Talent.com
Alteo
Chief Information Security, Risk and Compliance [#4958]Alteo • Montreal (administrative region), QC, Canada
Chief Information Security, Risk and Compliance [#4958]

Chief Information Security, Risk and Compliance [#4958]

Alteo • Montreal (administrative region), QC, Canada
2 days ago
Job type
  • Permanent
Job description

Chief Information Security, Risk and Compliance [#4958]

  • Montreal, QC

Alteo is looking for a Chief Information Security, Risk and Compliancefor a permanent position based in Montreal.
Your main role will be to support the maturation of the IT risk management and compliance system in order to address the organization's key challenges: implementing a security management system in accordance with international standards; measuring, managing, and controlling operational risks; ensuring platform compliance with payment market requirements; implementing and testing platform and service resilience mechanisms; responding to customer requirements in terms of security, business continuity, compliance, and data protection; managing operational risks and ongoing controls; contributing to the organization's cross-functional initiatives and activities.
Based on the group's strategy, you will be required to strengthen the measures deployed, implement operational risk management, deploy the permanent control system, promote and oversee its implementation, ensure that the IT continuity plan remains operational, and implement data governance.

Responsibilities:

Setting up the organization and governance of the business for North America

  • Establish an organizational and governance framework for the business linked to its management, with regular monitoring and reporting.
  • Develop lasting relationships with all stakeholders involved in the exercise of its mission.
  • Contribute, as needed, to studies and discussions on risk, security, compliance, and data governance.
  • Promote the “added value” of risk management, business continuity, compliance (including data protection), and ongoing control, and ensure smooth communication.

Information system security and resilience

  • Implement information security governance and organization for North America.
  • Define and obtain management approval for information system security guidelines and objectives for all activities within its scope.
  • Define and implement the general information system security policy. Implement procedures related to information system security.
  • Identify, analyze, and assess risks, threats, and consequences (risk mapping).
  • Study the system for controlling risks related to information system security, taking into account regulatory and legal requirements, as well as customer requirements.
  • Define and deploy plans for dealing with information system security risks.
  • Raise awareness and provide training on data security and protection issues: promote the IT security charter to all users.
  • Manage IT security incidents: activate crisis units in the event of a disaster and ensure the necessary coordination with the departments involved.
  • Ensure that audits and intrusion tests are carried out in accordance with the strategy, management needs, and regulatory and contractual requirements.
  • Lead initiatives to strengthen the security culture within the Canadian business and ensure that all stakeholders are involved in risk management, so that everyone fully embraces their role, the cost-benefit/risk ratio is favorable, and the accepted level of residual risk is aligned with the risk appetite defined by management.
  • Define and oversee the IT security management system (standards, tools, incident tracking, audits, etc.).
  • Monitor regulatory and technical developments to ensure that the information systems security policy is in line with these developments.
  • Support the pre-sales team in due diligence exercises conducted by customers in the North American region. Contribute to related projects and ensure compliance with contractual requirements.
  • Establish the framework and ensure the resilience of the provisions put in place for clients.
  • Ensure that annual tests are carried out, in coordination with clients and teams.
  • Ensure that existing certifications are maintained and that areas not covered (ISO 27001) are certified.
  • Ensure the production of SOC2 Type II reports at the required frequency.

Permanent control

  • Define, based on the guidelines of the governing bodies, the organization and governance of the permanent control system.
  • Assist managers/service managers in the deployment of the operational risk management and permanent control system at level 1, within their scope of responsibility. Ensure follow-up.
  • Using a holistic approach, ensure that operational risks are identified and qualified (e.g., self-assessment of risks and controls) and that the operational risk management system is deployed (e.g., management of outsourced services, implementation and monitoring of key risk indicators).

Compliance and personal data protection

Ensure legal, regulatory, and contractual compliance with regard to information system security and personal data protection at the regional level:

  • Recommend a compliance framework: identify non-compliance risks and ensure that appropriate prevention measures are implemented in accordance with the group's key compliance principles and legal, regulatory, and contractual provisions.
  • Ensure the compliance of contracts (customers, suppliers, employees) and contractual clauses to meet security, confidentiality, and personal data protection requirements.
  • Develop and implement all compliance-related instructions and procedures.
  • Ensure transparency and accountability in risk and compliance-related decision-making (reports and record-keeping, etc.).
  • Ensure compliance with applicable legal and regulatory obligations by drawing on the expertise of cross-functional group functions in this area.
  • Raise awareness and encourage employees to report violations of the code of conduct or compliance issues (through reporting channels and investigations, etc.).

