Security Advisor, Risk and Audit
5 days ago
Company Description
Our specialty is to optimize And we are proud of our expertise. We use our collective intelligence to impact people's lives by improving the efficiency of urban mobility.
Our innovative software solutions and expert services in the areas of public transit and postal operations are recognized around the world.
**Job Description**:
Reporting directly to the Director of Security (CSO), your duties are as follows:
- Carry out security threat and risk assessments (STRA) for the IT, software development, project management, and corporate services teams
- Update the security risk register and follow up on mitigation measures
- Participate in defining the security internal control framework
- Keep track of internal security audits for the SOC 2 and ISO 27001 certifications
- Contribute to writing procedures, manuals, and other security documentation
- Assist the Director of Security (CSO) in supporting the teams for implementing security controls
- Collaborate closely with the operational security team to ensure that security requirements are met
- Support the legal services team by validating security requirements in service proposals
**Qualifications**:
- University degree or relevant technical certification
- CISA, CRISC, CISSP, or equivalent certification
- More than 5 years of experience as an expert in security risk analysis and compliance
- Experience in the software-development industry, an asset
- Very good knowledge of security standards such as the ISO 27001 series, SOC 2 and CSA STAR
- Good knowledge of recognized methodologies for assessing risks and threats
- Good knowledge of GRC tools (Archer, ServiceNow, or others)
- Skills for analysis and problem solving
- Sense of initiative and autonomy
- Interest in collaboration and teamwork
- Be thorough, curious and listening to the organization’s needs
- Ability to write documentation in both French and English
Additional Information
At GIRO, you will be integrated quicky and called upon to make a concrete contribution The well-being and satisfaction of our employees is a value that we hold dear. Therefore, we offer a range of benefits, including:
- Flexible work schedule, including telecommuting
- A warm welcome and a progressive learning program
- Many recognition and team-building activities, including team breakfast, yoga or aerobic classes, Christmas party, sports activities, etc.
- A GIRO Day, where employees are encouraged to take part in outdoor activities
- A basic group insurance plan with premiums paid 100% by GIRO
- A health and physical-activity account of $600.00 per year
- Reimbursement of OPUS card or parking space
- Paid days off between Christmas and New Year’s Day.
Looking forward to meeting you
-
IT Audit Consultant, Risk
1 day ago
Montréal, Canada Richter Full time**Richter Office: Montreal** Richter is a Business | Family Office that provides strategic advice on business matters and on families’ financial and personal objectives across generations. With close to 100 years of experience advising at the intersection of family and business, Richter has developed an integrated approach to help business owners find...
-
Junior Advisor
1 week ago
Montréal, Canada Richter Full timeRichter, one of the largest independent accounting and consulting firms in Canada, is recognized as a Top Employer in Montréal and is always looking for top talent. Our firm, located in Montréal, Toronto and Chicago, distinguishes itself from all other accounting firms because of the commitment and cooperation of our employees, who are the key to our...
-
IT Audit Consultant, Risk
2 weeks ago
Montréal, Canada Richter Full time**Richter Office: Montreal** Richter is a Business | Family Office that provides strategic advice on business matters and on families’ financial and personal objectives across generations. With close to 100 years of experience advising at the intersection of family and business, Richter has developed an integrated approach to help business owners find...
-
Information Security Advisor
1 day ago
Montréal, Canada Equisoft Full time**Information security advisor** Equisoft, a leading global provider of digital business solutions for the insurance and wealth industries, is actively seeking new talent! If you are willing to play a strategic role that has a real impact on the organization's ongoing growth and you're looking to evolve within a dynamic international context, please send...
-
Chief Advisor Governance Audit
1 week ago
Montréal, Canada National Bank of Canada Full timeA career as a **Chief Advisor Internal Audit, Non-Financial Risks** in the Internal Audit team at National Bank, you will contribute to the team's audit mandates and advisory mandates while developing the knowledge of your colleagues in your area of expertise. As a specialized advisor in non-financial risks, you will be expected to lead and/or significantly...
-
Chief Advisor Internal Audit
7 days ago
Montréal, Canada National Bank of Canada Full timeA career as a Chief Advisor in the Internal Audit - Personal Banking, Client Experience and Compliance team means leading and/or contributing to audit or advisory mandates that are cross-functional in scope and involve multiple sectors. You will be required to train and coach your colleagues by sharing your knowledge in your field of expertise and to support...
-
Conseiller Adjoint, Audit Des Ti
2 weeks ago
Montréal, Canada Richter Full time**A day in the life of a Junior Advisor**: With experience Information technology security, in addition to audit and risk management, you will participate in the delivery of IT consulting and/or IT internal audit mandates. As a consultant with a focus on delivering mandates, you will mostly advise clients in Montreal, with some travel outside of the...
-
IT Security Risk Analyst
5 days ago
Montréal, Canada WSP Full timeWSP’s Information Security Office (ISO) is responsible for the deployment and maintenance of the information security framework for both the IT organization and wider business community. This includes the Governance mechanisms, policies and processes, tools and technologies, and employee training required to protect WSP information and that of our...
-
Security Advisor
2 weeks ago
Montréal, Canada Desjardins Full timeAs a security advisor, you help develop and optimize security measures to align with corporate objectives by planning, implementing and overseeing best practices to strengthen Desjardins's security posture. You help develop the Desjardins Group Security Office's priorities and governance, and work on different aspects of our security practices. You're...
-
Manager, Technology Risk Services
8 hours ago
Montréal, QC, Canada KPMG Canada Full timeOverview At KPMG, you'll join a team of diverse and dedicated problem solvers, connected by a common cause: turning insight into opportunity for clients and communities around the world. Our Technology Risk Services team is growing. We are looking for a Manager/Senior Manager to join our dynamic team in Montreal. Our IT audit service lines include: Assisting...