Connexion

Compétences recherchées — Connectez-vous et téléversez votre CV pour comparer avec votre profil
Gestion des risques Conformité réglementaire Analyse de données +6 autres

Détails du poste

  • Lieu de travail : Montreal (Hybride)
  • Type de poste : Permanent à temps plein

Job Title: Cybersecurity Metrics and Controls Specialist
Location: Montreal, QB
Job Type: Full-Time (FTE)
Work Model: Hybrid

Job Summary

We are seeking a Cybersecurity Metrics and Controls Specialist to join the Continuous Controls Monitoring (CCM) team within the Metric Design & Architecture function. The ideal candidate will define, implement, and optimize cybersecurity control metrics, collaborate with cross-functional stakeholders, and establish reporting frameworks that measure the effectiveness and maturity of technology and security controls.

Key Responsibilities
  • Define and document cybersecurity control and risk metrics for enterprise technology controls.
  • Develop Key Control Indicators (KCIs) and control measurement frameworks.
  • Collaborate with Technology Policy teams to ensure metric requirements are incorporated into policy design and governance.
  • Partner with business stakeholders and metric consumers to develop reporting frameworks and dashboards.
  • Work closely with CCM Data Acquisition and Tooling teams to implement control metrics.
  • Analyze technology processes and security data to ensure accurate measurement of control effectiveness.
  • Monitor control implementation, operational efficiency, and compliance across technology environments.
  • Support continuous improvement initiatives for cybersecurity metrics and reporting.
  • Provide insights and recommendations based on quantitative and qualitative analysis.
  • Collaborate with security, infrastructure, cloud, and application teams to strengthen enterprise security posture.
Required Skills
  • Information Security
  • Cybersecurity Controls
  • Continuous Controls Monitoring (CCM)
  • Risk Metrics
  • Key Control Indicators (KCI)
  • Security Governance
  • Technology Risk Management
  • Security Reporting
  • Data Analysis
  • Stakeholder Management
  • Security Policy
  • Control Frameworks
Technical Expertise
  • Identity & Access Management (IAM)
  • Authentication & Authorization
  • Data Security
  • Network Security
  • Application Security
  • System Security
  • Security Logging & Monitoring
  • Incident Response
  • Public Cloud Security (AWS, Azure, or GCP)
  • Technology Controls
  • Risk Assessment
Preferred Qualifications
  • 10+ years of experience in Information Security and/or Information Technology.
  • 5+ years of hands-on experience implementing cybersecurity or technology controls.
  • Experience designing cybersecurity metrics, reporting frameworks, and governance processes.
  • Cybersecurity certifications such as CISSP, CISM, CRISC, Security+, or equivalent are preferred.
Key Competencies
  • Strong analytical and strategic thinking.
  • Excellent communication and stakeholder management skills.
  • Ability to manage multiple priorities and work under tight deadlines.
  • Strong business acumen with customer-focused problem-solving capabilities.
  • Ability to make data-driven decisions and influence cross-functional teams.