Information Security Advisor conducting cyber-risk assessments and contract reviews for Sun Life, a global financial-services company.
Advising business and technology teams on security controls, compliance, and risk remediation.
Responsibilities
Conduct information security risk assessments for initiatives, projects, applications, cloud-based SaaS technologies, and third-party suppliers/external vendors
Review contracts to ensure inclusion of security requirements and interpret security clauses
Advise business groups on information security best practices and appropriate security controls
Assess initiatives and projects against Sun Life Information Security policies and directive requirements
Provide security consulting to protect confidential information from disclosure, modification, or destruction
Report assessment status, identified risks, and current work activities to management
Provide preliminary recommendations on information security-related risks
Track open information security risks and ensure remediation plans and target dates are established
Work with business and technology risk owners to achieve risk remediation
Collaborate with Business, Architecture, Infrastructure, Legal, Compliance and Risk, and Privacy teams
Requirements
University degree or college diploma in Computer Science, Engineering, Information Technology, Information Security and Risk Management, or comparable professional education/training relevant to IT Security management
Minimum 5 years of experience in Information Security and Information Technology
In-depth knowledge of information security and IT principles, protocols, practices, and industry standards
Experience conducting information security risk assessments, including cloud-based SaaS technologies such as AWS and Azure
Strong understanding of existing and emerging information security technologies
Strong communication and negotiation skills with senior staff and executives
Excellent report writing skills
Familiarity with contract wording and interpretation of security clauses
Ability to communicate with diverse business groups from a non-technical perspective and translate technical context into common business language
Ability to work with minimum supervision; strategic thinking, negotiation, and consensus-building abilities
Ability to work with diverse groups
Reliability Status Clearance required before starting employment
Government of Canada law enforcement inquiry and credit check
Must account for activities during any period lived or travelled outside Canada for 6 consecutive months during the last 5 years
Professional designation relating to Information Security, such as CISSP, CCSP, CISM, or CISA, is nice to have
Benefits
Wellness programs supporting mental, physical, and financial health
Variety of career paths with networking potential
Choice and flexibility to work from home or in the office based on business and Client needs
Incentive plans for eligible employees, subject to individual and company performance
Inclusive and supportive work environment
Accommodation in the application process for persons with disabilities
Security director at Intact, an insurer, protecting customer and broker digital channels and third - party risk platforms. Leading technical teams, governance, strategy, and security operations.
Enterprise Security Architect securing technology for Vancity, a member - owned Canadian credit union. Designing enterprise application security frameworks, controls, and risk - based cybersecurity solutions.
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.