13 Aug
|
Ju0026M Group
|
Montreal
13 Aug
Ju0026M Group
Montreal
Role Overview
- Join the Continuous Controls Monitoring (CCM) team as part of the Metric Design & Architecture function.
- Focus on quantifying and reporting the implementation correctness and operating efficiency of Technology controls.
- Work closely with Technology, Security, Policy, Data, and Reporting stakeholders to establish effective control metrics and reporting frameworks.
Key Responsibilities
- Establish and document Control/Risk metric definitions for Technology controls.
- Engage with stakeholders to understand processes and analyze data to develop accurate control measurements.
- Partner with Technology Policy teams to ensure control measurement and metric requirements are incorporated into policy design and updates.
- Collaborate with metric consumers to establish reporting frameworks that meet business and stakeholder requirements.
- Partner with CCM data acquisition and tooling teams to successfully implement cybersecurity and technology metrics.
- Define Key Control Indicators (KCIs), KPIs, and KRIs to measure control implementation completeness and effectiveness.
- Monitor control performance and identify gaps, weaknesses, and areas requiring remediation.
- Support control design, implementation, testing, monitoring, and effectiveness assessment.
- Provide risk and compliance reporting to stakeholders and senior management.
- Track control remediation activities and communicate progress, risks, and outstanding issues.
- Analyze quantitative and qualitative data to support informed risk and control decisions.
- Work with stakeholders across different levels and effectively manage expectations, priorities, and deadlines.
- Provide executive-level reporting and communicate complex cybersecurity and control-related information clearly.
Required Qualifications
- 10+ years of experience in Information Security, Cybersecurity, Information Technology, or a related field.
- 5+ years of hands-on experience with Technology or Cybersecurity control implementations.
- Strong experience with Cybersecurity Controls Frameworks and Governance.
- Hands-on experience with Controls Design, Implementation, Testing, and Effectiveness Assessment.
- Strong experience defining and implementing Security Metrics, KPIs, KRIs, and Key Control Indicators.
- Experience with Control Monitoring and Remediation Tracking.
- Strong understanding of Risk Management and Regulatory Compliance.
- Experience developing Risk & Compliance Reporting and management-level dashboards.
- Solid business acumen and strategic thinking.
- Excellent analytical and decision-making skills using quantitative and qualitative data.
- Strong stakeholder management and communication skills, including interaction with senior and executive-level stakeholders.
- Ability to manage multiple priorities and work effectively under tight deadlines and high-pressure situations.
Technical & Security Knowledge
- Knowledge of various Technology Control and Cybersecurity domains.
- Knowledge of Public Cloud technologies such as AWS, Azure, or GCP.
- Understanding of security concepts related to:
- Identity & Access Management
- Authentication & Authorization
- Data Security
- System Security
- Network Security
- Application Security
- Knowledge of Security Logging, Monitoring, and Incident Response.
- Understanding of cybersecurity risk, control monitoring, and security governance practices.
Preferred Qualifications
- Cybersecurity or Information Security certifications are preferred.
- Experience in GRC, Cyber Risk, Security Governance, or Continuous Controls Monitoring (CCM) is an advantage.
📌 Cybersecurity Metrics and Controls Specialist (Montreal)
🏢 Ju0026M Group
📍 Montreal