Chief Information Security Officer

2 months ago


Montréal, Canada The Globe and Mail Full time

COMPANY OVERVIEW

:

The Globe and Mail is a national icon and one of Canada's most recognized media brands. We proudly serve as a trusted destination for Canadians seeking the highest caliber of journalism, and we've garnered international acclaim for our data visualization, design, and creative storytelling.

We are committed to fostering diversity and inclusivity by reflecting all Canadians in both the stories that we tell and the composition of our workforce. We are proud partners with organizations like Indigenous Works, Pride at Work, the Canadian Centre for Diversity and Inclusion, and we are a signatory of the BlackNorth Initiative. Recognizing the importance of work-life balance, we offer flexible work arrangements and support programs. We also invest in our employees' growth through training and mentorship opportunities, enabling you to expand your skills and embrace new challenges.

No matter your position at The Globe, you'll be an integral part of an organization dedicated to making a positive difference in Canada. Join us.

CANDIDATE PROFILE:

Has an enterprise security focus Can create the appropriate security framework and posture for the organization’s digital assets Can develop a security aware culture and instill security discipline in each line of business Can enhance and drive cyber risk management framework and initiatives Can operate with some degree of autonomy while being fully accountable to the Governance Committee Is focused on strategy and framework and executes through a small team of direct reports or by working collaboratively with designated security functions embedded in other departments

POSITION OVERVIEW:

The Chief Information Security Officer is a critical member of The Globe's organization. This role owns the organization’s strategic vision for cyber security. We are looking for a leader who can define and translate the enterprise security risk requirements and constraints of the business into control measures and establish performance metrics. This role will manage a small team that will coordinate the implementation and management of security posture and compliance throughout the organization.

Strategy & Planning:

Maintain and improve cyber risk management framework Maintain and improve our security awareness training program Maintain and improve the enterprise’s security documents such as policies and standards, including all relevant stakeholders during composition maintain and improve the Business Continuity and Disaster Recovery Plan, where appropriate Enhance technology risk reporting  Ensure ongoing compliance with relevant security and privacy requirements and standards Act as point of contact by engaging in ongoing communications with peers, senior IT management as well as the various business groups to ensure enterprise wide understanding of security goals, to solicit feedback and to foster co-operation

Acquisition & Deployment:

Maintain up-to-date knowledge of the security industry best practices including awareness of new or revised security solutions as it relates to our business Oversee security budget to ensure cost effectiveness security solutions that improve overall enterprise security and mitigate the risks of new cyber-attacks and threat vectors in a fiscally responsible manner Oversee the deployment, integration, and implementation of all new security solutions and of any enhancements to the existing security solutions in accordance with industry best operating procedures Support Vendor Risk Management Program and Software Development Life-Cycle framework

Operational Management:

Responsible for compliance obligations such as Payment Card Industry, and support compliance with data protection requirements Supervise the design and execution of vulnerability assessments, penetration tests and security audits (monthly, quarterly, and annually as required) Assess security control findings and recommend solutions and/or compensating controls Ensure the enforcement of enterprise security policies Protect the organization from business risk associated with technology use. Participate in technical and change advisory boards as required Supervise all cyber security investigations and provide on-going communication with senior management and applicable points of contact throughout the enterprise Ensure adherence to the Incident Response Plan escalation procedures and notification Perform regular security awareness training for all employees and applicable service partner providers to ensure consistently high levels of compliance with enterprise security policies

KNOWLEDGE AND EXPERIENCE:

Extensive knowledge and experience in enterprise security architecture, infrastructure, and security operations Experience in designing and delivering employee security awareness training and security documentation Experience developing Business Continuity and Disaster Recovery Plans Strong knowledge and experience in cyber security and risk frameworks, standards, and industry best practices such as NIST CSF, ISO, PCI DSS, SOC2 Experience in implementing and managing Governance, Risk and Compliance frameworks Strong understanding of project governance and methodology Strong understanding of Data Privacy laws Strong understanding of operational security technologies and services such as firewalls and network security protocols, VPN, WAF and web protection, EDR, MDR, SIEM, digital forensics, email security, mobile security, ransomware protection, and DLP Strong understanding of virtualization and cloud technologies such as VMware, Amazon AWS, Microsoft Azure Strong knowledge and experience in vulnerability management program Familiarity with Windows, Unix/Linux, and Mac operating systems and applications and directory services

