Information Security Risk Management Analyst
Vancity View all jobs
- Vancouver, BC
- $92,700-115,000 per year
- Permanent
- Full-time
- Assist the Senior Manager, Information Security Compliance in developing and implementing a strategic approach to information security risk management across people, process, and technology.
- Lead the development and maintenance of Information Security risk and governance KPI's, KRI's, and SLA's. Assist with metrics creation and reporting. Provide reporting on the status of information security risks to leadership and stakeholders.
- Participates in third-party and supply chain cybersecurity risk assessments.
- Maintain the IT risk register on the GRC platform (Onetrust, Auditboard).
- Perform Security Threat Risk Assessments of all new projects and technology implementations.
- Develop and maintain IT and Security Risk Assessment processes and documentation.
- Advise various teams on risk mitigation and compensatory measures to reduce risks to acceptable levels, using knowledge of Vancity policies, technologies, standards and industry best practices.
- Foster a risk aware culture across the organization.
- Other duties as assigned.
- A bachelor’s degree or equivalent in Computer Science, Business, or a related field
- 3-5 years of progressive experience in information security risk management, preferably in a mid-sized corporate organization or a financial institution
- Information Security Certifications in one or more of the following are desirable: Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), or Certified Information Security Manager (CISM).
- In-depth understanding of risk management frameworks such as NIST RMF, NIST AI-RMF, ISO 31000, FAIR, and ISO 27001
- A good understanding of relevant standards and frameworks that apply to the financial services industry such as PCI/ SWIFT/ NIST/OSFI
- Strong understanding of regulatory requirements and standards (e.g., OSFI, BCFSA, PIPA, PIPEDA)
- An exceptional communicator - you are comfortable communicating with stakeholders across different levels of the organization. You demonstrate confidence and provide highly specialized technical expertise and advice.
- Flexible – You have a willingness to work in a highly flexible environment with multiple competing priorities.
- Organized - Good multi-tasking skills and the ability to prioritize work based on risk and business needs
- Living Wage Employer: We’re the largest private-sector Living Wage Employer in Canada and consistently ranked among Canada’s Top Employers.
- Customizable Benefits: Permanent employees receive flexible benefit packages that can be tailored annually to meet evolving needs.
- Generous Vacation: New employees start with 3-4 weeks of vacation per year, with additional days earned over time.
- Extra Stat Holidays: In addition to BC’s 11 statutory holidays, we offer 2 extra days, plus care days for personal or family illness.
- Immediate Health Coverage: Health and dental benefits begin on your hire date, with three levels of coverage to choose from.
- Defined Benefit Pension: Our retirement plan provides a guaranteed income for life, recognizing that retirement looks different for everyone.
BachelorsLicences & certifications Cert Info Systems Auditor
Cert Info Syst Security