Director of Cybersecurity responsible for assessing risks and implementing security solutions at Financeit. Collaborating with various teams to protect information in Canada and the US.
Responsibilities
Implementing and monitoring a comprehensive enterprise-wide information security risk management program
Establishing annual and long-range security and compliance goals.
Assessing the adequacy of, adherence to, and the effectiveness of Financeit’s information and data security framework
Preparing periodic reporting to Senior Management and quarterly updates to the Board of Directors on key items around privacy and security
Identifying required controls related to the availability, integrity and confidentiality of customers, business partners, employees, and business information, evaluating the effectiveness of control
Assess developing security threats and help Senior Management identify and effectively manage potential security problems that might arise from Financeit’s current or proposed activities
Understanding and interacting with the business to ensure the consistent application of policies and standards across all projects, systems, and services
Monitoring remediation of information security, data security, and cyber security threats and assisting the Chief Compliance Officer in reporting those threats to Senior Management and the Board
Coordinating Financeit’s information and data security audit programs, including SOC2 Type 2 and PCI-DSS
Collaborate closely with the development team to integrate security throughout the Software Development Lifecycle (SDLC), ensuring that secure coding practices are consistently followed, potential vulnerabilities are identified and addressed early, and the final product meets stringent security standards.
Support the organization's incident management process by identifying, investigating, and responding to security incidents, conducting root cause analysis, documenting findings, and implementing corrective actions to prevent future occurrences.
Manage the third-party risk management process by assessing the security posture of vendors, ensuring compliance with organizational policies, conducting thorough due diligence during onboarding, and continuously monitoring third-party activities to identify and mitigate ongoing risks.
Requirements
At least 6 years of deep working knowledge of IT technologies, security threats and information security risk management
CISSP, CISA, CRISC or other equivalent security credentials
Experience working with Governance, Risk and Compliance (GRC) platforms
Good understanding of financial services/lending
Ability to articulate IT security and technical issues in a clear and actionable manner to non-technical leadership
Strong understanding of organization and technology controls, security, and risk issues
Familiarity with the audit process and conducting risk-based audits
Interest and focus on the rapidly changing privacy regulatory landscape
Strong knowledge in risk management, vulnerability management, identity and access management, incident management, and third-party risk management
Benefits
An award-winning culture with a collaborative & inclusive team.
Competitive pay and performance-based bonus.
Committed to flexible work arrangements, offering hybrid workplace options.
Comprehensive medical, dental and vision coverage + Lifestyle Account.
RRSP Matching and Parental Leave Top UP Program.
In office massage, meditation & workout sessions.
Virtual events such as Lunch & Learns, company parties, fun team activities and charity initiatives.
Security Engineer focused on matching technology opportunities with customer business objectives at Tenable. Delivering technical presentations and driving successful customer engagements in cybersecurity solutions.
Business Development & Capture Lead for Global Spatial Technology Solutions driving revenue growth in defence sector. Engaging senior stakeholders and leading proposal development across global markets from a remote location.
IT & Security Specialist managing IT operations, security, and infrastructure for Senstar, a leader in security technology. Hands - on role blending end - user support, cybersecurity, and infrastructure management.
HR Systems Security Specialist responsible for design, configuration, and administration of security within Workday and SAP. Collaborating with HR and stakeholders to ensure effective access design and compliance.
Cybersecurity advisor working within the DCYB to develop IT security measures. Collaborating with teams to fortify cybersecurity posture and ensuring data protection for citizens.
Consultant in remuneration and occupational health and safety at the Quebec Federation of Municipalities. Ensuring employee needs match organizational requirements and promoting a safe work environment.
Cybersecurity Administrator providing operational support for compliance activities in information security. Assisting vendor risk management, audit coordination, and vulnerability tracking.
Sr. Manager leading cloud security, compliance, and governance at Metergy Solutions Inc. Drive regulatory adherence and risk mitigation across diverse cloud environments with a focus on security by design.
Security Advisor responsible for designing telecommunications network architectures at Alithya. Ensuring all components meet functional and non - functional requirements while adapting to new trends in the field.
Technical Lead in Cybersecurity Engineering at Morgan Stanley driving security initiatives. Collaborate with tech leaders to ensure enterprise - wide cybersecurity effectiveness and compliance in Montreal.