Senior Specialist, IT Security Risk Management
4 days ago
Job Requisition ID: 11493 Sector: Technology and Business Transformation Position Status: Permanent Full Time Position Type: Hybrid Office Location: Montreal (QC); Ottawa (ON)Language Designation: English Essential Language Skill Levels (Read/Write/Speak): ZZZ Travel Requirement: Limited Security Requirement: Secret Salary Range: $101,639.30 to $127,049.13 About CMHCThe work you do and the work we do together matters. We come to work every day with a common purpose: to contribute to a well-functioning housing system. At CMHC, we hold ourselves accountable for our results and support our colleagues in their achievements. We thrive on collaboration, connecting across CMHC and involving the right people to get our work done. Our leadership style is guided by trust, where our leaders favour an adaptive approach based on the needs of their teams. Join us and be part of a team that's committed to making a real difference and be part of something meaningful. What’s in it for you We’ve got the purpose, the people and the perks you need for a fulfilling career. Here’s the comprehensive and generous benefits you get when you’re a permanent employee:Annual Paid vacation.Annual individual performance incentive.Defined benefit pension plan.Comprehensive group insurance plan to support your well-being from day one.Support towards your personal and professional growth with training, mentorship and more. An inclusive workplace culture and environment.About the role:The Senior Specialist, IT Security & Risk Management is responsible for developing, implementing, and maintaining security policies, controls, and risk management practices that safeguard the organization’s information systems. This role works closely with cross‑functional teams to assess threats, respond to incidents, ensure regulatory compliance, and enhance the overall cybersecurity maturity of the organization.What you will do:Security Governance & ComplianceDevelop and maintain IT security policies, standards, and procedures.Support compliance initiatives (e.g., ISO 27001, NIST, PCI‑DSS, SOC 2, privacy regulations).Conduct regular security audits and risk assessments.Prepare documentation for internal and external audits.Risk ManagementLead risk assessments to identify gaps in systems, processes, and technologies.Maintain the enterprise IT risk register and track remediation activities.Provide recommendations to reduce risks and strengthen controls.Security Operations & Incident ResponseMonitor security alerts, investigate incidents, and coordinate response activities.Work with IT teams to ensure timely patching, vulnerability remediation, and system hardening.Support endpoint, network, cloud, and identity security initiatives.Technology & Project SupportParticipate in the security review of new systems, applications, and vendor solutions.Assess third‑party security risks and support procurement due diligence.Provide expert guidance on secure architecture and security-by-design practices.Awareness & TrainingContribute to cybersecurity awareness programs and training activities.Provide guidance to employees on best practices for protecting information assets.What you should have:Bachelor’s degree in Information Security, Computer Science, or related field.5–8 years of experience in IT security, risk management, or related roles.Certifications such as CISSP, CISM, CRISC, or ISO 27001 Lead Implementer (an asset).Strong understanding of security frameworks (NIST CSF, ISO 27001), cloud security, and risk methodologies.Experience with SIEM, vulnerability management tools, EDR, IAM, and cloud environments (Azure).Excellent analytical, communication, and problem‑solving skills.Posting closing date: Note, the competition will remain active until filled.Our commitment to diversity, equity, and inclusion We’re committed to employment equity and encourage women, Indigenous Peoples, persons with disabilities, veterans and persons of all races, ethnicities, religions, abilities, sexual orientations, and gender identities and expressions to apply. We also welcome applications from non-Canadians who are eligible to work in Canada. CMHC is an inclusive workplace where diversity of thought – and of people – are recognized, valued, and considered essential to achieving our mission. Learn more about our commitment to diversity and inclusion What happens after you apply We know that applying for a new job can be both exciting and daunting, and we appreciate your effort. Learn more about our hiring process. If you are selected for an interview or testing, please advise us if you require an accommodation. If you applied before and you were not successful don’t worry – we're always posting new positions, so don’t hesitate to give it another shot. We’re excited to see what you bring to the table this time around
-
Montreal (administrative region), Canada Canada Mortgage and Housing Corporation Full timeSenior Specialist, IT Security Risk ManagementJob Requisition ID: 11493Sector:Technology and Business TransformationPosition Status:Permanent Full TimePosition Type:HybridLanguage Skill Levels (Read/Write/Speak):ZZZTravel Requirement:LimitedSecurity Requirement:SecretSalary Range:$101,639.30to $127,049.13About CMHCThe work you do and the work we do together...
