Senior Information Security Specialist, Governance and Compliance
Full Time Permanent
Toronto, 4 days on site
Client: Canadian Tire
About Us
Canadian Tire Corporation, Limited (“CTC”) is one of Canada’s most admired and trusted companies. With more than 90 Owned Brands, 1,700 retail locations, financial services, exemplary e-commerce capabilities, and exciting market-leading merchandising strategies. We dream big and work as one to innovate with purpose for our customers at every level of our business, investing in new technologies and products, and doubling down on top talent to drive the company forward. We offer competitive salaries and wages to CTC employees, as well as store discounts, supported learning through our Triangle Learning Academy, Canadian Tire Profit Sharing, and retirement and savings programs for eligible employees. As part of our enhanced flex benefits program, we offer mental health benefits in the amount of $5,000 per year for benefits-eligible employees and their families, including total well-being, and mental health tools and resources for all employees. Join us in helping to make life in Canada better through living and working our Core Values: we are innovators and entrepreneurs at our core, outcomes drive us, inclusion is a must, we are stronger together and we take personal responsibility. It is an especially exciting time to join CTC and its family of companies where career opportunities are wide-ranging! Join us, where there's a place for you here.
Job Description
What you’ll do:
The Senior Information Security Specialist, Governance and Compliance will lead the charge in maintaining cyber security standards, responding to regulator and auditor inquiries, and providing an advisory function to the business surrounding cyber security governance.
- Provide senior level advisory services to cybersecurity, technology teams, and business team members, as required
- Create and maintain cyber security policies and standards
- Manage the cyber security policy exemption management processes by assessing policy exception requests, maintaining the exception workflows, and updating and keeping current the exception database
- Respond to external inquires regarding cyber security (e.g. ESG, regulators, etc.)
- Analyze and assess cyber security related business scenarios and prepares/presents position papers providing risk-based recommendations to assist the leadership team in making informed decisions
- Oversee and provide guidance on the cyber security configuration compliance management program for both on prem and cloud environments
- Oversee and provide guidance on the cyber security vulnerability, configuration & patch remediation management programs
- Oversee and provide guidance on the Cloud security compliance management program
- Design and perform annual reviews of configuration benchmarks for teams to follow for new and existing systems
- Keep current with ongoing trends and changes within the cyber security community
What you bring:
- University degree preferably in an IT related discipline
- CISSP, and/or CISM, and/or CISA, and/or CRISC designations would be an asset
- 8-10+ years experience in information security, and/or IT Audit/Compliance, and/or external audit
- Extensive experience with governance and risk policy review, creation, and implementation, particularly concerning Azure cloud
- Strong understanding of IT, cloud and cyber security concepts and best practices
- Strong technical writing skills for the creation of new security polices and controls
- Understands cyber security risks and control frameworks including NIST CSF, PCI DSS, CIS benchmark, MS Azure security benchmark and ISO 270001
- Extensive experience with Microsoft Azure Portal/Security Center to monitor and manage vulnerabilities, security policy compliance and all outstanding Microsoft recommendation
- Understanding of Agile concepts and practices
- Ability to communicate and influence effectively at all levels from technical staff to company leadership team
- Proven ability to weigh business needs with information security priorities and make sound risk-based judgement calls
- Experienced with analyzing and assessing cyber security related business scenarios, performing risk assessments, and preparing position papers outlining sound, risk-based recommendations
- Experienced with analyzing and assessing cyber security policy exception requests and providing risk-based recommendations
- Experience overseeing cyber security configuration compliance programs
- Experience overseeing cyber security vulnerability & patch management programs
- Experience overseeing Cloud security compliance management programs
- Experience with developing security baselines based on industry accepted CIS benchmark, MS Azure security benchmark, PCI DSS benchmark, etc. and conduct regular reviews to update existing custom baselines
- Experience with security assessment tools such as Tripwire, Nexpose, MS Defender, McAfee EPO, Kenna, etc.
- Technical knowledge including Linux, Windows, AIX, databases, network and security appliances and firewalls/IDS/IPS, web and cloud-based applications, secure coding practices, and cloud security
- Highly proficient with MS Office suite of products
Our Commitment to Diversity, Inclusion and Belonging
We are committed to fostering an environment where belonging thrives, and diversity, inclusion and equity are infused into everything we do. We believe in building an organizational culture where people are consistently treated with dignity while respecting individual religion, nationality, gender, race, age, perceived ability, spoken language, sexual orientation, and identification. We are united in our purpose of being here to help make life in Canada better.
Accommodations
We stand firm in our Core Value that inclusion is a must. We welcome and encourage candidates from equity-seeking groups such as people who identify as racialized, Indigenous, 2SLGBTQIA+, women, people with disabilities, and beyond. Should you require any accommodation in applying for this role, or throughout the interview process, please make them known when contacted and we will work with you to help meet your needs.
The pay range that the employer reasonably expects to pay for this position is between CA$64,000 and CA$106,000
Our voluntary benefits offering includes medical, dental, vision and retirement benefits.
Applications will be accepted on an ongoing basis.
Tundra Technical Solutions would like to thank you for the interest you have demonstrated in this opportunity. However, only candidates with the required skills will be contacted.
Tundra Technical Solutions is an Equal Opportunity/Affirmative Action Employer. We welcome and encourage diversity in our workplace.
Not interested in this position, but know somebody who might be? Check out our Referral Reward Program, referrals are a big secret behind our success. As always, we’re on the lookout for great people. And we know that you know great people!
Tundra Technical Solutions is among North America’s leading providers of Information Technology and Engineering staffing and consulting services. Our success and our clients’ success are built on a foundation of service excellence. Rather than continually trying to sell to new clients and companies and simply filling databases with candidates, we focus on developing stronger relationships and deeper knowledge of our existing clients’ challenges and opportunities.
Open ears. Open minds. Open futures