Cyber Security Governance and Compliance Advisor
5 days ago
Help bring research to life and drive your career forward with the National Research Council of Canada (NRC), Canada's largest research and technology organization.
We are looking for a Cyber Security Governance and Compliance Advisor to support our Knowledge, Information and Technology Services. Focusing on Cyber Security Governance and Compliance, this individual will be responsible for supporting adherence to regulatory requirements and information security standards. They will ensure policies and processes are properly designed and controls are operating effectively to meet regulatory and security requirements.
**The key activities for this position are the following**:
- Provide cyber security technical assessments in support of NRC’s Security Assessment and Authorization (SA&A) process;
- Manage the Identity, Credential, and Access Management (ICAM) cyber security processes and understand the requirements of ICAM within a research and technology organisation (RTO);
- Perform regular reviews of access rights, security tool agent health, and system configurations throughout the NRC environment. Challenge privileged access and enforce hardening directives to ensure that least privilege principles and approved configuration baselines are followed;
- Ensure that cyber security is onboarded into NRC activities and projects by providing advisory services to the Enterprise Architecture group and NRC employees;
- Lead and coordinate CDT’s cyber incident readiness exercises in order to test NRC’s ability to respond to cyber incidents. Represent the Cyber Defence Team in tabletop exercises lead by the NRC Incident Command Team;
- Develop and maintain standard operating procedures (SOPs) in the project implementation of NRC’s Security Operation Center;
- Establish key performance indicators to evaluate the effectiveness of NRC’s cyber defence strategy and to ensure that the Cyber Defence Team’s objectives are being achieved;
- Ensure compliance with GoC and industry recognized frameworks in order to improve NRC’s cyber security posture by coordinating cyber security maturity self-assessments and participating in continuous improvement initiatives;
- Deliver cyber security awareness sessions and other specialised training to NRC employees as part of NRC’s Security Awareness, Training, and Education (SATE) program;
- Achieve and maintain industry standard security certification appropriate for the position.
**Screening Criteria**:
**Education**:
Bachelor degree in Computer Science, Computer Engineering, Information Technology or Information Systems.
**Equivalency**
A college degree in an IT related field combined with Significant experience (at least 5 years) in IT Security may be considered.
For information on certificates and diplomas issued abroad, please see Degree equivalency
**Experience**:
- Significant experience in the IM/IT field, specifically in roles related to cyber security within a Security Operations Center (SOC) or similar environment;
- Significant experience in writing various types of documentation such as reports, briefing notes, technical guides, and standard operating procedures;
- Significant experience working with cyber security related policies, directives, standards and guidelines used in the Government of Canada;
- Significant experience working with industry best practices related to system hardening, cyber security controls, and baseline configurations;
- Experience in delivering presentations, briefings, or training sessions in both official languages, to small and large audiences;
- General experience in implementing adequate technical and organizational safeguards to protect IT assets, information, and the continuity of IT services;
- Experience in managing projects will be considered an asset.
**Condition of Employment**:
Secret (II)
**Language Requirements**:
Bilingual Imperative BBB/BBB
Information on language requirements and self-assessment tests
**Assessment Criteria**:
**Technical Competencies**:
- Extensive knowledge of the general principles of Cyber Security operations;
- Broad knowledge of cyber security related policies, directives, standards and guidelines used in the Government of Canada;
- Broad knowledge of cyber security standards and frameworks from NIST, CSE, ISO, CIS, etc;
- Demonstrated ability to deliver presentations and write policy and technical documents;
- Strong knowledge of identity and access management technologies;
- General knowledge of activities and technologies relevant to cyber security, including endpoint security, patch management, incident management, change management, network monitoring, malware analysis, vulnerability assessments, data loss prevention technologies etc.;
- Strong knowledge of query and scripting tools such as Microsoft PowerShell and Kusto as well as reporting tools such as Power BI Report Builder will be considered an asset;
- Platform specific security certification (e.g. Microsoft, AWS) will
-
Ottawa, Canada KPMG Canada Full timeManager - Cyber Security Strategy & Governance Join to apply for the Manager - Cyber Security Strategy & Governance role at KPMG Canada Overview At KPMG, you’ll join a team of diverse and dedicated problem solvers connected by a common cause turning insight into opportunity for clients and communities around the world. Our Cyber Security Services team in...
