Information Security Specialist
TechnologieDescription
Information Security Specialist
At CN, every day brings its share of stimulating and enriching challenges. You will operate in a dynamic environment where you will directly contribute to ensuring the optimal and secure functioning of our activities, while helping to keep the economy on track. We offer paid training and opportunities for development that allow you to build a long-term career, and we recognize employees who work hard and seek to make a difference. You will thrive in a culture focused on security, collaboration, and teamwork, where we act as ONE TEAM. The careers we offer are meaningful because the work we do has a real impact. Join us!
CN is looking for a Cybersecurity GRC (Governance, Risk, and Compliance) Analyst to support and develop its cybersecurity governance team.
Reporting to the Manager, Cybersecurity Governance, Risk, and Compliance, this person will contribute to achieving CN's cybersecurity governance objectives by translating security, risk management, and compliance requirements into practical processes, evidence, reports, and guidelines for IT and business stakeholders. The role primarily focuses on maintaining, supporting, and leveraging CN's Information Security Management System (ISMS).
Key Responsibilities
- Maintain, support, and leverage CN's cybersecurity GRC framework, including information classification, risk management processes, security policies, awareness activities, and continuous improvement to meet business needs.
- Proactively and pragmatically communicate and support security recommendations aligned with business objectives, leveraging ServiceNow workflows and maintaining appropriate stakeholder engagement to drive positive outcomes.
- Support control assessment, documentation, and maintenance activities to ensure security controls remain adequate, effective, and compliant with regulatory and cybersecurity requirements.
- Collaborate with the compliance team to ensure controls and compliance measures are correctly integrated into dashboards and reports supporting KPIs and global metrics.
- Track cybersecurity issues, risks, and corrective measures in ServiceNow's Integrated Risk Management (IRM) module, including tracking risk assessments, security test results, and their impact on the business.
- Provide guidance during the evaluation or review of new IT solutions and technologies, both new and existing, to ensure compliance with regulatory requirements, including Sarbanes-Oxley, PCI, and SWIFT, as well as security requirements, using ServiceNow's Third Party Risk Management workflow.
- Collaborate with other cybersecurity teams and IT stakeholders to understand, apply, and support the implementation of security requirements.
Experience
- Knowledge of IT operations and CN's business units is an asset.
- Minimum of 3 years of experience in cybersecurity, IT compliance, IT audit, or a related role.
- Practical experience with Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs).
- Previous experience in risk management is an asset.
- Experience with a GRC tool is an asset.
Education, Certifications, and Professional Titles
- Bachelor's degree in a field related to information technology or a related discipline, or equivalent work experience.
- Cybersecurity certifications such as Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), or any other relevant certification are an asset.
Technical Skills and Knowledge
- Knowledge of cybersecurity risk management practices.
- Knowledge of cybersecurity governance and compliance frameworks.
- Knowledge of industry standards and reference frameworks, including the ISO/IEC 27000 series, ISF, NIST special publications, risk management methodologies, and security assessment methodologies.
- Understanding of regulatory and legislative requirements for security and personal information protection, including the Sarbanes-Oxley Act, PCI DSS standard, and LPRPDE (PIPEDA).
- Knowledge of ServiceNow, including its ecosystem and workflows.
General Skills and Abilities
- High integrity and strong ethical standards.
- Customer-centric approach and ability to provide practical advice to IT and business stakeholders.
- Excellent communication and interpersonal skills.
- Team spirit and ability to collaborate to achieve common goals.
- Flexibility to manage multiple cases simultaneously and adapt to changing priorities.
About CN
CN is a global leader in transportation and a facilitator of commerce. Essential to the economy, its clients, and the communities it serves, CN safely transports more than 300 million tons of natural resources, manufactured products, and finished goods across North America each year. As the only railway connecting the east and west coasts of Canada to the southern tip of the United States via a network of 19,500 miles of rail, CN and its affiliated companies have contributed to the prosperity of communities and the sustainability of commerce since 1919. CN actively supports social responsibility and environmental management programs. At CN, we work as ONE TEAM, focusing on safety, sustainability, and our customers, while aiming for operational and supply chain excellence to achieve tangible results.
About CN
CN is a leading railway that generates sustainable value for our customers, shareholders, employees, and stakeholders, with an unwavering commitment to safety and service. Essential to the economy, customers, and communities it serves, CN safely transports more than 300 million tons of natural resources, manufactured products, and finished goods across North America each year. CN's extensive railway network spans over 30,000 km (nearly 20,000 miles), connecting the east and west coasts of Canada to the southern United States. Since 1919, CN and its affiliates have contributed to the prosperity of communities and the sustainability of commerce. CN drives the North American economy and is committed to social responsibility and environmental management programs.
At CN, we are determined to build the safest, most inclusive, and most sustainable railway in North America, reflecting the communities in which we operate. Studies show that candidates often hesitate to apply if they believe they do not meet 100% of the job requirements. To all potential candidates: even if you do not meet all the requirements listed in a job posting, we encourage you to apply.
If you need an accommodation for the recruitment process (including alternative document formats, accessible meeting rooms, or other accommodations), please contact our team at cnrecruitment@cn.ca.
As an employer subscribing to the principle of equal access to employment, CN will consider for employment all qualified candidates without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, and any other protected status under applicable law.
Please regularly check your emails, as candidate communications are sent via email.
Cette offre a été agrégée depuis indeed. Groupe Sentinella n'est pas l'employeur; postuler vous redirige vers le site original. Le texte intégral appartient à l'auteur de l'offre.
Envie qu'on travaille pour vous ?
Inscrivez-vous au banc de talents Sentinella. On vous contacte dès qu'un mandat correspond à votre profil — y compris des postes comme celui-ci.
Rejoindre le banc de talents