Technology and Cyber Risk Manager [OneIT]

WSP Canada
Montreal, Quebec, Canada
125K $ / an (estimé)
Temps plein
Nous sommes désolés. L'offre d'emploi que vous recherchez n'est plus disponible.

WSP's Information Security Office (ISO) is responsible for the deployment and maintenance of the information security framework for both the IT organization and wider business community.

This includes the Governance mechanisms, policies and processes, tools and technologies, and employee training required to protect WSP information and that of our clients.

To run our global Technology & Cyber Risk Management process, we are seeking a talented and experienced Senior Manager for Technology and Cyber Risk.

This role will report to the Global Director of IT Risk.

As a Senior Manager for Technology and Cyber Risk, your primary role will be to manage the full IT Risk Process from identification, assessment, mitigation and monitoring.

This role is a key player in fostering relationships and coordinating efforts to manage technology-related risks. It calls for a strong analytical ability, and the capacity to work effectively in a diverse, global environment.

MAIN RESPONSIBILITIES

Implement and maintain a comprehensive and effective IT risk management practice across the WSP global IT organisation.

This should include identification of potential IT risks, the evaluation of their impact, the formulation of strategies to mitigate these risks, and the tracking of their mitigation and / or acceptance.

Conduct regular monitoring and review of the IT risk management process to ensure its effectiveness and alignment to the organization's risk appetite and business objectives.

Establish reporting and communication methods that ensure that relevant stakeholders within IT and business leadership have an accurate and timely view of IT risks.

Analyse and process data related to risk, issues, and deficiencies to identify patterns and trends.

  • Work with WSPs Executive Risk Management (ERM) team on the evaluation and reporting of relevant IT Risks as part of the ERM process.
  • Lead and manage a team of risk analysts, fostering a collaborative environment that encourages open communication, mutual respect, and shared responsibility in managing cyber and technology risks.
  • Deliver risk management training within the IT community and establish a culture of risk-aware decision-making, accountability, and a commitment to maintaining an effective control environment.
  • Own and manage the evolution of the Integrated Risk Management Platform (Service-Now IRM). This includes entities, risk statements and controls management.
  • Be a subject matter expert in relation to IT risk and risk mitigation. Empower IT stakeholders to assume responsibility for the IT risks in their respective areas and encourage them to report any potential IT risks.
  • The successful candidate will work directly with all levels of IT Leadership and business stakeholders to ensure issues and risks are well understood so that effective decisions can be made.

Leadership and People Responsibilities :

  • Displays leadership and independence in performing their role.
  • High level of personal integrity, and the ability to professionally handle confidential matters and exude the appropriate level of judgment and maturity.
  • Develop positive working relationships with other team members and business partners and partners across teams to align with WSP internal and external client demands.
  • Capable of rapidly assimilating and internalizing complex business, technology, and risk management concepts and dependencies.
  • Able to exercise judgement when policies are not well-defined.
  • Critical thinker with strong problem-solving and organization skill.
  • Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate between specialized groups of business unit and IT professionals.
  • Ability to work with people from different backgrounds and cultures across the region and the world.
  • Accommodation of schedule for international conference calls.

Requirements : About you :

About you :

  • 8+ years related senior level experience in Information Security, IT Audit with at least 2 years in Risk Management.
  • Bachelor's degree in information technology, Computer Science, Engineering, or related field.
  • Experience working in large / global enterprise IT.
  • Working (not necessarily technical) knowledge of enterprise IT security concerns and technologies, including but not limited to VPNs, network security, encryption, authentication, application-level network protocols, Firewall, LAN / WAN, and TCP / IP
  • Knowledge of technology best practices (applications, network, etc)
  • Experience with IT Governance frameworks such as NIST and ISO 2700x
  • Experience with governance, compliance and audit within IT environments
  • Experience of risk management, including risk analysis, mitigation and monitoring
  • Knowledge of information security regulations
  • Excellent interpersonal and communication skills, able to interact with different layers of management.
  • Ability to work with minimal supervision and little to no instructions.
  • Strong organizational and project management skills.
  • Excellent analytical and diagnostic problem-solving skills
  • Demonstrated experience in understanding and demonstrating compliance with information security requirements.
  • Limited travelling may be required.

Due to the nature of this role, you may need to work outside of standard business hours occasionally.

