05 Aug
|
S.i. Systems
|
Toronto
05 Aug
S.i. Systems
Toronto
Duration: 1 year to start Location: Downtown Toronto or Waterloo (Hybrid - Once a week in office) Needs to be eligible for reliability clearance (Should have lived in Canada for the last 5 years) Reporting to the Director, Security Advisory Services, the Senior Information Security Advisor is aligned with one of the line of business.
The Senior Information Security Advisor manages the line of business ensuring Information Security Risk Assessments (ISRAs) for their initiatives are completed in a timely manner, security risks have valid action plans, and assists with compliance matters related to Information Security.
The Senior Information Security Advisor performs Information Security Risk Assessments (ISRAs) on initiatives, third-party/suppliers and applications, conducts contract reviews focused on security provisions, advises on security best practices, and reviews emerging security strategies.
The Senior Information Security Advisor interacts and collaborates with various teams, including Business, Architecture, Infrastructure, Compliance and Risk, Legal, and Privacy teams.
There is also interaction with external third-party/suppliers.
Must Haves Minimum 7 years experience in Information Security and/or Information Technology (IT), preferably with experience in Information Security Risk Management In-depth knowledge of Information Security and IT principles, protocols, practices, and industry standards Robust understanding of existing and emerging Information Security technologies (e.g., encryption, network/web application firewall, IDS/IPS, advanced malware protection, DDoS, DLP, SIEM, etc.) Extensive knowledge of various attack/threat vectors and determine the corresponding security controls to minimize and/or remediate the risk Strong understanding of cloud security and cloud-based technologies (e.g., AWS and Azure) Experience performing cloud security risk assessments.
Experience performing risk assessments of cloud-based (SaaS) technologies including but not limited to AWS and Azure Familiarity with contract wording and interpretation of security clauses Post-secondary education (University degree or college diploma) in Computer Engineering, Computer Science, Information Technology, Information Security and Risk Management or comparable professional education/training in a field relevant to Information Security Nice to Have Professional designation such as CISSP, CCSP, CISM, or CISA Experience interfacing with executives and negotiating with clients Report writing experience Responsibilities Provide support to the line of business initiatives and projects through conducting information security risk assessments, reviewing contracts to ensure inclusion of appropriate security provisions/requirements, performing supplier/third-party risk assessments, and advising on security best practices.
Provide support to the line of business to ensure the security controls implemented on their projects and initiatives align with Security Policy and Directive requirements.
Provide security consulting, using technical expertise, to guide and influence implementation of appropriate security controls in projects and initiatives to ensure the safeguarding and protection of confidential information to prevent accidental disclosure, modification or destruction, and improve the overall security posture.
Provide preliminary recommendations to the management team on information security related risks.
Track and manage open information security risks to ensure corresponding risk remediation plans and target dates are in place.
Work with respective risk owner to ensure risk action plans are valid and risks are remediated in a timely manner.
Provide reporting to management team on status of information security risks assessments, identified risks, policy exception requests, and current work activities.
📌 Senior Information Security Advisor to conduct Information Security Risk Assessments using cloud security and risk management practices - 1651/1657 (Toronto)
🏢 S.i. Systems
📍 Toronto