BDC Logo

BDC

INFOSEC PRODUCT OWNER, GRC

Posted 7 Days Ago
Be an Early Applicant
In-Office
Montréal, QC
Senior level
In-Office
Montréal, QC
Senior level
As a Product Owner in Cybersecurity, you will prioritize initiatives in technology risk management, performance measurement, and executive reporting while ensuring alignment with strategic objectives.
The summary above was generated by AI

We are banking at another level.

Choosing BDC as your employer means working in a healthy, inclusive, and skilled workplace that puts forward the best conditions to bring together unique teams where employees are empowered to act. It also means being at the centre of ambitious economic and financial projects to see further and to do things differently, to fuel the success of Canadian entrepreneurs.

Choosing BDC as your employer also means:

  • Flexible and competitive benefits, including an Employee Savings and Investment Plan where BDC matches part of your voluntary contributions, a Defined Benefit Pension Plan, a $750 wellness and health care spending account, to name a few   

  • In addition to paid vacation each year, five personal days, sick days as necessary, and our offices are closed from December 25 to January 1

  • A hybrid work model that truly balances work and personal life

  • Opportunities for learning, training and development, and much more... 

*Please note that this role requires bilingualism in English and French.

POSITION OVERVIEW

We are seeking a dynamic and driven Product Owner (PO) to join our Cybersecurity Governance, Risk & Culture department within the squad Risk & Value Office. In this pivotal role, you will be at the heart of InfoSec, championing technology risk management, strategic planning, performance measurement, and executive-level reporting.

As a Product Owner, you will work closely with your squad to maximize the value delivered by the Product, ensuring strong alignment with both BDC’s and InfoSec’s strategic objectives. You will be responsible for prioritizing and supporting the Squad delivering both operational activities and product evolutions. Collaboration is key—you will engage with other InfoSec squads, IT teams, and the organization’s lines of defense to align roadmaps but also support robust risk management and informed strategic decision-making.

You’ll be joining the team during an exciting transformation, as IT adopts a shared agile operating model. Squads are empowered to make key decisions within their scope, including defining their ways of working, and determining how best to achieve their goals and developing a mindset of continuous improvement.

Key Focus

The Product that the PO will support is responsible for delivering the following key InfoSec capabilities:

  • Technology Risk Management: Establish and maintain a robust technology risk framework to identify, assess, and monitor key threats and risk scenarios.

  • Performance Measurement: Develop and manage tools and methodologies to track InfoSec control performance and threat exposure across squads.

  • Reporting: Ensure timely, accurate, and standardized InfoSec reporting to executive stakeholders and governance bodies.

  • Budget Management: Oversee InfoSec financial planning and procurement activities to support strategic and operational priorities.

  • Transformation Support: Drive and coordinate the execution of strategic transformation initiatives impacting InfoSec and enterprise-wide programs

  • Strategic Planning: Support InfoSec leadership with the definition of yearly InfoSec objectives and maintain a capabilities portfolio to guide annual planning and investment decisions.

  • Quarterly Prioritization: Support InfoSec leadership to prioritize InfoSec activities to ensure strategic focus and a risk-based approach during IT quarterly planning for effective cross-functional delivery.

In the role, the PO will be responsible for:

  • Define and communicate a clear Product vision and strategy, creating and maintaining a visible Product Roadmap that highlights delivery priorities and key functionalities.

  • Manage the Product backlog and set priorities based on squad capacity, ensuring alignment with InfoSec and BDC objectives.

  • Oversee governance processes, compliance, and security controls assigned to the Product,

  • Coordinating delivery cadence and quarterly squad events.

  • Promote frequent, incremental product improvements that drive organizational value.

  • Track value realization through Objectives and Key Results (OKRs)

  • Delivering, as a Squad member, high-quality outputs focused on Product users.

CHALLENGES TO BE MET

  • Capability Evolution: Apply domain knowledge and experience to lead the continuous improvement of Product capabilities, with a focus on effectiveness, efficiency, and user experience.

  • Incremental and value-driven Delivery: Drive the continuous evolution of InfoSec capabilities by delivering measurable value through iterative improvements

  • Stakeholder Engagement: Gain buy-in and foster collaboration across departments with diverse priorities, promoting a culture of accountability around risks and controls.

  • Data-Driven Enablement: Leverage performance measurement frameworks to assess and enhance the maturity and impact of InfoSec controls.

  • Creative & Pragmatic Problem Solving: Combine analytical thinking with practical creativity to tackle challenges and deliver effective solutions.

