Position Name – Senior Security Advisor
Type of hiring – Fulltime
Location – Markham, ON (Mandatorily need to visit office 3 days – Mon/Tue/Wed)
Candidate needs to be onsite Mon/Tue/Wed (this is mandatory)
Job Description:
As Senior Advisor within the Security Advisory Services (SAS) team, this role will involve performing previews of Information Security Risk Assessments (ISRAs) deliverables for internal solutions and technology projects; and Third-Party Information Security Assessments (TPISA) deliverables
What you’ll do
- You will review (and where required) conduct ISRAs, TPISAs, manage and mitigate cybersecurity risks and conduct and other consulting requests.
- Provide oversight on assessments, risk identification and risk management processes, and tools for managing and reporting risks, and continuously improve the quality of services
- Identify gaps in existing processes and technology and develop remediation plans to address risks
- Assist in the development of cybersecurity risk reporting including the ongoing development and improvement of Key Risk Indicators (KRIs)
- Provide oversight to ensure identified cybersecurity risks are mitigated and are effectively communicated to partners, and managed with risk-prioritized timelines aligned with client’s risk appetite
Other key responsibilities include:
- Provide senior management and executives with information security trends, the status of identified risks, and the effectiveness of work activities
- Increase visibility of cybersecurity risks where and when appropriate with the respective collaborators when risk action plan target dates are not met
- Manage the pen test and business impact assessment programs
- Preparing for Internal Risks and Control Assessments
- Help improve team processes to continuously increase efficiency and quality standards
What you’ll bring:
- Minimum 10 Years of strong, progressive experience in all of cybersecurity risk assessments, vendor assessments, and continuous risk management.
- Strong understanding of cybersecurity industry standards, principles and practices, as well as risk concepts.
- Understanding of application security design & architecture is an asset.
- Proven management and leadership skills in communication, prioritization and developing talent
- Demonstrated ability to communicate complex issues in a clear and concise manner to a wide range of audiences and stakeholders
- Demonstrated ability to navigate through ambiguity and guide team through changes
- Ability to understand complex processes and make sound judgement calls.
- Ability to negotiate and influence others to achieve optimal results.
- Knowledge of Ariba and Archer or other GRC management platforms.
- Post-secondary education in Computer Science, Computer Engineering, IT Security, risk management, or comparable professional training.
- Professional designation relating to cybersecurity or IT risk (e.g. CISSP, CISA, CISM, CCSP/CCSK, GIAC) preferred.