FORMAL EDUCATION AND CERTIFICATIONS:

College diploma or university degree in the field of computer science and 10 years’ work experience or equivalent combination of education and experience. Certified in one or more of the following or similar certifications: ISACA CISM (Certified Information Security Manager) ISACA CRISC (Certified in Risk and Information Systems Control) ISC2 CISSP (Certified Information Systems Security Professional) GSLC (GIAC Security Leadership)

WHY CHOOSE THE GLOBE:
 

The Globe’s mission is to deliver essential content – news, information, analysis and insights – for aspiring individuals and strong communities.The Globe is committed to providing a respectful and inclusive workplace that upholds our values of integrity, collaboration, innovation and accountability.
 

As Canada’s most respected media brand The Globe is dedicated to making a difference to Canada and you can make a difference by working with us.

WE OFFER:

Competitive compensation to ensure we hire, retain and reward team members Hybrid work environment that promotes work-life balance Generous vacation and flexible work arrangements Parental leave top-up Competitive health and dental benefits Defined Benefit pension plan Annual wellness subsidy On-site chiropractor and registered massage therapist Employee and family assistance program Free digital subscription to and 40% off other Globe products Education assistance for external training courses

SUPPORTING YOUR GROWTH:

We are committed to creating equitable opportunities for all employees, to enable everyone to reach their full potential. This commitment is embedded in our strategic plan and core values. There are lateral and upward advancement opportunities for rewarding and developing careers. We believe in mentorship and collaborative peer-to-peer learning and have both formal and informal programs in place to encourage knowledge-sharing. We support continuing education and provide both internal and external opportunities for training and development.

  • Montréal, Canada Fed IT Full time

    Are you looking for a new professional challenge? System security no longer holds any secrets for you? Do you want to join a company that combines high standards, performance and kindness? So take 5 minutes to read this ad, your future may be at the bottom of this offer! First of all, let me introduce myself, I am Earvin from the Fed IT recruitment firm in...


  • Montréal, Canada Fed IT Full time

    Are you looking for a new professional challenge? System security no longer holds any secrets for you? Do you want to join a company that combines high standards, performance and kindness? So take 5 minutes to read this ad, your future may be at the bottom of this offer! First of all, let me introduce myself, I am Earvin from the Fed IT recruitment firm in...


  • Montréal, Canada Fed IT Full time

    Are you looking for a new professional challenge? System security no longer holds any secrets for you? Do you want to join a company that combines high standards, performance and kindness? So take 5 minutes to read this ad, your future may be at the bottom of this offer! First of all, let me introduce myself, I am Earvin from the Fed IT recruitment firm in...


  • Montréal, Quebec, Québec, Canada Fed IT Full time

    Are you looking for a new professional challenge? System security no longer holds any secrets for you? Do you want to join a company that combines high standards, performance and kindness? So take 5 minutes to read this ad, your future may be at the bottom of this offer! First of all, let me introduce myself, I am Earvin from the Fed IT recruitment firm in...


  • Montréal, Canada Monnaie Full time

    The Mint is hiring a Chief Information Officer (CIO) who can thrive in a dynamic and inclusive environment. Reporting to the Vice President, Corporate Security and Information Technology (IT), the Chief Information Officer will be responsible for the vision and strategic leadership for developing and implementing our IT initiatives. You will oversee the...


  • Montréal, Canada WSP Full time

    **Position Summary** WSP’s Information Security Office (ISO) is responsible for the deployment of the information security framework in to both the IT organization and wider business community. This includes the Governance mechanisms, policies and processes, tools and technologies, and employee training required to protect WSP information and that of our...


  • Montréal, Canada WSP Full time

    **WSP **is one of the world's leading professional services firms. Our purpose is to future proof our cities and environments. We have over 65,000 team members across the globe. In Canada, our 12,000+ people are involved in everything from environmental remediation to urban planning, from engineering iconic buildings to designing sustainable transportation...

  • Executive Assistant

    3 weeks ago


    Montréal, Canada Hydro Ottawa Full time

    Executive Assistant - Chief Information Technology Officer Division Executive Assistant - Chief Information Technology Officer Division locations: Ottawa, ON time type: Full time posted on: Posted 7 Days Ago job requisition id: R003770 At Hydro Ottawa, we empower the lives of the people in the communities we serve. As the electricity distributor to the...

