About the Role and Job:
Job Title: Senior Security Advisor
Location: Markham, ON
Model: Hybrid (3 Days Onsite (Mon/ Tues/ Wed))
Job Type: Full time
Senior Advisor, Security Advisory Services
As Senior Advisor within the Security Advisory Services (SAS) team, this role will involve performing previews of Information Security Risk Assessments (ISRAs) deliverables for internal solutions and technology projects; and Third-Party Information Security Assessments (TPISA) deliverables
What you’ll do
- You will review (and where required) conduct ISRAs, TPISAs, manage and mitigate cybersecurity risks and conduct and other consulting requests.
- Provide oversight on assessments, risk identification and risk management processes, and tools for managing and reporting risks, and continuously improve the quality of services
- Identify gaps in existing processes and technology and develop remediation plans to address risks
- Assist in the development of cybersecurity risk reporting including the ongoing development and improvement of Key Risk Indicators (KRIs)
- Provide oversight to ensure identified cybersecurity risks are mitigated and are effectively communicated to partners, and managed with risk-prioritized timelines aligned with client’s risk appetite
Other key responsibilities include:
- Provide senior management and executives with information security trends, the status of identified risks, and the effectiveness of work activities
- Increase visibility of cybersecurity risks where and when appropriate with the respective collaborators when risk action plan target dates are not met
- Manage the pen test and business impact assessment programs
- Preparing for Internal Risks and Control Assessments
- Help improve team processes to continuously increase efficiency and quality standards
What you’ll bring:
- Minimum 10 years of strong, progressive experience in all of cybersecurity risk assessments, vendor assessments, and continuous risk management.
- Strong understanding of cybersecurity industry standards, principles and practices, as well as risk concepts. Understanding of application security design & architecture is an asset.
- Proven management and leadership skills in communication, prioritization and developing talent
- Demonstrated ability to communicate complex issues in a clear and concise manner to a wide range of audiences and stakeholders
- Demonstrated ability to navigate through ambiguity and guide team through changes
- Ability to understand complex processes and make sound judgement calls.
- Ability to negotiate and influence others to achieve optimal results.
- Knowledge of Ariba and Archer or other GRC management platforms.
- Post-secondary education in Computer Science, Computer Engineering, IT Security, risk management, or comparable professional training.
- Professional designation relating to cybersecurity or IT risk (e.g. CISSP, CISA, CISM, CCSP/CCSK, GIAC) preferred.