
Technology Risk Management Specialist
- Calgary, AB
- Permanent
- Full-time
- Leveraging experience in Risk Management, develop and implement of the cybersecurity risk management program based on the Firm’s acceptable risk tolerance levels
- Conduct business impact analysis and information security risk assessment on new projects, initiatives, mergers and acquisitions
- Advise and support the business on day to day activities and provide guidance on the remediation plans to mitigate risk
- Document activities and findings in the risk assessment report review and approval processes
- Develop dashboards and reporting on Firm risk and compliance activities
- Track, monitor and follow up on all risk findings in the risk register
- Help evaluate and improve Cyber Security policies and ensure compliance by all stakeholders
- Work with Cyber Security team members in evaluating the efficacy of each control and provide recommendations to increase security posture
- Define, capture, and report Key Performance Indicators for security dashboards in the areas of risk and compliance management, Cyber Security training and awareness
- Actively participate in tabletop exercises and disaster recovery drills, and provide recommendations as part of lessons learned
- 10 years of experience in Cyber Security, with at least 5 years of Security GRC (Governance, Risk and Compliance) within a large organization
- Completion of CISM, CISSP or other relevant security certificates is considered an asset
- Knowledge and experience with Cyber Security and Information Technology domains
- Knowledge of cloud security (AWS & Azure)
- Demonstrated analytical and critical thinking skills when developing remediation recommendations and findings prioritization
- Deep knowledge and ability to apply frameworks and controls from international standards such as NIST and CIS
- Continuous research on current and emerging cyber threats, commonly used tactics, techniques and procedures by malicious actors