Senior Advisor - Governance, Risk and Compliance in Cybersecurity
TechnologieDescription
Introduction
The second largest public transportation network in the Montreal metropolitan region, exo operates train, bus, and adapted transportation services for the north and south crowns of Montreal.
At exo, you will find a human-sized organization, looking towards the future and innovation, serving the communities. A work environment where, depending on the nature of the job, flexible schedules and hybrid remote work are favored, facilitating the reconciliation of work and personal life.
Working at exo also means benefiting from a variety of advantages, such as: free Opus card, group insurance, pension plan, generous vacation, holidays, sick and personal leave, employee assistance program, free telemedicine service for you and your family, and a very dynamic social club. Join exo!
Under the responsibility of the Director of Information Security, you are the strategic owner of exo's cybersecurity governance, risk, and compliance (GRC) program. You design, drive, and evolve the global cybersecurity framework and represent the organization to the highest instances. Additionally, you are the official representative of exo to the Metropolitan Transportation Authority (ARTM) for mutualized governance in cybersecurity.
Main Responsibilities
- Design, deploy, and maintain the entire cybersecurity governance framework (policies, directives, standards, procedures, methodologies, and practices);
- Represent exo at the Regional Cybersecurity Governance Committee (ARTM-exo-STM-RTL-STL) and actively participate in the harmonization of frameworks;
- Drive compliance and certification to major standards (PCI-DSS, ISO 27001, NIST CSF, NIST 800-53, Law 25);
- Drive the cybersecurity incident response continuity program (PCA cyber) and contribute to the development of the mutualized PCA;
- Define and deploy the multi-year cybersecurity awareness and training strategy (campaigns, phishing simulations, employee and manager workshops, effectiveness measures);
- Lead the enterprise cybersecurity risk management program and critical risk mapping;
- Manage the third-party and supply chain risk program (critical vendor registry, risk scoring, contractual requirements, third-party audits);
- Administer the complete exception handling process (evaluation, decision, compensating measures, registry, follow-up);
- Define, validate, and drive all performance (KPI) and risk (KRI) indicators, produce and present executive reports, to the board of directors, risk management committee, and ARTM;
- Coordinate and act as the main point of contact during internal, external, and mutualized audits (ISO 27001 Certification, SOC 2 type 2, etc.);
- Provide all technical deliverables and evidence for the annual renewal of the cybersecurity insurance policy (in support of the Legal Service);
- Animate the cybersecurity strategic committee and practice communities;
- Represent exo to government instances (Government Cyber Defense Center, Transports Quebec, CCCS) under the delegation of the CISO.
The list of responsibilities and tasks mentioned above is summary and indicative. It is not a complete and detailed list of responsibilities and tasks that may be performed by the incumbent.
Normal Job Requirements
Education
- Master's or Bachelor's degree in cybersecurity, IT, risk management, or a related field.
Experience
- Minimum 10 years of experience in cybersecurity, including at least 6 years in strategic governance and compliance;
- Experience in a mutualized or multi-organizational context (major asset).
Skills and Abilities
- In-depth knowledge of ISO 27001, NIST CSF, NIST 800-53/800-161, Law 25 frameworks;
- Minimum two certifications among: CISSP, CISM, CRISC, CISA, ISO 27001 Lead Implementer/Auditor;
- Experience in the public/para-public sector or critical infrastructure;
- Current French and English in writing and speaking;
- Strategic leadership, executive influence, and marked political sense.
- Work Conditions
- Employment Period and Schedule
- Full-time permanent employment, 37.5 hours per week
- Location
- Headquarters, 1001 Boulevard Robert-Bourassa, 26th floor, Montreal, Quebec, H3B 4L4
The masculine is used in a generic way to lighten the text. Only the persons retained after the analysis of the applications will be contacted.
Activity Domain: Information Technology and Intelligent Transportation Systems
Executive Direction: Portfolio Projects and Technologies
Employment Status: Permanent
Work Schedule: Full-time
Workplace Type: Hybrid
Cette offre a été agrégée depuis indeed. Groupe Sentinella n'est pas l'employeur; postuler vous redirige vers le site original. Le texte intégral appartient à l'auteur de l'offre.
Envie qu'on travaille pour vous ?
Inscrivez-vous au banc de talents Sentinella. On vous contacte dès qu'un mandat correspond à votre profil — y compris des postes comme celui-ci.
Rejoindre le banc de talents