We use cookies to improve the user experience, analyze traffic and display relevant ads.
Details Accept
Enter position

Overview of salaries statistics of the profession "Information Security Risk Analyst in Canada"

Receive statistics information by mail
Unfortunately, there are no statistics for this request. Try changing your position or region.

Recommended vacancies

Security Compliance Analyst
Fortinet, Burnaby, BC
DescriptionWe are looking for a Security Compliance Analyst as a member of MIS team. This role will work to identify risk and ensure compliance with industry standards, relevant laws and regulations, industry best practices, and corporate policies. This position also assists in developing and maintaining internal security and operation framework. This team plays an integral role in our success, as the systems they manage underpin Fortinets day-to-day operations and a number of our client-facing applications. Responsibilities: •Work with operations staff to achieve compliance with SOC 2, ISO 27001, NIST, GDPR, and other security standards and regulatory frameworks. •Conduct risk assessment to information systems and business processes. •Develop IT policies and procedures, and provide improvement recommendations to current policies and procedures. •Collaborate with system administrators to ensure that appropriate controls are implemented, operating properly, in accordance with the corporate policies. •Conduct audit readiness assessments and coordinate with internal and external functions and audit resources. •Develop, collect and analyze security metrics to determine compliance and risk levels, as well as trends in systems and processes, and make recommendations on improvements and decisions based on information from the metrics. •Work closely with Corporate Information Security Team and other business units as required to understand IS related challenges and develop plans aimed at meeting those challenges. •Respond to request for information on security compliance from customers and partners. Qualifications and Experience: •Bachelor degree in Information Security/Systems, Computer/Electronic Engineering, Communications Engineering or related field, and eight (8) years of experience in information security, audit, compliance, risk management or related occupation •Experience in compliance management such as SOC 2, ISO 27001, NIST and GDPR. •Experience in design and implementation of information security policies and controls •Experience with core security technologies such as security information and event monitoring systems (SIEM), firewalls, network and host intrusion prevention and detection systems, proxies, vulnerability scanners, and anti-virus solutions •Experience with cloud security management •Demonstrated ability to understand and interpret audit, as well as security requirements •Superior interpersonal and communication skills •One or more of the following certifications preferred: ISO 27001 LA, CISSP, CCSP, CISA, and PMP #GD #LI-AV1
Security Compliance Analyst
Fortinet, Burnaby, BC
DescriptionWe are looking for a Security Compliance Analyst as a member of MIS team. This role will work to identify risk and ensure compliance with industry standards, relevant laws and regulations, industry best practices, and corporate policies. This position also assists in developing and maintaining internal security and operation framework. This team plays an integral role in our success, as the systems they manage underpin Fortinets day-to-day operations and a number of our client-facing applications. Responsibilities: • Work with operations staff to achieve compliance with SOC 2, ISO 27001, NIST, GDPR, and other security standards and regulatory frameworks. • Conduct risk assessment to information systems and business processes. • Develop IT policies and procedures, and provide improvement recommendations to current policies and procedures. • Collaborate with system administrators to ensure that appropriate controls are implemented, operating properly, in accordance with the corporate policies. • Conduct audit readiness assessments and coordinate with internal and external functions and audit resources. • Develop, collect and analyze security metrics to determine compliance and risk levels, as well as trends in systems and processes, and make recommendations on improvements and decisions based on information from the metrics. • Work closely with Corporate Information Security Team and other business units as required to understand IS related challenges and develop plans aimed at meeting those challenges. • Respond to request for information on security compliance from customers and partners. Qualifications and Experience: • Bachelor degree in Information Security/Systems, Computer/Electronic Engineering, Communications Engineering or related field, and eight (8) years of experience in information security, audit, compliance, risk management or related occupation • Experience in compliance management such as SOC 2, ISO 27001, NIST and GDPR. • Experience in design and implementation of information security policies and controls • Experience with core security technologies such as security information and event monitoring systems (SIEM), firewalls, network and host intrusion prevention and detection systems, proxies, vulnerability scanners, and anti-virus solutions • Experience with cloud security management • Demonstrated ability to understand and interpret audit, as well as security requirements • Superior interpersonal and communication skills • One or more of the following certifications preferred: ISO 27001 LA, CISSP, CCSP, CISA, and PMP #GD #LI-AV1
Information Technology Audit Senior Associate
PwC, Montreal, QC
A career in our External Audit Process Assurance practice, within Process Assurance services, will enable you to assist clients in optimising control activities, organisational strategy, and policies and procedures. You'll conduct transaction testing, perform readiness assessments, and leverage various technical Information Technology controls (e.g. databases, operating systems, data warehouses, and reporting tools) in order to help our clients achieve optimal operational efficiency.Our team helps organisations navigate the increasingly complex reporting environments by improving internal controls and increasing confidence in the quality of the information produced by their internal systems. We focus on the design, documentation, and operations of controls around the financial reporting process, including financial business process and Information Technology management controls.Meaningful work you'll be part ofAs a Information Technology Audit Senior Associate , you'll work as part of a team of problem solvers, helping to solve complex business issues from strategy to execution. Responsibilities include but are not limited to: •Provide management services, including assessment of technology risks, leveraging control frameworks (COSO, COBIT)•Participate in audits of IT Controls, testing of automated and manual business process controls, internal audits with an IT focus, Service Organization Control audits, ISO 27001 certification and projects in the general IT security space•Carrying out the work in an optimal fashion in compliance with deadlines and budgetary requirements outlined in the planning phase•Consult with our clients on operational controls and process improvement•Documenting clear and concise audit evidence obtained during the execution of the audit and validate their relevance and quality of information•Conducting analyses of control deficiencies noted during the course of the audit and their impact on financial data and the overall audit strategy•Establishing and maintaining collaborative relationships internally with PwC teams and external clients•Uphold the firm's code of ethics and business conductExperiences and skills you'll use to solve•Proven ability to document processes and controls, develop and execute testing programs•Strong knowledge of technology, IT practices and standards, infrastructure-related risks and controls in the areas of security and IT and IT control frameworks•Bachelor's degree in Accounting, Finance, Computer Science, or business related•Working towards CPA, CA, CMA, CGA, CIA, CGAP, Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM) or Certified Information Systems Security Professional (CISSP)•Strong in establishing priorities, and resolving problems•Exposure to data analytics and visualization tools•Excellent oral and verbal communication skills• The successful candidate requires fluency in English, in addition to French as they will be required to support or collaborate with English-speaking clients, colleagues and/or stakeholders during the course of their employment with PwC Canada • A demonstrated commitment to valuing differences and working alongside and/or coaching diverse people and perspectives Why you'll love PwC We're inspiring and empowering our people to change the world. Powered by the latest technology, you'll be a part of amazing teams helping public and private clients build trust and deliver sustained outcomes. This meaningful work, and our continuous development environment, will take your career to the next level. We reward your impact, and support your wellbeing, through a competitive compensation package, inclusive benefits and flexibility programs that will help you thrive in work and life. Learn more about us at http://pwc.com/ca/whypwc . Your Application to PwC We embrace new technology to deliver securely and differently for our candidates. To protect your personal information, apply at http://pwc.com/ca/careers and visit http://pwc.com/ca/applytopwc to learn more about what your recruitment experience could look like. The most connected firm through activity based working PwC Canada is committed to cultivating an inclusive, hybrid work environment - one that is collaborative, supportive and productive. We work in-person and virtually, as is best suited for our clients, teams and people. We want you to be intentional with your work, how you do it and where it's done. PwC offices are hubs of connectivity and learning. We strongly encourage our people to prioritise in-person work, whether it's in the office or at a client site. This means we expect you to be in-person (either with clients or in the office) at least half of your time. We know that hybrid work is all about balance, and capturing the benefits of in-person work is essential to your growth at the firm. Exact expectations for your team can be discussed with your interviewer. At PwC Canada, our most valuable asset is our people and we grow stronger as we learn from one another. We're committed to creating an equitable and inclusive community of solvers where everyone feels that they truly belong. We understand that experience comes in many forms and building trust in society and solving important problems is only possible if we reflect the mosaic of the society we live in.We're committed to providing accommodations throughout the application, interview, and employment process. If you require an accommodation to be at your best, please let us know during the application process.
