BDC Logo

BDC

INFOSEC SPECIALIST, GRC

Posted 6 Days Ago
Be an Early Applicant
In-Office
Montréal, QC
Senior level
In-Office
Montréal, QC
Senior level
The InfoSec Specialist will manage governance, risk, and compliance activities, ensuring robust risk management and strategic decision-making while contributing to InfoSec strategy and performance measurement.
The summary above was generated by AI

We are banking at another level.

Choosing BDC as your employer means working in a healthy, inclusive, and skilled workplace that puts forward the best conditions to bring together unique teams where employees are empowered to act. It also means being at the centre of ambitious economic and financial projects to see further and to do things differently, to fuel the success of Canadian entrepreneurs.

Choosing BDC as your employer also means:

  • Flexible and competitive benefits, including an Employee Savings and Investment Plan where BDC matches part of your voluntary contributions, a Defined Benefit Pension Plan, a $750 wellness and health care spending account, to name a few   

  • In addition to paid vacation each year, five personal days, sick days as necessary, and our offices are closed from December 25 to January 1

  • A hybrid work model that truly balances work and personal life

  • Opportunities for learning, training and development, and much more... 

POSITION OVERVIEW

The Cybersecurity Governance, Risk, and Culture department is seeking a talented individual to play a crucial role within the team, aligning these functions with BDC’s business objectives. The InfoSec Specialist will work collaboratively with InfoSec squads, IT teams, and other lines of defense to ensure robust risk management and strategic decision-making. This position encompasses more than traditional GRC activities, including performance measurement, strategic planning, and security reporting. The specialist will be part of a transformation towards an agile mindset, where squads are empowered to make key decisions within their scope, including how they work, which tools to use, and how to achieve their objectives.

KEY ACTIVITIES

You will be assigned to one of our squads and have the following responsibilities:

Governance, Risk, and Compliance

  • Develop and maintain governance documents (policies, directives, procedures, standards).

  • Establish and uphold our risk and controls framework.

  • Monitor compliance with legal, regulatory, and industry standards.

  • Perform and support control assessment activities (effectiveness, maturity).

  • Deliver comprehensive risk assessments/reviews, including identifying and documenting risks and controls.

  • Support internal and external audits and ensure audit readiness.

  • Track action plans.

  • Assess third-party security and perform ongoing monitoring activities.

Performance Measurement & Reporting

  • Define and track key performance indicators (KPIs) of our controls and key risk indicators.

  • Analyze trends and performance data to identify areas for improvement.

  • Prepare and deliver regular reports and dashboards for senior leadership.

Strategy & Strategic Planning

  • Contribute to the development of the InfoSec strategy and strategic plan.

  • Track the progress of the InfoSec strategic plan.

  • Identify emerging threats, risks, and opportunities to evolve our framework.

  • Support InfoSec transformation initiatives to align with new corporate and IT orientations.

CHALLENGES TO BE MET

  • Apply knowledge and experience through the development of governance documents and risk and controls framework across various technologies and processes using industry standards and best practices.

  • Perform in-depth analyses of our risks and controls, synthesize data and observations, and effectively communicate conclusions.

  • Gain buy-in and cooperation from stakeholders across departments with differing priorities and foster a culture of accountability over risks and controls.

  • Enable our governance capability through data-driven performance measurement to assess the effectiveness, efficiency, and experience of InfoSec controls.

  • Produce clear and structured documentation that supports transparency and traceability.

  • Stay ahead of new threats and adjust frameworks accordingly.

  • Apply strong analytical, problem-solving, and organizational skills.

  • Demonstrate leadership skills, work independently and thrive in a dynamic, deadline-focused environment.

  • Demonstrate excellent verbal and written communication skills in both official languages

WHAT WE ARE LOOKING FOR:

  • Candidates should possess at least five years of experience covering the following areas:

    • Development of governance documents

    • Management of risk and control frameworks

    • Risk assessment, including third-party risk assessment

    • IT audits and control assessments

    • Development of performance indicators and delivery of executive reports

    • Development of InfoSec strategy

  • Excellent knowledge of risk management and internal control frameworks such as ISO 27001, NIST, COBIT, OSFI.

  • Excellent knowledge and experience with Microsoft products and platforms (especially Excel, PowerPoint, PowerBi, SharePoint)

  • B.A./B.S in Computer Science, Information Security, Engineering, or equivalent discipline or CPA.

  • Relevant IT audit certifications are a plus, such as:

    • Certified in Risk and Information Systems Control (CRISC)

    • Certified Information Systems Auditor (CISA)

    • Certified Information Security Manager (CISM)

    • ISO 27001 Lead Implementer or Auditor

#INDHP 

Proudly one of Canada’s Top 100 Employers and one of Canada’s Best Diversity Employers, we are committed to fostering a diverse, equitable, inclusive and accessible environment where all employees can thrive and feel empowered to bring their whole selves to work. If you require an accommodation to complete your application, please do not hesitate to contact us at [email protected].

While we appreciate all applications, we advise that only the candidates selected to participate in the recruitment process will be contacted.

Top Skills

Cobit
Iso 27001
Excel
Microsoft Powerbi
Microsoft Powerpoint
Microsoft Sharepoint
Nist
Osfi

BDC Montréal, Québec, CAN Office

5 Place Ville Marie, Suite 400, , Montréal, Quebec , Canada, H3B 5E7

Similar Jobs

2 Days Ago
Hybrid
4 Locations
Junior
Junior
Cloud • Insurance • Professional Services • Analytics • Cybersecurity
The Distribution Enablement Analyst will support data projects, broker performance reporting, CRM management, and enhance distribution enablement functions with strong analytical skills.
Top Skills: Data Management ToolsExcelMS OfficeSalesforce
2 Days Ago
Remote
Hybrid
Montréal, QC, CAN
Senior level
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
The Senior Solution Sales Executive supports strategy and execution of sales in specialty solution areas, guiding customers in digital transformation through collaboration and specialized knowledge.
Top Skills: AICloud-Based TechnologyServicenow
2 Days Ago
Easy Apply
Hybrid
Montréal, QC, CAN
Easy Apply
Mid level
Mid level
Fintech • Financial Services
Develop and enhance low latency data processing systems while collaborating with research and trading teams, ensuring performance and scalability.
Top Skills: BoostC++LinuxStl

What you need to know about the Montreal Tech Scene

With roots dating back to 1642, Montreal is often recognized for its French-inspired architecture and cobblestone streets lined with traditional shops and cafés. But what truly sets the city apart is how it blends its rich tradition with a modern edge, reflected in its evolving skyline and fast-growing tech industry. According to economic promotion agency Montréal International, the city ranks among the top in North America to invest in artificial intelligence, making it le spot idéal for job seekers who want the best of both worlds.

Key Facts About Montreal Tech

  • Number of Tech Workers: 255,000+ (2024, Tourisme Montréal)
  • Major Tech Employers: SAP, Google, Microsoft, Cisco
  • Key Industries: Artificial intelligence, machine learning, cybersecurity, cloud computing, web development
  • Funding Landscape: $1.47 billion in venture capital funding in 2024 (BetaKit)
  • Notable Investors: CIBC Innovation Banking, BDC Capital, Investissement Québec, Fonds de solidarité FTQ
  • Research Centers and Universities: McGill University, Université de Montréal, Concordia University, Mila Quebec, ÉTS Montréal

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account