Specialist Information Security
Job Summary
The role of Specialist Information Security is responsible for defining, maintaining and supporting the Information Security framework and related processes. He / She is a specialist in information security management matters, including but not limited to understanding business risks, settings security requirements, associated metrics, compliance requirements, project support, GRC processes consulting and integration of regulatory requirements. The Specialist is charged with gaining widespread support of and compliance with information security requirements and policies.
Main Responsibilities
Governance - Risk - Compliance Practice
• Perform threat analysis, risk evaluations and security assessments, recommendations and ensure adherence to regulatory and information security requirements
• Develop and maintain policy, standards and processes to assess, report and remediate risk and compliance related issues
• Support the business initiatives, while making sure any I&T security risk introduced is properly managed
• Identify I&T risks, communication and development of "best practice" solutions, and implementation of mitigating controls consistent with company strategy
• Identify compliance risks and in implement plans to monitor and address those findings with relevant and feasible remediation plans
• Responsible to ensure that CN's internal technological processes and services comply with community expectations, laws, and regulations for privacy, security, and social responsibility
• Work with security and architecture teams to establish and review policies
Operating the Information Security Management System
• Implement and manage governance around security management both internally and externally in multiple vendor environments
• Perform process and control reviews to ensure that they align to CN's information security requirements
• Plan, coordinate and oversee activities related to the design, development and integration of information systems, operations systems and reporting systems in a security or risk context
• Monitor emerging IT security threats and trends
• Respond to vulnerabilities and threats
• Define hardening configurations
Information Security Consulting
• Assist our full stack development and DevOps teams in building secure software and infrastructure
• Work as an integral part of the DevOps team
• Provide guidance on emerging IT security threats and trends
• Provide guidance on compliance with laws, and regulations for privacy, security, and social responsibility
Requirements
Education/Certification/Designation
• B.S. degree in Computer Science, Information Systems or equivalent degree & experience
Skills/Knowledge
• Knowledge of Information Security Risk practices and frameworks
• Knowledge of Information Security Governance and Compliance frameworks
• Knowledge of various industry standards and frameworks including ISO/IEC 27000 series, ISF, NIST Special Publications, Risk Management methodologies, and security evaluations methodologies
• Knowledge of security regulations, Sarbanes-Oxley Act, PCI-DSS standard, OWASP.
• Knowledge of UNIX/Linux environments
• Knowledge of cryptography
• Programming experience in Python, PHP, Perl, Ruby, or other interpreted or compiled languages
• Detail-oriented self-starter with a high level of commitment and personal motivation
• Knack for prioritizing tasks and working in a fast-paced environment
• Strong oral and written language skills in French and English
• Relationship management skills
Experience
• Minimum 5-10 years overall work experience
• Minimum 5 years experience in information security discipline such as GRC, architecture or operation
• Experience performing security analysis and assessment
• Experience with Agile development
Assets
• Certifications in ITIL, CISSP, CISM, CISA, desirable
• Previous experience in Security Governance, Risk and Compliance