115 Cism jobs in Canada
Information Security Manager (Incident Response)

Posted 15 days ago
Job Viewed
Job Description
**Information Security Manager (Incident Response)**
Functional Area: Information Technology (ITM)
Career Stream: IT Risk & Compliance (RAC)
Role: Manager (MG2)
Job Title: Manager, Information Security 2
Job Code: MG2-ITM-SECR
Job Level: Level 10
Direct/Indirect Indicator: Indirect
**Summary**
The Cybersecurity Manager, specializing in **Incident Response and Forensics** , leverages knowledge of **advanced cyber threats** , attacker methodologies, and security technologies to proactively **identify and neutralize complex threats** within the enterprise environment. This specialist remains informed about emerging technologies and recommends strategic directions. A strong understanding of security best practices, excellent analytical and problem-solving skills, and the ability to work both independently and collaboratively within a team are essential for this role. The Senior Cybersecurity Specialist plays a crucial part in protecting our organization's digital assets and ensuring a robust security posture.
**Detailed Description**
Performs tasks such as, but not limited to, the following:
+ Performs strategic assessments to understand the current capabilities and future security needs of the enterprise. Recognizes and evaluates business security risks while defining appropriate risk-mitigating controls and technologies.
+ Takes a primary role in investigating and responding to complex security incidents identified through threat-hunting activities, including containment, eradication, and recovery efforts.
+ Presents incident details and findings to senior management.
+ Based on insights from threat hunting, recommends and drives the implementation of new or enhanced security controls and technologies to mitigate identified vulnerabilities and improve the organization's defense capabilities.
+ Provides technical leadership, guidance, and mentorship to junior threat hunters, fostering their professional development and enhancing the team's overall capabilities.
+ Defines the scope, objectives, and methodologies for threat-hunting engagements based on threat intelligence, business risk, and asset criticality. Oversees the planning, execution, and reporting of threat-hunting activities to ensure the efficient and effective identification of potential threats.
+ Identifies new and alternative approaches for implementing and managing security activities. Provides security consultation and implements appropriate controls to minimize the risk of potential revenue loss, missed business opportunities, or competitive disadvantages resulting from malicious attacks, accidental data corruption, or unauthorized access to sensitive company or customer information assets.
+ Maintains relationships with and consults industry-leading Information Security Associations, companies, and forums to stay updated on the latest technology and process advancements through education. Manages security trends and evaluates their effects on the CLS architecture and the security protection landscape.
+ Provides tier-three subject matter expert (SME) escalation support to the Service Desk for information security issues. This includes maintaining historical information, making adjustments, compiling statistics to enhance performance, and developing performance metrics.
+ Ensures that projects are selected based on key criteria and are diligent in selecting the most valuable projects within resource and budget constraints. Has the capability to request funding for larger projects, document the program,, and present improvements to senior management for approval.
+ Prepares clear and concise reports and presentations for both technical and non-technical audiences, including senior management, that summarize threat-hunting activities, findings, and actionable recommendations.
+ Offers strategic input for the development and maintenance of the organization's security roadmap, informed by insights gained from threat-hunting activities and the evolving threat landscape.
**Knowledge/Skills/Competencies**
+ Knowledge of operating systems (Windows, Unix, macOS), endpoint detection and response (EDR) solutions, antivirus software, and how threats manifest on endpoints is essential. This includes understanding system logs, processes, and file system activities.
+ Proficiency in using SIEM tools (e.g., Sumologic, Microsoft Sentinel) to aggregate, correlate, and analyze security logs and events from various sources is vital for identifying suspicious patterns and anomalies across the environment.
+ Sound Scripting Knowledge(eg: Python, bash, Ruby)
+ Strong understanding of cloud security concepts, platforms (AWS, Azure, GCP).
+ Experience in risk and compliance management and process development in the areas of information technology and security
+ Advanced knowledge of risk mitigation and business controls
+ Excellent communication and business writing skills, as well as the ability to develop executive-level presentations/strategies that include process diagrams and designs
+ Excellent problem resolution and creative problem-solving skills
+ Excellent project management skills and strong knowledge of change management processes
+ Strong customer management skills; ability to clearly articulate the role that IT can play in enhancing customers' activities.
**Physical Demands**
+ Duties of this position are performed in a normal office environment.
+ Duties may require extended periods of sitting and sustained visual concentration on a computer monitor or on numbers and other detailed data. Repetitive manual movements (e.g., data entry, using a computer mouse, using a calculator, etc.) are frequently required.
+ May require occasional on-call availability and response to security incidents outside of normal business hours.
**Typical Experience**
+ 10+ years of progressive experience in cybersecurity, with a significant focus on threat hunting, incident response for advanced threats, security operations, and digital forensics.
+ Demonstrated history of technical leadership and strategic thinking in security roles.
+ Extensive experience leading and managing complex security investigations and threat hunting engagements.
**Typical Education**
+ Bachelor's Degree in Computer Science, Information Security, or a related field.
+ Must have at least 2 of the below certifications:CompTIA Security+CompTIA Cybersecurity Analyst (CySA+)CompTIA Advanced Security Practitioner (CASP+)GIAC Certified Incident Handler (GCIH)GIAC Certified Forensic Analyst (GCFA)
+ Educational requirements may vary by geography.
**Notes**
This job description is not intended to be an exhaustive list of all duties and responsibilities of the position. Employees are held accountable for all duties of the job. Job duties and the % of time identified for any function are subject to change at any time.
Celestica is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.
