Senior Information Security Analyst, Third-Party Security and Data Breach Expert (T & I) (Telework/Hybrid)

CBC/Radio-Canada

$95K — $115K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • University degree in computer science, IT or information security.
  • Minimum five years of experience in IT risk governance and TPRM, including three years in information security.
  • Extensive knowledge of security technology and risk assessment methodologies.
  • Proven collaboration skills with legal teams on contractual security requirements.
  • Excellent communication skills, able to present technical concepts to non-technical audiences.
  • Strong analytical and problem-solving abilities.
  • Relevant professional security certifications a definite asset.

Responsibilities

  • Lead and oversee the organization-wide Third-Party Risk Management (TPRM) program.
  • Design and maintain third-party risk classification frameworks and security assessment questionnaires.
  • Evaluate the security posture of third parties through various compliance reports and certifications.
  • Formulate risk mitigation strategies and establish remediation plans with vendors.
  • Negotiate contractual security requirements with vendor security leaders.
  • Provide technical leadership during third-party security incidents or data breaches.
  • Maintain an up-to-date inventory of all external partners and their risk levels.

Benefits

  • Hybrid work arrangement combining in-office and remote work.
  • Engage with advanced technologies in data management, cloud, and IP broadcasting.
  • Solve complex, time-sensitive technical challenges related to broadcasting content.
  • Opportunity to champion security best practices across teams.
Full Job Description

Position Title:

Senior Information Security Analyst, Third-Party Security and Data Breach Expert (T & I) (Telework/Hybrid)

Status of Employment:

Permanent

Position Language Requirement:

English, French

Language Skills:

English (Reading - C - Advanced), English (Speaking - C - Advanced), English (Writing - B - Intermediate), French (Reading - C - Advanced), French (Speaking - C - Advanced), French (Writing - B - Intermediate)

This is a hybrid position with a mix of in-office and remote work. Work arrangements will be discussed with hiring managers per departmental guidelines.

Your Role


CBC/Radio-Canada is seeking a Senior Information Security Analyst, Third-Party Security and Data Breach Expert, to spearhead its Third-Party Risk Management (TPRM) program for external partners and vendors.

In this role, you will oversee and execute ongoing assessments of third-party technology risk to ensure vendor risks remain within acceptable tolerance thresholds while maintaining compliance with regulatory and organizational requirements. You will report the overall risk posture to information security governance and management committees. As a recognized subject matter expert, you will serve as a trusted adviser for governance, risk and compliance (GRC) across the organization.

This position can be based in Montreal or Toronto.

What’s in It for You

Challenges. We spend our days solving problems of all kinds. Media files are highly nuanced and incredibly complicated; updating, installing and supporting technologies that are organization-wide and that impact broadcasting content is a time-sensitive, complex technical feat. And that’s just the beginning. You’ll be working with leading-edge data management, cloud, IP broadcasting, AI, security and reliability technologies.

As Lead Analyst, you will:

  • Drive the TPRM Program: Lead and oversee the organization-wide Third-Party Risk Management (TPRM) program, from process development through to operational implementation.
  • Define Assessment Methodologies and Standards: Design, maintain and update third-party risk classification frameworks (criticality, data sensitivity) and security assessment questionnaires aligned with industry standards (e.g., ISO 27001, NIST).
  • Assess Compliance and Security Posture: Evaluate the security posture and maturity of third parties by reviewing SOC 2 Type II reports, ISO 27001 certifications, penetration test results and regulatory compliance attestations (e.g., GDPR, Quebec’s Law 25).
  • Address Risks and Recommend Mitigation: Assess identified security gaps, formulate risk mitigation strategies or compensating controls, and establish binding remediation plans with vendors.
  • Define and validate complex contractual security requirements, including audit rights, incident notification SLAs (24- to 48-hour response windows), encryption standards and business continuity plans.
  • Negotiate Directly With Partners and Vendors: Engage directly with vendor security leaders during contracting phases to advocate for and enforce organizational security requirements.
  • Provide technical leadership during third-party security incidents or data breaches.
  • Manage Third-Party Risk Registers: Maintain an up-to-date mapping and complete inventory of all external partners and their corresponding risk levels.
  • Oversee Periodic Reassessments: Schedule and perform ongoing security evaluations based on vendor criticality (e.g., annual reviews for high-risk third parties).
  • Champion security best practices across internal teams to foster a security-first mindset from contract initiation.
  • Advance the TPRM Strategy: Continuously adapt assessment processes in response to emerging cyber threats and regulatory updates.
  • Produce Governance Dashboards and Metrics (KPIs/KRIs): Report third-party risk metrics to leadership (e.g., assessment completion rates, turnaround times, open risk findings).
  • Maintain broad knowledge of best practices and trends in information security.

What You Bring

  • University degree in computer science, IT or information security.
  • Minimum five years’ experience in IT risk governance and TPRM, including a minimum of three years focused on information security.
  • Extensive knowledge of security technology and risk assessment methodologies, policies and processes.
  • Proven ability to collaborate with legal teams to define and negotiate contractual security and privacy requirements (e.g., security schedules, audit rights, data breach notification timelines).
  • Excellent written and verbal communication skills, with a demonstrated ability to translate complex technical concepts for non-technical decision-makers (e.g., governance committees, business units, legal teams).
  • Excellent analytical, evaluative and problem-solving abilities.
  • Experience with compliance programs as well as their technical and security requirements.
  • Technical expertise across key domains:
    • Standards and Frameworks: Strong command of industry standards such as ISO/IEC 27001, 27002, 27005, NIST SP 800-53 / 800-161, COBIT and ITIL.
    • Cloud and Web Architecture Security: Solid understanding of web infrastructure security and cloud architecture models.
    • Network and Security Technologies: Thorough understanding of network security architecture (LAN/WAN, firewalls, IDS/IPS, DNS, web filtering) and cryptographic principles (encryption at rest and in transit).
    • Architecture and Data Security: Working knowledge of database architecture concepts and secure software development best practices.
    • Operational Resilience and Physical Security: Solid understanding of business continuity and disaster recovery planning (BCP/DRP), operational resilience and physical security controls.
  • Relevant professional security certifications a definite asset (e.g., CISSP, CRISC, CBCP, CISA, CISM or equivalent).
  • Bilingualism (English and French) essential.

Candidates may be subject to skills and knowledge testing.

We thank all applicants for their interest, but only candidates selected for an interview will be contacted.

Primary Location:

1000, Rue Papineau, Montreal, Quebec, H2K 0C2

Number of Openings:

1

Work Schedule:

Full time

Similar Jobs

More Jobs at CBC/Radio-Canada

More Information Technology Jobs

Find similar Senior Information Security Analyst, Third-Party Security and Data Breach Expert (T & I) (Telework/Hybrid) jobs: