Bachelor's or Master's degree in Auditing, Cybersecurity, Engineering, Computer Science, or a related discipline.
3-6 years of experience in audits, assessments, or compliance reviews, with a focus on automotive, powersport, or technology-driven environments.
Experience in planning and executing audits across product development lifecycles, especially in cybersecurity and embedded systems.
Strong knowledge of ISO/SAE 21434 and UNECE R155, with familiarity with EU Cyber Resilience Act (CRA).
Ability to objectively assess cybersecurity processes and verify traceability of cybersecurity objectives and requirements.
Proven communication skills to identify and report on risks and non-conformities effectively.
Preferred certifications include ISO 27001 Lead Auditor, CISA, CISSP, or equivalent.
Responsibilities
Define audit criteria to establish quality benchmarks for the Cybersecurity Management System (CSMS).
Execute audit plans by scheduling audits from concept to production for embedded systems and connected technologies.
Analyze and report deviations by reviewing cybersecurity artifacts for compliance with standards.
Support root cause analysis by collaborating with various engineering and manufacturing teams.
Manage corrective actions by tracking remediation plans for identified non-compliance issues.
Provide strategic internal status reports on the health of the cybersecurity ecosystem and regulatory readiness.
Benefits
Annual bonus based on company's financial performance.
Generous paid time off for work-life balance.
Pension plan for retirement savings.
Collective saving opportunities for employees.
Industry leading healthcare fully covered by BRP.
Flexible work schedule to accommodate personal and family needs.
Variations in summer schedules by department or location.
Company-wide holiday season shutdown to promote employee rest.
Access to educational resources for professional growth.
Discounts on company products for employees.
Full Job Description
We are searching for an energetic, detail-driven, and forward-thinking powersport vehicle cybersecurity internal auditor to help strengthen cybersecurity practices across our product ecosystem.
In this role, your focus is strictly the "machine"-leading internal oversight to ensure our high-performance hardware, embedded systems, and connected vehicle tech remain resilient from concept to decommissioning. You will be the primary independent assessor of our Cybersecurity Management System (CSMS) and it's application on our vehicles, ensuring our technical work products and vehicle architecture comply with ISO/SAE 21434, UNECE R155 and the EU Cyber Resilience Act (CRA).
YOU'LL HAVE THE OPPORTUNITY TO:
Define audit criteria by establishing quality benchmark for the CSMS and work products to meet ISO/SAE 21434 and UNECE R155 ( content and container)
Execute audit plan by leading audit schedules from concept to production for all embedded systems and connected technologies.
Analyze & Report Deviations by evaluating Cybersecurity artifacts to ensure compliance with applicable standards
Support root cause analysis by partnering with vehicle engineering, powertrain, connectivity, cybersecurity, certification, manufacturing and global sourcing
Manage corrective actions by tracking remediation plans to ensure all non-compliance is resolved within defined timelines
Strategic status reporting ( internal) by providing health assessment of the cybersecurity powersports ecosystem and regulatory certification readiness
YOU'LL THRIVE IN THIS ROLE IF YOU HAVE THE FOLLOWING SKILLS AND QUALITIES:
Bachelor's or Master's degree in Auditing, Cybersecurity, Engineering, Computer Science, or a related discipline.
3-6 years of experience conducting audits, assessments, or compliance reviews within automotive, powersport, manufacturing, cybersecurity, or other technology-driven environments.
Demonstrated experience planning, executing, and reporting audits across product development lifecycles, preferably within cybersecurity, software, embedded systems, or regulated engineering environments.
Strong knowledge of ISO/SAE 21434 and UNECE R155/R156 requirements, with familiarity with the EU Cyber Resilience Act (CRA) and related cybersecurity regulatory frameworks.
Ability to objectively assess the effectiveness of cybersecurity processes, controls, and work products, and verify traceability between cybersecurity objectives, requirements, implementation, and verification activities.
Proven ability to identify, evaluate, and communicate risks, gaps, and non-conformities, providing stakeholders with clear context and recommendations to support effective remediation.
Skilled at translating complex technical and cybersecurity findings into concise, actionable insights and organizational health assessments for management and executive leadership.
Skilled in resolving conflicts and overcoming pushback through clear communication of audit context and risk-based evidence
Preferred certifications include ISO 27001 Lead Auditor, IATF 16949 Auditor, CISA, CISSP, or equivalent.
AT BRP, WHEN WE TALK ABOUT BENEFITS, WE GO ALL IN.
Let's start with a strong foundation - You want it, we have it:
Annual bonus based on the company's financial results
Generous paid time away
Pension plan
Collective saving opportunities
Industry leading healthcare fully paid by BRP
What about some feel good perks:
Flexible work schedule
A summer schedule that varies by department and location
Holiday season shutdown
Educational resources
Discount on BRP products
#LI-Hybrid #LI-SP1
About BRP Inc.
BRP Inc. is a Canadian company that designs, develops, manufactures, distributes, and markets powersports vehicles and propulsion systems. The company's products include Ski-Doo and Lynx snowmobiles, Sea-Doo watercraft, Can-Am on- and off-road vehicles, Alumacraft and Manitou boats, Evinrude and Rotax marine propulsion systems, and Rotax engines for karts, motorcycles, and recreational aircraft. BRP was founded in 1942 and is headquartered in Valcourt, Quebec.