Operational Information Security Specialist at Exposant 3 overseeing information security activities and implementing security controls. Collaborating on major projects within a human-centered and innovative firm.
Responsibilities
Responsible for supervising activities related to the operational security of information systems.
Responsibilities include conducting penetration tests, static and dynamic code analysis, and implementing application and infrastructure security controls to strengthen the protection of the client’s information assets.
Monitors potential threats and implements incident response plans to limit organizational impact.
In the event of a security breach, leads forensic investigations, including the collection and analysis of evidence necessary to support corrective actions.
Responsible for the maintenance and continuous optimization of security tools, such as firewalls and intrusion detection and prevention systems, ensuring they are regularly updated.
Collaborates with IT teams and other organizational units to ensure a consistent, proactive, and integrated approach to information security across the client’s environment.
Conduct penetration tests (infrastructure or application) according to the defined scope.
Document vulnerabilities discovered during penetration testing with supporting evidence and recommend corrective measures applicable to the client’s environment.
Conduct forensic investigations in the context of security incidents.
Support the security operations team in implementing security measures to enhance the robustness of controls needed to protect the client’s internet-facing systems and infrastructure.
Requirements
Hold a university degree in computer science, cybersecurity, or a related field, or an equivalency recognized by government standards.
Possess at least one of the following certifications: CISSP, CISA, CISM, CEH, CRISC, ISO/IEC 27001 Lead Implementer, ISO/IEC 27001 Lead Auditor, OSCP, CCSK, ISO 27005 Senior Lead Risk Manager, ISO 27032 Senior Lead Cybersecurity Manager.
Have at least 5 years of experience in operational information security.
Demonstrate hands-on experience implementing innovative security solutions and conducting infrastructure and application penetration tests, performing forensic investigations following security incidents, implementing application security controls such as WAF, CAPTCHA, MFA, and be proficient with cybersecurity tools.
Have participated in 2 large-scale projects involving the hardening of critical systems, involving complex environments with more than 500 users.
Demonstrate experience implementing protection measures for information assets, including the use of encryption solutions, firewalls, and intrusion detection systems.
Have experience operating security software such as SIEM or EDR solutions.
Have contributed to 2 projects in a cloud or hybrid environment as an Operational Security Specialist.
Benefits
A dynamic, supportive team culture based on trust and collaboration.
A flexible remote work environment.
The opportunity to contribute to large-scale projects in the technology sector.
Real opportunities for initiative, innovation, and professional development.
Information Security Advisor conducting cyber - risk assessments and contract reviews for Sun Life, a global financial - services company. Advising business and technology teams on security controls, compliance, and risk remediation.
Enterprise Security Architect securing technology for Vancity, a member - owned Canadian credit union. Designing enterprise application security frameworks, controls, and risk - based cybersecurity solutions.
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.
Join RBC's Application Security Group to develop innovative security solutions, mentor junior staff, and collaborate across teams to enhance decision - making and automate tasks.
Lead SCADA and cybersecurity engineer designing compliant substation systems for GE Vernova. Guiding project teams, vendor designs, estimates, and acceptance testing for cleaner energy infrastructure.