Senior Security Analyst to modernize the departmental IT security program in the public sector
S.i. Systems, Ottawa, ON
Our valued public sector client is in need of a Secret cleared, Senior Security Analyst to modernize the departmental IT security program in the public sector and provide surge capacity in various areas related to IT security services delivery, such as security assessment of systems and projects, and risk management. Tasks and Deliverables: Prepare/edit/format documents and digital medial material such as user manuals, technical reports, strategic and policy documentation, intranet page content, graphics, illustrations, presentations, user help file and frequently asked questions, to support DND/CAF IT Security Programme Review documentation and recommend updates and formats to optimize communication effectiveness with targeted audiences Coordinate information gathering and multi-stakeholders’ content contribution to deliver quality and integrated documentation; Experience Required: Ten (10) years of combined experience within the last fifteen years developing and editing documentation supporting IT Security programmes, policies, procedures, associated Risk Management methodologies and escalation briefing materials, in an enterprise context. A university degree in a related discipline from a recognized college or university Experience developing IT Security strategic plans, programmes, policies, directives, standards, guidance, and/or related compliance/technical reports for Government of Canada departments/agencies. Two (2) security related certifications Apply
Senior Secret cleared IT Security TRA and C&A Analyst to review, analyze, and apply GC IT Security policies, SA&A processes and risk mitigation str
S.i. Systems, Ottawa, ON
Our valued Public sector client is in need of a Senior IT Security TRA and C&A Analyst to review, analyze, and apply GC IT Security policies, SA&A processes and risk mitigation strategies. Provide services to assess and analyze risks and develop Statements of Sensitivity (SOS) and Threat and Risk Assessments (TRA) as required for Cyber Security and Identity Management (CSIM) to perform Security Assessment and Authorization (SA&A) for current and future computing initiatives. We are looking for someone with the following, but not limited to, experience: 10 years as a IT Security TRA and C&A Analyst Experience developing any one (1) or more of the following types of reports for a Canadian Public sector client: data security analysis Concept of operations Statement of Sensitivity (SoS) Threat and Risk Assessment (TRA) Privacy Impact Assessment (PIA) Vulnerability Assessment Risk assessment. Experience identifying and modelling threats that pose a risk to a client’s systems and data and applying safeguards according to these threats during system design Experience creating complete Security Control Profiles by performing all of the following tasks to ensure that the solution architecture and its supporting processes and policies are assessed completely: Identifying the scope of the project. Establishing the set of security architecture components. Crafting a control profile on a per-component basis where one control may apply differently to each component, requiring separate evidence. Providing documented guidance as to acceptable evidence per control per component. Experience verifying that security safeguards for IT systems and infrastructure meet Government of Canada policies and standards and have been implemented correctly to meet assurance requirements Experience providing guidance to their client concerning the mitigation of security risks within the Public Cloud environment Two valid certifications from the following list: CISSP (Certified Information Systems Security Professional) from International Info System Security Certification Consortium Inc. (ISC)2 CCSP (Certified Cloud Security Professional) from (ISC)²) CISSP / ISSEP (advanced specialty Information Systems Security Engineering Professional) from (ISC)2 CISSP / ISSAP (advanced specialty information Systems Security Architecture Professional) from (ISC)2 CISSP / ISSMP (advanced specialty Information Systems Security Management Professional) from (ISC)2 CPP (Certified Protection Professional) from ASIS; CISA (Certified Information Systems Auditor) from ISACA CRISC (Certified in Risk and Information Systems Control) from ISACA; CISM (Certified Information Security Manager) from ISACA CBCP (Certified Business Continuity Professional) from DRI Certificate of Cloud Security Knowledge (Cloud Security Alliance) Apply
Regulatory Examination Specialist - Information Security
TD, Toronto, ON
Hours 37.5 Workplace Model Hybrid Pay Details We're committed to providing fair and equitable compensation to all our colleagues. As a candidate, we encourage you to have an open dialogue with your recruiter and ask compensation related questions, including pay details for this role.Department Overview Department Overview Building a World-Class, Diverse and Inclusive Technology Team at TDWe can't afford to be boring. Neither can you. The scale and scope of what TD does may surprise you. The rapid pace of change makes it a business imperative for us to be smart and open-minded in the way we think about technology. TD's technology and business teams become more intertwined as new opportunities present themselves. This new era in banking does not equal boring. Not at TD, anyway. TD Regulatory, Audit & Compliance Assurance is home to a team of highly valued professionals who provide support for all P&T related Regulatory and support interactions which includes business, 2nd, or 3rd LOD led exams. They provide support for all P&T related Regulatory and support interactions which includes business, 2nd, or 3rd LOD led exams. Provides oversight and governance over remediation, site visits, supervisory and inquiry activities to meet commitments to Regulators. Also, responsible for Merger & Acquisition integration into Assurance functions. There's room to grow in all of it. Job Details About This Role We are looking for someone to join our Platforms & Technology Regulatory, Audit & Compliance Assurance organization as Regulatory Exam Lead. The successful candidate will Manage global regulatory examinations, on-going supervisions, request for information, formal meeting for all of Technology by conducting the following activities: •Facilitation of Technology Regulatory Responses: •Act as primary intake and facilitator for Technology related Regulatory activities and requests •Coordination with key stakeholders and SMES to collect artifacts and evidence to respond to request items •Review of artifacts and evidence for executive approval, content and redaction prior to submission to the regulators •Assurance of timely submission of artifacts and reporting to the regulators •Organize and file digital artifacts and evidence •Facilitation of Formal Meetings: •Act as primary coordinator and facilitator for Technology related Regulatory sessions •Facilitate the preparation of agendas, speaking notes and presentation decks by coordinating with TCOs and SMEs •Facilitation of preparatory meetings with key stakeholders to review agendas, speaking notes and presentation deck •Facilitation and hosting of Formal Meetings with Regulators •Facilitation of executive and stakeholder debrief meetings and follow up items •Management Reporting: •Communicate and provide status reporting of the above activities to management and stakeholders •Liaise with other regulatory relations stakeholders outside of Technology •Work with Enterprise Technology Regulatory Management to improve the regulatory program management process to ensure regulatory activities met commitments, are performed efficiently and delivered timely with quality results •Promote and foster a cohesive team and positive work environment that encourages innovation, creativity and collaboration •Build and maintain positive working relationships by effectively communicating and regularly sharing information, issues/points of interest, learnings and knowledge with the team, internal and external business partners •Support management and other team members in the achievement of individual, divisional and team goals Job Requirements What can you bring to TD? Share your credentials and your relevant experience and knowledge. It helps if you have: •Undergraduate Degree or Technical Certificate. (Graduate Degree preferred). •7+ years relevant work experience in technology •CRISC certification or equivalent experience •CISA certification or equivalent experience •CISSP certification or equivalent experience a plus •University degree or relevant field / equivalent experience •Excellent English communication skills (written and oral), with experience interacting with all levels of management both within Company and Customer organizations •Ability to work in a high paced, multifaceted environment with minimal supervision •Ability to work independently and often autonomously in the management of projects, teams and operational disciplines and apply strategic thinking throughout the execution of work plans •Diverse, innovative thinking with respect to reusability of architecture and processes •Sound management techniques, experience in problem resolution and development of strategies for operational improvement •Drive to boost your knowledge and expertise by staying abreast of industry and business trends •Willingness to work closely and effectively with clients, stay connected to business needs and direction Additional Information Additional Information Join in on what others in TD Technology Solutions are doing: •Inspire a positve work environment and help champion quality, innovation, teamwork and service to the business. •Learn voraciously, stretch your thinking, share your knowledge and educate others. •Communicate and collaborate with both technical and non-technical professionals. •Cultivate winning relationships by building trust with business and technology partners. •Share our commitment to productivity, effectiveness and operational efficiency. •Embrace change and witness amazing things happen - from the inside. •Make your mark. Join a dynamic team. Explore new ideas. This is your opportunity to impact the future of banking technology in areas and ways you've never imagined (at a bank)! Visit techjobs.td.com to learn more. Company Overview Our ValuesAt TD we're guided by our purpose is to enrich the lives of our customers, communities and colleagues, and share a set of values that shape our culture and guide our behavior. In exchange for how our colleagues show up to help TD succeed, we are committed to delivering a colleague experience grounded in Impact, Growth and a Culture of Care. No matter where you work across TD, we empower you to make an impact at work and in your community, explore and grow your career and be part of our caring and inclusive culture. Making Your Well-being a PriorityA supportive culture that promotes colleague well-being is core to who we are. At TD, we focus on total well-being with extensive programs to help colleagues assess, manage, and improve their well-being across four core pillars - physical, financial, social and mental/emotional. In addition, we champion a safe and inclusive work environment so colleagues feel a sense of belonging and feel supported in their personal and professional growth. Through our focus on well-being, we know that we can help our colleagues thrive, contribute to our culture of care, and support better business outcomes, because when colleagues feel their best, they're more likely to do their best. Our Total Rewards PackageOur Total Rewards package reflects the investment we make in our colleagues to help them, and their families achieve their well-being goals. Total Rewards at TD includes a base salary, variable compensation, and several other key plans such as health and well-being benefits including medical, dental, vision & mental health coverage, savings and retirement programs, paid time off, banking benefits and discounts, career development, and reward and recognition programs. How We WorkAt TD, we believe in-person connections fuel collaboration and collective creativity. Our workplace experience empowers colleagues to do great work side-by-side at TD locations, while offering flexibility to work remotely where it makes sense for the work and team. Our teams work in one of three workplace models: Hybrid, Onsite and Primarily Remote. Wherever our colleagues are working, they'll always have access to the TD community and experience our culture of care. Who We AreTD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities and colleagues.TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you've got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we're here to support you towards your goals. As an organization, we keep growing - and so will you. Inclusiveness Our Commitment to Diversity, Equity, and Inclusion At TD, we're committed to fostering an environment where all colleagues are encouraged to bring their authentic selves to work, experience equitable opportunities, and feel respected and supported. We're dedicated to building an inclusive workforce that reflects the diversity of the customers and the communities in which we live and serve. Accommodation Your accessibility is important to us. Please let us know if you'd like accommodations (including accessible meeting rooms, captioning for virtual interviews, etc.) to help us remove barriers so that you can participate throughout the interview process. How We're Helping Make an Impact in Communities TD has a long-standing commitment to help drive progress towards a more inclusive and sustainable future. That's why we launched the TD Ready Commitment in 2018, now a multi-year North American initiative. Under the TD Ready Commitment, we are targeting a total of $1 billion by 2030 in community giving four key, interconnected drivers of change: Financial Security, Vibrant Planet, Connected Communities, and Better Health. It's our goal to help support change, nurture progress, and contribute to making the world a better, more inclusive place for our customers, colleagues, and communities. We look forward to hearing from you!
