Cybersecurity Risk Management Expert
1 week ago
We are seeking a highly skilled Cybersecurity Risk Management Expert to join our team at SGS Société Générale de Surveillance SA. The ideal candidate will have a strong background in cybersecurity risk management, with experience in assessing and mitigating risks associated with data and technology environments.
About the Job:
The Cybersecurity Risk Manager will be responsible for evaluating overall cybersecurity risk, maintaining an active view, and reporting on the actual, mitigated, and residual cybersecurity risk in the organization. This role will also help further define the Cybersecurity Risk 2nd line of defense practices, including assessments, life-cycle practices, operational incident/response, service delivery, and BCP.
This position requires day-to-day responsibilities that include but are not limited to:
- Performing full range of technology and information and cyber security risk management lifecycle activities, including risk identification, assessment, reporting, and oversight of remediation planning and execution.
- Partnering with Chief Information Security Officer (CISO), and IT organizations to establish standards, policies, and develop KRIs and KPIs for measuring and monitoring cyber risks on a continuous basis.
- Developing and managing Information Technology & Information Security Risk Program, using standard risk taxonomy, such as FAIR.
- Providing and performing independent assurance and validation activities over common cybersecurity controls that include both administrative and technical.
- Assessing the accuracy, completeness, and sufficiency of the risk management governance framework, processes, and methodologies. Identifying and defining emerging cyber threats and risks to SG's environment.
- Performing effective challenge of all critical and highly sensitive processes & controls, and business continuity.
- Developing cyber security risk scenarios to identify potential attack vectors and TTP (tactics, techniques, and procedures) to guide the continuous improvement of firm's cyber defense posture. Leading and supporting selected cyber security remediation efforts, involved with strategic planning with 1LOD.
- Recommending enhancements to data & technology architectures, processes, and controls to improve cybersecurity, data, and technology risk management capabilities for high-risk processes, regulatory reporting, and risk oversight.
- Developing and rolling out tools for the aggregation and surveillance of cybersecurity risk, data risk & technology risk.
- Identifying legal, regulatory, and contractual requirements, and organizational policies and standards related to data management systems to determine their potential impact on the business objectives.
- Expanding operational risk processes, data collection, and issues management tools to track and report data-related operational risks and issues.
- Participating in and reviewing data breaches and technology incident/response escalation processes.
- Developing operational resiliency scenarios for stress testing and capital planning activities.
- Leading or supporting selected cybersecurity remediation efforts.
Requirements:
Must-Have:
- Bachelor's and/or master's degree in computer science, engineering, or relevant technical field.
- Understanding of financial services specifically within cyber and data privacy-related laws, regulations, frameworks, and guidelines (NYSDFS - 23NYCRR500, ECB, GDPR, GLBA, Regulation S-P, etc.).
- Experience in assessing design and operating effectiveness of technology controls.
- Solid foundation in information technology and information security principles. Familiar with common cybersecurity frameworks and standards such as NIST SP 800-53, NIST CSF, Mitre Attack, FFIEC CAT, CSC Top 20, COBIT, ISO 27000 series.
- Previous working experiences in cybersecurity operation and relevant security design knowledge.
- Previous work within Risk and/or Information Security/Cyber Security. Ideally, has worked in a 2 LOD Cyber Security Risk function.
- Background in IT Risk Assessment, IT Audit, Information Security Management.
- Experience integrating vulnerability and patch management tools with IT/IS risk program.
- Knowledge of US IT Security regulatory requirements and environment in financial services industry a plus (i.e., FFIEC, FINRA rules, SEC, NIST cybersecurity frameworks).
Nice to Have:
- IT Risk management or governance certifications (CGEIT, CRISC, CISA).
Salary Range: $120,000 - $180,000 per year, depending on experience.
Benefits:
We offer a comprehensive benefits package, including health spending ($2,000/year) and personal spending ($1,000/year) accounts with 75+ eligible reimbursement categories (health, training, electronics, etc.). Our fully sponsored virtual healthcare assistance and Employee Assistance Program provides support for you and your immediate family. We also offer various Employee Resource Groups (ERG) to engage with, such as Pride and Allies, American Women Network, Black Leadership Network, One Planet, etc.