  • Executive Assistant

    3 weeks ago


    Montréal, Canada Hydro Ottawa Full time

    Executive Assistant - Chief Information Technology Officer Division Executive Assistant - Chief Information Technology Officer Division locations: Ottawa, ON time type: Full time posted on: Posted 7 Days Ago job requisition id: R003770 At Hydro Ottawa, we empower the lives of the people in the communities we serve. As the electricity distributor to...


  • Montréal, QC, Canada Iceberg Cyber Security Full time

    Information Security AnalystWorking in the financial trading industry is highly motivating for security technologists because the environment is constantly changing at a fast pace, allowing you to work with cutting-edge technology. The exciting aspect of this opportunity is that you do not need current or previous experience within the security team of a...


  • Montréal, Canada WSP Full time

    **WSP **is one of the world's leading professional services firms. Our purpose is to future proof our cities and environments. We have over 65,000 team members across the globe. In Canada, our 12,000+ people are involved in everything from environmental remediation to urban planning, from engineering iconic buildings to designing sustainable transportation...


  • Montréal, Canada WSP Full time

    **Position Summary** WSP’s Information Security Office (ISO) is responsible for the deployment of the information security framework in to both the IT organization and wider business community. This includes the Governance mechanisms, policies and processes, tools and technologies, and employee training required to protect WSP information and that of our...


  • Montréal, Canada Transat AT Full time

    Company Description **Be part of the journey!** Come aboard a committed, caring company that needs you! Why should you join our team? We offer the pride of working for a local company with an international reach, with professionals who are passionate about travel! You'll evolve in a stimulating telecommuting environment where team cohesion is paramount....


  • Montréal, Canada Gatestone & Co. Inc Full time

    _**Join Our Team - Information Officer with Security Clearance**_ ** Paid Training ** | - **Competitive Salary ** | - **Flexible Hybrid Roles** * Are you ready to make a positive impact and assist Canadians nationwide? As an Information Officer representing the _**Federal Government of Canada**_, you'll provide top-notch service and guidance on government...


  • Montréal, Canada Cosmetic Physician Partners Full time

    **Role**: Chief Financial Officer (CFO) **Location**: USA or Canada (Main office in Montreal, Canada) **Reports to**: Daniel Schacter - CEO **About Cosmetic Physician Partners (CPP)**: **The Role**: As CFO, you will be responsible for overseeing all aspects of CPP's financial operations, with a particular focus on driving growth through strategic and...

  • Chief Analyst

    1 month ago


    montréal, Canada National Bank Full time

    As a Chief Analyst fund administration in the cotation & evaluation team at National Bank, you’ll be a contributor in the realisation of various key deliverables while working closely with other colleagues. With your leadership, your experience in derivative securities and your finance knowledge, yo


  • Montréal, QC, Canada Bedford GroupTRANSEARCH Full time

    About our ClientThe Canadian Institute of Mining, Metallurgy and Petroleum (CIM) is a leading non-profit organization dedicated to advancing knowledge, promoting innovation, recognizing excellence, and advocating for sustainable practices within the minerals, metals, materials, and petroleum sectors. With a vast network of members from industry, academia,...


  • Montréal, QC, Canada Bedford GroupTRANSEARCH Full time

    About our ClientThe Canadian Institute of Mining, Metallurgy and Petroleum (CIM) is a leading non-profit organization dedicated to advancing knowledge, promoting innovation, recognizing excellence, and advocating for sustainable practices within the minerals, metals, materials, and petroleum sectors. With a vast network of members from industry, academia,...


  • Montréal, Canada Addenda Capital Full time

    City: - Montréal, QC - Status: - Permanent, Full-time **Who we Are** Addenda Capital is a privately-owned investment management firm that favours a sustainable approach to wealth creation. The company offers a stimulating, positive and open-minded environment where integrity, collaboration and diversity are valued. Addenda integrates ESG (Environmental,...


  • Montréal, Canada I.G.S. security Full time

    Education: Secondary (high) school graduation certificate - Experience: 7 months to less than 1 year - or equivalent experience **Tasks**: - Establish work schedules and procedures - Handle emergency situations - Resolve work related problems - Supervise, co-ordinate and schedule (and possibly review) activities of workers - Train staff/workers in job...