Senior IT Security Policy Analyst, to increase their security standards and compliance to the Government of Canada Guidelines
S.i. Systems, Ottawa, ON
Our Valued Public Sector Client is looking for a Senior IT Security Policy Analyst, to increase their security standards and compliance to the Government of Canada Guidelines Over the past several years our Public clients go through the use of both internal staff and contracted resources, conducting many initiatives, including threat and risk assessments. These initiatives are a part of an ever increasing commitment to comply with Government of Canada and Departmental policy requirements including the Management of Information Technology Security Standard. The results of all of these individual initiatives were examined as part of an initiative to identify enterprise safeguard requirements. Most recently, our client has adopted the Security Assessment and Authorization (SA&A) process under the IT Security Guideline 33 (ITSG-33) guidance and require the support of external professional resources. Tasks: Review and revise the policies, directives, standards, procedures, or programs related to IM & IT security; Develop the policies, directives, standards, procedures, or programs related to IM & IT security; Provide IM & IT security advice, guidance or recommendations in direct or indirect support of program objectives; Prepare and make presentation to senior management regarding aspects of work deliverables; and Mentor, train and/or provide advice to technical employees Must have: 10 years of experience of developing security policies and methodologies Nice to have: University Degree 5 projects developing Certification and Accreditation (C&A) program or a Security Assessment and Authorization (SA&A) program 2 project completing Mentorship and knowledge Transfer Apply
IT Security Vulnerability Analyst
High Tech Genesis Inc., Ottawa, ON, CA
High Tech Genesis is hiring an IT Security Vulnerability Analyst with 10+ years of experience and Reliability clearance. This position involves a comprehensive range of responsibilities focusing on assessing, analyzing, and addressing IT security threats and vulnerabilities. The ideal candidate should possess skills in assessing IT security configurations, identifying vulnerabilities, managing security tools, and interpreting security policies.Roles and responsibilities:1. Assess, analyze, and/or implement:• Analysis tools utilized by threat agents, alongside various emerging technologies such as privacy enhancement, predictive analysis, VoIP, data visualization and fusion, wireless security devices, as well as PBX and telephony firewall solutions.• War dialers, password crackers;• Public Domain IT vulnerability advisory services;• Network scanners and vulnerability analysis tools such as SATAN, ISS, Portscan & Nmap;• Networking Protocols (HTTP, FTP, Telnet);• Internet security protocols such as SSL, S-HTTP, S-MIME, IPsec, SSH, TCP/IP, UDP,• DNS, SMTP, SNMP;• Wireless Security;• Intrusion detection systems, firewalls and content checkers; and,• Host and network intrusion detection and prevention systems - Anti-virus management;2. Identify threats to, and technical vulnerabilities of, systems including web-facing applications;3. Conduct on-site assessments and analysis of system security logs;4. Collect, collate, analyze and disseminate public domain information related to network computer threats and vulnerabilities, security incidents and incident responses;5. Prepare and/or deliver IT Security threat, vulnerability and/or risk briefings;6. Complete tasks directly supporting the departmental IT Security and Cyber Protection Program;7. Develop and deliver training material relevant to the resource category;8. Prepare plan and approach documents including rules of engagement documents;9. Conduct assessments on departmental solutions and provide a risk and impact-based observations;10. Review, analyze and report on existing or potential IT security threats or vulnerabilities using security analysis tools and other emerging technologies;11. Develop test plans and customized testing methodologies based on Project Authority or their delegate’s approved engagement plans;12. Develop tailor-made scripts for system and database scans, analyze scan results to identify vulnerabilities, assess associated risks and impacts, propose solutions, and estimate the effort needed for remediation actions;13. Conduct configuration review and analysis over departmental IT security solutions, checking settings and maintenance processes;14. Test deployed IT security solutions for known security weaknesses using vulnerability testing techniques;15. Consult, interview and follow-up with key stakeholders, as appropriate;16. Collect and perform documentation review and analysis;17. Assess the implementation and application of security policies and procedures;18. Examine compliance monitoring and reporting and identify areas of non-compliance; and,19. Recommend remediation options based on proven results.Required skills and experience:• MUST possess a degree, diploma or certificate from a recognized university or college in a related information technology discipline;• Assess IT security configuration using threat agents’ analysis tools and technologies;• Identify vulnerabilities in IT solutions’ code and configuration settings;• Configure and manage IT security tools;• Identify the technical threats to, and vulnerabilities of, a broad range of IT security technologies of IT solutions including databases;• Conduct reviews and analysis of IT security solutions and practices and provide risks and impact of deviations from good practices;• Interpret IT security policies and standards to assess adherence within IT security operations and systems; and• Craft personalized scripts for scanning systems and databases, then assess scan results to generate reports detailing weaknesses, along with their associated risks, impacts, recommended fixes, and the level of effort required for remediation actions.The candidate MUST possess at least two (2) of the following certifications:• Global Information Assurance Certification (GIAC)• Security Essentials Certification (GSEC)• GIAC Security Expert (GSE)• GIAC Penetration Tester (GPEN)• GIAC Certified Incident Handler (GCIH)• EC-Council Certified Ethical Hacker (CEH)• CompTIA PenTest+• CompTIA Advanced Security Practitioner (CASP+)• Offensive Security Certified professional (OSCP)Note 1: You MUST be legally entitled to work in Canada (i.e., possess Canadian Citizenship, Permanent Residency or Valid Work Permit).Note 2: High Tech Genesis Inc. is an Equal Opportunity Employer.Note 3: Please submit an MS Word version of your resume when applying for this position.Note 4: Salary is commensurate with experience.
ISL 27R - Senior Security Analyst
BC Public Service, Fort Nelson, BC
Posting Title ISL 27R - Senior Security Analyst Position Classification Information Systems R27 Union GEU Work Options Remote Location Abbotsford, BC V2S 1H4 CACampbell River, BC V9W 6Y7 CACranbrook, BC V1C 7G5 CAFort Nelson, BC V0C 1R0 CAHope, BC V0X 1L0 CAKamloops, BC V2H 1B7 CAKelowna, BC V1Z 2S9 CAMultiple Locations, BC CA (Primary)Nanaimo, BC V9T 6L8 CANelson, BC V1L 6K1 CAPrince George, BC V2N4P7 CASmithers, BC V0J 2N0 CASurrey, BC V4P 1M5 CAVancouver, BC V6B 0N8 CAVictoria, BC V9B 6X2 CAWilliams Lake, BC V2G 5M1 CASalary Range $88,636.83 - $101,099.95 annually which includes a 9.9% Temporary Market Adjustment* Close Date 4/7/2024 Job Type Regular Full Time Temporary End Date Ministry/Organization BC Public Service -> Min of Trans & Infrastructure Ministry Branch / Division Information Management Branch Job Summary Take the next step in your IT career with this rewarding opportunityThe Ministry of Transportation and Infrastructure (MoTI) plans transportation networks, provides transportation services and infrastructure, develops and implements transportation policies, and administers many related acts, regulations and federal-provincial funding programs. The Ministry strives to build and maintain a safe and reliable transportation system and provide affordable, efficient and accessible transportation options for all British Columbians. This work includes investing in road infrastructure, public transit, cycling network improvements and other green modes of transportation, reducing transportation-related greenhouse gas emissions, and strengthening the economy through the movement of people and goods. The Ministry invests in highway rehabilitation and side road improvements, which includes road resurfacing, bridge rehabilitation and replacement, seismic retrofits, intersection improvements and upgrades to smaller side roads to help connect communities.Within the Ministry of Transportation and Infrastructure, the Information Management Branch (IMB) is part of the Strategic and Corporate Priorities (SCP) division. The SCP division's mission is to be a trusted partner using talent and technology to collaboratively lead and facilitate cross-ministry and corporate initiatives that support innovation, service excellence, and an engaged workforce. To support the mission, the IMB is leading the delivery of user-centered digital data products in partnership with ministry programs to support an effective and integrated transportation system.The Senior Security Analyst delivers an information technology and operational technology security program, ensuring all systems conform to corporate security policy and security best practices. The Senior Security Analyst carries out vulnerability assessments on a variety of information technology and operational technology applications, networks and IoT devices at the Ministry's Regional Transportation Management Centre in Coquitlam, BC.Job Requirements: Degree in computer science field or equivalent and four years related experience; OR Diploma in computer science field or equivalent and five years related experience; OR Secondary school graduation or equivalent and seven years related experience. Certified Information Systems Security Professional designation or Certified Ethical Hacker designation, or equivalent. Experience with the use of vulnerability discovery tools, such as NMAP, Burp Suite, or Open Web Application Security Project Zed Attack Proxy (OWASP ZAP), or equivalent. Related experience includes the following: Experience, preferably with a security focus and in a Microsoft environment. Experience with all aspects of IT security including current technologies and best practices. Experience with the installation, configuration, maintenance and problem resolution of hardware, software, operating systems, and network components. Preference may be given to applicants with any of the following: Experience working with Operational Technology (OT). OT is defined as hardware and software that detects or causes a change through the direct monitoring and/or control of physical devices, processes and events in the enterprise. Experience with industrial control systems security. Experience conducting security threat risk assessments or web application security assessments. For questions regarding this position, please contact [email protected] .About this Position: Remote work is allowed, this position can work up to full time from their home in British Columbia subject to an approved telework agreement. This position can be based in any Ministry of Transportation & Infrastructureoffice. The locations listed above are to assist applicants in searching for this opportunity and are not a complete list of locations. An eligibility list may be established to fill future temporary and permanent vacancies. Please refer to MyHR for more information on Temporary Market Adjustments . Depending on the successful candidate's location, a bi-weekly isolation allowance may apply. Employees of the BC Public Service must be located in BC at the time of employment.Working for the BC Public Service: The BC Public Service is committed to creating a diverse workplace to represent the population we serve and to better meet the needs of our citizens. Consider joining our team and being part of an innovative, inclusive and rewarding workplace.The Indigenous Applicant Advisory Service is available to applicants that self-identify as Indigenous (First Nations, status or non-status, Métis, or Inuit) seeking work or already employed in the BC Public Service. For guidance on applying and interviewing, please contact [email protected] or 778-405-3452.The BC Public Service is an award-winning employer and offers employees competitive benefits, amazing learning opportunities and a chance to engage in rewarding work with exciting career development opportunities. For more information, please see What We Offer .To learn more about these B.C communities you can click on the Hello BC link here! How to Apply: Your application must clearly demonstrate how you meet the job requirements listed above.Cover Letter: NO - Please do not submit a cover letter as it will not be reviewed.Resume: YES - Ensure your resume includes your educational accomplishments, employment history including start and end dates (month and year) of your employment, and any relevant information that relates to the job to which you are applying.Questionnaire: YES - You will need to complete a comprehensive questionnaire to demonstrate how you meet the job requirements. Include all relevant information about your educational accomplishments and employment history including job titles, start and end dates (month and year) of your employment, and how you obtained your relevant experience. The questionnaire will take approximately 60 minutes to complete.Helpful tips, videos and more regarding the application process can be found on the Your Job Application page of MyHR. If you are experiencing technical difficulty applying, e-mail [email protected] , before the stated closing time, and we will respond as soon as possible.Additional Information: A Criminal Record Check (CRC) will be required.Applicants selected to move forward in the hiring process may be assessed on the Knowledge, Skills, Abilities and Competencies as outlined in the attached Job Profile located at the bottom of the posting.Applications will be accepted until 11:00 pm Pacific Time on the closing date of the competition.Job Category Information Management/Information Technology
