CrawlJobs Logo
C

Senior security specialist

https://www.randstad.com Logo

Randstad

Location Icon

Location:
Canada, Toronto

Category Icon
Category:
IT - Administration

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

Not provided

Job Description:

Our client is looking for a Senior Security Specialist for a 6 month contract in Toronto. This is a hybrid role 2 days per week onsite.

Job Responsibility:

  • Lead efforts to expand and improve cybersecurity governance and compliance in both IT and OT environments
  • Supporting annual PCI assessments by working with Qualified Security Assessors (QSAs) internal security teams, and business units to validate compliance and address findings
  • Develop and update critical governance documents such as security policies, standards, and procedures for both IT and OT environments
  • Lead the creation, review, and approval of cybersecurity policies and standards
  • Manage security documentation and audit artifacts to maintain accuracy, completeness and controlled access for cybersecurity governance
  • Work closely with IT, business teams, product delivery, digital transformation, infrastructure, vendors, internal and external audit committees to align security strategies and remediate risks
  • Assist GRC team in designing security-compliant solutions and provide expert consultation on security threats and controls
  • Foster collaboration across teams by effectively communicating complex security concepts
  • Work with project teams as a cybersecurity SME to recommend and implement security controls to address identified risks
  • Ongoing compliance work related to regulatory requirements and/or compliance with Metrolinx standards
  • Develop the security process, procedure, governance artifacts and security controls within the Cybersecurity Risk Management and Governance/Compliance Programs
  • Assist with security audits and threat/risk assessments
  • Communicate regularly with cybersecurity teams, internal stakeholders, project teams and representatives from various functional teams
  • Participate in the cybersecurity awareness programs to educate employees, contractors, and stakeholders on security best practices and compliance requirements
  • Collaborate with teams to ensure security awareness materials are tailored to address Metrolinx’s specific risks and regulatory needs

Requirements:

  • 7+ years’ experience in information security, including working with large security projects
  • 7+ years’ experience in OT environments and understanding the unique governance, risks and compliance requirements of OT systems and operations
  • Expertise in security governance, risk management, and compliance, including developing road maps, policies, standards, procedures and processes
  • Strong understanding of cybersecurity, governance, risk, and compliance (GRC) frameworks and regulatory requirements. (PCI-DSS, NIST, ISO 27001)
  • Strong communication, interpersonal and presentation skills for engaging with diverse stakeholders
  • Proven experience in contractual security requirements and third-party risk management through RFP processes and vendor evaluations throughout procurement life cycle
  • Ability to work in cross-functional teams, communicating complex technical information to all levels of the organization, including the leadership team
  • Proficient in cybersecurity risk management and third-party risk management tools (e.g., ServiceNow, One Trust, Audit Board)
  • Experience with development of security processes, procedures and standards documentation
  • Strong time management skills and the ability to prioritize project work and ongoing responsibilities
  • Strong reporting and presentation skills, with the ability to communicate security risks and compliance status to executives and stakeholders
  • Self-motivated with the ability to work independently in a fast-paced environment
  • Proficiency with standard Microsoft Office tools such as Word, Excel, PowerPoint, PowerBI, Visio and O365 SharePoint
What we offer:
  • Hybrid role: 2 Days onsite / 3 days remote
  • Earn a competitive rate within the industry

Additional Information:

Job Posted:
June 01, 2025

Expiration:
July 20, 2025

Employment Type:
Fulltime
Work Type:
Hybrid work
Job Link Share:
Welcome to CrawlJobs.com
Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.