Talent.com
CMHC - SCHL
Specialist, IT Security Risk ManagementCMHC - SCHL • Ottawa
Specialist, IT Security Risk Management

Specialist, IT Security Risk Management

CMHC - SCHL • Ottawa
8 hours ago
Job type
  • Full-time
  • Temporary
Job description

Job Requisition ID: 12395

Position Status: Temporary Full Time

Position Type: Hybrid

Office Location: Montreal (QC); Ottawa (ON)

Travel Requirement: Limited

Language Designation: English Essential

Language Skill Levels (Read/Write/Speak): ZZZ

Security Requirement: Secret

Salary: Our salaries generally range from $ 86,816.59 to $ 108,520.74 and are based on qualifications and experience.

About CMHC

The work you do and the work we do together matters. We come to work every day with a common purpose: to contribute to a well-functioning housing system.

At CMHC, we hold ourselves accountable for our results and support our colleagues in their achievements. We thrive on collaboration, connecting across CMHC and involving the right people to get our work done. Our leadership style is guided by trust, where our leaders favour an adaptive approach based on the needs of their teams.

Join us and be part of a team that's committed to making a real difference and be part of something meaningful.

What’s in it for you

We’ve got the purpose, the people and the perks you need for a fulfilling career. Here’s the comprehensive and generous benefits you get when you’re a contract employee:

  • Accrued vacation.
  • Annual individual performance bonus.
  • Group insurance coverage to support your well-being from day one.
  • Support towards your personal and professional growth with training, mentorship and more.
  • An inclusive workplace culture and environment.
  • While positions at CMHC require some in-office presence, alternative work arrangements may be considered for Indigenous candidates.

Members of the following employment equity deserving groups will be prioritized for this job: Indigenous Peoples

About the role

Join the Technology and Business Transformation team, in the Specialist, IT Security Risk Management position, where you will help identify, assess, monitor, and report cybersecurity and information security risks across CMHC. The role supports risk-informed decisions by working with business, technology, security, and governance stakeholders to understand risk exposure, treatment options, and control effectiveness.

The Specialist also supports cyber risk registers, remediation tracking, exception and acceptance processes, key risk indicators, and executive-level reporting aligned with CMHC’s risk appetite, enterprise risk practices, regulatory expectations, and recognized frameworks. This role works closely with cross‑functional teams to assess threats, respond to incidents, ensure regulatory compliance, and enhance the overall cybersecurity maturity of the organization.

This is a temporary position of a duration of 18 months.

What you will do:

  • Advise business, technology, and security stakeholders on information security risks, including impacts, mitigation strategies, remediation priorities, and risk acceptance requirements.
  • Promote and apply consistent information security risk management practices across projects, technologies, vendors, and operational processes.
  • Conduct, document, and communicate risk assessments, control effectiveness, residual risks, treatment options, and escalation requirements to support informed decision-making.
  • Maintain comprehensive risk documentation, including risk registers, exceptions, acceptances, remediation plans, and supporting evidence.
  • Monitor remediation activities by tracking commitments, target dates, dependencies, and progress with accountable risk owners.
  • Identify, analyze, and escalate high-priority, overdue, emerging, or systemic risks, control weaknesses, and issues requiring management or governance attention.
  • Develop cyber risk metrics, trends, dashboards, and reporting, and prepare clear updates for management, executives, governance committees, auditors, and regulators.
  • Enhance the organization's risk management maturity by improving methodologies, templates, taxonomies, scoring, quality assurance practices, and contributing to policies, standards, procedures, and regulatory impact assessments.

What you should have:

  • A bachelor’s degree in Information Security, Computer Science, or a related field, or an equivalent combination of education and experience.
  • At least 5+ years of experience in IT security, risk management, or related roles.
  • Certifications such as CISSP, CISM, CRISC, CGRC, ISO 27001, CISA, or similar (an asset).
  • Experience conducting security risk assessments, evaluating controls, documenting residual risk, and supporting treatment plans.
  • Knowledge of recognized frameworks such as NIST CSF, ITSG-33, COBIT, or similar.
  • Experience in a regulated, financial services, Crown corporation, or public-sector environment is considered an asset.

Posting closing date: Note, the competition will remain active until filled.

Our commitment to diversity, equity, and inclusion

We’re committed to employment equity and encourage women, Indigenous Peoples, persons with disabilities, veterans and persons of all races, ethnicities, religions, abilities, sexual orientations, and gender identities and expressions to apply. We also welcome applications from non-Canadians who are eligible to work in Canada.

CMHC is an inclusive workplace where diversity of thought – and of people – are recognized, valued, and considered essential to achieving our mission.

Learn more about our commitment to diversity and inclusion

What happens after you apply

We know that applying for a new job can be both exciting and daunting, and we appreciate your effort. Learn more about our hiring process. If you are selected for an interview or testing, please advise us if you require an accommodation.

If you applied before and you were not successful don’t worry – we're always posting new positions, so don’t hesitate to give it another shot. We’re excited to see what you bring to the table this time around!

