Information Security Officer at Vecima Networks responsible for ISMS maintenance and ISO compliance. Supporting governance activities, supplier security, and incident response during maternity leave coverage.
Responsibilities
Maintain and improve Vecima’s Information Security Management System (ISMS)
Support ISO/IEC 27001:2022 governance activities, including risk assessments, risk treatment tracking, control documentation, evidence collection, corrective actions, audit readiness, and follow-up on gaps
Coordinate periodic management reviews, policy and standards reviews, control updates, and related governance activities to support continuous improvement of the information security program
Maintain security metrics, dashboards, risk registers, and status reporting for leadership
Support and coordinate supplier security reviews, including due diligence, security questionnaires, risk assessments, remediation follow-up, and ongoing monitoring of higher-risk suppliers
Work with Supply Chain, Legal, internal business owners, and other stakeholders to ensure information security requirements are incorporated into supplier onboarding, contracting, monitoring, and offboarding processes
Use GRC, ISMS, and TPRM tools, including Optro (formerly AuditBoard), to manage security documentation, assessments, workflows, and evidence as applicable
Partner with internal stakeholders to define security requirements, assign action owners, track remediation, and escalate material security risks or unresolved issues as needed
Communicate security obligations, risks, and progress clearly to technical and non-technical audiences
Contribute to the development, implementation, and continuous improvement of the organization’s information security strategy aligned with business objectives
Stay current with emerging threats, security trends, and relevant technologies to help maintain an effective and practical security posture
Promote a strong culture of security awareness across the organization and support the delivery of effective security education and awareness activities
Support maintenance of the incident response plan and coordinate investigations, documentation, corrective actions, and follow-up activities related to security incidents
Requirements
Post-secondary education in Information Technology, Cybersecurity, Computer Science, or a related discipline, or an equivalent combination of education and experience
5+ years of relevant experience in information security, IT risk, compliance, audit, governance, or a related field
Strong practical experience with ISO/IEC 27001:2022 and with operating and maintaining an ISMS
Experience developing, maintaining, and improving information security policies, standards, procedures, and governance documentation
Experience performing or coordinating security risk assessments, audit support, remediation tracking, and evidence collection
Knowledge of cloud and SaaS environments and common security controls
Strong written and verbal communication skills, with the ability to work effectively with technical and non-technical stakeholders
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.
Join RBC's Application Security Group to develop innovative security solutions, mentor junior staff, and collaborate across teams to enhance decision - making and automate tasks.
Lead SCADA and cybersecurity engineer designing compliant substation systems for GE Vernova. Guiding project teams, vendor designs, estimates, and acceptance testing for cleaner energy infrastructure.
Senior security advisor simulating cyber threats and strengthening defenses for Desjardins, North America's largest cooperative financial group. Leading complex initiatives, methodologies and cybersecurity risk mitigation.
SA&A Lead securing Azure applications and Microsoft platforms for PLATO, Canada’s Indigenous - owned software testing company. Leading authorization, control testing, evidence collection, and risk remediation.
Senior security advisor simulating and mitigating cyberthreats for Desjardins, North America's largest cooperative financial group. Leading offensive security methodologies, tools and strategic initiatives.
Staff Product Security Engineer building customer identity and authentication services for Affirm’s buy - now - pay - later platform. Designing secure, scalable CIAM backend systems and integrations.
Senior Security Engineer securing AWS infrastructure, production systems, and AI - driven workflows. Building guardrails, vulnerability remediation, monitoring, and incident response for a rapidly scaling platform.