Compétences recherchées — Connectez-vous et téléversez votre CV pour comparer avec votre profil
Détails du poste
- Lieu de travail : Montreal (Hybride)
- Type de poste : Permanent à temps plein
Description du poste
Job Title: Cybersecurity Metrics and Controls Specialist
Location: Montreal, QB
Job Type: Full-Time (FTE)
Work Model: Hybrid
Résumé du poste
We are seeking a Cybersecurity Metrics and Controls Specialist to join the Continuous Controls Monitoring (CCM) team within the Metric Design & Architecture function. The ideal candidate will define, implement, and optimize cybersecurity control metrics, collaborate with cross-functional stakeholders, and establish reporting frameworks that measure the effectiveness and maturity of technology and security controls.
Responsabilités clés
- Define and document cybersecurity control and risk metrics for enterprise technology controls.
- Develop Key Control Indicators (KCIs) and control measurement frameworks.
- Collaborate with Technology Policy teams to ensure metric requirements are incorporated into policy design and governance.
- Partner with business stakeholders and metric consumers to develop reporting frameworks and dashboards.
- Work closely with CCM Data Acquisition and Tooling teams to implement control metrics.
- Analyze technology processes and security data to ensure accurate measurement of control effectiveness.
- Monitor control implementation, operational efficiency, and compliance across technology environments.
- Support continuous improvement initiatives for cybersecurity metrics and reporting.
- Provide insights and recommendations based on quantitative and qualitative analysis.
- Collaborate with security, infrastructure, cloud, and application teams to strengthen enterprise security posture.
Compétences requises
- Information Security
- Cybersecurity Controls
- Continuous Controls Monitoring (CCM)
- Risk Metrics
- Key Control Indicators (KCI)
- Security Governance
- Technology Risk Management
- Security Reporting
- Data Analysis
- Stakeholder Management
- Security Policy
- Control Frameworks
Expertise technique
- Identity & Access Management (IAM)
- Authentication & Authorization
- Data Security
- Network Security
- Application Security
- System Security
- Security Logging & Monitoring
- Incident Response
- Public Cloud Security (AWS, Azure, or GCP)
- Technology Controls
- Risk Assessment
Qualifications préférées
- 10+ years of experience in Information Security and/or Information Technology.
- 5+ years of hands-on experience implementing cybersecurity or technology controls.
- Experience designing cybersecurity metrics, reporting frameworks, and governance processes.
- Cybersecurity certifications such as CISSP, CISM, CRISC, Security+, or equivalent are preferred.
Compétences clés
- Strong analytical and strategic thinking.
- Excellent communication and stakeholder management skills.
- Ability to manage multiple priorities and work under tight deadlines.
- Strong business acumen with customer-focused problem-solving capabilities.
- Ability to make data-driven decisions and influence cross-functional teams.