Create a job alert for this search

Specialist, IT Security Risk Management • Ottawa

Similar jobs

Voldex Security and IT Operations Manager

VoldexOttawa, ON, CA
Full-time

Join Voldex as a Security and IT Operations Manager to enhance our device management and security processes in a dynamic gaming company.Drive secure and efficient environments for our remote teams.... Show more

 • Promoted

IT Security Roles at Cerebras Systems

Cerebras Systems, Inc.Ottawa, ON, CA
Full-time

Elevate your career in IT Security with Cerebras, where operational excellence meets innovative security practices in AI environments.This is your chance to secure and optimize crucial infrastructu... Show more

 • Promoted

Senior Cybersecurity Systems Specialist ADGA

Adga-Groupottawa, on, Canada
Full-time

Advance your career with ADGA as a Senior OT and Cybersecurity Systems Specialist.This role focuses on cybersecurity assessments and the integration of secure systems within critical infrastructure... Show more

 • Promoted

Security Governance, Risk and Compliance Specialist

Tecsys Inc.Ottawa, ON, CA
Full-time +1

Security Governance, Risk and Compliance Specialist.Having recognized the advantages of remote work, such as improved employee morale, increased productivity, and positive impacts on both employee ... Show more

 • Promoted

IT Security Risk Analyst

Onico SolutionsOttawa, ON, CA
Permanent

The IT Security Risk Analyst supports the Information Security Risk Management and Governance programs.They work with technology and business stakeholders to identify Information Security risks, co... Show more

 • Promoted

AWS IT Support Specialist (Secret Security Clearance)

Orion Innovationottawa, on, Canada
Full-time

We are seeking a Senior Infrastructure Engineer with a deep specialization in Security Design to lead the evolution of our cloud-native ecosystem.In this role, you will be responsible for architect... Show more

 • Promoted

HPE Senior Cybersecurity Initiative Lead

Hewlett Packard Enterpriseottawa, on, Canada
Full-time

Hewlett Packard Enterprise (HPE) is hiring a Senior Cybersecurity Initiative Lead focused on strengthening risk posture and regulatory compliance.This key role involves working closely with cyberse... Show more

 • Promoted

Senior Consultant, Cyber Risk Management & Transformation

BDO CanadaOttawa, ON, CA
Full-time

Putting people first, every day.BDO is a firm built on a foundation of positive relationships with our people and our clients.Each day, our professionals provide exceptional service, helping client... Show more

 • Promoted

Senior IT Compliance & Audit Lead — Remote

P2POttawa, ON, CA
Remote
Full-time

A leading crypto firm is seeking a senior IT audit professional.This fully remote role emphasizes managing SOC examinations and establishing audit rigor.Ideal candidates will have over 5 years of e... Show more

 • Promoted

Director of IT Security for Directive Consulting

DirectiveOttawa, ON, CA
Full-time

Enhance IT security as Director at Directive Consulting.Protect client data and manage risks within a fully remote framework.In this leadership role, you'll report to the Head of Finance and define... Show more

 • Promoted

Remote IT Security Risk Analyst: Governance & Risk

Onico SolutionsOttawa, ON, CA
Remote
Permanent

A leading IT security firm in Richmond Hill is looking for an IT Security Risk Analyst to support their Information Security Risk Management programs.The role requires expertise in risk assessments... Show more

 • Promoted

Senior OT and Cybersecurity Systems Specialist

Adga-Groupottawa, on, Canada
Full-time

Senior OT and Cybersecurity Systems Specialist.Compensation: CAD 100 - CAD 120 per hour.ADGA Group is a Canadian-owned defence and security company that provides integrated, mission‑critical techni... Show more

 • Promoted

Remote IT Security Consultant - Leading Security Initiatives

ExperisOttawa, ON, CA
Remote
Full-time

A leading technology staffing firm is seeking experienced IT Security Consultants to enhance cybersecurity initiatives across Canada.In this remote role, you will lead security implementations, con... Show more

 • Promoted

Remote Director of IT Security Role

DirectiveOttawa, ON, CA
Remote
Full-time

Shape Directive Consulting's cybersecurity landscape as the Director of IT Security.This fully remote position emphasizes strategic oversight of information security across multiple regions.As the ... Show more

 • Promoted

Security & IT Specialist

VoldexOttawa, ON, CA
Permanent

Voldex is a leading gaming company focused on Roblox, the most exciting ecosystem in gaming today.We are home to several of Roblox's top games, including Brookhaven, Driving Empire, and NFL Univers... Show more

 • Promoted

Cyber Security Project Manager- #26-07874

US Tech Solutionsottawa, on, Canada
Full-time

Coordinate and provide project management support for the planning and implementation of initiatives under Monitoring and Response, Operational Resilience and Cyber Planning and Resilience portfoli... Show more

 • Promoted

IT & Security Specialist

Senstar CorporationOttawa, ON, CA
Full-time

Senstar is a global leader in advanced perimeter intrusion detection and video management solutions.For over 40 years, we have protected critical infrastructure, national borders, and high‑value as... Show more

 • Promoted

IT Infrastructure and Security Manager

Senstar CorporationOttawa, ON, CA
Full-time

Become an IT Infrastructure and Security Manager at Senstar, a pioneer in security technology.Your role will encompass end-user support and overall management of complex IT environments.In this pos... Show more

 • Promoted

Senior Cybersecurity Transformation Lead (Enterprise Programs)

Hewlett Packard Enterpriseottawa, on, Canada
Full-time

Hewlett Packard Enterprise (HPE) is recruiting a Senior Cybersecurity Program Lead to strengthen its risk posture, support regulatory compliance, and protect the business as it scales.As a senior i... Show more

 • Promoted

Risk Management Transformation Specialist

PwC CanadaOttawa, ON, CA
Full-time

Be a strategic leader as a Risk Management Transformation Specialist.Oversee program assessments, advise on risk mitigation, and enhance client engagement through effective communication.As part of... Show more