Team management

  • Build and supervise the team of controllers under your hierarchical responsibility.
  • Ensure the development, expertise, and skills advancement of employees in the respective risks to be covered.
  • Ensure the setting of annual objectives and employee evaluations.

Profile:

  • Bachelor's/Master's Degree in IT or equivalent
  • 10+ years of experience in information systems auditing/control.
  • Proficiency in the banking and financial regulatory environment (business knowledge, operational risks, controls).
  • Experience in the electronic banking industry (an asset).
  • ISO27001, ITIL, COBIT, CEH, CISSP, CISA, CRISC, PMP certification (an asset).
  • Experience as a team manager.
  • Solid knowledge of IT, IT architecture, and related tools.
  • Solid knowledge of IT risk management, norms and standards, and cybersecurity.
  • Solid knowledge of process modeling and internal control frameworks (e.g., IIA, ISACA, etc.).
  • Proficiency in communication and facilitation tools and project management.
  • Excellent ability to analyze situations and operations, ability to synthesize information.
  • Managerial skills, good interpersonal skills, and ability to work with multicultural teams.
  • Proactive, ability to persuade.
  • Listening and negotiation skills, communication and diplomacy.
  • Leadership, initiative.
  • Rigorous, pragmatic, and methodical.

Profil:

  • Bac/Maîtrise en TI ou l'équivalent.
  • 10+ années d'expérience en audit/contrôle en systèmes d’information.
  • Maîtrise de l’environnement réglementaire bancaire et financier (connaissance métiers, risques opérationnels, contrôles).
  • Expérience dans l'industrie de la monétique (un atout).
  • Certification ISO27001, ITIL, COBIT, CEH, CISSP, CISA, CRISC, PMP (un atout).
  • Expérience comme gestionnaire d'équipe.
  • Solides connaissances en TI, architecture TI et outils associés.
  • Solides connaissances en gestion des risques TI, normes et standards, cyber-sécurité.
  • Solides connaissances en modélisation des processus, des cadres de référence de contrôle interne (ex : de IIA, ISACA...).
  • Maîtrise des outils de communication et d’animation et de la gestion de projets.
  • Excellente capacité d’analyse des situations et des opérations, esprit de synthèse.
  • Qualités managériales, bon relationnel et aptitudes à travailler avec des équipes multiculturelles.
  • Etre force de proposition, capacité à convaincre.
  • Ecoute et négociation, communication et diplomatie.
  • Leadership, esprit d’initiative.
  • Rigoureux, pragmatique et méthodique.
#J-18808-Ljbffr
Create a job alert for this search

Chief Information Security, Risk and Compliance [#4958] • Montreal (administrative region), QC, Canada

Similar jobs

Senior Director, IT Compliance and Risk Management

Intactmontreal (administrative region), qc, Canada
Full-time

Join Intact as a Senior Director of IT Financial Controls, where you will manage compliance and risk initiatives in a hybrid setting.Use your strategic insight to lead a high-performing team.In thi... Show more

 • Promoted

Director of IT Security for Directive Consulting

DirectiveMontreal (administrative region), QC, CA
Full-time

Enhance IT security as Director at Directive Consulting.Protect client data and manage risks within a fully remote framework.In this leadership role, you'll report to the Head of Finance and define... Show more

 • Promoted

IT Security and Operations Leader

Dialogue Technologies Inc.Montreal (administrative region), QC, CA
Full-time

Lead IT security initiatives as an IT Operations & Security Advisor.Focus on advanced support and project management within a flexible hybrid work framework.You will play a crucial role in ensuring... Show more

 • Promoted

Information Security Manager, Mergers & Acquisitions

WSP in CanadaMontreal (administrative region), QC, CA
Full-time

What if you could redefine what’s possible? With us, you can.We are the home of ambitious, passionate, and innovative world shapers.With an unmatched breadth and depth of engineering, advisory and ... Show more

 • Promoted

Head of Security, Global Portfolio Leader

Valsoft CorporationMontreal (administrative region), QC, CA
Full-time

Une entreprise de logiciels recherche un Responsable de la Sécurité pour diriger la sécurité de l'information dans divers secteurs.Ce poste requiert plus de 10 ans d'expérience en cybersécurité, av... Show more