At Celestica we are committed to fostering an inclusive, accessible environment, where all employees and customers feel valued, respected and supported. Special arrangements can be made for candidates who need it throughout the hiring process. Please indicate your needs and we will work with you to meet them.
**COMPANY OVERVIEW:**
Celestica (NYSE, TSX: CLS) enables the world's best brands. Through our recognized customer-centric approach, we partner with leading companies in Aerospace and Defense, Communications, Enterprise, HealthTech, Industrial, Capital Equipment and Energy to deliver solutions for their most complex challenges. As a leader in design, manufacturing, hardware platform and supply chain solutions, Celestica brings global expertise and insight at every stage of product development - from drawing board to full-scale production and after-market services for products from advanced medical devices, to highly engineered aviation systems, to next-generation hardware platform solutions for the Cloud. Headquartered in Toronto, with talented teams spanning 40+ locations in 13 countries across the Americas, Europe and Asia, we imagine, develop and deliver a better future with our customers.
Celestica would like to thank all applicants, however, only qualified applicants will be contacted.
Celestica does not accept unsolicited resumes from recruitment agencies or fee based recruitment services.
Information Security Management System Lead
Posted 8 days ago
Job Viewed
Job Description
Over the 60 plus years of Generac's history, we've been dedicated to energy innovation. From creating the home standby generator market category, to our current evolution into an energy technology solutions company, we continue to push new boundaries.
The ISMS Lead coordinates and maintains the daily operations of the Information Security Management System (ISMS) Program, ensuring compliance with ISO27001 and alignment with Generac's broader cybersecurity and compliance frameworks. The ISMS lead is the central point of contact for cross-functional control owners, capability teams, and audit stakeholders-supporting evidence collection, risk and control tracking, and the orchestration of ISMS-related deliverables across both internal ISMS assessments and external ISO27001 audits.
The ISMS Lead drives operational excellence through governance coordination, audit readiness, and performance monitoring. This includes facilitating working groups, tracking the Statement of Applicability (SoA), risk register updates, and corrective action plans. The role supports both corporate and subsidiary teams in implementing and sustaining ISMS requirements, helping to foster a culture of compliance and continuous improvement across the organization.
**Major Responsibilities**
+ Coordinates the day-to-day operations of the Information Security Management System (ISMS), ensuring alignment with ISO27001 and Generac's unified governance and compliance frameworks
+ Maintains the GRC platform, supporting timely delivery of compliance activities across policy owners, control implementers, and evidence contributors
+ Facilitates internal ISMS assessments, committee meetings, and working group sessions by preparing agendas, tracking action items, and reporting compliance progress
+ Supports capability teams, subsidiaries, and control owners by clarifying implementation expectations, audit documentation needs, and evidence quality standards
+ Tracks and manages the lifecycle of risks, controls, and corrective actions, including updates to the risk register and the Statement of Applicability (SoA)
+ Coordinate ISMS readiness efforts in preparation for external ISO27001 audits or other applicable certification assessments
+ Develops and refines ISMS-related documentation, including procedures, guidelines, control narratives, and support materials
+ Maintains dashboards and performance metrics related to audit readiness, non-conformity closure, and risk treatment activities
+ Identifies bottlenecks, overdue tasks, and control misalignments, escalating as needed to the IT GRC Capability Manager or Director of InfoSec
+ Ensures consistent version control, evidence traceability, and document quality across all submissions in support of audits or assessments
+ Collaborates with Capability Teams and subsidiaries to ensure control implementation aligns with policy and framework expectations
+ Monitors developments in ISO27001:2022, privacy regulations, and industry best practices to continuously improve the ISMS model and processes
+ Supports onboarding and enablement of new ISMS participants, including training on stakeholder roles, tool usage, and evidence responsibilities
+ Coordinates internal evidence gathering for ISMS assessments and external audits, including document requests, stakeholder interviews, and audit walkthrough preparation
**Minimum Job Requirements**
**Education**
+ Bachelor's Degree with Information Technology focus, or equivalent experience
**Work Experience**
+ 5 years experience in Information Security Management Systems or Cyber Security.
+ Proven experience supporting or coordinating ISO27001 compliance or certification efforts.
+ Experience working within a multi-framework compliance program (e.g., ISO27001, NIST, SOC 2, PCI, GDPR).
+ Understanding of risk assessment methodologies, control mapping, and evidence management practices.
+ Experience with GRC platforms, able to apply prior learnings to new GRC tools.
+ Experience with cross functional coordination, providing guidance to teams across IT and business functions
**Knowledge / Skills / Abilities**
+ Familiarity with cloud service models and control responsibilities in SaaS/PaaS/IaaS environments
+ Strong coordination, documentation, and communication skills for multi-stakeholder collaboration
+ Familiarity with unified control framework initiatives or crosswalks across security and privacy standards
+ Understanding of how compliance maps to internal business processes and capability team structures
+ Ability to coordinate evidence requests, policy updates, and SoA changes in a dynamic environment
+ Experience maintaining compliance metrics, dashboards, or remediation tracking reports
+ Knowledge of key control areas such as access control, data protection, vulnerability management, and incident response
**Preferred Job Requirements**
**Certification / License**
+ Certifications preferred: ISO27001 Lead Implementer or Auditor, CISA, CISSP, CISM, or SCF Certified Practitioner
**Great Reasons to work for Generac**
+ Competitive Benefits: Health, Dental, Vision, 401k and many more
+ Pride! When a storm strikes, Generac employees always rise to the occasion. Each time a storm hits, many employees volunteer their time with the customer support team or on the production line, while others go right into storm-affected areas to repair generators
+ Make a positive impact. Generac has always been community-minded and dedicated to giving back. The company proudly offers a Volunteer Time Off program, inviting team members to participate in charitable volunteer opportunities on company time.