-
Montreal, Quebec, Canada Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) Full timeJob Requisition ID:11493Sector:Technology and Business TransformationPosition Status:Permanent Full TimePosition Type:HybridOffice Location:Montreal (QC); Ottawa (ON)Language Designation:English EssentialLanguage Skill Levels (Read/Write/Speak):ZZZTravel Requirement:LimitedSecurity Requirement:SecretSalary Range:$101,639.30 to $127,049.13About CMHCThe work...
-
Montreal (administrative region), Canada CMHC Full timeOverviewJob Requisition ID: 11493Sector: Technology and Business TransformationPosition Status: Permanent Full TimePosition Type: HybridOffice Location: Montreal (QC); Ottawa (ON)Language Designation: English EssentialLanguage Skill Levels (Read/Write/Speak): ZZZTravel Requirement: LimitedSecurity Requirement: SecretSalary Range: $101,639.30 to...
-
Security Risk Management Specialist
4 weeks ago
Montreal, Canada Canonical Full timeOverview In security risk management we're looking to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security risk management team is the primary owner of the strategy and practices of how we identify, track and reduce our security risk across everything we do. To...
-
Montreal, Canada Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) Full timeSenior Manager, Information Security Governance and Risk Management Job Requisition ID: 11673 Position Status: Permanent Full Time Position Type: Hybrid Office Location: Montreal (QC); Ottawa (ON) Travel Requirement: Limited Language Designation: Bilingual Language Skill Levels (Read/Write/Speak): CBC Security Requirement: Secret Salary: $126,024.66 to...
-
Senior IT Security Risk Lead
2 days ago
Montreal (administrative region), Canada Canada Mortgage and Housing Corporation Full timeA national housing agency in Ottawa is seeking a Senior Specialist in IT Security Risk Management to develop and implement security policies while ensuring compliance with regulations. The ideal candidate will have a Bachelor's degree in Information Security or related fields and 5-8 years of experience. This position offers a hybrid work model and several...
-
Montreal, Quebec, Canada Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) Full timeJob Requisition ID:11673Position Status:Permanent Full TimePosition Type:HybridOffice Location:Montreal (QC); Ottawa (ON)Travel Requirement:LimitedLanguage Designation:BilingualLanguage Skill Levels (Read/Write/Speak):CBCSecurity Requirement:SecretSalary:Our salaries generally range from $ to $ and are based on qualifications and experience.About CMHCThe...
-
Montreal, Canada CMHC Full timeAbout CMHC The work you do and the work we do together matters. We come to work every day with a common purpose: to contribute to a well-functioning housing system. At CMHC, we hold ourselves accountable for our results and support our colleagues in their achievements. We thrive on collaboration, connecting across CMHC and involving the right people to get...
-
Montreal, Canada Tecsys Inc. Full timeSecurity Governance, Risk and Compliance SpecialistHaving recognized the advantages of remote work, such as improved employee morale, increased productivity, and positive impacts on both employee wellbeing and the environment, we are proud to be a digital-first company. Our digital-first work environment, combined with our conveniently located offices and...
-
Senior Manager, InfoSec Governance
4 weeks ago
Montreal, Canada CMHC Full timeA federal housing agency in Montreal is seeking a Senior Manager in Information Security Governance and Risk Management. In this pivotal role, you will lead a team of specialists and provide critical insights to production processes, working closely with leadership to drive risk analysis and remediation strategies. The ideal candidate has extensive...