12 Sep
|
Axelon Services
|
Calgary
12 Sep
Axelon Services
Calgary
"This role is currently work-from-home and will move to the office environment after the COVID-19 restrictions are lifted.”
RESPONSIBILITIES
-Implement and govern the Information Security policies, standards, controls baseline and controls maturity model
-Collaborate with technical staff including software developers, infrastructure engineers, security engineers and department leaders to execute on near- and long-term Information Security compliance programs
-Define, plan and lead projects to remediate vulnerabilities and other issues identified during audits and risk assessments
-drive remediation efforts to deliver remediation plans on time
-Support status reporting by producing metrics and PowerPoint presentations for governance committee meetings
-Review and validate evidence requested for audits to ensure it meets the appropriate validity standards
-Communicates and ensures programs are in compliance with applicable laws, regulations, policies, and standards
-Coordinate with First and Second Line Risk Teams, and Internal Audit to facilitate key compliance processes and identify acceptable levels of risk
-Serve as subject matter expert to internal business and technology teams on range of compliance standards as influenced by regulatory mandates (e.g. GLBA, GDPR, SOX 404, FFIEC CAT, etc.) and industry best practices (e.g. NIST CSF, ISO 27001, ITIL, COSO, COBIT, etc.)
-Participate in key initiatives as the subject matter expert to ensure alignment with Information Security and IT programs and initiativesBasic
-Minimum 7 years
-experience in Information Security, Internal Audit and/or IT Risk Management functions
-Proven experience and success with managing IT, Internal Audit or Information Security compliance programs
-Bachelor's or Master's Degree in Information Systems,
Computer Science or related discipline is highly desired. CISSP, CISA, CISM or CRISC certification is highly desired
Preferred
-Proven experience with IT and information security best practices
-Demonstrated technical abilities across a broad range of technologies: Windows, Linux, relational databases (Oracle, MS SQL, etc.), firewalls, routers, mobile devices, virtualization and cloud computing
-Minimum 5 years
- experience implementing information security risk, governance, and control frameworks such as ISO/IEC27000 series, NIST CSF, CSA CCM and PCI DSS
-Proven project management and organizational skills, specifically managing multiple, concurrent projects
-Strong interpersonal, written, and oral communication skills
-Highly self-motivated and directed professional, with keen attention to detail
-Excellent analytical, problem-solving and decision-making abilities?Able to effectively prioritize tasks in a high-pressure environment
-Strong customer service and solution-focused orientation
-Experience working in a team-oriented, collaborative environment The IT Governance, Risk & Controls (GRC) Leader is a key member of the Solium/ShareWorks team and is responsible for designing, documenting, implementing and governing Information Security controls and IT compliance programs to meet corporate, legal and regulatory requirements. The IT GRC Leader is also responsible for the creation and maintenance of the Cyber Assurance and IT Risk Management program documentation.
This position requires a strategic thinker with robust technology skills, collaboration abilities, detailed working knowledge of compliance best practices, and familiarity in implementing information security controls for maintaining compliance for a highly regulated business environment.
📌 Governance, Risk & Controls (GRC) Lead (Calgary)
🏢 Axelon Services
📍 Calgary