Recherche d'emploi > Toronto, ON > Information security

Information Security Governance & Compliance Specialist

Norton Rose Fulbright
Toronto
107.5K $ / an (estimé)
Temps plein

Role

The information security governance & compliance specialist takes responsibility for overseeing responses to support the client bids and client audit process, and the third-party supplier assessment process.

The role is a key part of assuring our clients on the technical security measures NRF has in place for protecting client data.

Providing project support for other security functional areas may also be required on an ad hoc basis.

Key Responsibilities

  • Technical SME for all client bids and client audit responses. Ensure NRF responses to client questions are consistent and appropriate.
  • Lead support for client bids and client audits. This involves the co-ordination of completing complex questionnaires received from clients, often with tight deadlines.
  • Technical assessor for NRF's third-party party supplier onboarding process, to ensure all new suppliers are thoroughly evaluated, and comply with NRF information security requirements
  • Provide information security & IT product knowledge support, including : Deep working knowledge of NRF global controls through liaising with regional IT teams Being responsible for the upkeep of central response and evidence database Continuous process improvements
  • Providing knowledge transfer to other governance & compliance analysts, when needed
  • Research and development of technology and processes to increase team efficiency and speed
  • Escalating appropriately, where policy compliance is not in place and tracking any remediation actions to completion.
  • Performing third-party party supplier risk assessments to ensure the protection of the firm and client data.
  • Remain current with developments in the Cyber domain.
  • Building relationships with key stakeholders to allow regular information sharing.
  • Achieving a balance between protecting the firm and ensuring that users can work effectively
  • Being pragmatic but cognisant of risk.

Skills and Experience Required

  • Education - an IT or information security qualification or + years' experience in a similar role.
  • ISO qualification and / or experience.
  • Excellent communication skills, both written and oral. The ability to articulate complex information security controls to a business audience is essential.
  • Stakeholder management skills. Ability to build relationships with team members and peers across the organization is vital to the success of this role.
  • Experience working in large, matrix and geographically dispersed global organizations where IT and information security have played a key role in the business.
  • Proven ability and understanding of the role of client bids and client audits in business development and the effective management of third-party risk.
  • Experience in using governance, risk & compliance (GRC) tools. OneTrust GRC and BitSight platform experience is an advantage.
  • An ability to learn quickly, solve problems and pragmatically address risk.
  • Experience with creating reports, dashboards and metrics for presentation.
  • A relevant industry certification, such as CISSP, CISM, CRISC, CISA or similar, is an advantage.

Ready to join a proactive and modern firm that provides an exceptional career experience in an inclusive and collaborative environment? Come join us!

As a global law firm, we embrace a culture of excellence and working hard, but always with a focus on flexibility, respect, diversity and openness.

We strive to create an equitable, inclusive environment where everyone can bring their whole self to work and realize their career potential.

To find out more about how we integrate diversity, equity and inclusion in everything we do please click .

If you are unable to apply for a position online or require any reasonable adjustments during the recruiting process, please contact to further discuss your needs.

Please note that applicants who receive an employment offer may be required during their employment with Norton Rose Fulbright to provide proof of vaccinations recommended from time to time by government or public health authorities.

Norton Rose Fulbright has a duty to accommodate those who are unable to get vaccinated due to protected grounds. For applicants who require an accommodation, please contact to discuss further.

We thank all candidates for their applications, but please note that we will be contacting only those whom we invite for an interview.

LI-Hybrid

Law around the world

Il y a plus de 30 jours
Emplois reliés
SAP
Toronto, Ontario

Cloud, Information Security, Cyber Security, ERP, Compliance, Technology, Security, Legal. Audit Specialist is a key partner with SAP External Auditors, as well as internal risk, continuous monitoring, remediation, and cyber compliance program managers. Demonstrate experience in the design, implemen...

Infotek Consulting Services Inc.
Toronto, Ontario

Provide leadership for the provision of technical expertise in development and support of activities, processes, procedures, and tools for protecting information security with a focus on application security. Research, design and implement application security solutions and practices. Direct testing...

The Toronto-Dominion Bank (Canada)
Toronto, Ontario

Compliance risk specialist with relevant experience in governance, risk and compliance management within a regulated industry. IT governance experience in information security and controls risk frameworks (i. Information Security or Technology risk and controls background in a financial industry a p...

S.i. Systems
Toronto, Ontario

Sr Data Architect to develop and implement data governance policies and frameworks to ensure data quality, security, and compliance for B2B applications (ServiceNow, NetCracker, Salesforce, Amdocs, BMC Remedy) for our large telecom client -. Develop and implement data governance policies and framewo...

The Toronto-Dominion Bank (Canada)
Toronto, Ontario

The Information Security Specialist within Assurance Operations is responsible for ensuring technology controls are sufficiently protecting business risk, through the application of the Technology Risk & Control framework, and overseeing security standards, policies and procedures. The Information S...

Independent Electricity System Operator
Mississauga, Ontario

Contribute to the development of Information Security standards and procedures for business units consistent with corporate security objectives and generally accepted and leading-edge Information Security practices and professional security standards and in coordination with IT Process Development L...

The Toronto-Dominion Bank (Canada)
Toronto, Ontario

Ensure the seamless integration of security practices into DevOps workflows, reducing security vulnerabilities and improving the security posture. Bachelor's degree in computer science, Information Security, or a related field. Develop, implement, and maintain security policies, standards, and guide...

University of Toronto
Toronto, Ontario

As Information Security Specialist, you will collaborate closely with the Manager, Information Security to contribute to the development and implementation of strategic and tactical planning of Temerty Medicine’s Information Security programs. Strong knowledge of information security, data governanc...

Jobber
Canada
Télétravail

Our Security Analyst, GRC, focuses on the governance side of security and is not a technical security operations position requiring specific technical certifications or experience. This role is ideal for entry-to-intermediate level candidates in the security, governance, risk and compliance space. T...

Air Canada
Toronto, Ontario

As a specialist you will be expected to lead the technical direction of cyber security technologies, deploy, and configure new cyber security technologies, develop standard operating procedures that will be used by members of the Cyber Security Operations Centre team, inspire and train a team of 7x2...