14 Sep
|
Jobtailor
|
Montreal
14 Sep
Jobtailor
Montreal
Conduct cybersecurity compliance reviews throughout the Lightspeed system lifecycle, including TRR, PDR, CDR, and other program milestones Gather, analyze, and maintain compliance evidence through interviews, documentation reviews, walkthroughs, and control validation activities Interpret cybersecurity and regulatory requirements and translate them into actionable compliance activities Collaborate with Engineering, Product Security, IT, and testing teams to verify cybersecurity controls are implemented and effective Track compliance activities, findings, remediation efforts, and action items Support implementation and maintenance of cybersecurity controls required to meet applicable obligations Monitor changes to cybersecurity standards and regulations and support compliance updates Prepare and maintain compliance documentation, assessment records, evidence repositories, and reports Provide guidance to cross-functional teams on compliance requirements, control implementation, and evidence collection Monitor and report on compliance activities, findings, and risks, escalating significant risks as appropriate Requirements
Diploma or Bachelor's Degree in Computer Science, Engineering, IT, Cybersecurity, or related field, or equivalent experience 3+ years supporting cybersecurity, compliance, governance, risk management, audit, assurance, or information security programs Experience assessing cybersecurity controls and compliance requirements Experience with NIST 800-53, NIST 800-171, ISO 27001, CMMC,
or similar frameworks Experience coordinating with technical and business stakeholders Solid analytical, organizational, and communication skills Knowledge of cybersecurity governance, risk management, compliance, and control assurance principles Experience reviewing technical documentation, system designs, security controls, and implementation evidence Certifications such as CISA, CRISC, Security+, CGRC, or ISO 27001 Lead Auditor are assets Knowledge of CNSSP-12 or CAIQ is an asset Experience with GRC, audit management, evidence management, or compliance tracking tools is an asset Core Competencies
Demonstrates expertise in cybersecurity compliance, risk management, and governance, with a strong ability to analyze and implement controls based on frameworks such as NIST and ISO. Proficient in collaborating with cross-functional teams to ensure effective compliance and documentation practices. Highest-signal resume keywords
Cybersecurity Compliance NIST 800-53 ISO 27001 Risk Management CISA Hard Skills
Cybersecurity Governance Compliance Assessment Control Validation Technical Documentation Review Evidence Collection Soft Skills
Analytical Skills Organizational Skills Communication Skills Certifications & Qualifications
CISA CRISC Security+ CGRC ISO 27001 Lead Auditor Industry Keywords
Cybersecurity Standards Compliance Documentation Control Assurance Governance Frameworks Risk Assessment Tools & Technologies
GRC Tools Audit Management Tools Compliance Tracking Tools
#J-18808-Ljbffr
📌 IT Governance, Risk, and Compliance Analyst (Montreal)
🏢 Jobtailor
📍 Montreal