Cybersecurity Risk Management Specialist

4 days ago


Montreal, Quebec, Canada Domtar Corporation Full time
Cybersecurity Risk Management Specialist

Domtar Corporation is seeking a highly skilled Cybersecurity Risk Management Specialist to join our team. As a key member of our IT Compliance & Governance Security team, you will play a critical role in maintaining and improving our IT risk management framework, managing IT exceptions, and performing 3rd party vendor risk assessments.

Key Responsibilities:
  • Maintain and improve an IT/Security Risk Assessment Framework
  • Document IT security risks, mitigating controls, and present them to risk owners for decision-making
  • Coordinate with the IT compliance team to ensure compensating controls have been put in place
  • Maintain the IT risk register throughout the IT risks lifecycle
  • Perform 3rd party and cloud vendor security posture assessments, document the assessments, and present the results to business owners
  • Review 3rd party contracts for IT security and data privacy-related clauses and work in collaboration with IT Procurement and Legal teams
  • Provide vendor selection services for cybersecurity aspects to help business units select a vendor as part of the RFP process
  • Document IT Exceptions, validate the needs from exception requestors and owners, and seek exception approval from Cybersecurity management
  • Document risk assessments as needed
  • Provide project advisory services to Business and IT projects on IT risk matters to ensure risk management activities during the project's lifecycle
  • Produce and report IT risk management KPI and KRI on a monthly basis
Requirements:
  • Bachelor's degree or 5 years of professional experience in Cybersecurity
  • Minimum of 8 years' experience in security governance, risk, and compliance (GRC)
  • Holds security-related certifications such as CISSP, CISM, CSSP, or similar considered an asset
  • Practical experience with implementing and/or working with IT Risk management frameworks
  • Practical experience with performing IT Risk assessments during projects and as part of security operations
  • Practical experience with security controls and risk mitigation measures implementation
  • Practical experience assessing 3rd party vendor risks and reviewing security and IT controls related assurances documentation provided by 3rd parties
  • Experience with project life cycles, particularly security risk analysis, solutions design, and broad systems integration
  • Ability to influence and engage with senior management
  • Worked in a decentralized environment (both technical and processes)
  • Excellent written (documentation) and verbal communication skills (English & French) a strong asset

Domtar Corporation is an equal-opportunity employer. Qualified applicants will be considered without regard to age, race, color, sex (including gender identity or expression, sexual orientation, and pregnancy), marital status, religion, national origin, genetic information, disability, or veteran status. We are also committed to ensuring reasonable accommodations for individuals protected by Section 503 of the Rehabilitation Act of 1974, and Title I of the Americans with Disability Act of 1990.



  • Montreal, Quebec, Canada Domtar Corporation Full time

    Cybersecurity Risk Management SpecialistIn collaboration with the IT Compliance & Governance Security team, the Cybersecurity Risk Management Specialist will play a vital role in enhancing the IT risk management strategy at Domtar Corporation. This position involves refining the IT risk management framework, overseeing IT exceptions, and conducting...


  • Montreal, Quebec, Canada Domtar Corporation Full time

    Cybersecurity Risk Management SpecialistIn collaboration with the IT Compliance & Governance Security team, the Cybersecurity Risk Management Specialist will play a vital role in enhancing the IT risk management practices at Domtar Corporation. This role involves the ongoing maintenance and enhancement of the IT risk management framework, overseeing IT...


  • Montreal, Quebec, Canada Domtar Corporation Full time

    Cybersecurity Risk Management SpecialistIn collaboration with the IT Compliance & Governance Security team, the Cybersecurity Risk Management Specialist will play a vital role in enhancing the IT risk management strategy at Domtar Corporation. This position involves refining the IT risk management framework, overseeing IT exceptions, and conducting...


  • Montreal, Quebec, Canada Domtar Corporation Full time

    Cybersecurity Risk Management SpecialistIn collaboration with the IT Compliance & Governance Security team, the Cybersecurity Risk Management Specialist will play a vital role in enhancing the IT risk management practices at Domtar Corporation. This role involves the ongoing maintenance and enhancement of the IT risk management framework, overseeing IT...


  • Montreal, Quebec, Canada Domtar Full time

    Job Overview The Cybersecurity Risk Management Specialist will play a vital role in supporting the IT Compliance & Governance Security team at Domtar. This position is essential for enhancing the IT risk management framework, overseeing IT exceptions, and conducting assessments of third-party vendors. The specialist will engage in both Business and IT...


  • Montreal, Quebec, Canada Domtar Corporation Full time

    Cybersecurity Risk Management SpecialistIn collaboration with the Manager of IT Compliance & Governance Security team, the Cybersecurity Risk Management Specialist will play a vital role in enhancing the IT risk management practices at Domtar Corporation. This includes the upkeep and refinement of the IT risk management framework, overseeing IT exceptions,...


