Jobs
>
Toronto

    Expert, Information Security Third Party Risk Management - Toronto, Canada - CN

    CN
    CN background
    Description
    Job Summary

    The purpose of this role is to maintain and grow an industry leading Information Security Third Party Risk Management (TPRM) practice to support the mission of empowering the business by building resilience against evolving cyber threats. This will include program governance, policy and guideline development, risk assessments, information protection contract clauses, continuous monitoring, compliance assessments, regulatory compliance assurance, due diligence and selection processes, technology and tool development and maintenance, cloud transformation, and stakeholder awareness and communication.

    This role oversees the development and operations of the third-party security function within CN's Chief Information Security Office (CISO). It interfaces with a variety of senior stakeholders within I&T and the business in order to develop and influence the required changes for the management of third-party security risks originating from suppliers, customers, subsidiaries, and cloud-based technology tools and platforms, to a level that is manageable and aligned to CN's business risk tolerance. They are a senior resource with an understanding of how to apply deep technical knowledge while coordinating activities between multiple internal groups and third-party organizations to enable business objectives by ultimately managing risk to a level that is acceptable for the organization.

    Main Responsibilities

    Practice Development and Planning


    •Align third party information security with organizational business goals


    •Oversee a broad range of Information Security activities related to third party suppliers, solutions, subsidiaries and customers, including large outsourcing initiatives ( I&T infrastructure and help desk managed services)


    •Develop and maintain a set of policies & guidelines specific to protecting CN's assets where they are accessed or managed by third parties


    •Create and maintain a TPRM practice, including a framework for evaluating and managing third party risk


    •Ensure information security requirements are integrated with procurement processes


    •Proactively monitor emerging trends and evolving threat landscapes to identify innovative ideas that would position CN to be an industry leader

    Operation and Execution


    •Identify, assess, and report critical and high risks involving third parties


    •Manage and escalate incidents such as a material control weaknesses and security breaches and working with the Security Operations Centre (SOC) as required


    •Report critical non-compliances and high risks to the appropriate business stakeholders


    •Write and negotiate contractual terms internally and with external partners and suppliers to ensure CN's business goals are met relating to information security


    •Ensure CN's Information Security policies & guidelines related to third parties meet regulatory requirements for security and privacy protection ( TSA directives, CCSPA requirements, privacy bills, etc.)


    •Enhance existing processes through innovation and continuous improvement


    •Subject Matter Expertise


    •Drive action across various internal and external stakeholders by communicating technical and process requirements


    •Provide leadership and expertise on matters relating to third party information security to various internal stakeholders, including I&T, Procurement, Internal Audit, Legal, Facilities Management, and Insurance teams


    •Discover and bring to light innovation opportunities and influence other groups to support and implement changes that will generate business value


    •Mentor resources, provide knowledge transfer, and delegate support tasks

    Organizational Impact

    Decision Making & Impacts

    The Expert, Information Security Third Party Risk Management implements the governance, risk, and compliance capabilities required to bring Information Security risks involving third party suppliers, solutions, subsidiaries, and customers to acceptable levels required to enable to enable the organization to achieve its business objectives.

    To achieve this they conduct strategic planning, create and maintain processes and tools, and coordinate activities between various internal teams and external organizations.

    Level of Interaction/Influence

    The Expert, Information Security Third Party Risk Management influences and drives action among various areas within the organization, including Legal, Procurement, Internal Audit, Facilities Management, Insurance, and different areas within I&T. They also drive action within external subsidiaries, suppliers, and customers.

    This would include incorporating Information Security requirements into procurement processes, ensuring I&T asset inventory systems include relevant data, influencing behaviours of Solution Architects to identify and mitigate high risks, negotiating contractual terms with Legal and Facilities Management, providing expertise to Internal Audit and Insurance teams, issuing Cybersecurity Policies and conducting compliance monitoring activities on subsidiaries, influencing external agencies and service providers to better align to CN's needs, working with customers on Information Security requirements and posture, and many other interactions with various internal and external stakeholders.