-
Ottawa, Canada KPMG Canada Full timeManager - Cyber Security Strategy & Governance Join to apply for the Manager - Cyber Security Strategy & Governance role at KPMG Canada Overview At KPMG, you’ll join a team of diverse and dedicated problem solvers connected by a common cause turning insight into opportunity for clients and communities around the world. Our Cyber Security Services team in...
-
Strategic Cyber Security
1 week ago
Ottawa, Canada KPMG Canada Full timeA leading professional services firm in Ottawa is seeking a Manager for Cyber Security Strategy & Governance. The ideal candidate will manage multiple client projects, advise on cyber security governance, and develop tailored strategies. Essential qualifications include extensive experience in managing cyber risk and strong technical knowledge in security...
-
Strategic Cyber Security
1 week ago
Ottawa, Canada KPMG Canada Full timeA leading professional services firm in Ottawa is seeking a Manager for Cyber Security Strategy & Governance. The ideal candidate will manage multiple client projects, advise on cyber security governance, and develop tailored strategies. Essential qualifications include extensive experience in managing cyber risk and strong technical knowledge in security...
-
Montreal, Toronto, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Surrey, Victoria, London, Halton Hills, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada Tecsys Inc. Full timeSecurity Governance, Risk and Compliance SpecialistHaving recognized the advantages of remote work, such as improved employee morale, increased productivity, and positive impacts on both employee wellbeing and the environment, we are proud to be a digital-first company. Our digital-first work environment, combined with our conveniently located offices and...
-
Cyber Security Practitioners
1 week ago
Ottawa, Ontario, Canada Communications Security Establishment Canada | Centre de la sécurité des télécommunications Canada Full time $103,114 - $139,841 per yearSalary:$103,114 -$139,841 // $ $Closing Date: Classification :UNMA-07 to UNMA-09 // UNMA-07 à UNMA-09Reference number:RF-14660About CSEThe Communications Security Establishment (CSE) is Canada's agency responsible for foreign signals intelligence, cyber operations and cyber security. Learn more aboutour mission.CSE is committed to fostering a culture of...
-
Cyber Security Analyst
4 weeks ago
Ottawa, Canada PrecisionERP PrecisionIT Full timeOverview PrecisionERP/IT is recruiting for a local Secret cleared Cyber Security Analyst to support the tuning of Microsoft Sentinel (SIEM) and policy control enforcement for an initial 6+ month contract to start onsite with our federal government client in Ottawa, ON. Responsibilities Tune and maintain Microsoft Sentinel (SIEM) to support security incident...
-
Cyber Security Analyst
4 weeks ago
Ottawa, Canada PrecisionERP PrecisionIT Full timeOverview PrecisionERP/IT is recruiting for a local Secret cleared Cyber Security Analyst to support the tuning of Microsoft Sentinel (SIEM) and policy control enforcement for an initial 6+ month contract to start onsite with our federal government client in Ottawa, ON. Responsibilities Tune and maintain Microsoft Sentinel (SIEM) to support security incident...
-
Cyber Security Analyst
3 weeks ago
Ottawa, Canada PrecisionERP PrecisionIT Full timeOverview PrecisionERP/IT is recruiting for a local Secret cleared Cyber Security Analyst to support the tuning of Microsoft Sentinel (SIEM) and policy control enforcement for an initial 6+ month contract to start onsite with our federal government client in Ottawa, ON. Responsibilities Tune and maintain Microsoft Sentinel (SIEM) to support security incident...
-
Cyber Security Analyst
4 weeks ago
Ottawa, Canada Defence Construction Canada Full timeThe Cyber Security Analyst helps implement and provides operational support for DCC’s cyber strategy. The incumbent acts as a key resource on cyber security and contributes to the prevention of security incidents. The Cyber Security Analyst configures, implements and supports information technology (IT) security devices and applications. The incumbent...