Role: Cybersecurity Metrics and Controls Specialist
Location: Montreal; Hybrid: 3 days a week in office
Long Term Contract(12 months contract to start with)
We need someone with expertise in Cybersecurity Controls, Controls Governance, Controls Testing, Metrics, KRIs/KPIs, and Risk & Compliance Reporting.
Mandatory Skills:
Cybersecurity controls framework and governance
Controls design, implementation, and effectiveness testing
Security metrics, KPIs, KRIs, and reporting
Risk management and regulatory compliance
Control monitoring and remediation tracking
Stakeholder management and executive-level reporting
Cybersecurity Metrics and Controls Specialist
The successful candidate will join the Continuous Controls Monitoring (CCM) team and be part of the Metric Design & Architecture team. The team quantifies and reports on the implementation correctness and operating efficiency of Technology controls.
· Establish and document Control/Risk metric definition for Technology controls by engaging with various Stakeholders, understanding processes and analyzing data for accurate measure.
· Engage with Technology Policy team to ensure Control Measurement/Metric requirements are met through Policy design/update process.
· Partner with various Metric consumers to establish Reporting framework meeting their requirements.
· Partner closely with CCM Data acquisition and tooling team for successful implementation of metrics
· 10+ years of experience in information security or/and information technology
· 5+ years hands-on experience with technology or cybersecurity control implementations.
· Ability to define metrics/ Key Control Indicators to show control implementation completeness
· Strong business acumen and a strategic mindset
· Experience working with and understanding the needs of customers or clients
· Strong interpersonal skills, to interact at all levels and be effective as part of a broader team
· Ability to manage expectations and handle high-pressure situations with tight deadlines
· Proven analytical skills decision-making ability based on quantitative and qualitative data. Knowledge of various domains of Technology control / Cybersecurity
· Knowledge of Public cloud technology
· Knowledge of security concepts and tools around Identity &Authentication, Data Security, System security, Network Security and Application security.
· Knowledge of security logging, monitoring, and incident response
· Cybersecurity certifications is preferred