Risk Management Specialist

  • Ottawa
  • Innovapost

What role will you play? : Reporting to the Security, SOC & IAM Lead for Risk Management, the Risk Management Specialist is responsible for the creation, implementation, and oversight of a wide series of strategies and programs designed to limit information risk across the organization and the business partners. The role will establish and lead an enterprise-wide information security risk function, ensuring that security and compliance risks related to information systems and assets are identified and managed to external regulatory and legislative requirements while also delivering against internal policy requirements.

The Risk Management Specialist acts as a central security reporting contact for different types of security analysis and reporting requests.

What you'll be responsible for :

  • Provide leadership, vision, and direction regarding IT risk to the management and executive team
  • Ensure that information security and risk is adequately represented on relevant business and governance forums and is known, well-integrated, and well-respected across the enterprise
  • Drive and maintain the information security management system to identify, quantify, catalog, and remedy information risk across the enterprise, escalating where necessary
  • Oversee the maintenance of a global information security and risk management policy set, including standards and processes that fit the organization at all levels
  • Manage physical security across the organization
  • Work with the Security Compliance & Security Operations teams to ensure an ongoing analysis of information security threats, vulnerabilities, and market trends and to determine potential impact on the organization’s risk posture
  • Conduct information risk assessments across the enterprise at suitable intervals, ensuring that key risk issues are understood, communicated, and tracked on the risk register
  • Regularly verify that required information security and risk controls are in place, raising audit report findings as non
  • compliances are found, and driving improvement
  • Conduct information risk assessments (e.g. phishing exercises) across the enterprise at suitable intervals in order to ensure that key risk issues are understood, communicated, and tracked on the risk register.
  • Assist in the management of, and participate in, the Information Security Advisory Committee (ISAC)
  • Manage the creation and production of timely, accurate, and informative business and IT metrics relating to security Utilize the metrics to prioritize key initiatives and respond to negative trend
  • Create, manage, and deliver to the staff effective information security awareness training, ensuring that this addresses key risk areas, offers insight into staff obligations under policy, and reflects current threats
  • Weekly reporting to management on all outstanding risks and action plans / remediation timeline.
  • Work with Business Solution Delivery teams to ensure that security controls are incorporated into all initiatives. This includes Shapeproper documentation of those controls which are the certified and accredited. Develop and maintain security metrics for the security organization
  • Work with Business Solution Delivery teams to include open risk into their backlog allowing them to be prioritized / remediated
  • Assist with the facilitation of the monthly Information Security Advisory Committee (ISAC) meeting for the Group of Companies
  • Contribute to external and internal communications and information-sharing in the event of a privacy breach or incident
  • Promote the use of security modelling and validation tools (i.e. SDElements, SonarQube, etc.) across the organization while also leveraging the tools output to aid in the completion of risk assessments

What does it take for this role to be yours? :

  • 5 - 10 years experience in successfully leading comparable, global information risk, security, and governance teams
  • 5 - 10 years technical leadership and people management experience
  • Client Management : experienced in effectively interacting and communicating with business partners
  • Security and Risk Management: knowledge of information security and risk control frameworks such as NIST, COBiT, ISO 27001, ITIL, and ISO 31000 is preferred; knowledge of technological trends and developments in the area of information security and risk management
  • Reporting: analytics and data exploration experience and knowledge
  • Strategic Thinking: Partner with key departments to continuaously refine risk management processes
  • Knowledge of, and experience with, various GRC Tools

Additional skills that set you apart :

  • Exceptional interpersonal skills, and proven to flourish working in a fast-paced environment
  • Ability to work effectively in a cross-disciplinary team, across multiple projects and multiple locations Sharp analytic and problem-solving capabilities that go beyond strict technical expertise
  • Broad IT knowledge and strong level of familiarity with a wide