 • Promoted

Governance, Risk & Compliance Consultant

MalleumMontreal, Montreal (administrative region), CA
Full-time

Governance, Risk & Compliance Consultant.Governance, Risk & Compliance Consultant.We are a premier cybersecurity consultancy, blending advanced offensive and defensive strategies to safeguard our c... Show more

 • Promoted

Information Security Consultant

ExperisMontreal (administrative region), QC, CA
Full-time

This range is provided by Experis.Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.Direct message the job poster from Experis.IT Security Consult... Show more

 • Promoted

Senior Director of Infrastructure & Security

Longbow-AdvantageMontreal (administrative region), QC, CA
Full-time

Become the Senior Director of Infrastructure and Security at Longbow Advantage, working remotely with some meetings in Montreal.Steer both security and cloud infrastructure strategy to safeguard se... Show more

 • Promoted

Strategic Information Security Architect

ColliersMontreal (administrative region), QC, CA
Full-time

Transform global security architecture as a Strategic Information Security Architect.Spearhead cloud migration security strategies while ensuring systems are secure and compliant.This pivotal role ... Show more

 • Promoted

Senior Information Security Analyst - ServiceNow (Toronto - Hybrid)

Capcomontreal (administrative region), qc, Canada
Full-time

Senior Information Security Analyst - ServiceNow (Toronto - Hybrid).The Senior Information Security Analyst (ServiceNow) is responsible for developing, implementing, and supporting technology proce... Show more

 • Promoted

Head of Risk - Remote

BitfinexMontreal (administrative region), QC, CA
Remote
Full-time

Be among the first 25 applicants.Inspired by Bitcoin's vision of financial freedom, we are committed to empowering individuals to transact and connect seamlessly across the globe.From the early day... Show more

 • Promoted

Leader en Cybersécurité à la Banque Nationale

National Bank of CanadaMontreal (administrative region), QC, CA
Full-time

Prenez les rênes de la sécurité de l’information à la Banque Nationale.En tant que vice-président et CISO, assurez la cybersécurité et la réduction des risques technologiques au sein de l’organisat... Show more

 • Promoted

Vice-président et Chef de la sécurité de l'information

National Bank of CanadaMontreal (administrative region), QC, CA
Full-time

Relevant du premier vice président – Chef des technologies et de la sécurité de l’information (CTO/GCISO), le ou la vice président(e) et Chef de la sécurité de l’information (CISO) est responsable ... Show more

 • Promoted

Head of Infrastructure & Security

Longbow-AdvantageMontreal
Full-time

We operate two connected businesses:.B2B SaaS platform serving enterprise warehouse and fulfillment operations, and.WMS implementation and professional services firm.Rebus ingests and stores sensit... Show more

 • Promoted

Information Technology Manager

Global Partner SolutionsDorval, QC, CA
Full-time

The purpose of this position is to provide strategic and operational leadership for the company’s technology and cybersecurity functions.This role ensures the reliability, security, and performance... Show more

 • Promoted

Canada IT Senior Manager: Strategy, Security & Operations

Brunelmontreal (administrative region), qc, Canada
Full-time

Une entreprise internationale de gestion de main-d'œuvre recherche un(e) Gestionnaire principal(e), TI pour diriger la stratégie et les opérations TI au Canada.Le candidat idéal aura plus de 10 ans... Show more

 • Promoted

Hybrid InfoSec Engineer - Montreal (Contract)

MindlanceMontreal, Montreal (administrative region), CA
Full-time

An innovative firm is seeking an Information Security Engineer for a hybrid role in Montreal.This position involves supporting technical discussions on application data flow and encryption requirem... Show more

 • Promoted

Sagard Cybersecurity Initiative Manager

Sagard Holdings Manager LPMontreal (administrative region), QC, CA
Full-time

Drive effective cybersecurity initiatives as Sagard's initiative manager.This role is pivotal in ensuring systematic execution and governance in security practices across the firm.Sagard is looking... Show more

 • Promoted

Remote Information Risk & Security Analyst

DexianMontreal (administrative region), QC, CA
Remote
Full-time

A leading IT services firm is seeking an Information Control Testing Specialist to manage information risk and ensure compliance with security policies.You will work on global initiatives, conduct ... Show more

 • Promoted

Leader IT et Sécurité chez Anyon Systems

Anyon Systems Inc.Montreal (administrative region), QC, CA
Full-time

Prenez les rênes des opérations informatiques chez Anyon Systems à Montréal.Nous recherchons un Leader IT et Sécurité pour diriger nos initiatives technologiques stratégiques.Dans ce rôle, vous ser... Show more