analyst, computer
Title posted on Jobillico -
Cybersecurity Risk Analyst
Posted on
September 20, 2024
by
Employer details
Produits forestiers Résolu
Job details
<span><p><span><span>Resolute Forest Products, founded more than two centuries ago, is a global leader in the forest products industry. Through the years, it has built more than 20 predecessor companies and supported hundreds of communities.</span></span></p> <p> </p> <p><span><span>The company owns or operates some 40 facilities, as well as power generation assets, in the United States and Canada. Our 6,600+ employees work hard to produce quality market pulp, tissue, wood products and papers that are marketed in over 60 countries. </span></span></p> <p> </p> <p><span><span>Resolute offers a rewarding and safe work environment with opportunities and challenges that will help grow your skills.</span></span></p> <p> </p> <p><span><span>The location in Montreal, (Quebec, Canada), is seeking talent to fill the position of <b>Cybersecurity Risk Analyst</b>. This job is full-time permanent.</span></span><br> </p> <p>By supporting the Manager of IT Compliance & Governance Security team, he/she will contribute the to IT risk management practice at Paper Excellence Group by maintaining and improving the IT risk management framework, manage IT exceptions and perform 3rd party vendor risk assessments. The resource will also participate to Business and IT projects and work with IT operation teams to assess risks and provide risk mitigation recommendations.</p> <p> </p> <p><b>IT/Security Risk Assessment Framework</b><br> ? Maintain and improve an IT/Security Risk Assessment Framework<br> ? Document IT security risk, mitigating controls and present them to risk owner for decision taking.<br> ? Coordinate with IT compliance team to ensure compensating controls have been put in place.<br> ? Maintain the IT risk register through out IT risks lifecycle.<br> ? Perform Privacy Impact Assessments (PIA). </p> <p><br> <b>3rd party vendors security assessment</b><br> ? Maintain and improve 3rd party vendors assessment methodology.<br> ? Perform 3rd party and cloud vendor security posture assessment, document the assessment and present the results to business owners.<br> ? Review 3rd party contracts for IT security and data privacy related clauses and work in collaboration with IT Procurement and Legal teams.<br> ? Maintain the Cloud vendor register. <br> ? Provide vendor selection services for cybersecurity aspects to help business units select a vendor as part of RFP process.</p> <p><br> <b>IT Exception Handling Process</b><br> ? Manage and maintain the IT Exception Handling Process.<br> ? Document IT Exceptions, validate the needs from exception requestors and owner, seek exception approval from Cybersecurity management.<br> ? Document risk assessment as needed.<br> ? Maintain the IT Exceptions register and follow-up on approved exceptions.</p> <p> </p> <p><b>Project advisory</b><br> ? Provide project advisory services to Business and IT projects on IT risk matters to ensure risk management activities during project?s lifecycle. Occasionally provide support to project security advisory team to document project security requirements and controls to implement.</p> <p><br> <b>Risk management KPI and KRI</b><br> ? Produce and report IT risk management KPI and KRI on a monthly basis.</p> <p><br> <b>Required Qualifications/Professional Experiences</b><br> ? Bachelor degree or 5 years of professional experience in Cybersecurity;<br> ? Minimum of 8 years? experience of security governance, risk and compliance (GRC);<br> ? Holds security related certifications such as CISSP, CISM, CSSP or similar an considered an asset;</p> <p>Preferred Qualifications/Professional Experiences/Years of Experience: <br> ? Practical experience with implementing and/or working with IT Risk management frameworks;<br> ? Practical experience with performing IT Risk assessment during projects and as part of security operations;<br> ? Practical experience with security controls and risk mitigation measures implementation.<br> ? Practical experience by assessing 3rd party vendor
-
LocationMontréal, QC
-
Workplace information
On site
-
SalaryNot available
-
Starts as soon as possible
- vacancies
1 vacancy
- Source
Jobillico
#14360613
Advertised until
2024-10-19
Important notice: This job posting has been provided by a partner site. Job Bank is not responsible for this content.
Report a problem with this job posting
Thank you for your help!
You will not receive a reply. For enquiries, please contact us.