Risk/Compliance Specialist - Senior
Assignment: RQ00161 - Risk/Compliance Specialist - Senior
Requisition: RQ00161
Job Title: Risk/Compliance Specialist - Senior
Client: Metrolinx
Start Date: 2025-09-08
End Date: 2026-03-06
Office Location: 277 Front Street West, Toronto
Business Days: 130.00
Location: Hybrid - 2 days in office/3 days remote
Public Sector Experience: Preferred
Must Haves:
- 7+ Leading security and vendor risk assessments, identifying risks and gaps, and developing mitigation strategies for third-party vendors.
- 7+ years Developing and implementing cybersecurity governance frameworks, policies, and procedures in collaboration with cross-functional teams.7+ Collaborating with internal teams and vendors to develop cybersecurity requirements for new solutions
- 7+ Developing the security process, procedure, governance artifacts and security controls within the Cybersecurity Risk Management and Governance/Compliance Programs.
- 7+ years experience in contract negotiation with procurement and legal teams through RFP processes and vendor evaluations throughout procurement life cycle
- 7+ years experience knowledge of industry standards and regulations such as PCI-DSS, NIST, ISO 27001
- 7+ years experience facilitating cybersecurity awareness training
Description
Responsibilities:
- Coordinate and perform risk assessments against a wide variety of inputs. Analyzes data from various sources to identify remediation of risks. Interprets policies, legislation and standards to adequately provide advice for management and executives.
General Skills:
- Experience interpreting requirements from those standards and translating them into actionable implementations Strong understanding of internal control frameworks, control mappings, and scoping Familiar with a broad range of technical concepts: logical access control, agile development process, secure coding principles, security architecture, information security, network security, and privacy Expertise in gap analysis, remediation, control design and risk assessments Exceptional verbal and written communication skills
- Desirable Skills:
- Experience with GRC (Governance, Risk, Compliance) tools is a plus
Deliverables
- Lead security and vendor risk assessments, identifying risks and gaps, and developing mitigation strategies for third-party vendors.
- Conduct detailed assessments of third-party vendors' security domains, communicate findings, prepare regular reports and updates to management and stakeholders.
- Develop and implement cybersecurity governance frameworks, policies, and procedures in collaboration with cross-functional teams.
- Provide support for audit, compliance, and regulatory requests. Precise and thorough documentation and analysis are essential for effective security auditing and compliance efforts.
- Collaborate with internal teams and vendors to develop cybersecurity requirements for new solutions, ensuring alignment with security policies and standards.
- Work with other team members to develop and align with cybersecurity requirements for solutions as required
- Work with project teams to recommend and implement security controls to address identified risks.
- Work with Enterprise Architecture, Solution Delivery, Security and Operations teams as part of a large program/project team to ensure security solutions and meet security compliance and security policies and standards
- Identify requirements for policies and standards, and work with relevant teams in creation, development, review and approval
- Act as a cybersecurity resource for new and upcoming project-based detail work
- Work with project teams to identify and recommend security controls to remediate security risks and issues
- Ongoing compliance work related to regulatory requirements and/or compliance to Metrolinx standards
- Develop the security process, procedure, governance artifacts and security controls within the Cybersecurity Risk Management and Governance/Compliance Programs.
- Assist with security audits and threat/risk assessments to ensure compliance with security policies, standards and procedures, and work with business/technical/operational areas in taking corrective actions on any identified security exposures
- Provide advice, risk assessment, recommendations and technical assistance in implementing security controls for projects
- Communicate regularly with cybersecurity teams, internal stakeholders, project teams and representatives from various functional teams, including escalating any matters to senior team members that require additional analysis
- Support the implementation of security principles, policies, and standards to align with industry best practices, ensuring security controls are integrated into system development, deployment, and operation
Additional Terms
Experience/skills required:
- A minimum of seven (7+) years of experience in information security. Including working with large security projects
- Strong communication, interpersonal and presentation skills for engaging with diverse stakeholders
- Expertise in security governance, risk management, and compliance, including developing road maps, policies, standards, procedures and processes
- Proven experience in contractual security requirements and third-party risk management through RFP processes and vendor evaluations throughout procurement life cycle
- Ability to work in cross-functional teams, communicating complex technical information to all levels of the organization, including the leadership team
- Proficient in cybersecurity risk management and third-party risk management tools (e.g., ServiceNow, OneTrust, Audit Board).
- Experience with development of security processes, procedures and standards documentation
- Strong knowledge of industry standards and regulations such as PCI-DSS, NIST, ISO 27001 and the ability to ensure compliance
- Strong time management skills and the ability to prioritize project work and ongoing responsibilities
- Self-motivated with the ability to work independently in a fast-paced environment in a fast-paced environment
- Proficiency with standard Microsoft Office tools such as Word, Excel, PowerPoint, PowerBI and Visio
Education:
- A current security designation (CISSP, CISM, CCSP or CISA)
Recommended Jobs
Clinical Psychologist
Experience the Matrix Providers Advantage. We strive to provide a framework of stability and structure for our valued employees, where you will experience lower provider-to-patient ratios and fair, …
Lead Software Engineer - Android (San Francisco)
Technology is at the heart of Disneys past, present, and future. Disney Entertainment and ESPN Product & Technology is a global organization of engineers, product developers, designers, technologists…
Machine Learning Engineer
If you are looking for a challenging and exciting career in the world of technology, then look no further. Skyworks is an innovator of high-performance analog semiconductors whose solutions are power…
Regulatory Affairs Specialist III - Urology
Additional Location(s): US-CA-Irvine; US-CA-Valencia; US-MA-Marlborough; US-MN-Maple Grove Diversity - Innovation - Caring - Global Collaboration - Winning Spirit - High Performance At B…
Senior Project Manager - Interior Design
This is more than a job - it’s a chance to take leadership to the next level, to lead a team of project managers and creative designers and to grow a portfolio of work that reflects a collective …
Care Manager (RN) (Must reside in CA) (San Francisco)
JOB DESCRIPTION Job Summary Molina Healthcare Services (HCS) works with members, providers and multidisciplinary team members to assess, facilitate, plan and coordinate an integrated delivery of …
Principal Scientist, Late Stage Upstream Process Development
Client is seeking an experienced and driven scientist/engineer to lead late-stage upstream cell culture process development activities for clinical and commercial-stage large molecule programs. This i…
New Release - The Five: Narratives of Victims and Narratives edited by Lee Rosen
San Diego, CA – October 1, 2024 – Cognella Academic Publishing is proud to announce the publication of The Five: Narratives of Victims and Survivors edited by Lee Rosen. The book provides readers wit…
Kitchen Team Member (Day Shift)
Michoacana Mia in San Diego, CA is looking for one cashier to join our 5 person strong team. We are located on 5971 University Ave Suite 307. Our ideal candidate is attentive and hard-working. Respo…
Occupational Therapist Assistant
Overview: Outpatient Occupational Therapist Assistant - COTA - Hand Therapy What has stood out to me most with AllStar is the massive amount of support and encouragement for growth. The autonomy t…