Senior Cyber Security Governance Specialist

6 days ago


Toronto, Ontario, Canada Canadian Tire Corporation Full time

About the Role

The Senior Information Security Specialist, Governance and Compliance will lead the charge in maintaining cyber security policies and standards, responding to regulator and auditor inquiries, and providing an advisory function to the business surrounding cyber security governance.

Key Responsibilities

  • Provide senior level advisory services to cybersecurity, technology teams, and business team members, as required
  • Maintain cyber security policies and standards
  • Respond to external inquires regarding cyber security (e.g. ESG, regulators, etc.)
  • Analyze and assess cyber security related business scenarios and prepares/presents position papers providing risk-based recommendations to assist the leadership team in making informed decisions
  • Oversee and provide guidance on the cyber security configuration compliance management program for both on prem and cloud environments
  • Oversee and provide guidance on the cyber security vulnerability, configuration & patch remediation management programs
  • Oversee and provide guidance on the Cloud security compliance management program
  • Design and perform annual reviews of configuration benchmarks for teams to follow for new and existing systems
  • Manage the cyber security policy exemption management processes by assessing policy exception requests, maintaining the exception workflows, and updating and keeping current the exception database
  • Keep current with ongoing trends and changes within the cyber security community

Requirements

  • University degree preferably in an IT related discipline
  • CISSP, and/or CISM, and/or CISA, and/or CRISC designations would be an asset
  • 8-10+ years experience in information security, and/or IT Audit/Compliance, and/or external audit
  • Strong understanding of IT, cloud and cyber security concepts and best practices
  • Understands cyber security risks and control frameworks including NIST CSF, CIS, COBIT 5, and ISO 270001
  • Experience with security assessment tools such as Tripwire, Nexpose, MS Defender, McAfee EPO, Kenna, etc.
  • Understanding of Agile concepts and practices
  • Ability to communicate and influence effectively at all levels from technical staff to company leadership team
  • Proven ability to weigh business needs with information security priorities and make sound risk-based judgement calls
  • Experienced with analyzing and assessing cyber security related business scenarios, performing risk assessments, and preparing position papers outlining sound, risk-based recommendations
  • Experienced with analyzing and assessing cyber security policy exception requests and providing risk-based recommendations
  • Experience overseeing cyber security configuration compliance programs
  • Experience overseeing cyber security vulnerability & patch management programs
  • Experience overseeing Cloud security compliance management programs
  • Experience with developing security baselines based on industry accepted CIS benchmark, MS Azure security benchmark, PCI DSS benchmark, etc and conduct regular reviews to update existing custom baselines
  • Experience with Microsoft Azure Portal/Security Center to monitor and manage vulnerabilities, security policy compliance and all outstanding Microsoft recommendations
  • Familiar with KQL (Kusto query language) to develop scripts to query Microsoft Azure policy database to report compliance status
  • Technical knowledge including Linux, Windows, AIX, databases, network and security appliances and firewalls/IDS/IPS, web and cloud-based applications, secure coding practices, and cloud security
  • Highly proficient with MS Office suite of products

Work Arrangement

We value flexibility. We have adopted a hybrid work model whereby employees use a combination of working in office and virtually in service of outcomes. Each leader is empowered to decide what work is best achieved in person based on the unique needs of their team.



  • Toronto, Ontario, Canada KPMG Canada Full time

    Cyber Security Strategy & Governance RoleWe are seeking a highly skilled Cyber Security Strategy & Governance Specialist to join our team at KPMG Canada. As a key member of our Cybersecurity Services team, you will be responsible for developing and implementing effective cybersecurity strategies and governance frameworks for our clients.Key...


  • Toronto, Ontario, Canada Maarut Inc Full time

    Maarut Inc is seeking a highly skilled Senior Technology Architect to join our team. The ideal candidate will have extensive knowledge and experience with cyber security frameworks and controls to reduce the impact of evolving cyber threats in the education sector. The Senior Technology Architect will be responsible for contributing to a tailored cyber...


  • Toronto, Ontario, Canada Maarut Inc Full time

    Maarut Inc is seeking a highly skilled Senior Technology Architect to join our team. The ideal candidate will have extensive knowledge and experience with cyber security frameworks and controls to reduce the impact of evolving cyber threats in the education sector. The Senior Technology Architect will be responsible for contributing to a tailored cyber...


  • Toronto, Ontario, Canada Foilcon Full time

    Job Title: Cyber Security SpecialistFoiling the Future of Cyber ThreatsAbout the RoleWe are seeking a highly skilled Cyber Security Specialist to join our team at Foilcon. As a key member of our security team, you will play a critical role in strengthening Ontario's cybersecurity infrastructure and protecting our digital assets.Key ResponsibilitiesDesign and...


  • Toronto, Ontario, Canada Foilcon Full time

    Job Title: Cyber Security SpecialistFoiling the Future of Cyber ThreatsAbout the RoleWe are seeking a highly skilled Cyber Security Specialist to join our team at Foilcon. As a key member of our security team, you will play a critical role in strengthening Ontario's cybersecurity infrastructure and protecting our digital assets.Key ResponsibilitiesDesign and...


  • Toronto, Ontario, Canada Foilcon Full time

    Job Title: Cyber Security SpecialistFoiling the Future of Cyber ThreatsAbout the RoleWe are seeking a highly skilled Cyber Security Specialist to join our team at Foilcon. As a key member of our security team, you will play a critical role in strengthening Ontario's cybersecurity infrastructure and protecting our digital assets.Key ResponsibilitiesDesign and...


