Job Requisition ID: 12395
Position Status: Temporary Full Time
Position Type: Hybrid
Office Location: Montreal (QC); Ottawa (ON)
Travel Requirement: Limited
Language Designation: English Essential
Language Skill Levels (Read/Write/Speak): ZZZ
Security Requirement: Secret
Salary: Our salaries generally range from $ 86,816.59 to $ 108,520.74 and are based on qualifications and experience.
About CMHC
The work you do and the work we do together matters. We come to work every day with a common purpose: to contribute to a well-functioning housing system.
At CMHC, we hold ourselves accountable for our results and support our colleagues in their achievements. We thrive on collaboration, connecting across CMHC and involving the right people to get our work done. Our leadership style is guided by trust, where our leaders favour an adaptive approach based on the needs of their teams.
Join us and be part of a team that's committed to making a real difference and be part of something meaningful.
What’s in it for you
We’ve got the purpose, the people and the perks you need for a fulfilling career. Here’s the comprehensive and generous benefits you get when you’re a contract employee:
- Accrued vacation.
- Annual individual performance bonus.
- Group insurance coverage to support your well-being from day one.
- Support towards your personal and professional growth with training, mentorship and more.
- An inclusive workplace culture and environment.
- While positions at CMHC require some in-office presence, alternative work arrangements may be considered for Indigenous candidates.
Members of the following employment equity deserving groups will be prioritized for this job: Indigenous Peoples
About the role
Join the Technology and Business Transformation team, in the Specialist, IT Security Risk Management position, where you will help identify, assess, monitor, and report cybersecurity and information security risks across CMHC. The role supports risk-informed decisions by working with business, technology, security, and governance stakeholders to understand risk exposure, treatment options, and control effectiveness.
The Specialist also supports cyber risk registers, remediation tracking, exception and acceptance processes, key risk indicators, and executive-level reporting aligned with CMHC’s risk appetite, enterprise risk practices, regulatory expectations, and recognized frameworks. This role works closely with cross‑functional teams to assess threats, respond to incidents, ensure regulatory compliance, and enhance the overall cybersecurity maturity of the organization.
This is a temporary position of a duration of 18 months.
What you will do:
- Advise business, technology, and security stakeholders on information security risks, including impacts, mitigation strategies, remediation priorities, and risk acceptance requirements.
- Promote and apply consistent information security risk management practices across projects, technologies, vendors, and operational processes.
- Conduct, document, and communicate risk assessments, control effectiveness, residual risks, treatment options, and escalation requirements to support informed decision-making.
- Maintain comprehensive risk documentation, including risk registers, exceptions, acceptances, remediation plans, and supporting evidence.
- Monitor remediation activities by tracking commitments, target dates, dependencies, and progress with accountable risk owners.
- Identify, analyze, and escalate high-priority, overdue, emerging, or systemic risks, control weaknesses, and issues requiring management or governance attention.
- Develop cyber risk metrics, trends, dashboards, and reporting, and prepare clear updates for management, executives, governance committees, auditors, and regulators.
- Enhance the organization's risk management maturity by improving methodologies, templates, taxonomies, scoring, quality assurance practices, and contributing to policies, standards, procedures, and regulatory impact assessments.
What you should have:
- A bachelor’s degree in Information Security, Computer Science, or a related field, or an equivalent combination of education and experience.
- At least 5+ years of experience in IT security, risk management, or related roles.
- Certifications such as CISSP, CISM, CRISC, CGRC, ISO 27001, CISA, or similar (an asset).
- Experience conducting security risk assessments, evaluating controls, documenting residual risk, and supporting treatment plans.
- Knowledge of recognized frameworks such as NIST CSF, ITSG-33, COBIT, or similar.
- Experience in a regulated, financial services, Crown corporation, or public-sector environment is considered an asset.
Posting closing date: Note, the competition will remain active until filled.
Our commitment to diversity, equity, and inclusion
We’re committed to employment equity and encourage women, Indigenous Peoples, persons with disabilities, veterans and persons of all races, ethnicities, religions, abilities, sexual orientations, and gender identities and expressions to apply. We also welcome applications from non-Canadians who are eligible to work in Canada.
CMHC is an inclusive workplace where diversity of thought – and of people – are recognized, valued, and considered essential to achieving our mission.
Learn more about our commitment to diversity and inclusion
What happens after you apply
We know that applying for a new job can be both exciting and daunting, and we appreciate your effort. Learn more about our hiring process. If you are selected for an interview or testing, please advise us if you require an accommodation.
If you applied before and you were not successful don’t worry – we're always posting new positions, so don’t hesitate to give it another shot. We’re excited to see what you bring to the table this time around!