+ We're an inclusive company that celebrates differences and keeps equity and respect at the forefront.
**Compensation:** Generac is committed to fair and equitable compensation practices. The salary range for this role when based in Colorado or California is $120,000 to $150,000. This compensation will ultimately be in line with the location in which the position is filled. Final compensation for this role will be determined by various factors such as a candidate's relevant work experience, skills, certifications, and geographic location.
**Physical Demands** : While performing the duties of this job, the employee is regularly required to talk and hear; and use hands to manipulate objects or controls. The employee is regularly required to stand and walk. On occasion the incumbent may be required to stoop, bend or reach above the shoulders. The employee must occasionally lift up to 25 - 50 pounds. Specific conditions of this job are typical of frequent and continuous computer-based work requiring periods of sitting, close vision and ability to adjust focus. Occasional travel.
_"We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, disability status, protected veteran status, or any other characteristic protected by law."_
Over the 60 plus years of Generac's history, we've been dedicated to energy innovation. From creating the home standby generator market category, to our current evolution into an energy technology solutions company, we continue to push new boundaries.
As one of the leaders and largest suppliers of power generation equipment and technology, the work we do touches millions of lives. Employees at Generac are encouraged to be innovative and are valued as an integral part of our global team. Our challenging goals develop knowledgeable employees dedicated to helping continue Generac's success. Generac provides individuals the opportunity to work in a fast-paced agile work environment where their work makes a difference in people's lives and their own.
Manager Information Security
Posted today
Job Viewed
Job Description
Job Description
Founded in 1974, CMiC today delivers comprehensive and advanced enterprise and field operations solutions, purpose-built for construction and capital projects companies. CMiC’s powerful software transforms how firms optimize productivity, minimize risk and drive growth by planning and managing all financials, projects, resources, and content assets - all from a single database platform.
In the past several years, the construction industry has experienced unprecedented changes driven by new technologies - including integration with multi-dimensional modeling, an explosion of cloud-based offerings and the demand for robust mobile capabilities. CMiC has kept pace by constantly upgrading and enhancing our advanced platform to reflect the changing needs of the industry, leading to significant growth as a company.
Job Overview/Position Summary
The Manager, Information Security will assist the Chief Information Security Officer (CISO) to develop and implement cybersecurity strategies that protect our organization's information assets and those of our customers’. This role requires a good understanding of cybersecurity principles, strong leadership skills, and the ability to collaborate across departments to achieve security goals
Primary Responsibilities:
- Assist in the development, implementation, and management of the organization's cybersecurity strategy.
- Monitor and analyze security threats, vulnerabilities, and incidents to identify risks and mitigate them effectively.
- Assist in the design and enforcement of security policies, standards, and procedures.
- Oversee implementation and evidence collection of the SOC 1 & 2 and ISO 27001 audits
- Collaborate with IT, legal, and other internal stakeholders to ensure alignment with security protocols and regulatory requirements.
- Provide technical and operational guidance in the development and implementation of information security programs.
- Manage security incidents and coordinate incident response efforts, including root cause analysis and remediation.
- Stay current with emerging security trends, technologies, and regulatory changes.
- Report on security metrics and provide updates to senior management and the Information and Privacy Governance Committee.
Other responsibilities
- Responsible for the development and maintenance of disaster recovery and business continuity plans and table top exercises.
- Responsible for regular security reviews and risk assessments to identify and address potential security weaknesses.
Requirements
Education and Experience:
- Bachelor's degree in Computer Science, Information Technology, or a related field.
- Certified Information Systems Security Professional (CISSP) or other relevant certifications.
- Minimum of 3 years of experience in information security management or a related role.
Skills and Competencies:
- A solid understanding of cybersecurity principles, network security, encryption, and vulnerability management
- Strong understanding of risk management framework and ability to identify, assess, and mitigate risks to the organization's information assets.
- Ability to develop and implement long-term security strategies that align with the organization's goals.
Preferred Qualifications (Optional)
- Strong knowledge of cybersecurity frameworks (e.g., NIST, ISO 27001, AICPA Trust Services Criteria) and regulatory requirements.
- Be a self-starter and take ownership of initiatives.
- Excellent analytical, problem-solving, and decision-making skills.
- Strong communication and interpersonal skills, with the ability to effectively communicate complex security concepts to non-technical stakeholders.
- Proven leadership abilities and experience in managing security team.
- Having IT Operational experience is a bonus.
Work Environment (Optional)
- CMiC has a hybrid work environment. Successful candidate is expected to be in the office one to two days a week.
Benefits
- Competitive benefits Package (including Health & Dental benefits)
- Paid vacation and personal days
- Townhall meetings where all employees are encouraged to participate in open discussions
- Located on York University’s campus, easily accessible by transit (TTC, GO, etc.), walking distance to shopping and restaurants
- Outdoor lunch space, including picnic tables
- An active Social Events Committee (past events include annual seasonal parties, pool and bowling tournaments, karaoke nights, Game nights, BBQs, and more)
- Health and Wellness focus including virtual yoga classes and wellness webinars
- RRSP Matching Program after 2 years of employment
- Experience in a rapidly growing, socially responsible corporation
CMiC is an Equal Opportunity Employer. In accordance with the Accessibility for Ontarians with Disabilities Act, 2005 and the Ontario Human Rights Code, CMiC will provide accommodation to applicants with disabilities throughout the recruitment, selection and/or assessment process. If selected to participate in the recruitment, selection and/or assessment process, please inform Human Resources staff of the nature of any accommodation(s) that you may require.