Preferred

  • Knowledge of Service-Now Integrated Risk Management platform (IRM)
  • Professional certification in one or more of the following disciplines - IT governance (e.g., CGEIT), security (e.g., CISSP, CISM), internal audit (CISA) or Payment Card Industry (PCI)

WSP is one of the world's leading professional services firms. Our purpose is to future proof our cities and environments.

We have over 65,000 team members across the globe. In Canada, our 12,000+ people are involved in everything from environmental remediation to urban planning, from engineering iconic buildings to designing sustainable transportation networks, from finding new ways to extract essential resources to developing renewable power sources for the future.

At WSP :

  • We value our people and our reputation
  • We are locally dedicated with international scale
  • We are future focused and challenge the status quo
  • We foster collaboration in everything we do
  • We have an empowering culture and hold ourselves accountable

Please Note :

Health and Safety is a core paramount value of WSP. Given the importance of keeping one another safe it is expected that you comply with our Health, Safety & Environment (HSE) policy at all times as well as client HSE policies when working at client locations.

Offers of employment for safety-sensitive positions involving fieldwork are contingent upon candidates being able to perform key physical tasks of the job as described in the job posting and interview.

This may include the ability to work in a variety of environmental conditions, such as remote or isolated areas, working alone, and in inclement weather (within safe and reasonable limits).

WSP welcomes and encourages applications from people with disabilities. Accommodations are available on request for candidates taking part in all aspects of the selection process.

WSP is committed to the principles of employment equity. Only the candidates selected will be contacted.

WSP does not accept unsolicited resumes from agencies. For more information please READ THE FULL POLICY.

Il y a 3 jours
Emplois reliés
Deloitte
Canada, Canada

Deloitte's Risk Advisory practice advises organizations on how to effectively mitigate risk and make informed and intelligent risk decisions around business processes, technology and operations. Our Risk Advisory business is expanding as we increasingly are asked to help organizations adapt and resp...

Intact Financial Corporation
Montréal, Québec

The successful candidate will manage teams that support critical functions including the installation and support of data center and server room equipment, IT disaster recovery coordination, and IT systems monitoring, alert management and resolution. We are currently seeking a highly skilled manager...

Medavie Blue Cross
Quebec, CA

Provide leadership and guidance in the development, implementation, and execution of the Company’s Enterprise Risk Management (ERM) Framework, including Risk Identification, Risk Assessment & Monitoring, and Reporting. Design and oversee the maintenance of the Company’s Risk Register and oversee cor...

emergiTEL Inc.
Montréal, Québec

The Manager, Cyber Security GRC & Process Improvement and his/her team are responsible for the cybersecurity controls, methodology and risk assessment, as well as compliance with the standards that AIM follows. Reporting to the Senior Director of IT and Cybersecurity, the Cybersecurity, GRC and Proc...

Deloitte
Montréal, Québec

You will also be able to learn and work in other quantitative and analytical areas such as forecasting and stress testing, customer behavior modeling, and new innovations such as machine learning and artificial intelligence. Would you like to further develop your career with our exponentially expand...

Deloitte
Canada, Canada

This includes, but is not limited to, people with disabilities, candidates from Indigenous communities, and candidates from the Black community in support of living our values, creating a culture of Diversity Equity and Inclusion and our commitment to our AccessAbility Action Plan , Reconciliation A...

Shopify
Anywhere - Canada

Collaborate with technical teams across Shopify to understand and assess IT and business risks, compile risk information in a manner that is easily consumable by stakeholders, and facilitates communication of findings. Proven experience performing assurance and advisory projects relating to Informat...

Groupe Touchette Inc
Montréal, Québec

Reporting to the National Director, Corporate Governance and Compliance, the Manager, Risk Management and Insurance is responsible for the planning, organization, control and efficient operation of the Insurance, Prevention and Management of Insurable Risks sector, in line with the organization's st...

Deloitte
Montréal, Québec

Additionally, you will also be able to learn and work in other quantitative and analytical areas such as credit modeling, forecasting and stress testing, customer behavior modeling, and with innovations such as Machine Learning and Artificial Intelligence. Would you like to further develop your care...

Deloitte
, Canada

This includes, but is not limited to, people with disabilities, candidates from Indigenous communities, and candidates from the Black community in support of living our values, creating a culture of Diversity Equity and Inclusion and our commitment to our. As a member of Deloitte’s dynamic and talen...