Culture:
We value diversity and inclusion at SGS Société Générale de Surveillance SA. Our Diversity & Inclusion Mission is to recruit, develop, advance, and retain a diverse workforce that reflects the communities we serve. Our hybrid work arrangement offers flexibility to work remotely, while promoting interaction and collaboration with colleagues. If you are passionate about cybersecurity risk management and want to make a difference in a dynamic and inclusive environment, we encourage you to apply.
-
Montreal, Quebec, Canada National Bank Full timeJob DescriptionWe are seeking a seasoned Cybersecurity and Technology Risk Management Expert to join our team at National Bank.About the RoleThis is a permanent, full-time position offering a competitive salary range of $120,000 - $180,000 per year, commensurate with experience.Key ResponsibilitiesManage relationships and build trust with business lines,...
-
Montreal, Quebec, Canada Cyber Crime Full timeCybersecurity Career at PwC CanadaWe are a leading professional services firm that helps organizations build trust and deliver sustained outcomes.As a Cybersecurity Strategist and Risk Management Expert at PwC Canada, you will focus on providing comprehensive security solutions and expertise across various domains to maintain the protection of client systems...
-
Cybersecurity Governance and Risk Expert
1 month ago
Montreal, Quebec, Canada Transat AT Full timeCybersecurity Specialist, Governance, Risks and ComplianceJob DescriptionAs a key member of the GRC cybersecurity team at Transat AT, you will collaborate closely with business units to ensure the company meets its compliance requirements. Your role will involve identifying and monitoring various business risks that may impact the organization.You will play...
-
Cybersecurity Risk Management Expert
1 day ago
Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full timeAbout the RoleWe are seeking a highly skilled Cybersecurity Risk Manager to join our team at SGS Société Générale de Surveillance SA. This is an exciting opportunity for a professional with expertise in cybersecurity risk management to contribute to our organization's success.Job DescriptionThe Cybersecurity Risk Manager will be responsible for...
-
Strategic Cybersecurity Risk Manager
4 weeks ago
Montreal, Quebec, Canada National Bank Full timeJob OverviewNational Bank is seeking a highly skilled Strategic Cybersecurity Risk Manager to join their Technology, Cyber and Data Risk Management team. This role will play a critical part in identifying and mitigating cybersecurity risks across the organization.About the RoleThis position requires an individual with 10+ years of experience in technology...
-
Cybersecurity Risk Advisory Expert
4 weeks ago
Montreal, Quebec, Canada Intact Financial Corporation Full timeAbout the RoleAs a Cybersecurity Risk Advisory Expert at Intact Financial Corporation, you will play a crucial role in promoting a strong cybersecurity regulatory compliance environment for our organization.
-
Cybersecurity Risk Manager
1 week ago
Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full timeJob SummaryCybersecurity Risk Manager (Data and Technology Expert)Societe Generale is seeking a skilled Cybersecurity Risk Manager to join its team in the US. As a key member of the RISQ/OPE organization, you will be responsible for evaluating overall cybersecurity risk, maintaining an active view, and reporting on the actual, mitigated, and residual...
-
Cybersecurity Risk Management Leader
3 weeks ago
Montreal, Quebec, Canada National Bank Full timeUnlock Your Potential as a Cybersecurity Risk Management LeaderWe are seeking an experienced and skilled Cybersecurity Risk Management Leader to join our Technology, Cyber and Data Risk Management team at National Bank. As a key member of our team, you will play a critical role in helping us achieve our mission to have a positive impact on people's...
-
Cybersecurity Risk Management Expert
3 weeks ago
Montreal, Quebec, Canada Produits forestiers Résolu Full timeResolute Forest Products, a global leader in the forest products industry, is seeking a Cybersecurity Risk Analyst to join its team. Based in Montreal, Quebec, Canada, this full-time permanent position offers a rewarding and safe work environment with opportunities for growth and skill development.About ResoluteFounded over two centuries ago, Resolute has...