  • Toronto, Ontario, Canada Foilcon Full time

    Job Title: Cyber Security SpecialistFoiling the Future of Cyber ThreatsAbout the RoleWe are seeking a highly skilled Cyber Security Specialist to join our team at Foilcon. As a key member of our security team, you will play a critical role in strengthening Ontario's cybersecurity infrastructure and protecting our digital assets.Key ResponsibilitiesDesign and...


  • Toronto, Ontario, Canada Hydro One Networks Inc Full time

    Cyber Security Role at Hydro One Networks IncHydro One Networks Inc is seeking a highly skilled Cyber Security professional to join our team. As a Cyber Security Specialist, you will play a key role in protecting our company's assets and ensuring the confidentiality, integrity, and availability of our data.Key Responsibilities:Translate technical cyber &...


  • Toronto, Ontario, Canada Hydro One Networks Inc Full time

    Cyber Security Role at Hydro One Networks IncHydro One Networks Inc is seeking a highly skilled Cyber Security professional to join our team. As a Cyber Security Specialist, you will play a key role in protecting our company's assets and ensuring the confidentiality, integrity, and availability of our data.Key Responsibilities:Translate technical cyber &...


  • Toronto, Ontario, Canada Maarut Inc Full time

    Job DescriptionThe Senior Cyber Security Architect role requires extensive knowledge and experience with cyber security frameworks and controls to reduce the impact of evolving cyber threats in the education sector, preferably the Ontario K12 school board environment. Knowledge and experience with online privacy and cyber safety as it applies to minors and...


  • Toronto, Ontario, Canada Maarut Inc Full time

    Job Title: Senior Cyber Security ArchitectMaarut Inc is seeking a highly skilled Senior Cyber Security Architect to join our team. As a key member of our security team, you will be responsible for designing and implementing robust cyber security frameworks to protect our organization's assets.Key Responsibilities:Develop and implement cyber security...


  • Toronto, Ontario, Canada Maarut Inc Full time

    Job Title: Senior Cyber Security ArchitectMaarut Inc is seeking a highly skilled Senior Cyber Security Architect to join our team. As a key member of our security team, you will be responsible for designing and implementing robust cyber security frameworks to protect our organization's assets.Key Responsibilities:Develop and implement cyber security...


  • Toronto, Ontario, Canada Maarut Inc Full time

    Job DescriptionAbout the RoleWe are seeking a highly skilled Senior Cyber Security Architect to join our team at Maarut Inc. As a key member of our security team, you will be responsible for designing and implementing robust cyber security frameworks to protect our organization's assets.Key ResponsibilitiesDevelop and implement tailored cyber security...


  • Toronto, Ontario, Canada Maarut Inc Full time

    Job DescriptionJob Title: Senior Cyber Security SpecialistJob Summary:We are seeking a highly skilled Senior Cyber Security Specialist to join our team at Maarut Inc. The successful candidate will be responsible for providing security design expertise and advice to internal stakeholders on design principles and best practices, as well as the development and...


  • Toronto, Ontario, Canada Maarut Inc Full time

    Job DescriptionJob Title: Senior Cyber Security SpecialistJob Summary:We are seeking a highly skilled Senior Cyber Security Specialist to join our team at Maarut Inc. The successful candidate will be responsible for providing security design expertise and advice to internal stakeholders on design principles and best practices, as well as the development and...


  • Toronto, Ontario, Canada Maarut Inc Full time

    Job Title: Senior Cyber Security ArchitectWe are seeking a highly skilled Senior Cyber Security Architect to join our team at Maarut Inc. As a key member of our security team, you will be responsible for designing and implementing robust cyber security frameworks to protect our organization's assets.Key Responsibilities:Develop and implement cyber security...


  • Toronto, Ontario, Canada Maarut Inc Full time

    Job Title: Senior Cyber Security ArchitectWe are seeking a highly skilled Senior Cyber Security Architect to join our team at Maarut Inc. As a key member of our security team, you will be responsible for designing and implementing robust cyber security frameworks to protect our organization's assets.Key Responsibilities:Develop and implement cyber security...


  • Toronto, Ontario, Canada Randstad Canada Full time

    Job Title: Cyber Security SpecialistAbout the Role:We are seeking a highly skilled Cyber Security Specialist to join our team at Randstad Canada. As a Cyber Security Specialist, you will be responsible for providing leadership and technical direction in the area of technology and cyber risk.Key Responsibilities: Initiate and provide leadership,...


  • Toronto, Ontario, Canada Maarut Inc Full time

    Job DescriptionRole SummaryMaarut Inc is seeking a highly skilled Senior Cyber Security Architect to join our team. The successful candidate will be responsible for developing and implementing cyber security frameworks and controls to reduce the impact of evolving cyber threats in the education sector.Key ResponsibilitiesContribute to the development of a...


  • Toronto, Ontario, Canada Maarut Inc Full time

    Job Title: Senior Cyber Security ArchitectWe are seeking a highly skilled Senior Cyber Security Architect to join our team at Maarut Inc. As a key member of our security team, you will be responsible for designing and implementing robust cyber security frameworks to protect our organization's assets.Key Responsibilities:Develop and implement cyber security...