Manager of Information Security
Posted today
Job Viewed
Job Description
Job Description
Manager of Information Security
Position Overview
The Manager of Information Security is responsible for safeguarding the organization's information systems by developing and implementing robust cybersecurity programs and policies. This role includes managing the day-to-day operations of the security team, identifying vulnerabilities, overseeing the installation and maintenance of security systems, conducting audits, and leading the response to cyber incidents
Key Responsibilities
Security Program Management:
- Develop, maintain, and enhance cybersecurity frameworks, controls, and safeguards.
- Identify vulnerabilities and implement measures to prevent security breaches.
- Conduct regular system audits to assess the effectiveness of security measures.
Operations and Incident Response:
- Supervise daily operations of the cybersecurity team to ensure timely delivery of goals.
- Manage responses to cyber incidents, including investigations and corrective measures.
- Establish disaster recovery procedures and conduct regular readiness drills.
System Management and Collaboration:
- Oversee the installation, maintenance, and troubleshooting of cybersecurity systems and software.
- Collaborate with departments to promote cybersecurity awareness and ensure compliance.
- Perform vendor risk assessments to verify third-party compliance with cybersecurity policies.
- Work with IT teams to integrate security and access controls into system architecture.
Professional Development and Leadership:
- Stay informed of the latest trends in cybersecurity and adjust strategies as necessary.
- Promote an inclusive workplace by prioritizing representation and fostering an environment free of discrimination and harassment.
Requirements
Experience & Education:
- 4+ years of experience in a cybersecurity management role.
- Degree or diploma in computer science/technology or equivalent education/experience.
- Familiarity with cybersecurity frameworks and standards (e.g., CIS, NIST, ISO 27001).
Knowledge, Skills, and Abilities:
- Excellent communication skills to convey technical information to non-technical audiences.
- Strong leadership and team-building abilities.
- Exceptional problem-solving and critical-thinking skills for effective risk mitigation.
- Organizational and project management skills to manage multiple priorities.
- Ability to work collaboratively with cross-functional teams and build strong relationships.
- Flexibility to adapt to evolving threats and security landscapes.
Preferred Qualifications
- Certifications such as CISSP, CISM, or CEH are considered assets.
- Experience in leading cross-departmental cybersecurity initiatives.
- Advanced knowledge of intrusion detection and prevention systems, firewalls, and threat management tools.
Rewards
- Opportunity to lead a dynamic security team in a key role.
- Competitive remuneration package.
- Professional development in a rapidly evolving field.
- Inclusive workplace culture that values diversity and promotes equity.
- On-call responsibilities and travel requirements provide opportunities for dynamic work experiences.
To Apply
Apply via the platform where you discovered this role.
Manager, Information Security Innovation Accelerator Engineer
Posted today
Job Viewed
Job Description
Overview
At KPMG, you'll join a team of diverse and dedicated problem solvers, connected by a common cause turning insight into opportunity for clients and communities around the world.
We are seeking a talented and innovative Security Engineer to join our Global Security Operations Center (GSOC) team. This role focuses on Innovation, ensuring that automation supports and is part of any operationalization activities while leveraging DevOps principles to enhance security operations.The ideal candidate will possess expertise in Palo Alto Cortex, Azure technologies including Logic Apps and Microsoft Sentinel, and ServiceNow, and be responsible for building, improving, and maintaining automated workflows to streamline security monitoring and incident response.
What You Will Do
- Ensure continuous improvement to GSOC processes and technology through automation.
- Support the Innovation Lead and liaise with KPMG teams, business stakeholders, and vendors to design and setup activities at different stages of a technical project.
- Installation, management, maintenance and support of GSOC technologies hosted on multiple environments including physical Data Centers, Azure public cloud and O365.
- Monitor systems, identify/resolve issues, prepare status reviews and reports; Compile and maintain the necessary documentation of all system designs, builds and modifications.
- Responsible for coordination and delivery of user training and training material.
- Manage support cases to ensure issues are recorded, tracked, resolved, and follow-ups are done in a timely manner.
What You Bring To The Role
- 3 years' experience automating security workflows using scripting languages such as Python, PowerShell, or Bash. 3 years' experience with Query Languages preferably KQL. 3+ years of experience working as a Security Engineer or in a Security Operations Center (SOC) environment.
- Bachelor's degree, Master's, or PhD in Computing, Information Security, or related field (or equivalent work experience). Certifications such as CISSP, CISM, AWS Certified Security - Specialty, Azure Security Engineer are a plus.
- Familiarity with threat intelligence platforms and SIEM tools. Strong hands-on experience with automation and Azure Security technologies (including Azure Sentinel, Logic Apps, etc.). Expert in scripting or development languages e.g. Python, and a query language e.g. KQL
- Deep understanding of security technologies, principles, and best practices related to incident response and threat detection.
- Proven expertise in DevOps tools and practices (e.g., Git, Jenkins, Terraform, Docker, Kubernetes).
