Information Security Governance Specialist
2 weeks ago
**OPTEL. Responsible. Agile. Innovative.**
OPTEL is a global company that develops transformative software, middleware and hardware solutions to secure and ensure supply chain compliance in major industry sectors such as pharmaceuticals and food, with the goal of reducing the effects of climate change and enabling sustainable living. If you are guided, as we are, by socio-eco-environmental values and want to participate in solving the biggest challenges facing our world today, here is how you can help:
**SUMMARY**
The primary mandate of the Information Security Governance Specialist is to define, design and maintain the governance, risk evolution and security architecture.
**RESPONSIBILITIES**
The primary responsibilities of the Information Security Governance Specialist are to:
- Implement internal guidance derived from internal policies and best practices;
- Ensure compliance with standards such as SOC2 and ISO-27001 with internal teams;
- Produce activity reports and recommend orientations and action plans in information security to the Director;
- Ensure the integration of provisions guaranteeing the respect of information security and legal requirements in our service and contract agreements;
- Advise and support management, analyze and evaluate the scope of decisions and orientations to achieve objectives aimed at minimizing security risks while improving OPTEL's information security maturity level and performance;
- Assist asset owners in the categorization of information assets under their responsibility and in conducting risk analyses;
- Develop and implement the information security training and awareness plan.
- Notify the CIO's office of any changes that may affect the Information Security Authority Registry;
- Document the security architecture of the solutions and that of OPTEL as a whole.
- Ensure the coordination and execution of information security projects.
**TASKS**
- Design, produce and validate deliverables to manage information security risks. In this capacity, he/she produces risk analyses, risk assessments, security advisories and treatment plans.
- Design and update the security architecture in collaboration with other architects;
- Carry out a roadmap to improve our level of maturity, particularly in the area of identity and access management.
- Produce management indicators for risk management and security architecture;
- Propose action plans and monitor their progress;
- Ensure that actions support the organization's information security risk management strategies and objectives in compliance with legal obligations and standards or regulations applicable to the organization.
- Collaborate in the design and evaluation of policies, processes and standards forming the information security governance framework.
- Produce communications, training and facilitate workshops in his/her field of expertise.
- Assist information security stakeholders in the exercise of their responsibilities, particularly with respect to risk management, information categorization, recovery plans and the implementation of security measures.
- Advise on risk management strategy;
- Participate in opportunity studies or other activities of the organization;
- Perform any other related duties.
**SKILLS AND QUALIFICATIONS REQUIRED**
- Undergraduate degree in an appropriate technology discipline;
- Five (5) years of relevant experience in information technology
- Bilingualism French/English
- Knowledge of information security and information technology standards (ISO-270XX, NIST800-53, CIS, ITIL);
- Knowledge of a risk analysis method (Mehari, Octave, Ebios, ISO-27005, NIST 800-30, etc)
- Knowledge of the regulatory framework surrounding the protection of personal information and investigations in Canada and Europe:
- Private Sector Privacy Act;
- General Data Protection Regulation (GDPR);
- Experience with Microsoft Azure and/or Google Cloud Platform;
- Technical knowledge related to network infrastructures;
**Assets**
- Experience working with Agile methodologies (Scrum, Kanban);
- Experience with SOC2 certification;
- Certifications or recognition that are an asset:
- Certified Information System Auditor (CISA);
- Certified Information Security Manager (CISM);
- Certified Information Systems Security Professional (CISSP);
- Certified in Risk and in Information Systems Control (CRISC);
- ISO 27001 Lead Implementer;
- ISO / IEC 27001 Lead Auditor;
- Any other relevant professional certification in information security or networking.
- Knowledge and experience with a risk management and compliance (GRC) tool.
