Conseiller senior en sécurité de l’information chez Exposant 3, firme de conseil en gestion et technologies. Gouvernance, risques, conformité et gestion des identités pour des projets d’envergure.
Responsibilities
Advise on, draft, and contribute to the evolution of the Information Security Policy, Information Security Management Framework, associated guidelines, and other governance documents
Ensure the compliance of information security practices, documents, and processes with the Act respecting governance and management of the information resources of public bodies and government enterprises (LGGRI)
Collaborate on information asset classification activities in accordance with the government model for classifying the security of digital data
Facilitate workshops and conduct and document risk analyses for projects and mandates
Contribute to the development, updating, and implementation of the information security training and awareness program
Collaborate in managing privacy incidents, including analysis, action coordination, and support for internal teams under Law 25
Assess the maturity of information security governance and make recommendations
Respond to requests for information security advice and provide guidance to mandates, projects, and business units
Contribute to identity and access management, including the authority registry, access analysis, and segregation-of-duties reviews
Contribute to the design and implementation of information security processes
Promote and ensure compliance with the Company's security policies, standards, and frameworks
Participate in integration sessions, meetings, and workshops with specialists in business, information, application, and technology domains
Present topics to various committees to simplify complex information and support decision-making
Transfer expertise to internal resources
Perform any other ad hoc tasks related to information security governance
Requirements
At least eight (8) years of experience delivering information technology security mandates, including at least five (5) years in security governance
Within the past five (5) years, completed at least two (2) mandates of at least 60 person-days each, such as strategic studies, security positions, or security assessments intended to support an organization's information technology security strategies or decisions
Within the past five (5) years, participated in at least one (1) mandate involving the application of principles, controls, or processes derived from ISO/IEC 27001, 27002, or 27005 standards
Hold at least one professional security certification: CISA, CISM, CRISC, ISO 27001–27005 (Lead Implementer, Lead Auditor, or Risk Manager), or CISSP
Benefits
A dynamic and supportive team culture built on trust and collaboration
A flexible remote work environment
The opportunity to contribute to major projects in the technology sector
Genuine opportunities to take initiative, innovate, and develop professionally
Information Security Specialist strengthening technology controls, security governance, and risk management at TD, a major North American bank. Advising partners, assessing controls, supporting audits, and responding to incidents.
Buildings, development and security Analyst supporting fire prevention, facility safety, and building management at Desjardins. Analyzing risks, developing safety plans, and implementing physical security systems.
BMO banking associate providing bilingual credit and lending sales and service remotely in Quebec. Handling customer contacts, credit decisions, compliance, and suspicious - activity reporting.
Principal Information Security Engineer defining scalable security strategy, architecture, automation, cloud, identity, and AI controls. Helping Arctic Wolf protect organizations worldwide and end cyber risk.
Consultant cybersécurité hybride à Montréal chez I - TRACING, pure - player indépendant en sécurité informatique. Conception, déploiement et support de solutions IAM, réseau, systèmes et applications.
Desjardins property technician supporting fire prevention, building safety, management, and build - out projects. Providing technical support, process coordination, user training, and operational guidance.