Senior Manager - Business Information Security (BISO), Deloitte Global Technology
Deloitte,
Job Type:Permanent Work Model:Hybrid Reference code:126047 Primary Location:Toronto, ON All Available Locations:Ottawa, ON Our Purpose At Deloitte, we are driven to inspire and help our people, organization, communities, and country to thrive. Our Purpose is to build a better future by accelerating and expanding access to knowledge. Purpose defines who we are and gives us reason to exist as an organization. By living our Purpose, we will make an impact that matters. Enjoy flexible, proactive, and practical benefits that foster a culture of well-being and connectedness. Experience a firm where wellness matters. Be expected to share your ideas and to make them a reality. Deloitte Global is the engine of the Deloitte network. Our professionals reach across disciplines and borders to develop and lead global initiatives. We deliver strategic programs and services that unite our organization.What will your typical day look like?As the Business Information Security (BISO) Senior Manager you will serve as a trusted advisor to solution architects, developers, technical risk analysts and others oninformation security principles, standards, and best practices. Key Responsibilities: Understand the assigned global line of business, gain familiarity with priorities and become an advocate forthe line of business within cybersecurity. Drive organizational change and work with multiple business units of a large organization to effect change. Oversee and help drive design and implementation of application security controls in support of compliancerequirements using secure design and development methodologies. Support the Secure Systems Development Lifecycle (SSDLC), including functional and non-functionalcybersecurity requirements. Strive for process improvement and automation; help development and operations team build automationfor repeatable Cyber related vulnerability management activities. Maintain awareness of evolving application security threats and inform development, business, and riskstakeholders. Provide application-specific security subject matter expertise to assigned customers. Evaluate the likelihood and impact of application vulnerabilities; develop and drive mitigation approaches. Lead, coach, and mentor project teams to incorporate security into enterprise and client-facing applications. About the teamDeloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in "what is" but rather "what can be" to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.Enough about us, let's talk about youRequired: 10+ years of related experience, including cybersecurity and/or risk management experience in organizations of a similar scale or client-service experience in the field. Minimum 5 years of experience in application security, software development, and/or security architecture. Minimum 5 years of leadership / team management experience. C-level and executive interaction experience. Demonstrated experience driving strategy with cross-functional executive level stakeholders. Demonstrated ability to drive organizational change and work with multiple business units of a large organization to effect change. Exceptional verbal and written communication skills. Must be able to interact effectively with professionals at all levels and communicate recommendations with diplomacy and tact. Knowledge of Azure, AWS, and GCP technologies. Experience conducting or managing application penetrating and/or vulnerability testing. Experience with cloud security principles and functions. Experience developing and communicating application security vision, strategy and roadmap. Familiarity with SOC 2 principles; experience in application security to meet SOC 2 requirements preferred. Solid capabilities across multiple security domains such as identity and access management (IAM), public-key encryption, security information and event management (SIEM), incident response, threat & vulnerability management Total RewardsThe salary range for this position is $104,000 - $215,000, and individuals may be eligible to participate in our bonus program. Deloitte is fair and competitive when it comes to the salaries of our people. We regularly benchmark across a variety of positions, industries, sectors, targets, and levels. Our approach is grounded on recognizing people's unique strengths and contributions and rewarding the value that they deliver.Our Total Rewards Package extends well beyond traditional compensation and benefit programs and is designed to recognize employee contributions, encourage personal wellness, and support firm growth. Along with a competitive base salary and variable pay opportunities, we offer a wide array of initiatives that differentiate us as a people-first organization. Some representative examples include: $4,000 per year for mental health support benefits, a $1,300 flexible benefit spending account, 38+ days off (including 10 firm-wide closures known as "Deloitte Days"), flexible work arrangements and a hybrid work structure.Our promise to our people: Deloitte is where potential comes to life. Be yourself, and more. We are a group of talented people who want to learn, gain experience, and develop skills. Wherever you are in your career, we want you to advance. You shape how we make impact. Diverse perspectives and life experiences make us better. Whoever you are and wherever you're from, we want you to feel like you belong here. We provide flexible working options to support you and how you can contribute. Be the leader you want to be. Be the leader you want to be Some guide teams, some change culture, some build essential expertise. We offer opportunities and experiences that support your continuing growth as a leader. Have as many careers as you want. We are uniquely able to offer you new challenges and roles - and prepare you for them. We bring together people with unique experiences and talents, and we are the place to develop a lasting network of friends, peers, and mentors. Our TVP is about relationships - between leaders and their people, the firm and its people, peers, and within in our communities.The next step is yours At Deloitte, we are all about doing business inclusively - that starts with having diverse colleagues of all abilities. Deloitte encourages applications from all qualified candidates who represent the full diversity of communities across Canada. This includes, but is not limited to, people with disabilities, candidates from Indigenous communities, and candidates from the Black community in support of living our values, creating a culture of Diversity Equity and Inclusion and our commitment to our AccessAbility Action Plan , Reconciliation Action Plan and the BlackNorth Initiative . We encourage you to connect with us at [email protected] if you require an accommodation for the recruitment process (including alternate formats of materials, accessible meeting rooms or other accommodations) or [email protected] for any questions relating to careers for Indigenous peoples at Deloitte (First Nations, Inuit, Métis). By applying to this job you will be assessed against the Deloitte Global Talent Standards. We've designed these standards to provide our clients with a consistent and exceptional Deloitte experience globally. Deloitte Canada has 30 offices with representation across most of the country. We acknowledge our offices reside on traditional, treaty and unceded territories as part of Turtle Island and is still home to many First Nations, Métis, and Inuit peoples. We are all Treaty people.Job Segment: Information Security, Cyber Security, Developer, Cloud, Risk Management, Technology, Security, Finance
ISL 24R - Information Security Analyst
BC Public Service, Fort Nelson, BC
Posting Title ISL 24R - Information Security Analyst Position Classification Information Systems R24 Union GEU Work Options Remote Location Burnaby, BC V3J 1N3 CACampbell River, BC V9W 6Y7 CAChilliwack, BC V4Z 1A7 CAFort Nelson, BC V0C 1R0 CAKamloops, BC V2H 1B7 CAKelowna, BC V1Z 2S9 CAMultiple Locations, BC CA (Primary)Nanaimo, BC V9T 6L8 CANelson, BC V1L 6K1 CAPrince George, BC V2N4P7 CASmithers, BC V0J 2N0 CASurrey, BC V4P 1M5 CAVancouver, BC V6B 0N8 CAVictoria, BC V9B 6X2 CAWilliams Lake, BC V2G 5M1 CASalary Range $78,729.94 - $ 89,687.19 annually which includes a 6.6% Temporary Market Adjustment*, plus $36.53 bi-weekly isolation allowance for Smithers; $53.13 bi-weekly Isolation allowance for Fort Nelson. Close Date 4/4/2024 Job Type Regular Full Time Temporary End Date Ministry/Organization BC Public Service -> Water,Land,ResourceStewardship Ministry Branch / Division IM/IT Governance and Digital Strategy Branch Job Summary Bring your in-depth knowledge and experience with Information Security to this opportunityNatural Resource Information & Digital Services (NRIDS)is the information management/information technology (IM/IT) service provider and organizational partner to the Natural Resource Ministries (NRM). As the centralized authority for all information, geospatialdata, and technology across the NRM, NRIDS is leading the transformation and modernization of business practices through new and innovative technology solutions, continuous improvement projects and operational IM/IT solutions.NRIDS provides broad information management services and leadership in data custodianship by way of the creation, maintenanceand publication of foundational datasets and geospatial information. NRIDS is also responsible for the full range of services to maintain and support all existing IT systems for the NRM as well as the development of new applications to deliver on government objectives. NRIDS is committed to client engagement and understanding the business needs of the NRM to identify where expert knowledge, technology and data/information solutions will help the sector deliver their programs and services more effectively.The purpose of this position is toconduct Threat Risk Assessments; lead the development of policies and standards for security information systems; provide security architecture planning; research and investigate incidents, threats, and exposures, and implement controls and risk-reducing measures to mitigate the threat of future exposures.Explore the opportunities and value working with our team can offer you: Why Work for the Ministry of Water, Land, Resource & Stewardship Job Requirements: Bachelor's degree in computer science/information technology or a related field, and a minimum of 6 months information security experience, OR A Diploma in computer science/information technology or related field, and a minimum of 1 year information security experience. An equivalent combination of education and experience may be considered. Experience in identifying and evaluating risks from a business and technological standpoint. Preference may be given to candidates with one or more of the following: Experience building and maintaining relationships with a wide range of partners in a workplace. Experience in conducting security threat and risk assessments. Professional designation as a Certified Information Systems Security Professional or Certified Information Security Manager, or equivalent certifications. For questions regarding this position, please contact [email protected] .About this Position: Currently there is one (1) permanent position available.Please refer to MyHR for more information on Temporary Market Adjustments .This position can be based in any Ministry of Water, Land, and Resource Stewardship office. Some of the locations available are Victoria, Prince George, Kamloops, Vancouver, Nanaimo, Surrey, Kelowna, Chilliwack, Campbell River, Fort Nelson, Nelson, Smithers and Williams Lake.Remote work is allowed, this position can work up to full time from their home in British Columbia subject to an approved telework agreement. The locations listed above are to assist applicants in searching for this opportunity and are not a complete list of locations.An eligibility list may be established for future permanent vacancies.Employees of the BC Public Service must be located in BC at the time of employment.Working for the BC Public Service:The BC Public Service is committed to creating a diverse workplace to represent the population we serve and to better meet the needs of our citizens. Consider joining our team and being part of an innovative, inclusive and rewarding workplace.The Indigenous Applicant Advisory Service is available to applicants that self-identify as Indigenous (First Nations, status or non-status, Métis, or Inuit) seeking work or already employed in the BC Public Service. For guidance on applying and interviewing, please contact [email protected] or 778-405-3452.How to Apply:Your application must clearly demonstrate how you meet the job requirements listed above.Cover Letter: NO - Please do not submit a cover letter as it will not be reviewed.Resume: YES - A resume is required as part of your application, however, it may not be used for initial shortlisting purposes.Questionnaire: YES - You will need to complete a comprehensive questionnaire to demonstrate how you meet the job requirements. Include all relevant information about your educational accomplishments and employment history including job titles, start and end dates (month and year) of your employment, and how you obtained your relevant experience. The questionnaire will take approximately 60 minutes to complete.Helpful tips, videos and more regarding the application process can be found on the Your Job Application page of MyHR. If you are experiencing technical difficulty applying, e-mail [email protected] , before the stated closing time, and we will respond as soon as possible.Additional Information:A Criminal Record Check (CRC) will be required.Applicants selected to move forward in the hiring process may be assessed on the Knowledge, Skills, Abilities and Competencies as outlined in the attached Job Profile located at the bottom of the posting.Applications will be accepted until 11:00 pm Pacific Standard Time on the closing date of the competition.Job Category Information Management/Information Technology, Policy, Research and Economics
