Search jobs > Ottawa, ON > Senior it governance

Senior IT Governance, Risk and Compliance Specialist and Auditor

Canadian Bank Note
Hybrid - Ottawa, Canada
$100K-$110K a year (estimated)
Permanent
Full-time

Description

Internal Job Title : Senior IT Governance, Risk and Compliance Specialist and Auditor

Job Type : Permanent, Full-Time

Job Location : 18 Auriga Drive, Ottawa ON

Work Model : Hybrid

Position Summary

As a Senior IT Governance, Risk and Compliance Specialist and Auditor in our Corporate Information Security group, you will play a central role in developing, delivering and managing risk and compliance programs spanning our organization.

You will participateextensively in relevant IT Security projects that support the needs of the organization.

CBN designs and develops industry leading solutions for the following domains : Border Security, Civil Identity, Driver Identification and Vehicle Information, Currency and Excise Control, and Lottery and Charitable Gaming. To learn more, visit .

What We Can Offer You

Compensation : We seek long term relationships with our employees and recognize and reward them with a competitive total compensation package that includes : An industry leading defined contribution pension plan with company matching contributions (up to 5%) and payment of service fees,Best-in-class health, medical and life insurance benefits;

Access to virtual and telehealth services and apps; and Very progressive fertility, adoption and surrogacy benefits to support all definitions of family.

Career : As a knowledge-based organization we will provide you with a wealth of learning opportunities and challenging work that will grow your knowledge, skills and abilities.

At CBN, we encourage and empower our employees to chart their own career path, putting you in control of your future.

Culture : Personal character is the foundation of our culture. CBN’s 7 Core Principles shape and guide our behaviours and underpin the sense of community you will experience at CBN.

Equity, diversity and inclusivity are important to us as an organization, and we are committed to fostering and developing a work environment where every employee is treated with dignity and respect.

What You Will Do

Compliance Monitoring and Management : Framework Implementation : Plan and facilitate the development and implementation of emerging compliance programs as required by the organization.

Compliance : Design, develop, deliver and lead our compliance programs, ensuring our IT systems and procedures comply with industry standards and regulations such as ISO 27001, PCI, and SOC2.

Framework Evaluation : Create, evolve, implement and maintain risk and compliance frameworks. Update internal control frameworks, assess gaps, and work with cross-organizational stakeholders and external partners to maintain compliance.

Internal Policies : Create internal policies and procedures to meet emerging or evolving standards and as new technologies or threats are defined.

Risk Assessment and Management : Risk Program : Developand maintain our ongoing IT Security risk management program following CBN standard procedures.

Set program objectives, develop schedules and establish expectations.Identify and Evaluate Risks : Collaborate with cross-organizational stakeholders and SME’sthroughout the business to continuously assess IT risks.

Risk Documentation : Document identified risks and communicate them to relevant cross-organizational stakeholders, updating risk registers, following up with risk owners and reporting to executive committees as necessary.

Audit Planning Execution and Reporting : Design Audit Programs and Schedules : Create detailed internal audit plans and schedules that align with the organization’s compliance requirements.

Conduct Audits : Lead comprehensive audits of IT systems, applications, and processes to ensure they meet appropriate security and compliance standards.

Document Findings : Prepare detailed reports on audit findings, update registers, highlight areas of concern, and assess corrective actions to ensure they will meet compliance requirements.

Present to Management : Present findings to senior management, Executive and Risk and Compliance Committees, ensuring transparency and accountability.

Technical LeadershipSupport Other Compliance Resources : Provide guidance and support across our organization(s) and to other CBN compliance and risk resources, helping them develop their skills.

Training and Development : Coach junior compliance resources and other staff on IT audit and compliance practices and risk management.

Investigations : As required assist in investigating security events and participate in relevant root cause analysis development.

Continuous Improvement : Process Enhancement : Continuously seek ways to improve processes and methodologies to enhance efficiency and effectiveness.

Aid in the maturation and evolution of our company wide Governance, Risk and Compliance (GRC) tool.Supervise Corrective Actions : Oversee the implementation of corrective actions to ensure compliance issues are resolved effectively and promptly.