  • Leadership in Dynamic Environments: Demonstrate leadership and adaptability in a fast-paced, deadline-driven context.

WHAT WE ARE LOOKING FOR

Education:

  • Bachelor’s degree in computer science, Information Security, Engineering, Business Administration, or a related field.

  • Relevant certifications (e.g., CISSP, CISM) are considered assets.

Experience: Minimum 7 years of experience in cybersecurity, risk management, or IT governance, including:

  • Implementing and managing technology risk frameworks, conducting risk assessments, and aligning risk scenarios with business objectives.

  • Contributing to or leading the development of InfoSec strategies, annual planning cycles, and capability roadmaps

  • Experience designing and implementing KPIs, control effectiveness metrics, and dashboards; delivering executive-level reports and insights.

  • Participation in or leadership of enterprise-wide transformation initiatives, especially those involving InfoSec, IT operating models, or agile adoption.

  • Experience managing budgets, tracking financial performance, and supporting procurement processes within a governance framework

  • Framework Expertise: Strong knowledge of risk and control frameworks such as ISO 27001, NIST, SCF, and OSFI guidelines.

  • Agile Delivery: Hands-on experience or strong interest with agile multi-team delivery frameworks (e.g., SAFe), backlog management, quarterly planning, and iterative value delivery. Relevant certifications are considered assets (PSPO or equivalent).

Technical Proficiency:

  • Excellent command of Microsoft tools and platforms, especially Excel, PowerPoint, Power BI, SharePoint and Azure DevOps Board Management (or equivalent).

  • Excellent verbal and written communication skills in both official languages (French, English)

Proudly one of Canada’s Top 100 Employers and one of Canada’s Best Diversity Employers, we are committed to fostering a diverse, equitable, inclusive and accessible environment where all employees can thrive and feel empowered to bring their whole selves to work. If you require an accommodation to complete your application, please do not hesitate to contact us at [email protected].

While we appreciate all applications, we advise that only the candidates selected to participate in the recruitment process will be contacted.

Top Skills

Azure Devops
Excel
Microsoft Power Bi
Microsoft Powerpoint
Microsoft Sharepoint

BDC Montréal, Québec, CAN Office

5 Place Ville Marie, Suite 400, , Montréal, Quebec , Canada, H3B 5E7

Similar Jobs

3 Hours Ago
Hybrid
Montréal, QC, CAN
Senior level
Senior level
Agency • Digital Media • eCommerce • Professional Services • Software • Analytics • Consulting
Lead design and development of a cloud-based platform, manage team tasks, review code, support production releases, and ensure information security practices are followed.
Top Skills: AngularCloud-Native TechnologiesDockerJavaKafkaKubernetesMicroservicesMongoDBReactRestful ServicesSpringSpring BootSpring Cloud
3 Hours Ago
Easy Apply
Hybrid
Montréal, QC, CAN
Easy Apply
Mid level
Mid level
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
The role involves selling IoT solutions to mid-sized customers by managing the entire sales process, from prospecting to closing deals.
Top Skills: Salesforce (Sfdc)
Junior
Beauty • Robotics • Design • Appliances • Manufacturing
The Inventory Control & Compliance Coordinator manages inventory records, audits transactions, ensures compliance with policies and SOX, and collaborates with various teams for data integrity.
Top Skills: ExcelMicrosoft TeamsMS OfficePower BIPowerPointSharepoint

What you need to know about the Montreal Tech Scene

With roots dating back to 1642, Montreal is often recognized for its French-inspired architecture and cobblestone streets lined with traditional shops and cafés. But what truly sets the city apart is how it blends its rich tradition with a modern edge, reflected in its evolving skyline and fast-growing tech industry. According to economic promotion agency Montréal International, the city ranks among the top in North America to invest in artificial intelligence, making it le spot idéal for job seekers who want the best of both worlds.

Key Facts About Montreal Tech

  • Number of Tech Workers: 255,000+ (2024, Tourisme Montréal)
  • Major Tech Employers: SAP, Google, Microsoft, Cisco
  • Key Industries: Artificial intelligence, machine learning, cybersecurity, cloud computing, web development
  • Funding Landscape: $1.47 billion in venture capital funding in 2024 (BetaKit)
  • Notable Investors: CIBC Innovation Banking, BDC Capital, Investissement Québec, Fonds de solidarité FTQ
  • Research Centers and Universities: McGill University, Université de Montréal, Concordia University, Mila Quebec, ÉTS Montréal

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account