Building What Matters for Future Generations to Thrive.
Senior analyst conducting security risk assessments, compliance, and governance.
21 days ago ago
Expert & Leadership (13+ years)
Full Time
Toronto, ON, CA
Hybrid
Company Size
9,000+ Employees
Service Specialisms
Construction
Project Management
and more…
Sector Specialisms
Civil
Nuclear
Industrial
Utilities
Transport
Role
Description
policy development
compliance review
risk assessment
control implementation
framework design
reporting
Develop and maintain information security governance documentation, including policies, standards, procedures, and guidelines.
Collaborate with Internal Audit, Legal, Privacy, and other stakeholders to ensure IS policies and controls meet all regulatory and organizational requirements.
Ensure you and your family receive the services needed to support your mental, emotional, and physical well-being.
Conduct monthly compliance reviews with security service providers to ensure adherence to SLAs and contractual requirements.
Recommend and implement appropriate controls to address identified security risks and enhance organizational security.
Prepare periodic reports and presentations for senior management, steering committees, and the board of directors.
Provide backup support for other security team members as needed.
Design, operate, and manage a compliance framework aligned with ISO 27001, including associated controls.
Provide expert consultative advice to Information Services (IS) and business units to support informed risk management decisions.
Identify opportunities to improve processes for security risk identification and management.
Assess security controls of vendors and third parties safeguarding company assets through contract and compliance reviews.
Conduct comprehensive security risk assessments for new and existing services, applications, technologies, and vendors. Clearly document and communicate findings to relevant stakeholders.
Facilitate audits and risk reviews with internal/external auditors, clients, and business teams; ensure timely response and track remediation to closure.
Monitor the effectiveness of security controls through the design and implementation of KPIs and KRIs for reporting.
Requirements
networking
security
compliance
cissp
bachelor's
8 years
Influencing: Ability to positively influence colleagues and gain genuine agreement.
Strong understanding of computer networking concepts, protocols, and IT security methodologies.
Bachelor's degree in Computer Science, Information Security, or a related field.
Minimum 8 years of experience in IT, with at least 5 years in information security/compliance or IT audit, and 3 years in security risk management.
Capacity to manage multiple priorities and meet tight deadlines.
Strong analytical and problem-solving skills.
Demonstrated results orientation, energy, and self-motivation.
In-depth knowledge of legal and regulatory compliance standards (e.g., GDPR, PCI-DSS, PHIPA, ISO 27001, NIST).
Problem Solving: Proficient in applying logic and techniques to resolve complex issues; skilled in asking probing questions to achieve optimal outcomes.
Stakeholder Management: Ability to influence with and without direct authority; high emotional intelligence and organizational awareness.
Decision Making: Sound judgment and decision-making in complex, dynamic environments; innovative risk orientation.
Ability to adapt to evolving technical, regulatory, and compliance environments.
Proven ability to work collaboratively within a team environment.
Excellent verbal and written communication skills.
Adaptive Thinking: Effective change leadership and critical thinking skills; sound analysis and logical reasoning.
Business Acumen: Deep understanding of business operations, trends, and technologies impacting the organization.
Professional certifications such as CISM, CISA, CRISC, or CISSP are considered assets.
Benefits
Information not given or found
Training + Development
Information not given or found
Interview process
Information not given or found
Visa Sponsorship
Information not given or found
Security clearance
Information not given or found
Company
Overview
2.5 km bridge
Cable-stayed Bridge
Connecting Windsor, Ontario, and Detroit, Michigan.
260,000 people
Water Treatment Plant
Supplies water to over 260,000 people in Saskatchewan.
Spanning over 150 years.
Operates in civil infrastructure, urban transportation, and energy solutions.
Involved in planning, financing, and execution through public-private partnerships.
Advanced urban transportation projects, such as the Réseau express métropolitain (REM).
Advancing projects like the Darlington Small Modular Reactor.
Committed to sustainability and cutting-edge technology.
Culture + Values
Prioritized as the number one value, with a strong emphasis on maintaining a safe and healthy work environment, aiming for a 'zero injury' culture.
Integral to the company's professional conduct, ensuring transparency and honesty in all interactions.
Significant importance is placed on integrating environmentally responsible practices into its operations.
Reflects the communities in which it operates, with a commitment to equity, diversity, and inclusion.
Supported by both financial and non-financial rewards aimed at recruiting, developing, and retaining talent, thus motivating employees and enhancing their work experience.
Environment + Sustainability
64% Revenue
Sustainability Projects Contribution
A significant portion of the company's revenue is generated from projects focused on clean energy and sustainable development.
Net Zero 2050
Emissions Target
The company aims to achieve net zero emissions by the year 2050 as part of its sustainability strategy.
Focus on clean energy solutions with in-house design and engineering capabilities.
Development of green energy projects, including the Darlington Small Modular Reactor (SMR) for efficient nuclear power.
Involved in large-scale energy storage projects to supply clean and reliable electricity.
Inclusion & Diversity
19% Women Executives
Female Representation in Leadership
19% of executives at the VP-level and above are women, reflecting progress in gender diversity at senior levels.
275M Indigenous Procurement
Procurement from Indigenous Businesses
Significant procurement from Indigenous businesses, amounting to $275 million in goods and services, demonstrates commitment to Indigenous partnerships.
Has developed a robust inclusion and diversity strategy aimed at fostering a diverse and inclusive workplace.
Guided by the Diversity & Inclusion Council, which comprises both leadership and employees to champion these efforts.
Focus on three key outcomes: improving diversity across all areas and levels of the organization, enhancing employee engagement, and fostering an inclusive culture.
Initiatives include the creation of Indigenous-led joint ventures and fostering the inclusion, engagement, and participation of Indigenous workers and communities in projects throughout Canada.