Senior Security Advisor - Refugee Hiring Toronto Bookmark Share Print 10 0 0

Listing Description

Our employer partner, a Canadian financial services company that operates equities, fixed income, derivatives, and energy markets exchanges is looking to add a driven and detailed Senior Security Advisor t to their team!

Reporting to the Senior Manager - Governance Risk Compliance (GRC) department, the Senior Security Advisor will contribute to the development, maturing, implementation and operation of the company information security program and cybersecurity governance structure. This role will provide support in assessing and managing cybersecurity risks, ensuring alignment with security policies and industry best practices.  The Advisor will work collaboratively with various business units and technology teams to promote a strong security culture and enhance the overall security posture and resilience of TMX Group.


Key Responsibilities:
  • Cybersecurity Policy Framework: Support the development and maintenance of the company Cybersecurity Policy Framework, considering specific security profiles and risk tolerances of various business units, systems, and cloud environments.
  • Cybersecurity Risk Assessments: Conduct Threat and Risk Assessments (TRAs) on various business units and initiatives, focusing on financial systems and their associated threats. Critically, these assessments must reflect the specific threats and vulnerabilities faced by each business unit, while considering both their individual risk appetite and the enterprise risk appetite of the company as a whole. Provide input to risk mitigation strategies and remediation plans.
  • Security Standards and Guidelines: Assist in the development and implementation of security standards, guidelines, and best practices, ensuring alignment with industry standards such as NIST and ISO 27000 series. Adapt these standards to address the unique security challenges of businesses, cloud environments, AI, and GenAI technologies.
  • Security Awareness and Training: Contribute to the development and delivery of cybersecurity awareness training programs for personnel and teams across the company, tailored to different roles and responsibilities.
  • Cybersecurity Reporting: Assist in the development of security metrics: KRIs and KPIs. Contribute to reports related to the status of cybersecurity and the execution of risk remediation plans.
  • Data Privacy and Protection: Support the implementation and maintenance of data privacy and protection policies and procedures, ensuring compliance with relevant regulations like PIPEDA (Canada), GDPR (EU), and CCPA (California). Assist in conducting data protection impact assessments and data breach response activities.
  • Third-Party Risk Management: Contribute to the development, maturing, and implementation of a third-party risk management program, assessing and managing risks associated with all third-party relationships, including vendor security assessments.
  • Security Incident Response Planning: Participate in security incident response planning and contribute to the development and maintenance of incident response procedures. Note: Incident response execution is the responsibility of the Information Security Operations team.
  • Cybersecurity Resilience: Work with business units to integrate cybersecurity considerations into their business resilience plans. Help guide them in establishing and operating adequate plans to ensure business continuity in the face of cyber threats.
  • Cybersecurity Exercises and Testing: Contribute to the development and execution of cybersecurity Table Top Exercises for business units to enhance their preparedness for cyber incidents. Assist in defining the objectives and scope of regular penetration tests for technology systems.
  • Regulatory Compliance: Support compliance with relevant regulatory frameworks, such as PCI DSS, SOX, OSFI (Canada), or GLBA, by monitoring regulatory changes, conducting compliance assessments, and developing remediation plans.
  • Business Continuity and Disaster Recovery: Ensure cybersecurity considerations are integrated into business continuity and disaster recovery planning efforts.
  • Collaboration and Communication: Work closely with ITSS Architecture, Security Operations teams, Enterprise Risk Management, and other key stakeholders. Foster a collaborative environment to ensure effective communication and alignment on security initiatives.
  • Research and Innovation: Stay abreast of emerging cybersecurity threats, trends, and technologies, including those related to cloud environments, AI, and GenAI frameworks. Conduct research and analysis to identify innovative approaches and solutions for managing information security risks within the company.
  • Vendor Security Assessments: Support the assessment of vendor products and services from a security perspective, providing recommendations related to purchase and merger & acquisition activities.

  • Qualifications:
  • University undergraduate degree in Computer Science, Engineering or a related field.
  • 5+ years of experience in information security or a related field, with experience in financial market infrastructure strongly preferred.
  • Proficiency in conducting threat and risk assessments, particularly within the context of financial systems.
  • Experience in developing, implementing, and operating information security programs and practices.
  • Strong understanding of cybersecurity frameworks and standards such as NIST, ISO 27001, and CISSP.
  • Knowledge of capital markets and cloud environments, including their security considerations.
  • Familiarity with AI and GenAI frameworks and their associated security risks.
  • Excellent communication, collaboration, and interpersonal skills, with the ability to interact effectively with both technical and non-technical audiences.
  • Strong analytical and problem-solving skills.
  • Knowledge of Python and process automation is considered a plus.
  • CISSP, CISA, CISM, or similar certifications are considered assets.
  • We appreciate all applicants interested in this opportunity, however; only selected candidates will be contacted regarding next steps.


    Listing Details

    • Citizenship: Not Provided
    • Incentives: Not Provided

     

    • Education: Not Provided
    • Travel: Not Provided
    • Telework: Not Provided


    About Us

    NinjaJobs is a community-run job platform developed by information security professionals. Our unique approach of focusing strictly on cybersecurity positions allows us to personalize the user experience.

    Our Contacts

    1765 Greensboro Station Pl.
    Suite 900
    Tysons Corner Va 22102

    (703) 594-7765