Providing you with the support you need to be at your best
Our Values, The KPMG Way
Integrity
, we do what is right |
Excellence
, we never stop learning and improving |
Courage
, we think and act boldly |
Together
, we respect each other and draw strength from our differences |
For Better
, we do what matters
KPMG in Canada is a proud equal opportunities employer and we are committed to creating a respectful, inclusive and barrier-free workplace that allows all of our people to reach their full potential. A diverse workforce is key to our success and we believe in bringing your whole self to work. We welcome all qualified candidates to apply and hope you will choose KPMG in Canada as your employer of choice.
Adjustments and accommodations throughout the recruitment process
At KPMG, we are committed to fostering an inclusive recruitment process where all candidates can be themselves and excel. We aim to provide a positive experience and are prepared to offer adjustments or accommodations to help you perform at your best. Adjustments (informal requests), such as extra preparation time or the option for micro breaks during interviews, and accommodations (formal requests), such as accessible communication supports or technology aids, are tailored to individual needs and role requirements. You will have an opportunity to request an adjustment or accommodation at any point throughout the recruitment process. If you require support, please contact KPMG's Employee Relations Service team by calling
Manager, Information Security Innovation Accelerator Engineer (GT&K)
Posted 2 days ago
Job Viewed
Job Description
Overview
At KPMG, you’ll join a team of diverse and dedicated problem solvers, connected by a common cause: turning insight into opportunity for clients and communities around the world.
We are seeking a talented and innovative Security Engineer to join our Global Security Operations Center (GSOC) team. This role focuses on Innovation, ensuring that automation supports and is part of any operationalization activities while leveraging DevOps principles to enhance security operations.The ideal candidate will possess expertise in Palo Alto Cortex, Azure technologies including Logic Apps and Microsoft Sentinel, and ServiceNow, and be responsible for building, improving, and maintaining automated workflows to streamline security monitoring and incident response.
What you will do
Ensure continuous improvement to GSOC processes and technology through automation.
Support the Innovation Lead and liaise with KPMG teams, business stakeholders, and vendors to design and setup activities at different stages of a technical project.
Installation, management, maintenance and support of GSOC technologies hosted on multiple environments including physical Data Centers, Azure public cloud and O365.
Monitor systems, identify/resolve issues, prepare status reviews and reports; Compile and maintain the necessary documentation of all system designs, builds and modifications.
Responsible for coordination and delivery of user training and training material.
Manage support cases to ensure issues are recorded, tracked, resolved, and follow-ups are done in a timely manner.
What you bring to the role
3 years’ experience automating security workflows using scripting languages such as Python, PowerShell, or Bash. 3 years’ experience with Query Languages preferably KQL. 3+ years of experience working as a Security Engineer or in a Security Operations Center (SOC) environment.
Bachelor’s degree, Master’s, or PhD in Computing, Information Security, or related field (or equivalent work experience).
Certifications such as CISSP, CISM, AWS Certified Security – Specialty, Azure Security Engineer are a plus.
Familiarity with threat intelligence platforms and SIEM tools. Strong hands-on experience with automation and Azure Security technologies (including Azure Sentinel, Logic Apps, etc.). Expert in scripting or development languages e.g. Python, and a query language e.g. KQL
Deep understanding of security technologies, principles, and best practices related to incident response and threat detection.
Proven expertise in DevOps tools and practices (e.g., Git, Jenkins, Terraform, Docker, Kubernetes).
Providing you with the support you need to be at your best
Our Values, The KPMG Way
Integrity , we do what is right | Excellence , we never stop learning and improving | Courage , we think and act boldly | Together , we respect each other and draw strength from our differences | For Better , we do what matters
KPMG in Canada is a proud equal opportunities employer and we are committed to creating a respectful, inclusive and barrier-free workplace that allows all of our people to reach their full potential. A diverse workforce is key to our success and we believe in bringing your whole self to work. We welcome all qualified candidates to apply and hope you will choose KPMG in Canada as your employer of choice.
Adjustments and accommodations throughout the recruitment process
At KPMG, we are committed to fostering an inclusive recruitment process where all candidates can be themselves and excel. We aim to provide a positive experience and are prepared to offer adjustments or accommodations to help you perform at your best. Adjustments (informal requests), such as extra preparation time or the option for micro breaks during interviews, and accommodations (formal requests), such as accessible communication supports or technology aids, are tailored to individual needs and role requirements. You will have an opportunity to request an adjustment or accommodation at any point throughout the recruitment process. If you require support, please contact KPMG’s Employee Relations Service team by calling .
Information Security Specialist
Posted today
Job Viewed
Job Description
Work Location:
Toronto, Ontario, Canada
Hours
37.5
Line Of Business
Technology Solutions
Pay Details
$91,200 - $136,800 CAD
TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
Job Description
Job Summary:
The Senior Information security analyst is responsible for identifying, assessing, prioritizing, and coordinating responses to security vulnerabilities within the organization's systems, applications, and networks. This role requires a deep understanding of vulnerability management, risk assessment, and cross-functional collaboration to ensure timely remediation and alignment with organizational security objectives.
Key Responsibilities
Vulnerability Management and Triage:
- Oversee the end-to-end vulnerability triage process, including identification, assessment, prioritization, and tracking.
- Develop and maintain a triage framework that balances risk levels, exploitability, and business impact.
- Analyze vulnerability reports from various sources (e.g., scanners, penetration tests, threat intelligence) to determine criticality.
- Ensure vulnerabilities are accurately classified and assigned to the appropriate teams for remediation.
Collaboration And Coordination
- Work closely with system owners, application teams, DevOps, and IT infrastructure to drive vulnerability remediation.
- Act as a liaison between technical teams and business stakeholders to communicate risk and remediation priorities effectively.