    Requirements

    Education/Certification/Designation


    • degree in Computer Science, Information Systems or other related field, or equivalent work experience

    Skills/Knowledge


    •Broad skillset and depth of expertise in technical areas of information security and how they impact business objectives


    •Demonstrated capability to understand the security implications of complex business operations and how they are linked to technological solutions that provide practical risk mitigation and business enablement


    •Good knowledge of existing and emerging technologies and architecture principles involved in complex information and technology systems


    •Significant and proven experience in applying a structured approach to problem resolution


    •Sufficient knowledge on matters relating to third party information security


    •Excellent written and verbal communication skills as well as business acumen


    •Detail-oriented self-starter with a high level of commitment and personal motivation


    •Knack for prioritizing tasks and working in a fast-paced environment


    •Able to learn quickly to keep pace with rapidly evolving technology and cybersecurity environments


    •Able to lead initiatives to completion with minimal management oversight


    •Able to communicate in a clear, concise manner


    •Experience with contract and supplier negotiations


    •Able to multi-task and work effectively across multiple organizational units


    •Security assessment experience


    •Strong understanding of security frameworks including NIST CSF, NIST SP 800-53, and ISO-270001


    •Strong understanding of regulatory requirements including SOX, PIPEDA, HIPAA and TSA


    •Deep understanding of security threat landscape


    •Ability to translate complex technical topics into simple business language for business audiences


    •Experience developing and delivering executive level presentations


    •Relationship management skills


    •Experience dealing with third parties


    •Strong process orientation


    •Recognized security certifications ( CISSP, CISM, CRISC, CISA)

    Specific skills per speciality

    Experience


    •Minimum 5 years experience in Information Security


    •10+ years of I&T experience or 5+ years in a similar role


    •10-15 years overall work experience


    •Assets


    •Knowledge of railway systems


    •Good understanding of Cloud Computing


    •Understanding of both IT and OT systems

    Working Conditions

    Occasional business travel (Canada and US) in accordance with CN policy

    Thisposition is posted as a grade LEVEL 7. For internal candidates, note that thegrade level of the position may adjust based on the employee's experience.



  • TD Bank Toronto, Canada

    Lieu de travail: · Toronto, Ontario, Canada · Horaire: · 37.5 · Secteur d'activité: · Gestion des risques · Détails de la rémunération: · Description du poste: · Department Overview · Environment, Social & Governance Credit Risk Management (ESG-CRM) under Non-Financial Risk Manag ...


  • TD Bank Toronto, Canada

    394414BR · Risk Management · Toronto, ON · January 11, 2023 · Company Overview · Department Overview · As an independent team within the Risk Management group, Operational Resilience works with business units and corporate partners to ensure ongoing management of operational risk ...


  • TD Bank Toronto, Canada

    393532BR · Risk Management · Toronto, ON · January 11, 2023 · Company Overview · Department Overview · As an independent team within the Risk Management group, Operational Resilience works with business units and corporate partners to ensure ongoing management of operational risk ...

  • Bechtel

    Risk Manager

    1 week ago


    Bechtel Toronto, Canada

    **Requisition ID: 269666** · - ** Relocation Authorized: None**: · - ** Telework Type: Full-Time Office/Project**: · - ** Work Location: Toronto, ON** · **About Us** · Core to Bechtel are our values and commitments - we live for a challenge, we do the right thing, we take care of ...

  • Canada Life Assurance Company

    Manager Risk

    4 days ago


    Canada Life Assurance Company Toronto, Canada

    **Job Description**: · Reporting to the AVP, Risk & Controls, this is a critical role leading 3 direct reports within a small, closely connected team supporting Individual Customer and Advisory Network business units at Canada Life. The Individual Customer (IC) business unit is r ...


  • Metro Inc. Toronto, Canada

    **Position Title**: · ***Manager Risk Management · **Requisition ID**: 32856 · **Career Group (ADSP)**: · ***Administrative · **Division**:Nat - Finances · **Department**: · ***Risk Management · **Work Location**:METRO ON DUNDAS STREET W (#A-DUND) · **Province**:Canada : Ontario ...


