What you'll do
Developing and maintaining Information and Cyber Security Governance documents, including Policies, Standards, and Procedures/Guidelines/Process documents.
Obtaining agreement, managing, monitoring, and reporting on cyber risks.
Conducting annual risk assessments to identify any new or change in list of CTB's crown jewels.
Preparing reports on CTB's cyber risk profile for the Cross-functional Risk Committee (CRC).
Promoting a strong cyber risk and information security culture within the organization.
Performing annual Information Security and Control vendor assessments on all CTB vendors in accordance with the Outsourcing Policy.
Reviewing hardware and software to identify any gaps in services and solutions.
Ensuring deficiencies are remediated and conducting appropriate tests to verify the operating effectiveness of controls.
Building and maintaining effective partnerships with various stakeholders across the organization.
Developing, implementing, and rolling out a self-assessment process that incorporates risk and controls assessment in day-to-day activities.
Assisting vendor management in ensuring successful execution of the Annual IT Inherent Risk Assessment, including adjusting execution for any changes to the CEO/CFO certification process arising from new and/or changing risk areas.
Contributing to the identification and adoption of state-of-the-art tools, technology, and techniques to optimize risk and controls assessment services.
Escalating any material cyber-related issues and observed non-compliance or unethical behavior.
What you bring
University degree or college diploma in technology.
Completed professional certifications, such as CISSP, CISM, CISA, CCSP etc.
7+ years of experience in understanding risks, audits and processes relating to Information/Cyber Security and IT.
5+ years of strong management experience in a complex organization.
Experience designing and implementing security programs with a focus on governance, cyber security, security monitoring and vulnerability management.
Thorough understanding and experience of various Information and Cyber Security standards and frameworks, such as NIST CSF, ISO 27001/2, CSA, PCI DSS and COBIT etc.
Good knowledge and understanding of regulatory requirements applicable to Canadian FIs.
The ability to clearly and confidently communicate risks and associated trade-offs.
Excellent relationship management, consulting, problem-solving and report writing skills.
Flexible to adjust to changing priorities and timelines.
Ability to travel as required to other office locations such as Toronto, Welland and Calgary.
We’re always looking for great talent! In addition to competitive pay, we offer:
Comprehensive benefits and retirement programs
Performance incentives, Continuing Education Programs
Other perks to support your well-being
Career growth opportunities and product discounts
Our typical hiring range is between $79,000.00 and $131,000.00 per annum. Salary decisions are also dependent on other factors such as your experience, job-related knowledge, skills and competencies, market location, industry benchmarks, internal equity and other role-specific requirements. We're committed to attracting top talent. For critical roles, the compensation offering will be reviewed to ensure alignment with market rate and conditions and the unique value you bring to the role. #LI-AG2
This posting represents an existing vacancy within our organization.À propos de nous
Chez Services Canadian Tire Limitée/Banque Canadian Tire, il est de notre mandat de continuer à créer des solutions financières novatrices et avantageuses pour nos clients. Notre gamme croissante d’articles et de services témoigne de la contribution dynamique de nos employés et notre succès repose sur une vision forte, des clients fidèles et notre capacité à constituer des équipes qui reflètent la diversité des clients et des communautés dans lesquelles nous vivons et travaillons. Joignez-vous à nous, il y a une place pour vous ici!
Notre engagement envers la diversité, l’inclusion et l’appartenance
Nous nous engageons à favoriser un environnement où le sentiment d’appartenance est florissant et où la diversité, l’inclusion et l’équité font partie intégrante de tout ce que nous faisons. Nous croyons en la création d’une culture organisationnelle où les gens sont traités en tout temps avec dignité dans le respect de la religion, de la nationalité, du sexe, de la race, de l’âge, de la capacité perçue, de la langue parlée, de l’orientation sexuelle et de l’identité de chacun. Nous sommes unis dans notre objectif d’être ici pour contribuer à améliorer la vie au Canada.
Accommodements
Nous tenons fermement à notre valeur fondamentale d’inclusion. Nous accueillons et encourageons les candidats issus de groupes en quête d’équité, comme les personnes racisées, les Autochtones, les membres de la communauté 2SLGBTQIA+, les femmes, les personnes handicapées et autres. Si vous avez besoin d’accommodements pour postuler à ce poste ou lors de l’entrevue, veuillez-nous le faire savoir lorsque vous nous contacterez, et nous travaillerons avec vous pour répondre à vos besoins.
Chef, Sécurité de l’information • Oakville