ISL 27R - Senior Information Security Analyst
BC Public Service, Fort Nelson, BC
Posting Title ISL 27R - Senior Information Security Analyst Position Classification Information Systems R27 Union GEU Work Options Remote Location Burnaby, BC V3J 1N3 CACampbell River, BC V9W 6Y7 CAChilliwack, BC V4Z 1A7 CAFort Nelson, BC V0C 1R0 CAKamloops, BC V2H 1B7 CAKelowna, BC V1Z 2S9 CAMultiple Locations, BC CA (Primary)Nanaimo, BC V9T 6L8 CANelson, BC V1L 6K1 CAPrince George, BC V2N4P7 CASmithers, BC V0J 2N0 CASurrey, BC V4P 1M5 CAVancouver, BC V6B 0N8 CAVictoria, BC V9B 6X2 CAWilliams Lake, BC V2G 5M1 CASalary Range $88,636.83 - $101,099.95 annually which includes a 9.9% Grid Temporary Market Adjustment* $53.13 bi-weekly isolation allowance for Fort Nelson $36.53 bi-weekly isolation allowance for Smithers Close Date 4/8/2024 Job Type Regular Full Time Temporary End Date Ministry/Organization BC Public Service -> Water,Land,ResourceStewardship Ministry Branch / Division IM/IT Governance and Digital Strategy Branch Job Summary Contribute your valued expertise in strategy, design and service delivery to this fast-paced opportunity Natural Resource Information & Digital Services (NRIDS) is the information management/information technology (IM/IT) service provider and organizational partner to the Natural Resource Ministries (NRM). As the centralized authority for all information, geospatial data, and technology across the NRM, NRIDS is leading the transformation and modernization of business practices through new and innovative technology solutions, continuous improvement projects and operational IM/IT solutions.NRIDS provides broad information management services and leadership in data custodianship by way of the creation, maintenance and publication of foundational datasets and geospatial information. NRIDS is also responsible for the full range of services to maintain and support all existing IT systems for the NRM as well as the development of new applications to deliver on government objectives. NRIDS is committed to client engagement and understanding the business needs of the NRM to identify where expert knowledge, technology and data/information solutions will help the sector deliver their programs and services more effectively.The Natural Resource ministries provide a challenging opportunity to develop and execute a security program for 6 BC Government Ministries. Many projects and/or programs require cross-ministry oversight, where corporate security policy, procedures and relevant legislation must be well understood to be successful. The senior security analyst will play a key role to deliver an information technology security program, and meets the highest security standards for a variety of sensitive information for citizens that consume our services.Explore the opportunities and value working with our team can offer you: Why Work for the Ministry of Water, Land, Resource & Stewardship .Job Requirements: Bachelor's degree in computer science/information technology or a related field, and a minimum of two (2) years information security experience, OR A Diploma in computer science/information technology or a related field, and a minimum of four (4) years information security experience OR An equivalent combination of education and experience may be considered. Two (2) years experience in identifying and evaluating risks from a business and technological standpoint. Preference may be given to candidates with one or more of the following: Experience building and maintaining relationships with a wide range of partners in a workplace. Experience in conducting security threat and risk assessments. Professional designation as a Certified Information Systems Security Professional or Certified Information Security Manager, or equivalent certifications. Experience conducting information security investigations. For questions regarding this position, please contact [email protected] About this Position: Currently there is 1 permanent opportunity available. Remote work is allowed. This position can work up to full time from their home in British Columbia as per the Telework Agreement. This position can be based in any Ministry of Water, Land, and Resource Stewardship office. Some of the locations available are Victoria, Prince George, Kamloops, Vancouver, Nanaimo, Surrey, Kelowna, Chilliwack, Campbell River, Fort Nelson, Nelson, Smithers and Williams Lake. The locations listed are to assist applicants in searching for this opportunity and are not a fulsome list of locations. Alternate locations may be considered. An eligibility list may be established for future permanent vacancies. Employees of the BC Public Service must be located in BC at the time of employment. Please refer to MyHR for more information on Temporary Market Adjustments .Working for the BC Public Service: The BC Public Service is committed to creating a diverse workplace to represent the population we serve and to better meet the needs of our citizens. Consider joining our team and being part of an innovative, inclusive and rewarding workplace.The Indigenous Applicant Advisory Service is available to applicants that self-identify as Indigenous (First Nations, status or non-status, Métis, or Inuit) seeking work or already employed in the BC Public Service. For guidance on applying and interviewing, please contact [email protected] or 778-405-3452.The BC Public Service is an award-winning employer and offers employees competitive benefits, amazing learning opportunities and a chance to engage in rewarding work with exciting career development opportunities. For more information, please see What We Offer .How to Apply: Your application must clearly demonstrate how you meet the job requirements listed above.Cover Letter: NO - Please do not submit a cover letter as it will not be reviewed.Resume: YES -A resume is required as part of your application, however, it may not be used for initial shortlisting purposes.Questionnaire: YES -You will be prompted to complete a comprehensive online questionnaire to demonstrate how you meet the job requirements. Ensure you include all relevant information about your educational accomplishments and employment history including job titles, start and end dates (month and year) of your employment, and how you obtained your relevant experience. Please allot approximately 60 minutes to complete the questionnaire.Helpful tips, videos and more regarding the application process can be found on the Your Job Application page of MyHR. If you are experiencing technical difficulty applying, e-mail [email protected] , before the stated closing time, and we will respond as soon as possible.Additional Information: CRC - A Criminal Record Check (CRC) will be required.Applicants selected to move forward in the hiring process may be assessed on the Knowledge, Skills, Abilities and Competencies as outlined in the attached Job Profile located at the bottom of the posting.Applications will be accepted until 11:00 pm Pacific Standard Time on the closing date of the competition.Job Category Information Management/Information Technology
ISL 21R - Security and Financial Systems Governance Analyst
BC Public Service, Vancouver, BC
Posting Title ISL 21R - Security and Financial Systems Governance Analyst Position Classification Information Systems R21 Union GEU Work Options Hybrid Location Multiple Locations, BC CA (Primary)Vancouver, BC V6B 0N8 CAVictoria, BC V9B 6X2 CASalary Range As of April 7, 2024, $69,760.70 - $79,322.69 Close Date 4/9/2024 Job Type Regular Full Time Temporary End Date Ministry/Organization BC Public Service -> Ministry of Finance Ministry Branch / Division CAS/OCG Job Summary An excellent career opportunity to apply your security expertise, analytical and organizational competencies in an innovative environment.The Office of the Comptroller General (OCG) is the lead governance organization for the financial management function in the BC Government. OCG's strategic objectives include setting the strategic direction for government's financial management functions including frameworks, systems and people. It ensures an effective corporate governance framework that supports the delivery of government programs and ensures accountability.The Corporate Accounting Services (CAS) supports the Comptroller General in meeting their broad statutory responsibilities by managing the design, development, delivery, and ongoing support for the mission-critical Corporate Financial System (CFS) for the BC Government.Under the guidance and support of the Senior Team Lead, IM-IT Governance and Strategy, the Security and Financial Systems Governance Analyst will play a key role in safeguarding the integrity of the Province's financial information by: Conducting risk-based reviews of the Branch's internal controls to ensure robust financial data integrity. Overseeing activities related to the Province's financial IT ecosystem, ensuring a secure and efficient system. Coordinating assessments conducted by independent parties, developing action plans based on the findings. Tracking progress on the Branch's strategic initiatives and ensuring alignment with organizational goals. This role demands an understanding of second line-of-defense activities, with a focus on maintaining the highest standards in financial information security.Job Requirements: Diploma in computer science related field OR completion of coursework leading to information security credential; AND One (1) year of experience in applying and actively interpreting information technology management and security best practices and organizational policies; OR An equivalent combination of education, training, and experience. Preference may be given to applicants with one (1) or more of the following: Additional education and/ordesignation: degree, diploma, designation or equivalent in accounting, auditing, and/or risk management. Experience in accounting, auditing, and/or risk management . Experience in assessing or advising on controls and risks for a complex financial or Enterprise Resource Planning (ERP) system. For questions regarding this position, please contact [email protected] .About this Position: Flexible work options are available; this position may be able to work up to four (4) days at home per week subject to an approved telework agreement. This position can be based out of any of the location(s) listed above. An eligibility list may be established to fill future temporary and permanent vacancies. Employees of the BC Public Service must be located in BC at the time of employment.Working for the BC Public Service: The BC Public Service is committed to creating a diverse workplace to represent the population we serve and to better meet the needs of our citizens. Consider joining our team and being part of an innovative, inclusive and rewarding workplace.The Indigenous Applicant Advisory Service is available to applicants that self-identify as Indigenous (First Nations, status or non-status, Métis, or Inuit) seeking work or already employed in the BC Public Service. For guidance on applying and interviewing, please contact [email protected] or 778-405-3452.The BC Public Service is an award-winning employer and offers employees competitive benefits, amazing learning opportunities and a chance to engage in rewarding work with exciting career development opportunities. For more information, please see What We Offer .How to Apply: Your application must clearly demonstrate how you meet the job requirements listed above.Cover Letter: NO - Please do not submit a cover letter as it will not be reviewed.Resume: YES - A resume is required as part of your application, however, it may not be used for initial shortlisting purposes.Questionnaire: YES - You will need to complete a comprehensive questionnaire to demonstrate how you meet the job requirements. Include all relevant information about your educational accomplishments and employment history including job titles, start and end dates (month and year) of your employment, and how you obtained your relevant experience. The questionnaire will take approximately 60 minutes to complete.Helpful tips, videos and more regarding the application process can be found on the Your Job Application page of MyHR. If you are experiencing technical difficulty applying, e-mail [email protected] , before the stated closing time, and we will respond as soon as possible.Additional Information: A Criminal Record Check (CRC) will be required.Applicants selected to move forward in the hiring process may be assessed on the Knowledge, Skills, Abilities and Competencies as outlined in the attached Job Profile located at the bottom of the posting.Applications will be accepted until 11:00 pm Pacific Standard Time on the closing date of the competition.Job Category Information Management/Information Technology
