29 Aug
|
Canadian Tire
|
Oakville
29 Aug
Canadian Tire
Oakville
Oakville, ONFull timeJR The Information and Cyber Security Governance (IRGS) function is a dedicated team responsible for effectively managing and controlling information and cyber security within an organization. They develop and maintain policies, standards, and procedures/guidelines/process documents related to information and cyber security. The team identifies, assesses, and manages cyber risks, performs risk assessments, and reports on the organization's cyber risk profile. They promote a strong cyber risk and information security culture throughout the organization.Additionally, the IRGS team conducts vendor assessments, reviews hardware and software for security gaps, remediates deficiencies, and tests control effectiveness. They build partnerships with stakeholders across the organization, implement self-assessment processes incorporating risk and controls assessment in day-to-day activities, and contribute to adopting state-of-the-art tools and techniques. The team also escalates significant cyber-related issues or observed non-compliance or unethical behavior.It's important to note that the IRGS team reports directly to the Chief Information Security Officer (CISO)of CTB, who oversees the organization's overall information and cyber security strategy. This reporting relationship ensures alignment with strategic goals and facilitates effective coordination, collaboration, and decision-making between the IRGS function and other areas of the organization.In summary, the IRGS function plays a vital role in governing and managing information and cyber security to protect the organization's assets, data, and systems from potential threats while maintaining a direct line of communication with senior leadership through its reporting structure to the CISO.What you'll doThe Specialist is a key player responsible for spearheading initiatives to identify, investigate, communicate, resolve, and improve information securitygovernance,riskand compliancein our IT investments.You will partner withacross the organization,including,Technology, Enterprise Risk Management, InternalAudit, PCI Compliance,V endorM anagementand other stakeholdersto assess cybersecurity risks for the organization, including 3rd party risk, while helping teams determine mitigation strategies tomaintain and/or reducetheresidualriskofthe organization.Be the champion in risk assessment of technologies and processes in the setting,
including our digital crown jewels and other compliance impacting technologies and processes.Connect the dots to improve and enhance risk assessment processes.Understand and collaborate with stakeholders for prioritizing and mitigating vulnerabilities identified within the setting through vulnerability assessment, penetration testing, application security testing and/or any other risk assessment activity.Following up on vulnerabilities, configuration and cloud gaps and track remediationHelp further mature existing vulnerability management programAssess third-party risk on the use of vendors for day-to-day operations.Provide oversight, reporting, and metrics on risk functions.Performing security risk assessments for various projects and changes. And assisting with and documenting identified risk for presentation and approval from business and leadership as appropriate.Anticipate risk and assist owners in building action plans for risk mitigation.Review risk assessments of non-senior team members and peersValidating operating effectiveness of IT general controlsMaintaining risk and controls repositories and documentationProviding support for policy exception management proceduresAssisting with metrics and reportingManage platforms/applications within the mandate of the teamWhat you bringUniversity degree or college diploma in technology.Possess one or more professional certifications, such as CISSP, CISM, CISA, CCSP, CRISC etc.Up to 5+ years of experience in understanding risks, audits and processes relating to Information/Cyber Security and IT.Excellent communication skillsGood documentation and presentation skillsCreative thinker who takes initiativeProblem solver with the ability to analyze and prioritize to meet business objectivesCollaborative team player with superior influencing skills,
who builds relationships easilyOrganized individual who is always seeking to automate or improve efficiency of proceduresCreative thinker who is observant to seek new opportunities and perceptive to abstract ideasGoal driven individual to seek out continuous improvement opportunitiesThe ability to take a collaborate approach to build strong relationships and have positive team experiencesFlexible and dynamic individual who is able to adjust and prioritize accordingly to adapt to business demands and requirementsSolid foundation of relevant technical skillsDemonstrates behaviors of transparency, accountability agility and learning from others that will support your successGood understanding of vulnerability and configuration management procedures and how those impact an organization.Good knowledge and understanding about penetration testing and application securityGood scripting skills using Python or similar toolsExperience with developing dashboards using Power BIUnderstands/Experience in risk assessments including third-party riskGood understanding and some experience of managing applications/platformsHave knowledge of security governance frameworks, policies and standardsUnderstands principles of security controls testingAudit and/or IT risk managementKnowledge of IT risk and control frameworks, COBIT 5, NIST CSF & ISO27001, CISUnderstand System Development Life Cycle (SDLC) process and agile methodologiesFamiliarity with Data Privacy and Protection standards PCI, PII.Basic knowledge of cryptography and encryption algorithms.Familiarity with identity management controls including Multi Factor Authentication and Single Sign On.We're always looking for great talent! In addition to competitive pay, we offer:Comprehensive benefits and retirement programsPerformance incentives, Continuing Education ProgramsOther perks to support your well-beingCareer growth opportunities and product discountsBroadband Salary Range: $64,000.00 - $106,000.00Salary decisions are also dependent on other factors such as your experience, industry benchmarks, internal equity and other role-specific requirements. For critical roles, the compensation offering will be reviewed to ensure alignment with market rate and conditions and the unique value you bring to the role. #LI-AG2This posting represents an existing vacancy within our organization.We may use artificial intelligence tools as part of our recruitment process to assist in the initial screening of resumes. All hiring decisions, including candidate evaluation, selection, and disposition, are made by human recruiters.About UsAt Canadian Tire Services Limited/Canadian Tire
📌 Senior Compliance Security Specialist (Oakville)
🏢 Canadian Tire
📍 Oakville