- Company Name
- ALFACONSEIL.CA
- Job Title
- Conseiller·ère Sécurité TI – Évaluation des risques & Gouvernance
- Job Description
-
Job title: IT Security Advisor – Risk Assessment & Governance
Role Summary:
Lead the assessment and enhancement of cybersecurity posture across an application portfolio, ensuring alignment with global standards and regulatory frameworks. Drive secure design, implementation, and monitoring throughout project lifecycles while guiding IT teams and stakeholders.
Expectations:
- Deliver risk evaluations and protection recommendations for applications, infrastructure, and operational practices.
- Maintain compliance with Canadian and international standards (NIST, ISO, COBIT, PCI, GDPR, Loi 25).
- Communicate findings and progress to technical and non‑technical audiences.
- Facilitate remediation, exception management, and continual security improvement.
Key Responsibilities:
- Conduct comprehensive security posture reviews for the application portfolio.
- Verify compliance with regulatory and framework requirements.
- Embed cybersecurity requirements into every phase of the software development lifecycle.
- Advise IT teams on secure architecture, design, and delivery.
- Recommend appropriate controls for applications, infrastructure, and processes.
- Produce, update, and disseminate key risk, performance, and progress indicators.
- Support risk assessments, vulnerability remediation, and exception handling.
- Present security analyses and findings to technical and non‑technical stakeholders.
Required Skills:
- Proficient in authentication, monitoring, access control, auditing, and cryptography.
- Hands‑on knowledge of application architecture and technology environments.
- Strong communication, service orientation, collaborative mindset, and positive leadership.
- Familiarity with tools: Amazon Web Services (AWS), Microsoft Azure, VMware, WAF, SG, Checkpoint, Cisco, Jenkins, GitHub, Bitbucket, Datadog, Splunk, CloudWatch, CloudTrail, Aqua, Nexus IQ, Snyk, Artifactory.
Required Education & Certifications:
- Bachelor’s degree in Information Technology or related field.
- Minimum 5 years of cybersecurity experience.
- Recognized certifications: CISSP, CISM, CISA, CEH, or equivalent.
- Preferred: Cloud security certifications such as CCSP, AWS Security, Azure Security Engineer.