Infosec Specialist, Grc
2 weeks ago
We are banking at another level.
Choosing BDC as your employer means working in a healthy, inclusive, and skilled workplace that puts forward the best conditions to bring together unique teams where employees are empowered to act. It also means being at the centre of ambitious economic and financial projects to see further and to do things differently, to fuel the success of Canadian entrepreneurs.
Choosing BDC as your employer also means:
- Flexible and competitive benefits, including an Employee Savings and Investment Plan where BDC matches part of your voluntary contributions, a Defined Benefit Pension Plan, a $750 wellness and health care spending account, to name a few- In addition to paid vacation each year, five personal days, sick days as necessary, and our offices are closed from December 25 to January 1- A hybrid work model that truly balances work and personal life- Opportunities for learning, training and development, and much more...
POSITION OVERVIEW
The Cybersecurity Governance, Risk, and Culture department is seeking a talented individual to play a crucial role within the team, aligning these functions with BDC’s business objectives. The InfoSec Specialist will work collaboratively with InfoSec squads, IT teams, and other lines of defense to ensure robust risk management and strategic decision-making. This position encompasses more than traditional GRC activities, including performance measurement, strategic planning, and security reporting. The specialist will be part of a transformation towards an agile mindset, where squads are empowered to make key decisions within their scope, including how they work, which tools to use, and how to achieve their objectives.
KEY ACTIVITIES
You will be assigned to one of our squads and have the following responsibilities:
Governance, Risk, and Compliance- Develop and maintain governance documents (policies, directives, procedures, standards).- Establish and uphold our risk and controls framework.- Monitor compliance with legal, regulatory, and industry standards.- Perform and support control assessment activities (effectiveness, maturity).- Deliver comprehensive risk assessments/reviews, including identifying and documenting risks and controls.- Support internal and external audits and ensure audit readiness.- Track action plans.- Assess third-party security and perform ongoing monitoring activities.
Performance Measurement & Reporting- Define and track key performance indicators (KPIs) of our controls and key risk indicators.- Analyze trends and performance data to identify areas for improvement.- Prepare and deliver regular reports and dashboards for senior leadership.
Strategy & Strategic Planning- Contribute to the development of the InfoSec strategy and strategic plan.- Track the progress of the InfoSec strategic plan.- Identify emerging threats, risks, and opportunities to evolve our framework.- Support InfoSec transformation initiatives to align with new corporate and IT orientations.
CHALLENGES TO BE MET-
- Perform in-depth analyses of our risks and controls, synthesize data and observations, and effectively communicate conclusions.- Gain buy-in and cooperation from stakeholders across departments with differing priorities and foster a culture of accountability over risks and controls.- Enable our governance capability through data-driven performance measurement to assess the effectiveness, efficiency, and experience of InfoSec controls.- Produce clear and structured documentation that supports transparency and traceability.- Stay ahead of new threats and adjust frameworks accordingly.-
- Demonstrate leadership skills, work independently and thrive in a dynamic, deadline-focused environment.- Demonstrate excellent verbal and written communication skills in both official languages
WHAT WE ARE LOOKING FOR:- Development of governance documents- Management of risk and control frameworks- Risk assessment, including third-party risk assessment- IT audits and control assessments- Development of performance indicators and delivery of executive reports- Development of InfoSec strategy- Excellent knowledge of risk management and internal control frameworks such as ISO 27001, NIST, COBIT, OSFI.- Excellent knowledge and experience with Microsoft products and platforms (especially Excel, PowerPoint, PowerBi, SharePoint)- B.A./B.S in Computer Science, Information Security, Engineering, or equivalent discipline or CPA.- Relevant IT audit certifications are a plus, such as:
- Certified in Risk and Information Systems Control (CRISC)- Certified Information Systems Auditor (CISA)- Certified Information Security Manager (CISM)- ISO 27001 Lead Implementer or Auditor
INDHP
.