- Collaborate with threat intelligence teams to assess the real-world impact of vulnerabilities.
Risk Assessment And Prioritization
- Develop and maintain a risk-based approach to prioritize vulnerabilities based on business context, likelihood of exploitation, and potential impact.
- Establish timelines for remediation based on severity and compliance requirements.
Process Improvement
- Implement and optimize workflows for vulnerability triage and reporting.
- Continuously review and refine vulnerability management policies, processes, and tools.
- Stay updated on evolving industry best practices and emerging threats
Reporting And Metrics
- Define and track key performance indicators (KPIs) for vulnerability management, such as mean time to remediate (MTTR) and vulnerability closure rates.
- Create regular reports on vulnerability status and risk posture for executive leadership and technical teams.
Leadership And Team Management
- Manage and mentor the vulnerability triage team, ensuring high performance and professional growth.
- Provide training and guidance to enhance the team's technical expertise and analytical skills.
- Foster a culture of security awareness and proactive risk management across the organization.
Container Security
- Provide technical expertise and oversight for container scanning, container vulnerability prioritization, and remediation.
- Be a lead contributor to enterprise-level initiatives pertaining to container security and risk remediation.
- Effectively communicate critical vulnerabilities, their impacts, associated risk, and remediation priorities to cross-functional leadership teams.
- Help build and enforce technology controls, along with container security standards to ensure best practices are followed, when building and deploying application containers.
- Influence behavior to reduce risk and foster a strong technology risk management culture throughout the bank.
Qualifications
Education: Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience).
Experience
- 5+ years of experience in vulnerability management, security operations, or related fields.
- 2+ years of experience in a leadership or management role
Technical Skills
- Expertise in vulnerability scanning tools (e.g., Qualys, Nessus, Rapid7).
- Knowledge of CVSS (Common Vulnerability Scoring System) and threat modeling.
- Strong understanding of operating systems, cloud platforms, networks, and application security.
- Familiarity with compliance frameworks (e.g., ISO 27001, NIST, PCI-DSS).
- Soft Skills:
- Strong analytical and problem-solving skills.
- Excellent verbal and written communication skills, with the ability to present technical information to non-technical audiences.
- Proven ability to manage multiple priorities and work under tight deadlines.
Preferred Qualifications
- Certifications such as CISSP, CISM, CEH, or GIAC.
- Experience with threat intelligence platforms and integration.
- Familiarity with automation tools and scripting languages (e.g., Python, PowerShell).
Who We Are
TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities and colleagues.
TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you've got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we're here to support you towards your goals. As an organization, we keep growing – and so will you.
Our Total Rewards Package
Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical, and mental well-being goals. Total Rewards at TD includes a base salary, variable compensation, and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off, banking benefits and discounts, career development, and reward and recognition programs. Learn more
Additional Information
We're delighted that you're considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we're committed to providing the support our colleagues need to thrive both at work and at home.
Please be advised that this job opportunity is subject to provincial regulation for employment purposes. It is imperative to acknowledge that each province or territory within the jurisdiction of Canada may have its own set of regulations, requirements.
Colleague Development
If you're interested in a specific career path or are looking to build certain skills, we want to help you succeed. You'll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD – and we're committed to helping you identify opportunities that support your goals.
Training & Onboarding
We will provide training and onboarding sessions to ensure that you've got everything you need to succeed in your new role.
Interview Process
We'll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.
Accommodation
Your accessibility is important to us. Please let us know if you'd like accommodations (including accessible meeting rooms, captioning for virtual interviews, etc.) to help us remove barriers so that you can participate throughout the interview process.
We look forward to hearing from you
Language Requirement (Quebec Only)
Sans Objet
Be The First To Know
About the latest Cism Jobs in Canada !
Information Security Officer
Posted 2 days ago
Job Viewed
Job Description
**Responsibilities:**
+ Perform security reviews on SaaS and PaaS products
+ Performing security assessment on Saas & Paas
+ Ability to engage in deep technical discussions with other Engineering groups, as well as ability to convey the same concepts and issues at an elevated level to senior leadership.
+ Ability to execute technical responsibilities, including, Design / Architecture reviews, Code / Configuration reviews and vulnerability assessment.
+ Develops security architecture, strategy, planning, and problem-solving solutions on an enterprise level.
+ Identify opportunities to automate and standardize information security controls and for the supported groups
+ Resolve any vulnerabilities or issues detected in an application or infrastructure
+ Analyze source code to mitigate identified weaknesses and vulnerabilities within the system
+ Review and validate automated testing results and prioritize actions that resolve issues based on overall risk
+ Scan and analyze applications with automated tools, and perform manual testing if necessary
+ Reduce risk by analyzing the root cause of issues, their impact, and required corrective actions
+ Direct the development and delivery of secure solutions by coordinating with business and technical contacts
+ Recommend security solutions according to Security Policy and Practices established by Citigroup.
+ Establish and maintain relationships with domain architects, project managers, and others within the technology development unit.
+ Maintains continuous awareness of business, technical, and infrastructure issues and acts as a sounding board or consultant to aid in the development of creative GCP security architecture solutions.
+ Interfaces with vendors to security assess their technology and to guide their product roadmap based on Citi's security requirements.
