This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are seeking a Information Security Consultant to join our client's team. We need a highly skilled and adaptable professional to support a diverse range of technology-driven projects across our organization. This is a dynamic role where you'll apply your expertise in a fast-paced environment, working with various teams and leaders to deliver successful outcomes.
Job Responsibility:
Review enterprise architectures, network designs, and cloud deployments to derive required security controls and identify design risks, compliance gaps, and remediation recommendations
Develop secure architecture patterns, configuration standards, design documents, and operational runbooks aligned with regulatory requirements and industry frameworks
Lead or support security incident response activities, including investigation, containment, root-cause analysis, recovery coordination, and post-incident reporting
Develop and maintain incident playbooks, escalation procedures, evidence collection guidelines, and integration
Provide guidance during critical incidents, communicate business impacts to leadership, ensure lessons learned are documented, and drive the implementation of corrective actions to reduce recurrence and improve organizational readiness
Work with cross-functional IT, business, and vendor teams to ensure secure solution implementation and adherence to enterprise security policies
Requirements:
Have minimum of 10 years hands-on Information Security experience in roles involving security engineering, security architecture or security operations
Bachelor’s degree in Information Security, Information Technology, Computer Science, Engineering, or related discipline
Industry certifications such as CISSP, CISM, CCSP, CCIE
Proven experience leading or contributing to enterprise security projects involving technology integration, process enhancement, or control implementation
Experience in configuring, deploying, managing, Endpoint Detection & Response (EDR) platforms (e.g. Microsoft Defender, SentinelOne)
Experience with Vulnerability Management tooling, lifecycle processes, remediation validation, and reporting (e.g., Qualys, Veracode)
Experience in Next-Generation Firewall (NGFW) capabilities, including Secure Sockets Layer (SSL) inspection, threat prevention, content filtering, micro-segmentation, application control, and network policy tuning
Experience in Security Information and Event Management (SIEM) use cases, tuning, threathunting integration, and log onboarding (e.g. Splunk, Sentinel, Sumo Logic)
Experience in Cloud and Hybrid Security technologies, with hands-on understanding of native controls (e.g. Azure Defender)
Extensive experience in Intrusion Prevention and Detection (IPS/IDS) including deployment, tuning, ruleset management, and vendor-agnostic architectures
Working knowledge of regulatory and security frameworks (e.g. ISO 27001, NIST, CIS Controls, PCI-DSS, PIPEDA/FOIP, HIPA/PHI)
Experience with threat intelligence, security analytics, deep-learning or machine-learning-based detection and SIEM use cases
What we offer:
Opportunity to lead and shape the modernization of platforms
Collaborative environment working closely with stakeholders from various business areas and Information Management & Technology team
Chance to develop and implement cutting-edge solutions
Platform to showcase excellent presentation skills by regularly updating and engaging with project stakeholders and IT leadership