Conseiller en gouvernance de la sécurité de l'information senior intervenant dans un projet client. Travail à Québec dans la ville du secteur public.
Responsibilities
Validate business cases and advise stakeholders on their development
Define, document, and communicate guiding principles for the design, implementation, deployment, and support of selected solutions
Follow up with division heads of the Digital Security and Cyberdefense Directorate (DSNC) when required, according to established processes
Plan, control, and support activities related to information security
Develop strategies and guidance for the evolution of information technologies
Conduct knowledge transfer to the teams of the Digital Security and Cyberdefense Directorate (DSNC) regarding work performed
Identify governance needs and directions for information security based on business requirements
Participate in designing and/or validating governance and information security solutions, ensuring their consistency and integration with reference standards
Participate in orientation studies, opportunity assessments, and preliminary analyses
Define security orientations for systems taking into account technological directions and business needs, and ensure their implementation
Perform risk analyses
Coordinate work
Support the project team regarding governance, security, and strategic directions
Requirements
University undergraduate degree (Bachelor's) in computer science, information technology, or a related field recognized by the Ministry of Education, or equivalent
Twelve (12) years of experience in information technology, accumulated over the last 15 years
Eight (8) years of relevant experience in information security governance during organizational and/or technological changes, accumulated over the last ten (10) years
Participation as an information security governance advisor on at least one (1) development, verification, or compliance project of information security processes, or managing exemptions, exceeding 1,000 person-days
Participation as an information security governance advisor on at least one (1) project developing an incident response strategy exceeding 1,000 person-days
At least one (1) year of hands-on experience in developing security strategies
One (1) year of experience in malware analysis in a client/server environment
One (1) year of experience with standards and frameworks such as NIST CSF, COBIT, and CIS Controls
Five (5) years of experience in risk analysis and risk appetite assessment in an environment comparable to the ministry
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.
Join RBC's Application Security Group to develop innovative security solutions, mentor junior staff, and collaborate across teams to enhance decision - making and automate tasks.
Lead SCADA and cybersecurity engineer designing compliant substation systems for GE Vernova. Guiding project teams, vendor designs, estimates, and acceptance testing for cleaner energy infrastructure.
Senior security advisor simulating cyber threats and strengthening defenses for Desjardins, North America's largest cooperative financial group. Leading complex initiatives, methodologies and cybersecurity risk mitigation.
SA&A Lead securing Azure applications and Microsoft platforms for PLATO, Canada’s Indigenous - owned software testing company. Leading authorization, control testing, evidence collection, and risk remediation.