  • Metro Inc. Toronto, Canada

    **Position Title**: · ***Manager Risk Management · **Requisition ID**: 32856 · **Career Group (ADSP)**: · ***Administrative · **Division**:Nat - Finances · **Department**: · ***Risk Management · **Work Location**:METRO ON DUNDAS STREET W (#A-DUND) · **Province**:Canada : Ontario ...


  • Scotiabank Toronto, Canada

    Requisition ID: 168394 · Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture. · **Job Purpose** · Working within GRM, you will be responsible for driving improvements in collection strategies by leading the production of policies, ...


  • Sun Life Toronto, Canada

    You are as unique as your background, experience and point of view. Here, you'll be encouraged, empowered and challenged to be your best self. You'll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspir ...


  • HomeEquity Bank Toronto, Canada

    WHO WE ARE · HomeEquity Bank is a Schedule 1 Canadian chartered bank and the leading national provider of reverse mortgages, with a growing portfolio. As the only bank solely dedicated to serving homeowners 55 and up, we're passionate about helping Canadian homeowners live retire ...

  • TD Bank

    Manager, Group Risk

    12 hours ago


    TD Bank Toronto, Canada

    **TD Description** · Stay current and competitive. Carve out a career for yourself. Grow with us. · **Department Overview** · - Enterprise Risk Management (ERM) is responsible for building organizational capability in managing risk on a more integrated and comprehensive basis for ...

  • Scotiabank

    Manager Credit Risk

    2 days ago


    Scotiabank Toronto, Canada

    Requisition ID: 175543 · Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture. · **Purpose of Job**: · The Manager, Portfolio Insights, SDA Risk, GRM will monitor key risk performance of the Retail Automotive portfolio, and contrib ...


  • CareRx Toronto, Canada

    **About CareRx Corporation** · CareRx is Canada's leading provider of specialty pharmacy services to seniors. We serve more than 96,000 residents in over 1,600 seniors and other communities (long-term care homes, retirement homes, assisted living facilities, and group homes). We ...

  • HSBC

    Traded Risk Manager

    6 days ago


    HSBC Toronto, Canada

    Opening up a world of opportunity. · We're a financial services organization serving more than 39 million customers across the globe through our Wealth & Personal Banking, Commercial Banking and Global Banking & Markets businesses. · We're here to use our unique expertise, capabi ...


  • Vale Canada Toronto, Canada

    **Risk Management Specialist** · **Join Vale today. Continuously learn throughout your career.** · **Who We Are**: · Welcome to Vale in Canada. As a leader in the mining industry, our responsibility is to positively impact our people, communities, and the environment. We value ou ...

  • Rogers Communications

    Manager, Risk Rprtg

    6 days ago


    Rogers Communications Toronto, Canada

    As Manager of Enterprise Risk Management - Financial Risk for Rogers Bank, this position supports foundational elements of the Enterprise Risk Management framework across the Bank. Financial Risk components of this framework, including but not limited to the Credit Risk oversight ...


  • Ministry of Public and Business Service Delivery Toronto, Canada

    Are you a dynamic and purpose-driven leader with a strong background in insurance and risk management? Are you seeking an opportunity to showcase your inclusive and collaborative leadership style within a motivated team? If you thrive in a fast-paced environment and are excited a ...

  • TD Bank

    Manager, Group Risk

    12 hours ago


    TD Bank Toronto, Canada

    406395BR · Risk Management · Toronto, ON · April 17, 2023 · Company Overview · Department Overview · Enterprise Risk Management (ERM) is responsible for building organizational capability in managing risk on a more integrated and comprehensive basis for the organization and for p ...

  • TD Bank

    Risk Manager, Data

    1 week ago


    TD Bank Toronto, Canada

    402569BR · Corporate Development / Strategy / Design · Toronto, ON · March 10, 2023 · Company Overview · Department Overview · The independent Operational Risk Management (ORM) team works in partnership with the business units and corporate groups of TD Bank Group to further the ...


  • CURO Financial Technologies Corp Toronto, Canada

    Overview: · **This is a fully remote position, based in Canada.** · CURO is one of the largest, fastest growing full-spectrum consumer credit lenders in the United States and Canada. Our licensed, direct lending products and heightened customer service focus are at the core of wh ...