Cyber Security Strategy, Supervisor (Canada)
RSM International View all jobs
- Toronto, ON
- $75,000-120,000 per year
- Permanent
- Full-time
- Oversee the delivery and management of diverse cybersecurity engagements including the strategic assessment, roadmap development, and coordination of projects that improve cyber program maturity across a variety of cyber disciplines.
- Manage and expand key client accounts and relationships to drive the transformation of clients' operational resilience and cybersecurity agendas
- Communicate effectively with client management and project leaders to build and maintain strong client relationships
- Conduct cybersecurity governance and compliance assessments against various regulatory and industry standards, including but not limited to the NIST CSF, ISO 22301, HIPAA/HITECH, HITRUST CSF, Privacy, FFIEC, FINRA, DORA, NIST SP 800-53 and/or Cyber Resilience
- Design and implement cybersecurity controls that address risk and unify requirements across multiple cybersecurity frameworks
- Assist clients in designing and implementing cybersecurity remediation strategies to enhance the overall maturity of their cybersecurity programs by identifying suitable technologies, policies, and organizational structures
- Clearly articulate findings, observations and recommendations to senior management and clients, both in writing and verbally
- Develop target operating models for cyber security programs including budgets, resource levels, reporting structure, etc
- Advise clients on security budget allocation and resource planning (human and technical) to ensure the security program is sustainably supported and scalable
- Lead the development and ongoing management of multi-year security roadmaps, ensuring tactical projects remain prioritized and aligned with long-term strategic maturity goals
- 5 - 8 years of experience:
- Building, leading and developing high performing teams
- Supporting or operating as a virtual CISO for mid-market clients, providing consistent leadership and oversight of their cybersecurity programs.
- Mentoring and influencing others both internally and within client organizations
- Managing client work and drive client communications with limited oversight from RSM Senior Leadership
- Managing budgets and resource allocation including, but not limited to program and project management
- Oversee security projects from inception to completion, ensuring they are delivered on time and within budget
- Monitor project progress, identify potential roadblocks, and implement corrective actions to ensure timely delivery
- Executing cyber program assessments including risk assessments and control maturity assessments against frameworks such as NIST or CIS
- Developing prioritized observations as well as developing and communicating strategic roadmaps to enable an organization’s incremental maturity of their cybersecurity posture
- High degree of integrity and confidentiality, as well as ability to adhere to company policies and best practices
- Demonstrated ability to perform quantitative and qualitative analysis of security data
- Basic knowledge of common compliance requirements (e.g., NIST, ISO, CIS, GDPR, CCPA, PCI, HIPPA, HITRUST, DFARS, CMMC, etc.)
- Passion for cybersecurity and ability to self-direct and teach themselves about new and emerging cybersecurity concepts.
- Excellent written and verbal communication skills, with a focus on translating technical requirements for business stakeholders.
- Ability to manage and prioritize multiple tasks in a fast-paced environment, particularly in support of cybersecurity project lifecycles.
- Willingness to travel up to 30% to client sites for various engagements.
- Strong interpersonal skills with a proven track record in a professional services firm, large consultancy, or similar environment.
- Demonstrated ability to collaborate effectively, especially with cross-functional teams.
- Proficiency in Microsoft suite of tools including Excel, OneNote, etc. is desired
- Understanding of secure cloud architecture and design as well as certifications in solutions such as AWS or Azure
- Practical hands-on experience with IT infrastructure components such as servers, firewalls, IDS systems and other network infrastructure components
- Practical hands-on experience with security tools, such as vulnerability scanning solutions, SIEM, EDR, GRC, SOAR, etc.
- Practical hands-on experience with digital identity tools such as Okta, SailPoint, Saviynt, or Microsoft
- Experience using data visualization tools (e.g., Power BI, Tableau) to create meaningful security metrics
- One or more security focused certifications: Certified Information Systems Security Professionals® (CISSP®); Certified Information Systems Auditor® (CISA®); Certified Information Security Manager® (CISM®), etc.
- One or more project management certifications: Certified Associate in Project Management (CAPM) or Project Management Professional (PMP)
- Certifications in business continuity, such as CBCP, ACBP or cybersecurity, such as CISSP, CISM, or CISA.