IT Security Risk Analyst [OneIT]
WSP Canada, Montreal, QC
WSP's Information Security Office (ISO) is responsible for the deployment and maintenance of the information security framework for both the IT organization and wider business community. This includes the Governance mechanisms, policies and processes, tools and technologies, and employee training required to protect WSP information and that of our clients. To run our global Technology &Cyber Risk Management process, we are seeking 2 IT Risk Analysts. This role will report to the Senior Manager for Technology and Cyber Risk. As a Risk Analyst, you will be supporting the Technology &Cyber Risk Manager in running IT risk management process . You will work closely with IT teams to manage technology-related risks and foster relationships. This role requires good analytical, excellent organizational skills and the ability to work effectively in a diverse, global environment. You will need to be able to prioritize tasks and manage your time effectively. MAIN RESPONSIBILITIES Support the implementation of a comprehensive and effective IT risk management practice across the WSP global IT organisation. This should include facilitating the identification of potential IT risks, the evaluation of their impact, the formulation of strategies to mitigate these risks, and the tracking of their mitigation and/or acceptance. Assist the Security Risk Manager in conducting regular monitoring and review of the IT risk management process to ensure its effectiveness and alignment to the organization's risk appetite and business objectives. Facilitate delivery of IT risk management training within the IT community and support establishing a culture of risk-aware decision-making, accountability, and a commitment to maintaining an effective control environment. Analyze and process data related to risks, issues and deficiencies to identify patterns and trends. Create visualizations and reports that communicate the insights gained from the data. Understand and assimilate rapidly technology, and risk management concepts and dependencies. Be a subject matter expert in relation to the management of the Integrated Risk Management Platform (Service-Now IRM). This includes entities, risk statements and controls management. Be the central point of contact for all support related to the Risk platform. Proactive and display independence and autonomy in performing the role. Requirements: About you: 3 to 5 years related experience in Information Technology, experience in Security is a plus. Knowledge of technology (applications, network, etc) Experience with IT Governance frameworks such as ISO 27001 Experience with governance, compliance, and audit within IT environments Limited travelling may be required. A degree in information technology, or related field. Experience working in large/global enterprise IT is a plus. Due to the nature of this role, you may need to work outside of standard business hours occasionally. Preferred Knowledge of Service-Now Integrated Risk Management platform (IRM) Professional certification is a plus, in one or more of the following disciplines - IT governance (e.g., CGEIT), security (e.g., CISSP, CISM), internal audit (CISA) or Payment Card Industry (PCI) WSP is one of the world's leading professional services firms. Our purpose is to future proof our cities and environments.We have over 65,000 team members across the globe. In Canada, our 12,000+ people are involved in everything from environmental remediation to urban planning, from engineering iconic buildings to designing sustainable transportation networks, from finding new ways to extract essential resources to developing renewable power sources for the future.At WSP: We value our people and our reputation We are locally dedicated with international scale We are future focused and challenge the status quo We foster collaboration in everything we do We have an empowering culture and hold ourselves accountable Please Note:Health and Safety is a core paramount value of WSP. Given the importance of keeping one another safe it is expected that you comply with our Health, Safety & Environment (HSE) policy at all times as well as client HSE policies when working at client locations.Offers of employment for safety-sensitive positions involving fieldwork are contingent upon candidates being able to perform key physical tasks of the job as described in the job posting and interview. This may include the ability to work in a variety of environmental conditions, such as remote or isolated areas, working alone, and in inclement weather (within safe and reasonable limits).WSP welcomes and encourages applications from people with disabilities. Accommodations are available on request for candidates taking part in all aspects of the selection process.WSP is committed to the principles of employment equity. Only the candidates selected will be contacted.WSP does not accept unsolicited resumes from agencies. For more information please READ THE FULL POLICY.
Intermediate Project Analyst to coordinate activities for a network security project
S.i. Systems, Vancouver, BC
Our client is looking for an Intermediate Project Analyst to coordinate activities for a network security project10-month contract, 20hrs/week, working primarily remote within BC. Must Have:3-5 years related experience in a project coordination or project management in a technical environmentFamiliarity with managing projects in kanban/agile style and utilizing work management tools such as Jira.Nice to Have:Experience with the gaming industry. Experience working with a Crown corporation.Experience with Evergreen IT and coordinating technical debt. Demonstrated experience with moderate to large technical implementations, preferably in the Identity & Access Management, Networking Systems, and Information Security spaces.Responsibilities:Data Analysis: collecting, analyzing, and interpreting project data to identify trends, patterns, and insights that can inform decision-making and drive project success. Reporting: generating regular reports, dashboards, and presentations to communicate project status, progress, and key performance indicators to stakeholders, product owners, and leadership. Project Planning Support: assisting in project planning activities, including defining project scope, objectives, timelines, and deliverables, to ensure alignment with organizational goals and priorities. Risk Management: identifying, assessing, and mitigating project risks by analyzing potential issues, developing risks mitigation strategies, and monitoring risk factors throughout the project lifecycle. Documentation Management: maintaining accurate and up-to-date project documentation, including project plans, meeting minutes, action items, and decision logs, to ensure compliance with organizational standards and facilitate knowledge transfer. Resource Allocation: supporting product owners in resource allocation activities by tracking resource availability, utilization, and allocation to ensure optimal utilization of resources and alignment with project requirements. Stakeholder Communication: facilitating communication and collaboration among agile team members, stakeholders, and cross-functional teams to ensure alignment on project objectives, priorities, and deliverables. Quality Assurance: monitoring project deliverables and processes to ensure they meet quality standards, adhere to project requirements, and align with organizational policies and procedures.Process Improvement: identifying opportunities for process improvement, efficiency gains, and best practices in project management methodologies, tools, and processes to enhance project outcomes and drive continuous improvement. Support to Product Owners: providing administrative and analytical support to product owners, including scheduling meetings, preparing, agendas, tracking action items, and assisting with project-related tasks as needed to facilitate project success. Other tasks as reasonably required by the Project Manager. Apply
DevSecOps – Senior Security Scanning Analyst (GCS)
RBC, Toronto, ON
Job SummaryJob DescriptionWhat is the opportunity?We are looking for a DevSecOps Senior Security Scanning Analyst. who is energetic, enthusiastic, well organized and has a passion for cybersecurity and development to join our team. We are a team that requires an eager go-getter who wants to take charge, provide valuable client support and become a dependable team player within the organization. We focus specifically on security scanning of Infrastructure such as Servers, VMs, Workstation, Network devices etc. Were looking for an experienced Developer who has a deep interest in Python Development, Cloud & Cyber Security to join us on our journey to scaling out our Scanning operations. Youll have the opportunity to work with some of the most advanced security scanning technologies while developing solutions to automate & enhance scan operations.What will you do?Designing, modifying, developing, writing, and implementing software programming applications for target systems using agile methods.Acquiring client requirements; and resolving workflow problems through automation optimization.Writing source codes for new applications, and/or generating and enhancing code samples for existing applications.Utilizing automated testing tools to perform the testing and maintenance.You will engineer & maintain a highly scalable, flexible, and fault-tolerant Infrastructure Security Tool instance hosted on-prem and cloud. Transition services to Infrastructure code.Co-lead the ongoing enhancements to our security Scanning services. Further security integration and collaboration with our core CI/CD Pipeline.Perform health checks on the scanning tools to monitor stability and verify scan jobs are completed promptly to ensure a smooth security scanning operation.Introduce further cross-collaboration integrations to our scanning tools such as Log Management (Splunk, Datadog, Kibana, Grafana, Prometheus), Tableau Reporting, ServiceNow CMDB, and Slack notifications.Learn how to interpret Vulnerability scan results and investigate False Positive ClaimsWhat do you need to succeed?Must-haveStrong Python programming skills; making API Calls, hands-on experience with GitHub and familiarity with managing Infrastructure as CodeStrong understanding of UNIX, Linux, Windows infrastructure and cloud computing technologiesExcellent communication skills with demonstrated ability to communicate in technical and non-technical environments.Experience in troubleshooting large applications with multiple data sources and system interfaces.Problem-solving ability to analyze and prioritize work to meet business objectives in a secure and risk-based approach.Analytical mindset and awareness of fundamental security practicesExperience with vulnerability management processes and scanning products (such as Tenable, Qualys, Aqua, Prisma)Nice-to-haveFamiliarity with Service Now, JIRA, Confluence and working in an agile environment.Experience with public and private cloud platforms such as AWS, Azure, GCP, OpenShift or PCFSecurity or Cloud-related CertificationsFamiliarity with the financial services industry is a plus, but not required (well teach you the business domain knowledge!)Whats in it for you? We thrive on the challenge to be our best, progressive thinking to keep growing, and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference to our communities, and achieving success that is mutual.A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicableLeaders who support your development through coaching and managing opportunitiesAbility to make a difference and lasting impactWork in a dynamic, collaborative, progressive, and high-performing teamFlexible work/life balance optionsOpportunities to do challenging workOpportunities to take on progressively greater accountabilitiesOpportunities to building close relationships with clients#techpj#LI-POST#Li-hybridJob SkillsInformation Technology (IT) Infrastructure, Programming Languages, Software Change Request Management, Software Development Life Cycle (SDLC), Software Engineering, Software Integration Engineering, Software Product Design, Software Product Technical Knowledge, Software Release Management, System Testing ToolsAdditional Job DetailsAddress:330 FRONT ST W:TORONTOCity:TORONTOCountry:CanadaWork hours/week:37.5Employment Type:Full timePlatform:Technology and OperationsJob Type:RegularPay Type:SalariedPosted Date:2024-03-28Application Deadline:2024-05-03Inclusion and Equal Opportunity EmploymentAt RBC, we embrace diversity and inclusion for innovation and growth. We are committed to building inclusive teams and an equitable workplace for our employees to bring their true selves to work. We are taking actions to tackle issues of inequity and systemic bias to support our diverse talent, clients and communities.We also strive to provide an accessible candidate experience for our prospective employees with different abilities. Please let us know if you need any accommodations during the recruitment process.Join our Talent CommunityStay in-the-know about great career opportunities at RBC. Sign up and get customized info on our latest jobs, career tips and Recruitment events that matter to you.Expand your limits and create a new future together at RBC. Find out how we use our passion and drive to enhance the well-being of our clients and communities at jobs.rbc.com.
