Information Security Officer

3 days ago


Montreal administrative region, Canada SGS Société Générale de Surveillance SA Full time

Responsibilities The Vulnerability Management Lead is responsible for the AMER region’s vulnerability management and configuration management program. The position requires excellent communication skills (written and verbal) and a strong ability to influence others. The ideal candidate will be able to demonstrate practical and in-depth knowledge of running an effective vulnerability & / or configuration management program including dynamically responding to emerging threats in the financial services industry. The role also calls for strong technical analysis and process improvement skills and the ability to present to senior management on the state of, and proposals to improve, the program. Working knowledge of cybersecurity and risk assessment frameworks (e.g., NIST) and regulations applicable to the financial services industry (e.g., NYDFS 500, FINRA, SEC) is preferred. The Vulnerability Management Lead is a member of the Cyber Threat Defense (CTD) team within the AMER Data and Cyber Security (ISR) department and reports to the Director of CTD. This position requires strong collaboration across GBSU and GTS departments in the Americas and globally with SG CERT, ISR and GTS teams. ESSENTIAL JOB FUNCTIONS Vulnerability & Configuration Management Lead the AMER vulnerability & configuration management programs – Act as the main point of contact and expert in Vulnerability Management and configuration management; including overseeing the risk of zero-day vulnerabilities, oversee patching/remediation and risk acceptance of vulnerabilities where appropriate. Oversee the discovery, evaluation, and implementation of vulnerability scanning, patch and configuration review, penetration testing. Present operating and steering committees for projects to senior management on a quarterly basis. Develop and oversee annual roadmaps of initiatives to align with overall InfoSec and business objectives/strategy. Develop and manage detailed vulnerability reviews and assessments, and patching and configuration reviews: (1) Assess potential damage of security flaws and assist in the implementation of corrective actions; (2) Identify, document, and report security issues and concerns to management; and (3) Monitor corrective actions and recommending cost-effective preventive measures to preclude recurrences. Review and sign-off on all recommendations on possible improvements resulting from the work performed as part of projects. Draft and publish communications for management as new threats emerge. Improve the reporting framework that will provide regular metrics and statistics about our business and IT environment; analyze trends in security events, activities, etc. to better understand risks, insufficiencies in our solutions, staffing shortages, etc.; report security metrics and statistics to the CISO and other key stakeholders such as the COO, CIO, and CTO. Profile required LANGUAGE Ability to communicate in English, both orally and in writing, is a requirement as the person in this position will need to collaborate regularly with colleagues and partners in the United States. OUR BENEFITS Competitive compensation & benefits offering, including but not limited to: Minimum of 20 Vacation days+ 4personal days Supportive Maternity, paternity, parental and adoption leave policy Health spending($2,000/year) andpersonal spending($1,000/year)accountswith 75+ eligible reimbursement categories (health, training, electronics etc.) Fully sponsored virtualhealthcare assistanceandEmployee Assistance Programto you and your immediate family Various Employee Resource Groups(ERG) to engage withsuch as Pride and Allies, American Women Network, Black Leadership Network, One planet, etc. Aculture of continuous developmentby encouraging our employees varioustraining programs(online training and coaching platform such as Coursera, GoFluent, Pluralsight, First Finance, and others) Business insight Societe Generale is committed to offering an inclusive recruitment experience to all candidates. If you require any reasonable accommodations during the recruitment process, please do not hesitate to let our Recruiters know. OUR CULTURE At Societe Generale, we live by our 4 core values of commitment, responsibility, team spirit and innovation. We are engaged and demonstrate consideration for others. We act ethically and with courage. We focus our talent and energy on collective success. We experiment and propose new ideas. This way, we maximize our ability to serve client needs and anticipate market changes. Societe Generale is committed to strengthening bonds with colleagues, communities, and the world in which we live, because relationships are at the heart of how we operate. For more information about our Culture and Conduct initiatives, please visit this link ( D&I Our Diversity & Inclusion Mission: Recruit, develop, advance, and retain a diverse workforce that is united in our efforts to enhance our competitive position and deliver innovative solutions to our clients. Our Diversity & Inclusion Vision: Engaged workforce that is demographically diverse in a way that reflects the communities in which we operate Inclusive culture and workplace that recognizes employees' unique needs and utilizes their diverse talents Engage our community and marketplace, and position the organization to meet the needs of all its clients For more information about our D&I initiatives, please visit this link ( #J-18808-Ljbffr



