Back to all jobs
AI-translated

INFORMATION SECURITY MANAGER (ISM)

Professional services
Gravity ConseilQuebec City, QC, CAPosted 2026-07-31

Description

Description

We are looking for an Information Security Manager (ISM) to join our team of advisors at our Quebec office as a permanent position.

This position is hybrid. 2 days per week at the Quebec office

As an advisor/consultant for Chrome Technologies, the candidate will work with our clients to complete the projects they have entrusted to us.

The organization is looking for two Information Security Managers (ISMs) specialized in third-party security to contribute to the evaluation and management of risks related to suppliers, partners, and external technological environments.

The responsible office operates in the fields of third-party security, technological security, and process governance. The selected resources will have a strategic role in analysis, evaluation, and recommendation to ensure an adequate level of security for the organization's third parties.

The role requires a strong risk analysis capability, a good understanding of technological vulnerabilities, and excellent collaboration with internal stakeholders.

Tasks

  • Conduct an evaluation of the governance and security posture of third parties
  • Assess the levels of criticality of suppliers and partners based on identified vulnerabilities
  • Serve as a resource person for internal teams regarding third-party issues
  • Analyze information security risks, taking into account technological and governance aspects
  • Identify issues, risks, and mitigation measures required
  • Participate in the definition and improvement of third-party risk management practices
  • Collaborate with IT, security, governance, and business teams
  • Communicate security requirements and recommendations to stakeholders
  • Participate in the coordination of multi-stakeholder cases

Requirements

  • Bachelor's degree in a relevant discipline
  • Minimum 4 years of experience in information technology and/or information security
  • Experience in third-party risk management
  • Good understanding of technological vulnerabilities and security practices
  • Knowledge of IT environments in large organizations
  • General knowledge of defense mechanisms and enterprise security controls
  • Experience in multi-stakeholder contexts
  • Expertise in communicating security needs, processes, and requirements
  • Understanding of exploitation concepts in security
  • Experience in contractual negotiation
  • Very good command of French and English

Skills sought

  • Strong analytical and synthesis capabilities
  • Excellent communication and dissemination skills
  • Autonomy and rigor
  • Ability to work in complex and cross-cutting environments
  • Sense of collaboration and stakeholder management

This posting was aggregated from indeed. Groupe Sentinella is not the employer; applying takes you to the original site. The full text belongs to the original poster.

Want us in your corner?

Join the Sentinella talent bench. We'll reach out when a mandate matches your profile — including roles like this one.

Join the talent bench