-
Spécialiste Infosec Grc
2 weeks ago
Montréal, Canada Business Development Bank of Canada Full timeViens faire banque à part. Choisir BDC comme employeur, c’est évoluer dans un milieu de travail sain, inclusif, riche de compétences et qui met de l'avant les meilleures conditions pour rassembler des équipes uniques où le pouvoir d'agir est réel. C’est aussi être au centre de projets économiques et financiers ambitieux afin de voir plus loin et...
-
Lead Specialist, Security Grc
2 weeks ago
Montréal, Canada Cogeco Communications Inc. Full timeOur culture lifts you up—there is no ego in the way. Our common purpose? We all want to win for our customers. We aim to always be evolving, dynamic, and ambitious. We believe in the power of genuine connections. Each employee is a part of what makes us unique on the market: agile and dedicated. Time Type: Regular Job Description: Lead Specialist,...
-
Infosec Specialist
2 weeks ago
Montréal, Canada Business Development Bank of Canada Full timeNo other bank is doing what we do. At BDC, we help Canada and its entrepreneurs create a prosperous, inclusive and green economy. Our mission is to help Canadian businesses thrive by providing financing, capital and advisory services. We’re devoted to Canadian entrepreneurs. We’re also dedicated to our employees. Adaptable. Inspiring. Different....
-
Testing Specialist
4 weeks ago
Montréal, QC, Canada Avanciers Inc. Full timeAvanciers is a premier IT Staffing/Consulting organization and we are currently recruiting for a long term contract role for one of our premier client in Canada for IT Control Testing Specialist This is based in Montreal, QC, Canada (Hybrid) role and client is actively hiring for this position. Fluency in both spoken and written French is mandatory. Job...
-
Testing Specialist
4 weeks ago
Montréal, QC, Canada Avanciers Inc. Full timeAvanciers is a premier IT Staffing/Consulting organization and we are currently recruiting for a long term contract role for one of our premier client in Canada for IT Control Testing Specialist This is based in Montreal, QC, Canada (Hybrid) role and client is actively hiring for this position. Fluency in both spoken and written French is mandatory. Job...
-
Application Security Specialist
3 days ago
Montréal, Canada Workleap Full timeCompany Description Workleap is an ecosystem of powerfully simple employee and digital experience software that helps modern workplaces have a greater impact— fast. Built for today’s leaders and their teams, Workleap products aim to make work really work by fostering engagement, performance, growth, and productivity within organizations. **Job...
-
Security Specialist
2 weeks ago
Montréal, Canada Ubisoft Full time**Company Description** Ubisoft’s 19,000 team members, working across more than 30 countries around the world, are bound by a common mission to enrich players’ lives with original and memorable gaming experiences. Their commitment and talent have brought to life many acclaimed franchises such as Assassin’s Creed, Far Cry, Watch Dogs, Just Dance,...
-
Enterprise Resource Planning Specialist
2 weeks ago
Montréal, Canada NTT DATA Full time**Job Description**: Job Description: SAP Security Roles - Create/Build/Maintain (Everyday activity depends on requests/tickets) Security Audit and remediations (quarterly) SAP GRC config and upgrade ( once a year for few activities and some are once in 2 years depends on new version) CPGRC License upgrade yearly Implementation of Security authorizations for...
-
Privacyops Specialist
7 days ago
Montréal, Canada Potloc Full timeEnglish version below_ **A PROPOS DE POTLOC Nous sommes des experts dans la collecte et la centralisation d'informations précieuses qui permettent à nos clients de mieux comprendre leurs défis et de les relever avec succès. Comment? En ciblant des répondants à nos sondages sur les réseaux sociaux grâce à une géolocalisation avancée et à un...
-
Incident Manager
4 days ago
Montréal, Canada GSOFT Full timeCompany Description We’re GSoft, home to a family of software products that lay the groundwork for a better employee experience. Our goal is to make work simpler, kinder, and faster. Specifically, we help companies get the most out of Microsoft 365 with ShareGate. We help managers grow their teams with Officevibe. And we ensure every onboarding is a...