Senior Cyber Security Analyst, IAM Onboarding (GCS)
RBC, Toronto, ON
Job SummaryJob DescriptionWhat is the opportunity? The ideal candidate is passionate about information security for Identity Access Management capabilities across tools, applications, and systems. As a Senior Cyber Security Analyst in the Identity Access Management (IAM) Team, you will work with the IAM Application Onboarding Team to integrate RBC applications onto IAM solutions (CyberArk, Entra ID (Azure), Sailpoint IIQ, GDS, etc). This process will require you to work with a wide range of technology and business stakeholders to implement IAM solutions, managing end to end. What will you do?Work with business partners and application teams across RBC Enterprise to explain the onboarding process and document requirements.Work with business partners and application teams to ensure data remediation is completed including orphan, description clean-up, role creation, Segregation of Duties (Toxic Combination) policy creation in the IAM SailPoint Tool.Provide Consultative services to ensure teams are in compliance with our standards within Global Cyber Security (GCS)Identify and Report security risks in accordance to our RBC StandardsParticipate in internal/external audits, establish, monitor, and coordinate action plans.Accountable for consultation and issue resolution as first point of inquiry/escalation and problem resolution for IAM onboarding activities.Participates in project planning and management activities across multiple effortsParticipate in all aspects of onboarding testing as requested by the onboarding team: This may include:Test case scenarios creation and assisting with test case writingAssisting with FST, UAT, OAT, and PIV testingProvide support with tasks and ad hoc requests as requiredSuggest/document solutions to improve the efficiency of the onboarding process.What do you need to succeed?Must-haveIn depth experience with IAM solutions.IAM experience with strong knowledge in Requirements methods: interviewing, data modeling, business process modeling, business object modeling and user interface designHands-on with different requirement methodologies: methodology of Object Orientation, Use Cases, Unified Modeling Language, Agile and waterfall approachExperience with the IAM domain including related IAM capabilities & toolsUnderstanding of Cloud Identity as a service (IDaaS) for SaaS, PaaS and IaaSUnderstanding of various technology platforms and application stack configurations (LDAP, Active Directory, ZVM, etc)Data analysis and reporting skills.Nice-to-haveIdentity and access management provisioning and de-ProvisioningExperience working with SailPoint IIQ, Cyberark, Azure AD, ServiceNowIT Standards, Methodologies, CMM & audit requirementsAuthentication - SSO (Single Sign on), Multi-Factor AuthenticationAuthorization (Role Based Access Authorization and Conditional Access Control)Familiar with Agile methodologies and tools including Jira, ConfluenceProfessional certification(s) related to information security or information risk management such as CRISC, CISA, CISM, CISSPWhats in it for you? We thrive on the challenge to be our best, progressive thinking to keep growing, and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference to our communities, and achieving success that is mutual.A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicableLeaders who support your development through coaching and managing opportunitiesAbility to make a difference and lasting impactWork in a dynamic, collaborative, progressive, and high-performing teamA world-class training program in financial servicesFlexible work/life balance optionsOpportunities to do challenging workOpportunities to take on progressively greater accountabilitiesOpportunities to building close relationships with clientsAccess to a variety of job opportunities across business and geographies#techpj#LI-POST#LI-hybridJob SkillsConfidentiality, Cyber Security Management, Decision Making, Detail-Oriented, Encryption Software, Group Problem Solving, High Impact Communication, Information Security Management, Information Technology SecurityAdditional Job DetailsAddress:VANCOUVER MAIN BRANCH (B), 1055 GEORGIA ST W:VANCOUVERCity:VANCOUVERCountry:CanadaWork hours/week:37.5Employment Type:Full timePlatform:Technology and OperationsJob Type:RegularPay Type:SalariedPosted Date:2024-04-04Application Deadline:2024-05-03Inclusion and Equal Opportunity EmploymentAt RBC, we embrace diversity and inclusion for innovation and growth. We are committed to building inclusive teams and an equitable workplace for our employees to bring their true selves to work. We are taking actions to tackle issues of inequity and systemic bias to support our diverse talent, clients and communities.We also strive to provide an accessible candidate experience for our prospective employees with different abilities. Please let us know if you need any accommodations during the recruitment process.Join our Talent CommunityStay in-the-know about great career opportunities at RBC. Sign up and get customized info on our latest jobs, career tips and Recruitment events that matter to you.Expand your limits and create a new future together at RBC. Find out how we use our passion and drive to enhance the well-being of our clients and communities at jobs.rbc.com.
Technology Risk Oversight Senior Analyst, Global Risk and Brand Protection
Deloitte,
Job Type:Permanent Work Model:Remote Reference code:126162 Primary Location:Toronto, ON All Available Locations:Toronto, ON; Burlington, ON; Calgary, AB; Ottawa, ON; St. John's, NL; Vancouver, BC; Victoria, BC Our Purpose At Deloitte, we are driven to inspire and help our people, organization, communities, and country to thrive. Our Purpose is to build a better future by accelerating and expanding access to knowledge. Purpose defines who we are and gives us reason to exist as an organization. By living our Purpose, we will make an impact that matters. Enjoy flexible, proactive, and practical benefits that foster a culture of well-being and connectedness. Experience a firm where wellness matters. Be expected to share your ideas and to make them a reality. What will your typical day look like? Strategic Align with the firm's technology risk management strategy to actively contribute to the development of best practices, based on research and industry best practices in regulatory and risk governance matters. Gain awareness of new and emerging technologies being deployed and assist the firm in strengthening internal controls and improving technology risk management and business performance. Demonstrate and encourage an agile mind set to enable effective IT risk management while driving adaptability to ongoing changes in technologies, risks, regulations, and stakeholder expectations. Gain awareness of implementable risk governance methodologies and programs that deliver on stakeholder expectations and support the strategic and annual planning processes with a focus on maturing the Technology & Cyber Risk Management capabilities. Operational Support the first line of defense technology risk policy review processes. Fulfill activities to determine the effectiveness of technology controls mitigating key technology risks, support the identification of control enhancements in end-to-end processes, provide challenges on remedial actions, and share insights and best practices with relevant business units as a proactive measure to reduce the likelihood and impact of future risk events. Demonstrate and apply strong project management skills, inspire teamwork and responsibility with team members, and use current technology and tools to enhance the effectiveness of deliverables and services. Support assessment activities through remote or onsite assessments with various subject matter experts. Support initiatives to educate technology functions on technology risk management requirements according to regulatory requirements, firm policy, data classification, client commitments, etc. Demonstrate and apply a working understanding of technology trends to identify issues and communicate this information to the management team through written correspondence and verbal presentations. Work alongside project managers to: Document results of the work performed Review deliverables for completeness and accuracy Assist with preparing team operational schedules and cost estimates Provide additional project management and administration support to management and leadership, as required Perform other job-related duties, as assigned. Relationship Management Build strong relationships with key internal stakeholders and relevant first line of defense Technology Risk Management, technology teams, and member firms, as needed. Maintain regular communication with the management team, including escalation of findings, where applicable. About the team Global Risk & Brand Protection protects, preserves and enhances the Deloitte brand. We navigate the dynamic risk landscape across the areas of risk management, confidentiality & privacy, cyber security oversight, regulatory, independence & conflicts, and Anti-Corruption/financial crimes. We foster trusting relationships across the Deloitte network through collaboration, facilitation and responsive guidance.Enough about us, let's talk about you Basic knowledge of significant security and privacy laws and regulations in the Americas, Europe, Middle East, Asia, Africa, and Oceania is preferable (e.g., GDPR). Working knowledge in two or more of the following IT and risk domains: cloud hosting, infrastructure, cyber security, secure SDLC, service management, data protection, privacy, IT risk management, maturity assessments, third-party risk management. (Cloud, RPA, Artificial Intelligence) and ways of working (Agile/SAFe) in the context of applicable regulatory requirements and IT delivery model. Experience in developing and applying standards, principles, methods, and supporting IT risk governance practices in a medium-scale to large-scale Information Security, Technology environments. Analytical and problem-solving mindset; demonstrated ability to synthesize large amounts of data in short periods of time for consumption by multiple stakeholders. Effective relationship-building, communication, presentation, and interpersonal skills. Highly disciplined, with strong organizational abilities. Ability to multi-task, prioritize work and work independently. Possess exceptional level of integrity and customer focus. Total RewardsThe salary range for this position is $69,000 - $114,000, and individuals may be eligible to participate in our bonus program. Deloitte is fair and competitive when it comes to the salaries of our people. We regularly benchmark across a variety of positions, industries, sectors, targets, and levels. Our approach is grounded on recognizing people's unique strengths and contributions and rewarding the value that they deliver.Our Total Rewards Package extends well beyond traditional compensation and benefit programs and is designed to recognize employee contributions, encourage personal wellness, and support firm growth. Along with a competitive base salary and variable pay opportunities, we offer a wide array of initiatives that differentiate us as a people-first organization. Some representative examples include: $4,000 per year for mental health support benefits, a $1,300 flexible benefit spending account, 38+ days off (including 