14 Sep
|
Jobtailor
|
Ottawa
- Conduct cybersecurity compliance reviews throughout the Lightspeed system lifecycle, including TRR, PDR, CDR, and other program milestones
- Gather, analyze, and maintain compliance evidence through interviews, documentation reviews, walkthroughs, and control validation activities
- Interpret cybersecurity and regulatory requirements and translate them into actionable compliance activities
- Collaborate with Engineering, Product Security, IT, and testing teams to verify cybersecurity controls are implemented and effective
- Track compliance activities, findings, remediation efforts, and action items
- Support implementation and maintenance of cybersecurity controls required to meet applicable obligations
- Monitor changes to cybersecurity standards and regulations and support compliance updates
- Prepare and maintain compliance documentation, assessment records, evidence repositories, and reports
- Provide guidance to cross-functional teams on compliance requirements, control implementation, and evidence collection
- Monitor and report on compliance activities, findings, and risks, escalating significant risks as appropriate
Requirements
- Diploma or Bachelor's Degree in Computer Science, Engineering, IT, Cybersecurity, or related field, or equivalent experience
- 3+ years supporting cybersecurity, compliance, governance, risk management, audit, assurance, or information security programs
- Experience assessing cybersecurity controls and compliance requirements
- Experience with NIST 800-53, NIST 800-171, ISO 27001, CMMC, or similar frameworks
- Experience coordinating with technical and business stakeholders
- Solid analytical, organizational, and communication skills
- Knowledge of cybersecurity governance, risk management, compliance, and control assurance principles
- Experience reviewing technical documentation, system designs, security controls, and implementation evidence
- Certifications such as CISA, CRISC, Security+, CGRC, or ISO 27001 Lead Auditor are assets
- Knowledge of CNSSP-12 or CAIQ is an asset
- Experience with GRC, audit management, evidence management, or compliance tracking tools is an asset
Core Competencies
Demonstrates expertise in cybersecurity compliance, risk management, and governance, with a strong ability to analyze and implement controls based on frameworks such as NIST and ISO. Proficient in collaborating with cross-functional teams to ensure effective compliance and documentation practices.
Highest-signal resume keywords
- Cybersecurity Compliance
- NIST 800-53
- ISO 27001
- Risk Management
- CISA
Hard Skills
- Cybersecurity Governance
- Compliance Assessment
- Control Validation
- Technical Documentation Review
- Evidence Collection
Soft Skills
- Analytical Skills
- Organizational Skills
- Communication Skills
Certifications & Qualifications
- CISA
- CRISC
- Security+
- CGRC
- ISO 27001 Lead Auditor
Industry Keywords
- Cybersecurity Standards
- Compliance Documentation
- Control Assurance
- Governance Frameworks
- Risk Assessment
Tools & Technologies
- GRC Tools
- Audit Management Tools
- Compliance Tracking Tools
#J-18808-Ljbffr
📌 IT Governance, Risk, and Compliance Analyst (Ottawa)
🏢 Jobtailor
📍 Ottawa