Position Title: Lead Information Security Analyst, Data Protection Specialist (T & I) (Telework/Hybrid)
Status of Employment:Permanent
Position Language Requirement:English, French
Language Skills:English (Reading - C - Advanced), English (Speaking - C - Advanced), English (Writing - B - Intermediate), French (Reading - C - Advanced), French (Speaking - C - Advanced), French (Writing - B - Intermediate)
Unposting Date: 2026-09-29 11:59 PM
Behind the scenes, but ahead of the curve: help us develop the next-generation public service media organization.Technology & Infrastructure (T&I) is the backbone and the future-forward arm of CBC/Radio-Canada. Our purpose is to constantly innovate to evolve and maintain the Corporation's technology and infrastructure. We are the people that make stuff work. We make connections between media content, systems, people and places. We are the space in between.
This is a hybrid role with a mix of in-office and remote work. Work arrangements will be discussed with hiring managers per departmental guidelines.Your RoleCBC/Radio-Canada is seeking a Lead Analyst, Data Protection Specialist, to design, lead and evolve the Corporation's data security program.
In this role, you will provide technical and operational leadership to safeguard sensitive data and personal information throughout the data life cycle (collection, processing, storage, transmission, archiving and destruction). You will collaborate closely with Legal Services, privacy officers, enterprise architects and IT Operations to align data security with regulatory requirements and industry standards.
This position can be based in Montreal or Toronto.What's in It for YouChallenges. We spend our days solving problems of all kinds. Media files are highly nuanced and incredibly complicated; updating, installing and supporting technologies that are organization-wide and that impact broadcasting content is a time-sensitive, complex technical feat. And that's just the beginning. You'll be working with leading-edge data management, cloud, IP broadcasting, AI, security and reliability technologies.
As Lead Analyst, you will:- Define data security strategy: Develop and refine the road map for the Corporation's data protection program.
- Implement data classification: Establish and deploy data classification policies and frameworks.
- Administer data protection technologies: Select, deploy and optimize data loss prevention (DLP) tools.
- Protect cloud and hybrid environments: Design security controls tailored to cloud-hosted data and hybrid architectures.
- Partner on compliance and policy frameworks: Work closely with the policy, compliance and legal affairs lead to align security controls with statutory requirements.
- Manage the data security risk register: Document, maintain and map risks related to confidentiality, potential data breaches and approved exceptions.
- Adjudicate and govern exception requests: Evaluate, document and follow up on exception requests when standard security controls cannot be immediately applied, ensuring appropriate compensating controls are established.
- Lead data breach response: Actively participate in investigations of suspected or confirmed data breaches in co-ordination with the Information Security, Legal Services and Incident Response teams.
- Develop metrics and dashboards: Define and track key performance indicators (KPIs) and key risk indicators (KRIs) to monitor program effectiveness.
- Assess program maturity: Plan and conduct periodic evaluations, performance reviews and audits of data protection controls to identify gaps, measure maturity progress and formulate recommendations for continuous improvement.
- Maintain industry expertise: Stay current on information security best practices and industry trends.
What You Bring- University degree in computer science, IT or information security.
- Minimum five years' experience in data protection, privacy security, DLP or data governance, including at least three years in an information security role.
- Proven track record of implementing and evaluating technical data protection programs within large, complex organizations.
- Deep technical expertise in data protection, including cryptography (encryption at rest and in transit, PKI), DLP tools (network, endpoint, cloud), CASB technologies and SQL/NoSQL databases.
- Extensive knowledge of security technology and risk assessment methodologies, policies and processes.
- Excellent written and verbal communication skills, with a demonstrated ability to translate complex technical concepts for non-technical decision-makers (e.g., governance committees, business units, legal teams).
- Excellent analytical, evaluative and problem-solving abilities.
- Experience with compliance programs as well as their technical and security requirements.
- Technical expertise across key domains:
- Standards and Frameworks: Strong command of industry standards such as ISO/IEC 27001, 27002, 27005, NIST SP 800-53 / 800-161, COBIT and ITIL.
- Cloud and Web Architecture Security: Solid understanding of web infrastructure and cloud environment security.
- Network and Security Technologies: Thorough understanding of network architectures (LAN/WAN, routers), network security technologies (firewalls, IDS/IPS, DNS, web filtering) and cryptographic principles (encryption at rest and in transit).
- Architecture and Data Security: Working knowledge of database architecture concepts and secure software development best practices.
- Operational Resilience and Physical Security: Solid understanding of business continuity and disaster recovery planning (BCP/DRP), operational resilience and physical security controls.
- Relevant professional security certifications a definite asset (e.g., CISSP, CRISC, CBCP, CISA, CISM or equivalent).
- Bilingualism (English and French) essential.
Candidates may be subject to skills and knowledge testing.
We thank all applicants for their interest, but only candidates selected for an interview will be contacted.
Primary Location:1000, Rue Papineau, Montreal, Quebec, H2K 0C2
Number of Openings:1
Work Schedule:Full time