  • Montreal (administrative region), Canada SGS Société Générale de Surveillance SA Full time

    Responsibilities The Vulnerability Management Lead is responsible for the AMER region’s vulnerability management and configuration management program. The position requires excellent communication skills (written and verbal) and a strong ability to influence others. The ideal candidate will be able to demonstrate practical and in-depth knowledge of running...


  • Montreal (administrative region), Canada SGS Société Générale de Surveillance SA Full time

    Responsibilities The Vulnerability Management Lead is responsible for the AMER region’s vulnerability management and configuration management program. The position requires excellent communication skills (written and verbal) and a strong ability to influence others. The ideal candidate will be able to demonstrate practical and in-depth knowledge of...


  • Montreal, Quebec, Canada GCOO Full time

    Skills and Qualifications:Knowledge and Experience:4-5 years of information security experience, with hands-on expertise in vulnerability managementStrong communication skills, capable of presenting to various levels, from technical to senior managementProficiency in MS Office suiteStrong analytical, problem-solving, and process improvement skillsFamiliarity...


  • Montreal, Quebec, Canada GCOO Full time

    ABOUT THE JOB: Group Chief Operating Office (GCOO)'s vision is to enable best-in-class operational excellence across the Group leveraging on Technology (Digital, Data and AI) and Talents. Group COO functions are the foundations that will enable and support business efficiency, differentiation, and development. GCOO leverages on its 5 Functions to meet...

  • Cybersecurity Analyst

    2 weeks ago


    Montreal (administrative region), Canada Canada Mortgage and Housing Corporation Full time

    Select how often (in days) to receive an alert: Cybersecurity Analyst (Information Security) Job Requisition ID: 11489 Sector:Technology and Business Transformation Position Status:Permanent Full Time Position Type:Hybrid Language Skill Levels (Read/Write/Speak):ZZZ Travel Requirement:Limited Security Requirement:Reliability Status Salary Range:$71761.28to...


  • Montreal (administrative region), Canada Canada Mortgage and Housing Corporation Full time

    Select how often (in days) to receive an alert: Cybersecurity Analyst (Information Security) Job Requisition ID: 11489 Sector: Technology and Business Transformation Position Status: Permanent Full Time Position Type: Hybrid Language Skill Levels (Read/Write/Speak): ZZZ Travel Requirement: Limited Security Requirement: Reliability Status Salary Range: $ to $...

  • Cybersecurity Analyst

    2 weeks ago


    Montreal (administrative region), Canada Canada Mortgage and Housing Corporation Full time

    Select how often (in days) to receive an alert:Cybersecurity Analyst (Information Security)Job Requisition ID: 11489Sector:Technology and Business TransformationPosition Status:Permanent Full TimePosition Type:HybridLanguage Skill Levels (Read/Write/Speak):ZZZTravel Requirement:LimitedSecurity Requirement:Reliability StatusSalary Range:$71761.28to...


  • Montreal, Quebec, Canada McKesson Full time $108,100 - $180,100

    McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve – we care.What you do at McKesson matters. We foster a...


  • Montreal, Quebec, Canada Societe Generale Full time

    Reference 25000Q4PResponsibilitiesThe Vulnerability Management Lead is responsible for the AMER region's vulnerability management and configuration management program. The position requires excellent communication skills (written and verbal) and a strong ability to influence others. The ideal candidate will be able to demonstrate practical and in-depth...


  • Montreal (administrative region), Canada iA Financial Group Full time

    Information Security Advisor, Risk and Compliance Build the future with us Join the Information Security Vice-Presidency during a major transformation and help strengthen the security culture within iA Financial Group. As an Information Security Advisor, Risk and Compliance, you will play a strategic role in operationalizing risk management and compliance...