Various Other Duties and Responsibilities

Qualifications

Knowledge and Experience

  • Bachelor’s degree in Information Systems (or similar) or equivalent combination of education and / or relevant work experience
  • Certification in a relevant audit discipline : . BSI Lead Auditor, ISACA CISA, PECB Sr. Lead Auditor, PCI-ISA.
  • Certification in one (or more) of the following compliance frameworks : ISO27001-2013 / 2022, ISO 14298, NASPO, PCI-DSS v4.0SANS, ISACA.
  • Extensive experience in on (or more) of the following : SOC 1, SOC 2 (Type I and II), FedRamp, relevant ITSGs, CSA and CSA Star-II
  • Comprehensive knowledge in multiple domains, including IT infrastructure, risk management, compliance and auditing standards
  • Excellence in translating complex compliance requirements to business leaders.
  • Comprehensive knowledge of industry recognized threat and risk management methodologies (HTRA, TRA, TVRP, ITSG-33)
  • Comprehensive knowledge of Unified Compliance Frameworks and GRC tools
  • Thorough knowledge of current security trends, threat vectors and cyber security TTPs
  • 8+ years of experience in a relevant compliance, risk or auditing role
  • 5+ years of experience in cyber and / or corporate security organization
  • 5+ years of experience in developing and delivering compliance and risk assessments, creating, and presenting reports to executives and handling external auditors.
  • Experience in IT operations or IT infrastructure desirable

Soft Skills and Abilities

  • Critical thinking skills
  • Organization and time management skills
  • Interpersonal skills
  • Coaching skills
  • Teamwork and collaboration
  • Growth mindset

Mandatory Requirements

  • Fluency in English (fluency in Spanish is an asset)
  • Ability to travel domestically. 6-8 weeks / year

Security Clearance Requirements

Ability to obtain and maintain Government of Canada Secret (Level II) personal security clearance.

About Us

As an Equal Opportunity Employer, Canadian Bank Note Company, Limited is committed to achieving a skilled workforce that reflects the diversity of the Canadian population.

We encourage applications from women, visible minorities, people with disabilities and Aboriginal people. Canadian Bank Note Company Limited is committed to developing inclusive, barrier-free selection processes and work environments.

30+ days ago
Related jobs
BMO
Canada, Canada

Supports and maintains effective governance and ensure that IT governance, risk and audit programs are implemented, managed, monitored, and strengthened in technology. Acts as a IT risk management subject matter expert and trusted advisor on relevant regulations, policies and internal directives and...

Just Energy
Canada

Additionally, the Senior Specialist will be responsible for being a Subject Matter Expert (SME) to Supervisor with training, updating process documents, projects, new initiatives and other duties as assigned. Work with vendors, utilities, market participants and internal teams via phone, conference ...

BMO
Canada, Canada

Supports and maintains an effective governance framework that defines the ways and methods governance is implemented, managed, monitored and strengthened in technology. The framework components working well together allow for a holistic view for stakeholders into the issues, opportunities and status...

Shopify
Anywhere - Canada

Collaborate with technical teams across Shopify to understand and assess IT and business risks, compile risk information in a manner that is easily consumable by stakeholders, and facilitates communication of findings. Upskill resources across the team on IT knowledge, expanding team capacity for IT...

BMO
Canada, Canada

Through policy development and implementation, the incumbent will define in the methodology how the non-financial risk framework is executed and the associated risks are managed, monitored, and reported across the enterprise. Collaborates effectively with colleagues within the second line (including...

STRABAG INC
ON, Kanada

The Senior Advisor will play a key role in enhancing the organization's public image, fostering positive relationships with stakeholders, and ensuring that community concerns and input are integrated into decision-making processes. Strong writing, editing, and public speaking skills with the ability...

S.i. Systems
Ottawa, Ontario

Senior Technical Business Analyst with public sector project management experience to work on multiple process improvement projects within the ITSM space including: User Persona, User Lifecycle, and government restructuring. IT service management applications, IT application development and maintena...

York Region District School Board
Ontario, Canada

AN EQUAL OPPORTUNITY EMPLOYER-It is the policy of District School Board Ontario North East to support fair, equitable and transparent hiring and promotion practices for all qualified employees and applicants for employment in order to attract and retain quality employees who facilitate the learning ...

S.i. Systems
Ottawa, Ontario

Understanding requirements and use cases, implementing integration services in Azure, and ensuring compliance with the latest security standards and protocols. Proven ability to collaborate effectively with both business and technical stakeholders to gather and understand requirements, define high-l...

Coinbase
Canada
Remote

The Senior Accounting Manager, Subscription and Services Revenue will lead a team that supports the quote-to-cash and record-to-report cycles, and will have the opportunity to work with leaders across Coinbase to solve complex problems and shape the vision and strategy for the Subscription & Service...