a rapidly evolving business landscape by delivering innovative services and leveraging cutting-edge...


  • Montreal, Quebec, Canada Intelcom Full time

    About IntelcomIntelcom is a leading provider of last-mile connectivity solutions in the e-commerce sector. Our teams across Canada and our network of independent contractors work together to drive our daily operations.Our VisionWe aim to stay ahead in a rapidly evolving business landscape by delivering innovative services and leveraging cutting-edge...


  • Montreal, Quebec, Canada Intelcom Full time

    About IntelcomWe're a leading last-mile carrier in the e-commerce sector, with a strong presence across Canada and a network of independent contractors. Our goal is to stay ahead of the curve in a rapidly evolving business landscape.Job OverviewWe're seeking a highly skilled Cybersecurity Analyst to support our various projects and initiatives. As a key...


  • Montreal, Quebec, Canada Intelcom Full time

    About IntelcomWe're a leading last-mile carrier in the e-commerce sector, with a strong presence across Canada and a network of independent contractors. Our goal is to stay ahead of the curve in a rapidly evolving business landscape.Job OverviewWe're seeking a highly skilled Cybersecurity Analyst to support our various projects and initiatives. As a key...


  • Montreal, Quebec, Canada nugget Full time

    About the RoleThe Threat Modeling Analyst is responsible for identifying and mitigating potential threats and vulnerabilities across company systems and communicating the issues with the appropriate teams. This role requires a strong understanding of cybersecurity principles and the ability to work collaboratively with cross-functional teams to introduce...

  • Cybersecurity Analyst

    2 weeks ago


    Montreal, Quebec, Canada nugget Full time

    About the RoleThe Threat Modeling Analyst is responsible for identifying and mitigating potential threats and vulnerabilities across company systems and communicating the issues with the appropriate teams. This role requires a strong understanding of cybersecurity principles and the ability to work collaboratively with cross-functional teams to introduce...


  • Montreal, Quebec, Canada Intelcom Full time

    About IntelcomIntelcom is a leading provider of last-mile connectivity solutions in the e-commerce sector. Our teams across Canada and our network of independent contractors work together to deliver exceptional services and drive innovation.Our VisionWe strive to be at the forefront of the business sector, not just following trends, but shaping the future....


  • Montreal, Quebec, Canada Intelcom Full time

    About IntelcomIntelcom is a leading provider of last-mile connectivity solutions in the e-commerce sector. Our teams across Canada and our network of independent contractors work together to deliver exceptional services and drive innovation.Our VisionWe strive to be at the forefront of the business sector, not just following trends, but shaping the future....


  • Montreal, Quebec, Canada Intelcom Express Inc. Full time

    Job Title: Cybersecurity AnalystWe are seeking an experienced Cybersecurity Analyst to join our DETECT team at Intelcom Express Inc. responsible for overall monitoring of our environment. The ideal candidate will have five years of experience performing various monitoring activities such as SOC monitoring, threat monitoring, attack surface management, and...


  • Montreal, Quebec, Canada Intelcom Express Inc. Full time

    Job Title: Cybersecurity AnalystWe are seeking an experienced Cybersecurity Analyst to join our DETECT team at Intelcom Express Inc. responsible for overall monitoring of our environment. The ideal candidate will have five years of experience performing various monitoring activities such as SOC monitoring, threat monitoring, attack surface management, and...


  • Montreal, Quebec, Canada Resolute Forest Products Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Risk Analyst to join our team at Resolute Forest Products. As a key member of our IT Security team, you will play a critical role in maintaining and improving our IT risk management framework, managing IT exceptions, and performing 3rd party vendor risk assessments.Key ResponsibilitiesMaintain and...


  • Montreal, Quebec, Canada Resolute Forest Products Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Risk Analyst to join our team at Resolute Forest Products. As a key member of our IT Security team, you will play a critical role in maintaining and improving our IT risk management framework, managing IT exceptions, and performing 3rd party vendor risk assessments.Key ResponsibilitiesMaintain and...


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Risk Manager to join our Risk Management Department. As a key member of our team, you will be responsible for evaluating and managing cybersecurity risks across our organization.Key ResponsibilitiesPerform comprehensive risk assessments and develop strategies to mitigate cybersecurity...


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Risk Manager to join our Risk Management Department. As a key member of our team, you will be responsible for evaluating and managing cybersecurity risks across our organization.Key ResponsibilitiesPerform comprehensive risk assessments and develop strategies to mitigate cybersecurity...