Information Security Specialist
TechnologyDescription
Type
Full-time
Work Schedule
You want to join the team of a leading Canadian company? Support the success of top-tier clients? Collaborate with a team of diverse talents that will foster your professional growth? Look no further: a world of exciting challenges awaits you at TRSB, Canada's leading translation firm.
TRSB is looking for an experienced Information Security Specialist to support our organization in establishing a robust security framework. The incumbent of this position will actively contribute to the development and implementation of security policies, the management of compliance requirements (including SOC 2), and the creation of operational processes (procedures, controls, security questionnaire responses).
Your daily activities:
Threat Monitoring
- Monitor and proactively analyze security data to detect advanced threats and vulnerabilities.
- Produce key indicators (risk and performance) and actionable intelligence to strengthen the organization's security posture.
Security Incident Response
- Manage security incidents, from initial analysis to complete resolution.
- Conduct post-incident reviews and recommend preventive measures.
Risk and Vulnerability Assessment
- Independently conduct in-depth security assessments to identify vulnerabilities and recommend remediation strategies.
- Maintain the information security risk register, oversee audits, and assess the security practices of vendors.
Security Awareness and Guidance
- Develop information security awareness materials.
- Serve as a subject-matter expert to support the cybersecurity program's objectives and compliance initiatives.
Policies and Governance
- Write, update, and maintain information security policies, procedures, and standards (access management, passwords, network security, PAP, etc.).
- Ensure documentation aligns with best practices (NIST, ISO 27001, etc.).
Compliance and Audit (SOC 2)
- Coordinate SOC 2 compliance activities (Types 1 and 2), including audit preparation.
- Document and implement the required security controls.
- Manage evidence collection and requirement tracking with external auditors.
Security Questionnaires
- Respond to security questionnaires from clients or partners (cybersecurity, privacy, business continuity, etc.).
- Collaborate with internal teams to obtain relevant technical or organizational answers.
Security Controls Implementation
- Participate in the definition and implementation of technical and organizational controls (access management, logging, backups, etc.).
- Collaborate with IT, operations, development, and product teams to integrate security into operations.
Security Procedures and Processes
- Develop security intervention procedures (incident response, vulnerability management, SIEM alert handling, etc.).
- Establish reproducible and well-documented processes.
What you'll need
- Strong knowledge of SOC 2, ISO 27001, NIST, and CIS Controls standards
- Experience in writing policies and security documentation
- Ability to understand technical concepts and communicate them to non-technical audiences
- Knowledge of cloud environments AWS, Azure, and GCP (an asset)
- CCSP, CISM, or ISO 27001 Lead Implementer certification
This position may suit you if you
- Hold a degree in information security, information technology, or a related field;
- Have a minimum of three to five years of experience in a similar role in information security or governance;
- Are proficient in both French and English, both orally and in writing;
- Can manage multiple projects with diligence and autonomy;
- Have experience with GRC (Governance, Risk, and Compliance) tools;
- Have experience with the GRC tool DRATA (an asset).
We offer our teams benefits as valuable as their contributions
- Competitive salary
- Comprehensive group insurance
- Collective REER
- Hybrid remote work option
- Reimbursement for sports activity subscription fees
- Coverage of professional organization contribution fees
- Referral program
- Discounts for public transportation
- Birthday leave
This posting was aggregated from indeed. Groupe Sentinella is not the employer; applying takes you to the original site. The full text belongs to the original poster.
Want us in your corner?
Join the Sentinella talent bench. We'll reach out when a mandate matches your profile — including roles like this one.
Join the talent bench