Regional Information Security Officer

4 months ago


Montreal, Canada WSP Full time

Description

Regional Information SecurityOfficer(LAC)

About usWSPis a global consulting firm assisting public and private clients to plan, develop, design, construct, operate and maintain thousands of critical infrastructure projects around the world. 

Position Summary

WSP’s Information Security Office (ISO) is responsible for the deployment and maintenance of the information security framework for both the IT organization and wider business community. This includes the Governance mechanisms, policies and processes, tools and technologies, and employee training required to protect WSP information and that of our clients. 

The role of Regional Information Security Officer reports directly to the Business Information Security Officer and is responsible fordelivering the Information Security Framework into the applicable region of WSP. This is primarily an internally facing role, although some interaction with clients and third parties may be required.

This position requires a senior management professional with relevant experience and a strong working knowledge of IT security, risk management, regulatory compliance, information and public cloud service technology, IT operations management principles, and third-party security management.

Responsibilities

Work with the Business Information Security Officer, Regional Business and IT Leadership and peers within the Information Security Office to ensure the following deliverables are effectively and consistently delivered for the region under their area of responsibility.

Information Security Strategy:Collaborate with the Business Information Security Officer to define the regional organization's information security strategy, vision, and goals. Translate strategic objectives into actionable plans and initiatives that align with business objectives and industry best practices. Senior Stakeholder Engagement and Relationship Management:Develop highly effective relationships with business and IT leadership within their areas of responsibility, in order to deliver the information security strategy and goals and the management of security risk. Information Security Governance: Oversee WSPs implementation and maintenance of its ISO27001 aligned Data and Information Security Management System. Establish and maintain the Information Security Governance framework; including running the Information Security Committees; coordinating IS risk management, executive reporting and participate in other forums where information security input and approval is required based on documented policies and processes. Risk Management: Oversee the identification, reporting, assessment, and mitigation of information security risks. Work closely with cross-functional teams to ensure risk management practices are embedded in business processes and projects. Monitor the effectiveness of risk mitigation measures and drive continuous improvement. Security Awareness and Training: Develop and deliver comprehensive security awareness and training programs to promote a security-conscious culture. Collaborate with stakeholders to address security education needs and ensure employees understand their roles and responsibilities in protecting information assets.Communicate the value of information technology (IT) security throughout all levels of the organization stakeholders. Acquisition, Mergers and Integrations: Direct the security matters relating to all aspects of Acquisitions, Mergers, Integrations and Divestments. Including the security evaluation of potential acquisitions through to the integration of the acquired businesses into WSP’s security ecosystem.  Client Support:Develop and maintain a program of client support, to ensure that all client security requirements are identified, assessed, delivered and reported to relevant business leaders.  Vendor Risk Management:Develop and maintain a robust vendor risk management program. Conduct assessments of vendors and service providers to ensure they meet information security requirements and adhere to contractual obligations. Incident Response and Management: Develop and maintain an incident response plan and coordinate the response to information security incidents. Lead investigations, root cause analyses, and corrective actions to mitigate the impact of incidents and prevent future occurrences; liaise with external organizations (clients, law enforcement, local governments) as required.

Security Reporting and Metrics: Develop and maintain metrics, reports, and dashboards to track the effectiveness of the information security program. Provide regular updates to senior leadership on the organization's security posture and recommend remedial actions as needed.

Leadership and People Responsibilities:

Displays leadership and independence in performing their role, with an ability to make complex decisions with limited input and review from senior staff. High level of personal integrity, and the ability to professionally handle confidential matters and exude the appropriate level of judgment and maturity. Assist in the hiring, training, and coaching of new and existing staff, and provide coaching to staff executing all aspects of information security and risk assessment and support.  Develop positive working relationships with other team members and business partners and partner across teams to align with WSP internal and external client demands. Capable of rapidly assimilating and internalizing new complex business, technology, and risk management concepts and dependencies. Capable of clearly defining, presenting and selling recommended strategies to senior management teams in a business or technical context as appropriate. Critical thinker with strong problem-solving skills, project management skills; financial/budget management, scheduling and resource management.  Able to interpret and apply laws, regulations, policies and guidance relevant to the organization information security objectives. Able to exercise judgement when policies are not well-defined. Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate between specialized groups of business unit and IT professionals. Accommodation of schedule for international conference calls, limited travel within the regions you are responsible for.  Ability to work with people from different backgrounds and cultures across the region and the world. 

