Description
A career as a Senior Cybersecurity Advisor in the Information Security team at National Bank means playing a key role in continuously improving the security posture of technological solutions. This position allows you to contribute to large-scale projects thanks to your expertise in risk assessment, application security and strategic support for our technology and business teams.
Your job
- Assess the cybersecurity posture of a portfolio of technological solutions
- Analyze compliance with Canadian and international cybersecurity standards and regulatory frameworks
- Recommend concrete security measures based on industry best practises
- Support the business and it teams in integrating cybersecurity requirements from the earliest project phases
- Provide strategic and tactical direction in information security
- Facilitate risk assessments, support remediation of vulnerabilities and oversee security exceptions
Your team
Within the Information Security sector, you are part of a team that works collaboratively, proactively and innovatively to advance the Bank's cybersecurity practises. You report to the Senior Manager - Cybersecurity and work with multiple business units and it teams. Our hybrid and agile environment fosters initiative and knowledge sharing. You will have the opportunity to have a real impact while contributing to the security culture and the continuous improvement of our internal processes.
The Bank values continuous development and internal mobility. Our personalised training programs, based on on on-the-job learning, help you master your profession and develop new fields of expertise. Tools such as the Data Academy, Language Training, Harvard Learning Centre and coaching and mentoring support are available to you at any time.
Prerequisites
- Bachelor’s degree in Cybersecurity, it or any other relevant field, combined with a minimum of 5 years of experience
- At least one cybersecurity certification (e.g., CISSP, CISM, CISA, CEH)
- Experience in information security (authentication, cryptography, access control, etc.)
- Solid understanding of application architecture and concepts related to cloud environments (AWS, Kubernetes, OpenShift, etc.)
- Experience in risk assessment using recognised tools and knowledge of security repositories (NIST, ISO, PCI, OSFI, Bill 25, , etc.)