25 Aug
|
Cassels Brock u0026 Blackwell
|
Toronto
25 Aug
Cassels Brock u0026 Blackwell
Toronto
About Cassels:
Cassels Brock & Blackwell LLP is a leading national law firm serving the transaction, advocacy, and advisory needs of clients across Canada’s most dynamic industries. From offices in Toronto, Vancouver, and Calgary, our litigators act on complex commercial disputes for multinational, national, and mid-market clients. We combine rigorous advocacy with practical judgment, inventive strategy, and an unwavering focus on achieving efficient, business-minded outcomes.
Our Culture:
At Cassels, our mission is to attract, retain and promote individuals of exceptional ability and talent from as broad a range of backgrounds as possible. We offer meaningful career opportunities, invest in professional growth, and foster an inclusive environment. Our Firm’s success is built on the unique skills, perspectives, experiences and values of each individual. We encourage a corporate culture that respects and celebrates the dignity, value and diversity of all.
Role Overview:
Cassels is seeking a Senior Information Security, GRC Analyst in our Information Technology department, reporting to the Assistant Director, Information Security. This role provides governance, risk, compliance, assurance, and security advisory support across the Firm's information security program. The role conducts security risk and control assessments for IT projects, systems, applications, cloud services, integrations, and material technology changes; provides security advisory services to technology and business stakeholders; maintains ISMS documentation and evidence; coordinates client, audit, and assessment responses; manages third-party security risk activities; and helps ensure that security risks, control gaps, exceptions, and remediation activities are identified, documented, tracked, and reported.
The successful candidate will be responsible for:
- Establishing and maintaining processes for the collection, validation, organization, and retention of evidence required to demonstrate compliance with security, regulatory, contractual, client, and ISMS requirements.
- Monitoring and reporting on remediation activities related to security findings, audit observations, risk treatment plans, policy exceptions, control deficiencies, and technology issues, escalating overdue or high-risk items as appropriate.
- Conducting security risk and control assessments for IT projects, systems, applications, cloud services, integrations, and material technology changes, providing practical security guidance throughout the project lifecycle.
- Maintaining and enhancing the Firm's threat catalogue, ensuring threats remain relevant, accurately described, and appropriately mapped to organizational assets, risk assessments, and security controls.
- Reviewing proposed technology solutions, integrations, configurations, and changes to identify security risks, control gaps, and opportunities to improve the Firm’s security posture.
- Reviewing and assessing security configuration baselines, build standards, and supporting documentation maintained by IT teams to identify security risks, control gaps, and deviations from Firm security requirements.
- Participating in the change management process by assessing the security impact of proposed changes and advising on required controls, approvals, testing, documentation, and risk treatment.
- Supporting security incident management by ensuring incidents are documented, corrective actions are tracked, control gaps are identified, and post-incident lessons learned are incorporated into the ISMS, risk register, and control improvement activities.
- Coordinating client security assessments, questionnaires, audits, and assurance activities by gathering and validating security information, coordinating evidence collection, tracking findings and remediation activities, and maintaining audit readiness.
- Performing security due diligence and risk assessments of third-party vendors, service providers, and cloud services, documenting findings and recommending appropriate risk treatment actions.
- Providing operational security support where required.
The successful candidate must have the following education, experience and/or demonstrated skills:
- University degree in Computer Science, Information Security, Information Technology, or a related discipline, or an equivalent combination of education, professional certifications, and practical experience.
- Professional certification in information security, governance, risk management, or audit, such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer, or equivalent.
- Minimum eight years of progressive experience in information security, including significant experience in governance, risk management, compliance, security assessments, audit support, third-party risk management, and security advisory functions.
- Demonstrated experience conducting security risk assessments for technology projects, enterprise applications, cloud services, infrastructure platforms, third-party services, and material technology changes.
- Strong knowledge of information security principles, control frameworks, and risk management methodologies, and the ability to apply them in practical business and technology environments.
- Strong knowledge and practical experience applying information security governance, risk management, and assurance frameworks, including:
1. ISO 27001, ISO 27002, and ISO 42001
2. AICPA Trust Services Criteria (SOC 2)
3. NIST Cybersecurity Framework (CSF)
4. NIST SP 800-53
5. CIS Critical Security Controls
- Cloud Security Alliance Cloud Controls Matrix (CSA CCM)
- Strong understanding of security technologies and control domains including identity and access management, privileged access management, multi-factor authentication, cloud security, endpoint security, vulnerability management, encryption, logging and monitoring, email security, network security, and data protection technologies.
- Demonstrated knowledge of security architecture and secure design principles, including the ability to assess cloud-based solutions and provide security guidance for Microsoft Azure, Microsoft 365, identity and access management, integrations, and enterprise technology projects. SC-100 Certification would be a definite asset.
- Strong understanding of the security, privacy, governance, and risk implications of artificial intelligence (AI), generative AI, automation platforms,
and citizen development technologies, including experience evaluating risks, assessing controls, and providing security guidance for their adoption and use.
- Experience supporting audits, client security assessments, security questionnaires, and evidence collection activities in regulated or security-conscious environments.
- Experience performing security due diligence and risk assessments of third-party vendors, service providers, and cloud-based solutions.
- Excellent analytical, problem-solving, and critical thinking skills, with the ability to assess complex situations and make sound risk-based recommendations.
- Strong oral and written communication skills, with the ability to communicate technical and risk concepts effectively to both technical and non-technical audiences.
- Strong interpersonal skills and the ability to build productive working relationships with business stakeholders, technology teams, auditors, vendors, and clients.
- Highly organized with strong attention to detail and the ability to manage multiple priorities and competing deadlines.
- Self-motivated, proactive, and capable of working independently with minimal supervision.
- Demonstrated ability to exercise sound qualified judgment and maintain confidentiality when dealing with sensitive information.
- Ability to work effectively in a fast-paced environment and adapt to changing priorities and business requirements.
- Availability to participate in incident response and critical issue management activities, including occasional after-hours support when required.
Employment Type: Permanent, Full-Time
(This role is open to candidates from Toronto, Calgary or Vancouver)
Salary: $100,000 – $125,000 Annually (commensurate with skills and experience)
What we offer:
- Competitive compensation + Extended Health & Dental Care.
- RRSP Matching Program.
- Education/tuition allowance.
- Fitness Reimbursement Program.
- Diversity and Inclusion Centric Culture
- A Culture of Wellness: Cassels recognizes the importance of wellness and provides a comprehensive program that addresses the mental and physical well-being of our employees by providing resources, services, training and support on an ongoing basis.
- A fully stocked kitchen with healthy snacks, plus coffee, tea, and drinks throughout the year.
- A business casual dress code (client/day specific).
- Employee referral bonus.
- A hybrid work environment.
Cassels is an equal opportunity employer committed to fostering a workplace where people of all identities and lived experiences feel valued, respected, and supported. We are dedicated to removing barriers and ensuring equitable access to employment. We strongly encourage applications from Indigenous peoples, racialized people, people with disabilities, 2SLGBTQIA+ communities, and individuals with intersectional identities.
All qualified candidates are welcome to apply. Accommodations for disabilities, accessibility needs, or cultural practices are available throughout the recruitment process upon request. Please contact our recruiter with any questions or accommodation needs.
We wish to thank all applicants for their interest, however, only candidates selected for interviews will be contacted. We regret that we are unable to respond to individual inquiries about application status, unless required for accommodation purposes.
📌 Senior Information Security, GRC Analyst (Toronto)
🏢 Cassels Brock u0026 Blackwell
📍 Toronto