Finance/Budgetary Responsibilities:

Support the Business Information Security Officerin developing the budget projections based on objectives

Qualifications

Requirements

Required

5+ years related senior level experience in InformationSecurity, IT risk, IT Audit or a similar position involving IT and business change Graduate of college or university, preferably with a degree in computer science or information management, or Professional certification in one or more of the following disciplines — IT governance (e.g., CGEIT), security (e.g., CISSP, CISM), internal audit (CISA). Working (not necessarily technical) knowledge of security technologies (encryption, data protection, network intrusion prevention, host intrusion prevention, firewalls, privilege access, etc.) Working (not necessarily technical) knowledge of information technologies (networking concepts, protocols, servers, workstations, laptops, LAN/WAN, wired/wireless, TCP/IP, cloud computing.) Working (not necessarily technical) knowledge of IT security technologies (network security, encryption, data protection, network intrusion prevention, host intrusion prevention, firewalls, privileged access, etc.) Working (not necessarily technical) knowledge of enterprise IT threats and vulnerabilities (including but not limited to attacks and attack trends, ransomware, social engineering, advanced persistent threats, threat actors, etc.) Knowledge of security best practices (physical, technical and organizational controls) Experience with IT and IS Governance frameworks such as COBIT, ITIL, NIST-CSF and ISO 2700x Experience with governance, compliance and audit within IT environments Experience of risk management, including risk analysis, mitigation and monitoring Knowledge of information security regulations and legislation applicable to WSP Fluency in written and spoken English.

Preferred

Master's or other advanced degree in IT, Computer Science, Engineering or related field. Master’s degree in Business Administration or related field.

  • Montreal, Quebec, Canada US Tech Solutions Full time

    About the Role We are seeking a skilled Chief Information Security Officer to join our team at US Tech Solutions. This is a unique opportunity for an experienced professional to lead our information security initiatives and drive growth in this critical area.Job Description: The successful candidate will be responsible for implementing and maintaining robust...


  • Montreal, Canada Brain Finance Full time

    BrainFinance is a leading financial technology company that provides responsible and constructive credit solutions to consumers. We are redefining access to credit through our revolutionary technology that utilizes machine learning and automation capabilities to offer better and simpler financial services to everyone.A true innovation lab, our team consists...


  • Montreal, Quebec, Québec, Canada BrainFinance Full time

    (Hybrid model - In-office presence on Wednesdays only)BrainFinance is a leading financial technology company that provides responsible and constructive credit solutions to consumers. We are redefining access to credit through our revolutionary technology that utilizes machine learning and automation capabilities to offer better and simpler financial services...


  • Montreal, Canada Brain Finance Full time

    p>BrainFinance is a leading financial technology company that provides responsible and constructive credit solutions to consumers. We are redefining access to credit through our revolutionary technology that utilizes machine learning and automation capabilities to offer better and simpler financial services to everyone.A true innovation lab, our team...


  • Montreal, Quebec, Canada Brain Finance Full time

    About the RoleWe are looking for a seasoned Information Security Officer to join our team at BrainFinance. As our ideal candidate, you will have a proven track record of safeguarding IT infrastructure and data from security threats.Daily ResponsibilitiesDevelop and implement information security strategies, policies, and standards.Ensure compliance with...


  • Montreal, Canada Flare Full time

    We are a team of mission-driven people who want to enable companies to protect themselves against cyber crimes, and we’re damn passionate about it. We thrive on trust, operate with integrity and above all support our people so they can do their best work and be their best selves. If you continuously challenge yourself to learn and grow, are driven by the...


  • Montreal, Canada BrainFinance Full time

    Job Title:Information Security OfficerAbout the Role:We are seeking a highly skilled Information Security Officer to join our team at BrainFinance. As a key member of our security team, you will be responsible for safeguarding our IT infrastructure and data from security threats.Key Responsibilities:Lead the development and implementation of information...


  • Montreal, Quebec, Canada QUANTEAM (Groupe RAINBOW PARTNERS) Full time

    Job Title: Chief Information Security Officer - Application Security ExpertWe are seeking a highly skilled Chief Information Security Officer (CISO) to join our team at Quanteam (Groupe RAINBOW PARTNERS). As a CISO, you will be responsible for enhancing the security framework of an international bank based in Montreal by conducting thorough security...