-
Cybersecurity Risk Manager
1 week ago
Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full timeAbout the JobCybersecurity Risk Manager - Data Protection and Resilience ExpertAt SGS Société Générale de Surveillance SA, we are seeking an experienced Cybersecurity Risk Manager to join our team. The successful candidate will be responsible for evaluating overall cybersecurity risk, maintaining an active view, and reporting on actual, mitigated, and...
-
Cybersecurity Risk Manager
1 week ago
Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full timeAbout Societe GeneraleSociete Generale is a leading international financial services group that specializes in serving the needs of its clients, who are primarily corporate and investment banking clients. Our mission is to contribute to the sustainable growth of our clients through our expertise, understanding of risks, and risk management techniques.We have...
-
Montreal, Quebec, Canada Banque Nationale du Canada Full timeJob DescriptionWe are seeking a seasoned Strategic Technology and Cybersecurity Risk Manager to join our team at Banque Nationale du Canada. As a key member of our Technology, Cyber and Data Risk Management sector, you will play a critical role in ensuring the security and resilience of our technology infrastructure.In this position, you will be responsible...
-
Cybersecurity Compliance Expert
7 days ago
Montreal, Quebec, Canada Mindsec Full timeWe are seeking a seasoned Cybersecurity Compliance Expert to join our team at Mindsec. With a strong background in technology risk management and compliance, you will play a critical role in helping our customers achieve and maintain compliance with industry standards.Job SummaryAs a Cybersecurity Compliance Expert, you will be responsible for providing...
-
Cybersecurity Risk Expert Lead
3 weeks ago
Montreal, Quebec, Canada National Bank Full timeAbout the RoleAs a Senior Cyber Security Advisor at National Bank, you will play a critical role in protecting our organization's digital assets and ensuring the confidentiality, integrity, and availability of sensitive information. This is an exciting opportunity to leverage your cybersecurity expertise and experience to drive business growth while...
-
Cybersecurity Risk Manager
1 week ago
Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full timeAbout the RoleThe Cybersecurity Risk Manager plays a pivotal role in defining 2nd line of defense processes, policies, and tools for Societe Generale's data and technology environments. This position involves evaluating overall cybersecurity risk, maintaining an active view, and reporting on actual, mitigated, and residual cybersecurity risk within the...
-
Cybersecurity Risk Management Specialist
1 week ago
Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full timeAbout the JobAt SGS Société Générale de Surveillance SA, we are seeking a highly skilled Cybersecurity Risk Manager to join our team in the Americas Region. This role is responsible for evaluating overall cybersecurity risk, maintaining an active view, and reporting on actual, mitigated, and residual cybersecurity risk in the organization.The successful...
-
Cybersecurity Risk Management Professional
1 week ago
Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full timeJob SummarySociete Generale seeks a highly skilled Cybersecurity Risk Management Professional to join our team in the United States. This role requires expertise in assessing and mitigating cybersecurity risks, developing risk management programs, and collaborating with IT organizations to establish standards and policies.About the JobThe successful...
-
Cybersecurity Risk Advisory Specialist
3 weeks ago
Montreal, Quebec, Canada Intact Financial Corporation Full timeAbout the RoleWe are seeking a highly skilled Cybersecurity Risk Advisory Specialist to join our team at Intact Financial Corporation.Job SummaryAs a Cybersecurity Risk Advisory Specialist, you will play a critical role in helping us promote a strong cybersecurity regulatory compliance across our organization. You will work closely with our Cybersecurity...
-
Cybersecurity Risk Management Lead
1 week ago
Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full timeAbout the RoleWe are seeking a highly skilled Cybersecurity Risk Management Lead to join our team at SGS Société Générale de Surveillance SA. In this role, you will be responsible for evaluating overall cybersecurity risk, maintaining an active view, and reporting on actual, mitigated, and residual cybersecurity risk in the organization.Key...
-
Chief Cybersecurity Risk Strategist
4 weeks ago
Montreal, Quebec, Canada National Bank Full timeSenior Cyber Security AdvisorA career as a Senior Cybersecurity Advisor at National Bank means acting as a cybersecurity expert and providing tactical and strategic guidance, as well as advice to help business and technical teams achieve acceptable security risk postures. It is through your diplomacy, as well as your knowledge of governance processes, risk...