**Qualifications:**
+ 6-10 years of relevant experience as an ISO officer
+ Proficiency in application, architecture, information, and cyber security
+ Proficiency in one or more: GCP, AWS and Azure
+ Advanced proficiency with Microsoft Office tools and software
+ Consistently demonstrates clear and concise written and verbal communication
+ 5-10 years of experience in Application Security and/or Security Architecture
+ 5-10 years of experience Public & Private Cloud Security
**Education:**
+ Bachelor's degree/University degree in Information Security/Computer Science/Electrical, Mechanical Engineering /Information Technology or equivalent experience
+ Master's degree preferred
+ Professional certifications, such as CISSP and CSSLP, or willingness to obtain certification within 12-18 months of start date.
This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required
**About Citi**
Citi, the leading global bank, has approximately 200 million customer accounts and does business in more than 160 countries and jurisdictions. Citi provides consumers, corporations, governments, and institutions with a broad range of financial products and services, including consumer banking and credit, corporate and investment banking, securities brokerage, transaction services, and wealth management.
As a bank with a brain and a soul, Citi creates economic value that is systemically responsible and in our clients' best interests. As a financial institution that touches every region of the world and every sector that shapes your daily life, our Operations & Technology teams are charged with a mission that rivals any large tech company. Our technology solutions are the foundations of everything we do from keeping the bank safe, managing global resources, and providing the technical tools our workers need to be successful to designing our digital architecture and ensuring our platforms provide a first-class customer experience. We reimagine client and partner experiences to deliver excellence through secure, reliable, and efficient services.
Our commitment to diversity includes a workforce that represents the clients we serve from all walks of life, backgrounds, and origins. We foster an environment where the best people want to work. We value and demand respect for others, promote individuals based on merit, and ensure opportunities for personal development are widely available to all. Ideal candidates are innovators with well-rounded backgrounds who bring their authentic selves to work and complement our culture of delivering results with pride. If you are a problem solver who seeks passion in your work, come join us. We'll enable growth and progress together.
---
**Job Family Group:**
Technology
---
**Job Family:**
Information Security
---
**Time Type:**
Full time
---
**Primary Location Full Time Salary Range:**
$120,800.00 - $170,800.00
---
**Most Relevant Skills**
Please see the requirements listed above.
---
**Other Relevant Skills**
For complementary skills, please see above and/or contact the recruiter.
---
_Citi is an equal opportunity employer, and qualified candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other characteristic protected by law._
_If you are a person with a disability and need a reasonable accommodation to use our search tools and/or apply for a career opportunity review_ _Accessibility at Citi ( _._
_View Citi's_ _EEO Policy Statement ( _and the_ _Know Your Rights ( _poster._
Citi is an equal opportunity and affirmative action employer.
Minority/Female/Veteran/Individuals with Disabilities/Sexual Orientation/Gender Identity.
Information Security Specialist
Posted 8 days ago
Job Viewed
Job Description
Toronto, Ontario, Canada
**Hours:**
37.5
**Line of Business:**
Technology Solutions
**Pay Details:**
$91,200 - $136,800 CAD
TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
**Job Description:**
**Responsibilities:**
+ Provide consultation and advice to partners on a broad range Technology Controls / Information Security programs / policies / standards and incidents for own specialized area
+ Conduct project consulting on assessment of risk, definition of required controls, appropriateness of implemented control procedures, vulnerability assessments and any other relevant areas
+ Lead or contribute to completion of risk and control design assessments for an application portfolio, articulate and document impact of control gaps to the business and the overall Bank, risk mitigation and remediation plans, remediation strategy document as applicable
+ Contribute to the definition, development, and oversight of a global security management strategy and framework
+ Ensure technology, processes, and governance are in place to monitor, detect, prevent, and react to both current and emerging technology / security threats against TDBG's business
+ Develop on-going Technology Risk reporting, monitoring key trends and defining metrics to regularly measure control effectiveness for own area
+ Work proactively with technology partners / stakeholders and service/platform owners to ensure all technology security components are integrated into the bank's overall Enterprise Architecture, and any control gaps are addressed.
+ Consult on Regulatory compliance requirements, reporting and questions
+ Provide support and consulting in preparation for Audits and in composing management responses and appropriate remediation activities
+ Participate in computer security incident responses relevant to business (or enterprise wide) and represent respective function and Enterprise position to the business, and business needs to incident response team
+ Continuously enhance knowledge / expertise in own area
+ Keep current on emerging trends / developments and grow knowledge of the business, analytical tools and techniques
+ Prioritize and manage own workload to deliver quality results and meet assigned timelines
+ Support a positive work environment that promotes service to the business, quality, innovation and teamwork and ensure timely communication of issues/ points of interest
+ Identify and recommend opportunities to enhance productivity, effectiveness and operational efficiency
+ Establish effective relationships across multiple business and technology partners, program and project managers
+ Participate in knowledge transfer within the team and business units
**Requirements:**
+ 7+ years of relevant experience
+ Expert knowledge of IT security and risk disciplines and practices
+ Advanced knowledge of of organization, technology controls / security/ risk issues
+ Experience as a lead expert resource in technology controls and information security
+ Strong presentation skills and ability to work with stakeholders at all different levels
+ University degree
+ Information security certification / accreditation an asset
#LI-TECH
**Who We Are:**
TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities and colleagues.
TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you've got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we're here to support you towards your goals. As an organization, we keep growing - and so will you.
**Our Total Rewards Package**
Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical, and mental well-being goals. Total Rewards at TD includes a base salary, variable compensation, and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off, banking benefits and discounts, career development, and reward and recognition programs. Learn more ( Information:**
We're delighted that you're considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we're committed to providing the support our colleagues need to thrive both at work and at home.