  • Montreal, Quebec, Canada Domtar Corporation Full time

    Cybersecurity Risk Management SpecialistIn collaboration with the Manager of IT Compliance & Governance Security team, the Cybersecurity Risk Management Specialist will play a vital role in enhancing the IT risk management practices at Domtar Corporation. This includes the upkeep and refinement of the IT risk management framework, overseeing IT exceptions,...


  • Montreal, Quebec, Canada Resolute Forest Products Full time

    Cybersecurity Risk Management OpportunityResolute Forest Products, a leading company in the pulp and paper industry, is seeking a highly skilled Cybersecurity Risk Management Specialist to join its team in Montreal, Quebec, Canada.The successful candidate will be responsible for maintaining and improving the IT risk management framework, managing IT...


  • Montreal, Quebec, Canada Resolute Forest Products Full time

    Cybersecurity Risk Management OpportunityResolute Forest Products, a leading company in the pulp and paper industry, is seeking a highly skilled Cybersecurity Risk Management Specialist to join its team in Montreal, Quebec, Canada.The successful candidate will be responsible for maintaining and improving the IT risk management framework, managing IT...


  • Montreal, Quebec, Canada Domtar Corporation Full time

    Cybersecurity Risk and Compliance Specialist In collaboration with the Manager of IT Compliance & Governance Security team, the Cybersecurity Risk and Compliance Specialist will play a vital role in enhancing the IT risk management framework at Domtar Corporation. This position involves the management of IT exceptions and conducting thorough assessments of...


  • Montreal, Quebec, Canada Domtar Corporation Full time

    Cybersecurity Risk and Compliance Specialist In collaboration with the Manager of IT Compliance & Governance Security team, the Cybersecurity Risk and Compliance Specialist will play a vital role in enhancing the IT risk management framework at Domtar Corporation. This position involves the management of IT exceptions and conducting thorough assessments of...


  • Montreal, Quebec, Canada Produits forestiers Résolu Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Risk Management Specialist to join our team at Produits forestiers Résolu. As a key member of our IT Security Governance team, you will play a critical role in maintaining and improving our IT risk management framework, managing IT exceptions, and performing 3rd party vendor risk assessments.Key...


  • Montreal, Quebec, Canada Produits forestiers Résolu Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Risk Management Specialist to join our team at Produits forestiers Résolu. As a key member of our IT Security Governance team, you will play a critical role in maintaining and improving our IT risk management framework, managing IT exceptions, and performing 3rd party vendor risk assessments.Key...


  • Montreal, Quebec, Canada Domtar Full time

    Cybersecurity Risk and Compliance Specialist As a vital member of the IT Compliance & Governance Security team, the Cybersecurity Risk and Compliance Specialist will play a crucial role in enhancing the IT risk management practices at Domtar. This position involves the continuous improvement of the IT risk management framework, overseeing IT exceptions, and...


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    About the RoleThe Risk Management Department at SGS Société Générale de Surveillance SA is seeking a highly skilled Cybersecurity Risk Manager to join our team. As a key member of our Risk Management team, you will play a critical role in evaluating and managing cybersecurity risks across the organization.ResponsibilitiesDevelop and implement effective...


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    About the RoleThe Risk Management Department at SGS Société Générale de Surveillance SA is seeking a highly skilled Cybersecurity Risk Manager to join our team. As a key member of our Risk Management team, you will play a critical role in evaluating and managing cybersecurity risks across the organization.ResponsibilitiesDevelop and implement effective...


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    Key ResponsibilitiesThe Risk Management Division plays a crucial role in the sustainable development of SGS Société Générale de Surveillance SA by leveraging its expertise in risk evaluation and management strategies. The primary objective of this department is to independently analyze, assess, manage, and monitor risk-taking activities to achieve...


  • Montreal, Quebec, Canada SGS Société Générale de Surveillance SA Full time

    Key ResponsibilitiesThe Risk Management Division plays a crucial role in fostering the sustainable development of SGS Société Générale de Surveillance SA by leveraging its expertise in risk analysis and management methodologies. The primary mission of this division is to independently evaluate, monitor, and manage risk-taking activities to achieve...


  • Montreal, Quebec, Canada Domtar Corporation Full time

    Cybersecurity Risk Analyst Job DescriptionWe are seeking a highly skilled Cybersecurity Risk Analyst to join our team at Domtar Corporation. As a Cybersecurity Risk Analyst, you will play a critical role in maintaining and improving our IT risk management framework, managing IT exceptions, and performing 3rd party vendor risk assessments.Key...


  • Montreal, Quebec, Canada Domtar Corporation Full time

    Cybersecurity Risk Analyst Job DescriptionWe are seeking a highly skilled Cybersecurity Risk Analyst to join our team at Domtar Corporation. As a Cybersecurity Risk Analyst, you will play a critical role in maintaining and improving our IT risk management framework, managing IT exceptions, and performing 3rd party vendor risk assessments.Key...