**BENEFITS AND ADVANTAGES**
- Competitive compensation
- Flex hours
- Ability to work on site or remotely
- On-site presence once every two weeks or as needed
- Virtual health clinic and employee assistance program
- Group and dental insurance from day one
- Group RRSP and TFSA with employer contribution from day one
- On-site amenities (free parking and power stations, free coffee and fruit)
- 50%
-
Information Security Analyst Cybersecurity
2 weeks ago
Quebec City, Canada Simons Full timeJob description **Information Security Analyst — Cybersecurity**: **IT**: **Québec**: **Simons Campus - IT**: - Full timeThe Information Security Analyst will act as a cybersecurity technical expert and implement practices to ensure information security and sound IT governance. The analyst will advise department leaders in order to protect the personal...
-
Application Security Specialist
2 weeks ago
Quebec City, Canada EXFO Full timeApplication Security Specialist **Main locations**:Quebec, Quebec, CA - Ville Saint-Laurent, Quebec, CA**Job Type**:Full-time**Workplace type**:Hybrid**Offer number**:3432EXFO develops smarter test, monitoring and analytics solutions for the global communications industry. We are trusted advisers to fixed and mobile network operators, hyperscalers and...
-
Lead Advisor
2 weeks ago
Quebec City, Canada InnovMetric Software Inc. Full timeOverview: Join a growing company where your expertise in governance, compliance, and risk management will help elevate operational excellence and support continued growth. As our company navigates ongoing evolution and growing contractual and regulatory demands, we are seeking a lead advisor to structure and drive initiatives related to data governance,...
-
Cyber Security Specialist
3 weeks ago
Quebec, Canada NDT Global Full timeNDT Global is the leading provider of inline diagnostic solutions, advanced data insights, and integrity management services that safeguard energy-sector infrastructure. The company is recognized for its expertise in both ultrasonic inspection technologies — such as Pulse Echo, Pitch-and-Catch, Phased Array, and Acoustic Resonance (ART Scan) — and...
-
Cyber Security Specialist
6 days ago
Quebec, Canada NDT Global Full timeNDT Global is the leading provider of inline diagnostic solutions, advanced data insights, and integrity management services that safeguard energy-sector infrastructure. The company is recognized for its expertise in both ultrasonic inspection technologies — such as Pulse Echo, Pitch-and-Catch, Phased Array, and Acoustic Resonance (ART Scan) — and...
-
Cyber Security Specialist
3 weeks ago
Quebec, Canada NDT Global GmbH & Co. Full timeJob Description About NDT Global NDT Global is the leading provider of inline diagnostic solutions, advanced data insights, and integrity management services that safeguard energy-sector infrastructure. The company is recognized for its expertise in both ultrasonic inspection technologies — such as Pulse Echo, Pitch-and-Catch, Phased Array, and Acoustic...
-
Cyber Security Specialist
3 weeks ago
Greater Quebec City Metropolitan Area, Canada NDT Global Full timeAbout NDT Global NDT Global is the leading provider of inline diagnostic solutions, advanced data insights, and integrity management services that safeguard energy-sector infrastructure. The company is recognized for its expertise in both ultrasonic inspection technologies — such as Pulse Echo, Pitch-and-Catch, Phased Array, and Acoustic Resonance (ART...
-
Cyber Security Specialist
3 weeks ago
Quebec (QC), Canada NDT Global Full timeAbout NDT GlobalNDT Global is the leading provider of inline diagnostic solutions, advanced data insights, and integrity management services that safeguard energy-sector infrastructure. The company is recognized for its expertise in both ultrasonic inspection technologies - such as Pulse Echo, Pitch-and-Catch, Phased Array, and Acoustic Resonance (ART Scan)...
-
Quebec, Canada Windmill Microlending Full timeSend some details about yourself, including your interest in working at Windmill, relevant experience, and your resume toGovernment Relations and Funding Agreements SpecialistAbout Windmill MicrolendingWindmill Microlending enables immigrants and refugees to build careers in Canada while reducing poverty and labour shortages. We do this by offering...
-
Security Guard
1 day ago
White City, Canada Paladin Security Full timeSecurity Guard Paladin Security offers top industry wages, free training in the fundamentals of security, First Aid/CPR and Non-Violent Crisis Intervention, a recognition and rewards program, excellent promotional opportunities, supplied uniforms, flexible hours and a comprehensive benefit package. Duties Include: - Foot patrol of buildings both interior...