Please be advised that this job opportunity is subject to provincial regulation for employment purposes. It is imperative to acknowledge that each province or territory within the jurisdiction of Canada may have its own set of regulations, requirements.
**Colleague Development**
If you're interested in a specific career path or are looking to build certain skills, we want to help you succeed. You'll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD - and we're committed to helping you identify opportunities that support your goals.
**Training & Onboarding**
We will provide training and onboarding sessions to ensure that you've got everything you need to succeed in your new role.
**Interview Process**
We'll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.
**Accommodation**
Your accessibility is important to us. Please let us know if you'd like accommodations (including accessible meeting rooms, captioning for virtual interviews, etc.) to help us remove barriers so that you can participate throughout the interview process.
We look forward to hearing from you!
**Language Requirement (Quebec only):**
Sans Objet
Federal law prohibits job discrimination based on race, color, sex, sexual orientation, gender identity, national origin, religion, age, equal pay, disability and genetic information.
Information Security Specialist
Posted 8 days ago
Job Viewed
Job Description
Toronto, Ontario, Canada
**Hours:**
37.5
**Line of Business:**
Technology Solutions
**Pay Details:**
$91,200 - $136,800 CAD
TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and skill development are defining features of the colleague experience at TD. Our compensation policies and practices have been designed to allow colleagues to progress through the salary range over time as they progress in their role. The base pay actually offered may vary based upon the candidate's skills and experience, job-related knowledge, geographic location, and other specific business and organizational needs.
As a candidate, you are encouraged to ask compensation related questions and have an open dialogue with your recruiter who can provide you more specific details for this role.
**Job Description:**
**Responsibilities:**
+ Provide consultation and advice to partners on a broad range Technology Controls / Information Security programs / policies / standards and incidents for own specialized area
+ Conduct project consulting on assessment of risk, definition of required controls, appropriateness of implemented control procedures, vulnerability assessments and any other relevant areas
+ Lead or contribute to completion of risk and control design assessments for an application portfolio, articulate and document impact of control gaps to the business and the overall Bank, risk mitigation and remediation plans, remediation strategy document as applicable
+ Contribute to the definition, development, and oversight of a global security management strategy and framework
+ Ensure technology, processes, and governance are in place to monitor, detect, prevent, and react to both current and emerging technology / security threats against TDBG's business
+ Develop on-going Technology Risk reporting, monitoring key trends and defining metrics to regularly measure control effectiveness for own area
+ Work proactively with technology partners / stakeholders and service/platform owners to ensure all technology security components are integrated into the bank's overall Enterprise Architecture, and any control gaps are addressed.
+ Consult on Regulatory compliance requirements, reporting and questions
+ Provide support and consulting in preparation for Audits and in composing management responses and appropriate remediation activities
+ Participate in computer security incident responses relevant to business (or enterprise wide) and represent respective function and Enterprise position to the business, and business needs to incident response team
+ Continuously enhance knowledge / expertise in own area
+ Keep current on emerging trends / developments and grow knowledge of the business, analytical tools and techniques
+ Prioritize and manage own workload to deliver quality results and meet assigned timelines
+ Support a positive work environment that promotes service to the business, quality, innovation and teamwork and ensure timely communication of issues/ points of interest
+ Identify and recommend opportunities to enhance productivity, effectiveness and operational efficiency
+ Establish effective relationships across multiple business and technology partners, program and project managers
+ Participate in knowledge transfer within the team and business units
**Requirements:**
+ 7+ years of relevant experience
+ Expert knowledge of IT security and risk disciplines and practices
+ Advanced knowledge of of organization, technology controls / security/ risk issues
+ Experience as a lead expert resource in technology controls and information security
+ Strong presentation skills and ability to work with stakeholders at all different levels
+ University degree
+ Information security certification / accreditation an asset
#LI-TECH
**Who We Are:**
TD is one of the world's leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities and colleagues.
TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you've got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we're here to support you towards your goals. As an organization, we keep growing - and so will you.
**Our Total Rewards Package**
Our Total Rewards package reflects the investments we make in our colleagues to help them and their families achieve their financial, physical, and mental well-being goals. Total Rewards at TD includes a base salary, variable compensation, and several other key plans such as health and well-being benefits, savings and retirement programs, paid time off, banking benefits and discounts, career development, and reward and recognition programs. Learn more ( Information:**
We're delighted that you're considering building a career with TD. Through regular development conversations, training programs, and a competitive benefits plan, we're committed to providing the support our colleagues need to thrive both at work and at home.
Please be advised that this job opportunity is subject to provincial regulation for employment purposes. It is imperative to acknowledge that each province or territory within the jurisdiction of Canada may have its own set of regulations, requirements.
**Colleague Development**
If you're interested in a specific career path or are looking to build certain skills, we want to help you succeed. You'll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD - and we're committed to helping you identify opportunities that support your goals.
**Training & Onboarding**
We will provide training and onboarding sessions to ensure that you've got everything you need to succeed in your new role.
**Interview Process**
We'll reach out to candidates of interest to schedule an interview. We do our best to communicate outcomes to all applicants by email or phone call.
**Accommodation**
Your accessibility is important to us. Please let us know if you'd like accommodations (including accessible meeting rooms, captioning for virtual interviews, etc.) to help us remove barriers so that you can participate throughout the interview process.
We look forward to hearing from you!
**Language Requirement (Quebec only):**
Sans Objet
Federal law prohibits job discrimination based on race, color, sex, sexual orientation, gender identity, national origin, religion, age, equal pay, disability and genetic information.