10 firm-wide closures known as "Deloitte Days"), flexible work arrangements and a hybrid work structure.Our promise to our people: Deloitte is where potential comes to life. Be yourself, and more. We are a group of talented people who want to learn, gain experience, and develop skills. Wherever you are in your career, we want you to advance. You shape how we make impact. Diverse perspectives and life experiences make us better. Whoever you are and wherever you're from, we want you to feel like you belong here. We provide flexible working options to support you and how you can contribute. Be the leader you want to be. Be the leader you want to be Some guide teams, some change culture, some build essential expertise. We offer opportunities and experiences that support your continuing growth as a leader. Have as many careers as you want. We are uniquely able to offer you new challenges and roles - and prepare you for them. We bring together people with unique experiences and talents, and we are the place to develop a lasting network of friends, peers, and mentors. Our TVP is about relationships - between leaders and their people, the firm and its people, peers, and within in our communities.The next step is yours At Deloitte, we are all about doing business inclusively - that starts with having diverse colleagues of all abilities. Deloitte encourages applications from all qualified candidates who represent the full diversity of communities across Canada. This includes, but is not limited to, people with disabilities, candidates from Indigenous communities, and candidates from the Black community in support of living our values, creating a culture of Diversity Equity and Inclusion and our commitment to our AccessAbility Action Plan , Reconciliation Action Plan and the BlackNorth Initiative . We encourage you to connect with us at [email protected] if you require an accommodation for the recruitment process (including alternate formats of materials, accessible meeting rooms or other accommodations) or [email protected] for any questions relating to careers for Indigenous peoples at Deloitte (First Nations, Inuit, Métis). By applying to this job you will be assessed against the Deloitte Global Talent Standards. We've designed these standards to provide our clients with a consistent and exceptional Deloitte experience globally. Deloitte Canada has 30 offices with representation across most of the country. We acknowledge our offices reside on traditional, treaty and unceded territories as part of Turtle Island and is still home to many First Nations, Métis, and Inuit peoples. We are all Treaty people.Job Segment: Cyber Security, Senior Brand Manager, Law, Risk Management, Developer, Security, Marketing, Legal, Finance, Technology
Analyst, Information Security
Fed IT, Montreal, QC
Hello,I'm Clémence, recruitment and business development consultant at FED IT, a recruitment agency specializing in IT professions.I work on two types of recruitment: temporary and permanent.All our consultants are IT experts who speak your language and work in your environment. We cover the full range of IT professions: development, business intelligence and infrastructure.Do you like a challenge and want to join an enthusiastic, dynamic team? Your technical knowledge and focus on the customer experience will help you excel in this position. We are looking for an Information Security Analyst to contribute to the evolution of our security strategy and prioritize the implementation of key initiatives. Under the supervision of the Team Leader, Information Security, you will play a key role in protecting our organization's confidential and sensitive information. This includes securing online and onsite infrastructures, monitoring daily activities to identify irregularities and suspicious activity, and detecting and mitigating the risk of a breach. In the event of a breach, the analyst will be on the front line, advising and actively participating in incident response efforts to eradicate the incident and thereby identify, contain and facilitate recovery efforts. What will you do: - You monitor infrastructure activity using logs and analytics ; - You assess attack surface and risk levels through vulnerability testing and analysis; - You provide security advice in the various stages of systems and services procurement and deployment; - 50% governance 50% operational - You advise and participate in the response to cyber incidents, identify the root cause and recommend corrective and preventive actions to be applied; - You maintain relevant documentation (i.e. policies, SOPS, IRP, etc.); - You work in collaboration with external security partners and consultants.- You have a minimum of five (5) years' experience in network administration (client workstations and servers). (client workstations and servers); - You have a minimum of three (3) years' experience in system administration (Switch, Router, Firewall); - You have professional certification in information security (AZ-900, Security+, SSCP, GSEC, NSE 4, CCNA); - You have an understanding of cybersecurity frameworks, standards and guidelines such as such as NIST CSF, ISO 27001 and financial services industry regulations industry regulations; - You are familiar with the Microsoft ecosystem; - Experience as a technology security specialist in networks, servers, databases, software development or another technical discipline will be considered. other technical discipline will be considered an asset. Skills and Abilities: - You are a creative thinker and motivated to work independently and directly with teams from different business units; - You demonstrate dedication, teamwork and professionalism; - You have the ability to communicate effectively and efficiently with diverse audiences; - You have a professional level of English and French, both written and spoken (English is essential for day-to-day tasks).
Analyst, Compliance and Risk Management
KPMG, Toronto, ON
OverviewAt KPMG, you'll join a team of diverse and dedicated problem solvers, connected by a common cause: turning insight into opportunity for clients and communities around the world. Our Compliance & Risk Management Group in Business Enablement Services is looking for an Analyst, Risk Management, to join our growing team. The Compliance & Risk Management Group helps ensure the firm and its personnel are in compliance with Professional, Regulatory, and KPMG Global policies and standards. This role focuses on monitoring for compliance with standards and policies pertaining to personal independence, including those established by the Securities and Exchange Commission (SEC), Public Company Accounting Oversight Board (PCAOB), CPA Code of Professional Conduct (CPA Code), IESBA Code of Ethics for Professional Accountants (IESBA Code) and American Institute of Certified Public Accountants (AICPA). This is a remote position. What you will do Develop an understanding of the applicable independence rules and KPMG internal policies, through consulting with subject matter experts and reading policies in our internal risk management manual. Conduct personal independence compliance audits, monitoring for compliance with firm and professional independence standards. Assess, summarize, and escalate potential policy breaches to the Compliance Manager. Monitor the KICS help desk (email/telephone) / research and respond to inquiries related to reporting investments in KICS and personal independence policies, ensuring timely and accurate responses. Assist partners and staff with other compliance tasks as required. Provide support on ad-hoc project work. Assist with the development of other operational/project documentation. At times, business needs arise, and employees are required and agree to work beyond their normal workday or work week to fulfill the accountabilities required for their job. Likewise, people need time to devote to personal matters, and our approach to flexibility provides for this. What you bring to the role Post-Secondary education in a related discipline, or equivalent work experience in an administrative function with a background in business or finance preferred. Demonstrated research and analytical skills with the ability to interpret and apply standards accordingly. Proficient written and verbal communication skills including the ability to respond promptly and professionally to requests and inquiries. Experience working in a high-volume work environment with the ability maintain high quality deliverables while prioritizing and working under pressure. Ability to work independently with minimal supervision and collaboratively as part of a remote team. Experience engaging with senior level stakeholders, and the ability to build and maintain professional relationships at all levels of the organization. The ability to handle sensitive/confidential information appropriately. Proficiency with Microsoft suite of products, including advanced skills with Excel (specifically VLOOKUP and pivot table). Proficiency in English at a business level is required. This position requires written and oral fluency in English. The successful candidate may be required to support or collaborate with English-speaking colleagues or stakeholders while at KPMG. KPMG BC Region Pay Range Information The expected base salary range for this position is $53,000 to $79,500 and may be eligible for bonus awards. The determination of an applicant's base salary within this range is based on the individual's location, skills & competencies, and unique qualifications. In addition, KPMG offers a comprehensive and competitive Total Rewards program Providing you with the support you need to be at your best For more information about KPMG in Canada's Benefits and well-being, click here . Our Values, The KPMG WayIntegrity, we do what is right | Excellence, we never stop learning and improving | Courage, we think and act boldly | Together, we respect each other and draw strength from our differences | For Better, we do what matters KPMG in Canada is a proud equal opportunities employer and we are committed to creating a respectful, inclusive and barrier-free workplace that allows all of our people to reach their full potential. A diverse workforce is key to our success and we believe in bringing your whole self to work. We welcome all qualified candidates to apply and hope you will choose KPMG in Canada as your employer of choice. For more information about Inclusion, Diversity & Equity in Recruitment, please click here . Adjustments and accommodations throughout the recruitment processAt KPMG, we strive for an inclusive recruitment process that allows all candidates to Come As You Are and Thrive with Us. We aim to provide a positive experience and are ready to offer adjustments or accommodations to help you perform at your best. Adjustments (an informal request), i.e. extra preparation time or the option for micro breaks during interviews, and accommodations (a formal request), i.e. accessible communication supports or technology aids are tailored to individual needs and role requirements. To begin a confidential conversation about adjustments or accommodations at any point throughout the recruitment process, we encourage you to contact KPMG's Employee Relations Service team for support by emailing [email protected] or by calling 1-888-466-4778, Option 3. For information about accessible employment at KPMG, please visit our accessibility page .