  • Montreal, Quebec, Canada National Bank Full time

    We are seeking an experienced Senior Director to lead our Information Security Strategy team at the National Bank in Montreal, Quebec. As a key member of our IT and Operations sector, you will play a crucial role in optimizing portfolio management and prioritizing information security initiatives.About the RoleDevelop and implement strategic planning and...


  • Montreal, Canada GeoComply Full time

    h3>Chief Information Security Officer (Montreal, QC)About GeoComplyWe’re GeoComply! We are at the forefront of geolocation, cybersecurity, and anti-fraud innovation, developing and delivering cutting-edge technologies to help ensure regulatory compliance, combat bad online actors, alleviate user friction, and protect businesses from fraud.Achieving...


  • Montreal, Quebec, Canada The Post At Mint Hill Llc Full time

    About The RoleWe are seeking a highly skilled Chief Information Security Officer to lead our cloud infrastructure security transformation. As a key member of our IT team, you will be responsible for developing and implementing security best practices to secure our infrastructure and systems.Key Responsibilities:Lead and coach a team of security specialists...


  • Montreal, Canada Anywr Canada Full time

    **About Anywr Canada**Anywr Canada is a dynamic and fast-growing SaaS company that values innovation and customer satisfaction. We are seeking an experienced Information Security Specialist to join our team in Montreal, Canada.**Estimated Salary:** $120,000 per year (plus annual bonus)Job Description:We are looking for a highly skilled Information Security...


  • Montreal, Quebec, Canada Flare Full time

    Chief Information Security OfficerWe are a team of mission-driven professionals dedicated to protecting companies against cyber threats.This role is highly dynamic, requiring both strategic thinking and tactical execution of security best practices. The ideal candidate will have broad technical knowledge of cybersecurity principles, cloud security, network...


  • Montreal, Canada AKUR8 Full time

    About UsAkuras is a pioneering Insurtech firm revolutionizing insurance pricing and reserving with cutting-edge machine learning. Our SaaS platform leverages transparent AI and predictive analytics to inject speed, performance, and reliability into insurers' pricing and reserving processes.Powered by skilled R&D, Product & Actuarial teams, we've developed...


  • Montreal, Quebec, Canada I.G.S. security Full time

    Job TitleSecurity Operations SupervisorAbout the RoleWe are seeking a skilled Security Operations Supervisor to join our team at I.G.S. security. This is a full-time position responsible for supervising and coordinating the activities of security guards, providing technical advice and recommending measures to improve productivity and product quality.Key...


  • Montreal, Quebec, Canada Alstom Full time

    Job Description:About Alstom:We are a leading global company in the transport sector, offering a diverse range of products and services for rail transport infrastructure.Estimated Salary Range:$120,000 - $180,000 per yearKey Responsibilities:Implement and maintain robust cybersecurity measures to protect our OT infrastructure.Develop and enforce security...


  • Montreal, Quebec, Canada GeoComply Full time

    Secure the Future with GeoComplyWe are at the forefront of geolocation, cybersecurity, and anti-fraud innovation. As a trusted partner to leading global brands and regulators for over ten years, we've achieved significant business and revenue growth, dubbed a tech 'Unicorn.'As the Chief Information Security Officer (CISO) at GeoComply, you will be the key...


  • Montreal, Canada PSP Investments Full time

    EXPERIENCE THE EDGE At PSP, we encourage our employees to grow, forge powerful relationships, contribute and fuel inspired investment launchpads. We are committed to a culture that fosters collaboration and allows us to think beyond, in an interconnected way. We advocate for our employees to speak-up, learn, experiment, share, and be part of an where...


  • Montreal, Quebec, Canada National Bank Full time

    About the RoleWe are seeking a highly skilled and experienced Strategic Information Security Director to join our team at National Bank. As a key member of our organization, you will be responsible for developing and implementing strategic plans for information security initiatives.Key ResponsibilitiesDevelop and Implement Strategic Plans: Collaborate with...


  • Montreal, Canada Flare Full time

    p>We are a team of mission-driven people who want to enable companies to protect themselves against cyber crimes, and we’re damn passionate about it. We thrive on trust, operate with integrity and above all support our people so they can do their best work and be their best selves. p>Flare is looking for an experienced Chief Information Security Officer...