
Senior Manager, Cybersecurity Operations
Canada Mortgage and Housing Corporation
- Ottawa, ON
- 126.025-157.531 $ par an
- Permanent
- Temps-plein
- Annual paid vacation.
- Annual individual performance incentive.
- Defined benefit pension plan.
- Comprehensive group insurance plan to support your well-being from day one.
- Support towards your personal and professional growth with training, mentorship and more.
- An inclusive workplace culture and environment.
- Manage and supervise day-to-day security operations to safeguard the organization's data and assets and ensure the effective functioning of security tools and platforms to maintain optimal service delivery including threat detection, incident response, vulnerability management, and continuous monitoring of IT infrastructure.
- Collaborate with key departments (e.g., IT, legal, compliance, and HR) to ensure risk management practices are integrated into all aspects of the business (proactive threat identification, vulnerability management) and lead the development of effective cybersecurity protocols to guide operations and ensure consistency across security activities.
- Provide regular reporting to senior leadership to: highlighting trends, areas of concern, recommendations for continuous improvement, status of cybersecurity compliance efforts, risk management initiatives, and the effectiveness of cross-department collaboration in maintaining a secure and compliant security and IT environment.
- Ensure the proper configuration of security and cybersecurity tools (e.g., SIEM, firewalls, intrusion detection/prevention systems) to align with organizational security policies and best practices, and continuously optimize their performance for maximum effectiveness and relevant to regulatory requirements and that they remain current and capable of defending against the latest threats, vulnerabilities, and compliance requirements.
- Oversee relationships with third-party security tool vendors, ensuring contractual obligations are met, and managing product evaluations, renewals, and escalations related to performance issues or tool enhancements.
- Direct and oversee regular vulnerability assessments across the organization's IT infrastructure, applications, and cloud environments, identifying potential risks and areas of weakness and collaborating with relevant teams to implement corrective actions where feasible.
- Establish a risk-based prioritization framework for discovered vulnerabilities, ensure continuous monitoring and automated scanning of systems for vulnerabilities in collaborate with IT infrastructure, application development, and network teams for vulnerabilities to be promptly addressed with effective remediation plans and oversee the validation and verification process post-remediation to ensure vulnerabilities are properly mitigated, and the systems have been securely patched and tested for resilience.
- Lead incident response efforts, ensuring a swift, coordinated, and effective response to security breaches and incidents ie: to investigate, contain, and remediate security incidents, while minimizing business impact and aligns with both operational and compliance requirements. Ensure that all departments understand their roles in responding to security incidents and mitigating any potential business impact.
- Undergraduate degree in Cyber Security, Computer Security, Information Systems Security, Computer Science or in a related field. An equivalent combination of education and/or experience can be considered.
- A Professional designation, such as Certified Information Security Manager (CISM).
- 10 years experience in IT Security and/or in information security working with cybersecurity frameworks, privacy regulations, and industry standards, including data protection laws and principles governing confidentiality, integrity, availability, authentication, and non-repudiation and an expertise in incident framework and methodologies (data breaches, denial of service attacks, insider threats, etc.).
- 5 years of management experience providing leadership and direction to cybersecurity staff.
- Advanced proficiency in:
- identifying and assessing a wide range of cyber threats (e.g., malware, ransomware, insider threats) and vulnerabilities (e.g., software flaws, configuration weaknesses, network security gaps).
- identifying and remediating application vulnerabilities, including secure software development practices, common vulnerabilities (e.g., OWASP Top 10), and tools for vulnerability scanning and penetration testing to enhance application security and mitigate risks.
- Advance knowledge of:
- personally Identifiable Information (PII) data security standards and regulations (e.g., GDPR, CCPA, HIPAA), including best practices for securing sensitive data, ensuring compliance, and implementing effective privacy protections to prevent unauthorized access or breaches.
- current industry methods for evaluating, implementing, and using security tools for assessment, monitoring, detection, and remediation of security threats. Extensive experience in developing, documenting, and refining cybersecurity processes and procedures that align with operational requirements and ensure consistent, repeatable actions in response to security events, incidents, and audits.
- how traffic flows across IT networks, including knowledge of TCP/IP, the OSI model, and associated network protocols. Proficient in ITIL frameworks for service management, with the ability to design, implement, and optimize network security controls aligned with operational needs.
- Strong ability to:
- identify emerging trends in security operations (analysis of incident data, vulnerability reports, and threat intelligence) combined with extensive experience conducting vulnerability assessments, performing regular scans (using industry-leading tools) and identifying critical vulnerabilities in systems, applications, and networks.
- communicate (written and verbal) both in English and French combined with the ability to negotiate, influence and challenge various audiences.
- Certified Information Systems Security Professional (CISSP), GIAC Security Leadership (GSLC), GIAC Critical Controls Certification (GCCC) or other relevant IT Security licence, designation, or certificate.
- Experience and knowledge of security technologies such as identity management, computer forensics, application security and network security technologies.
- Experience and/or knowledge of recognized standards. E.g. NIST CSF, ISO 27001/27002, ITSG-33, OSFI B13, CIS, etc.
- Knowledge of Canadian laws and Government of Canada regulatory requirements and standards. E.g. Treasury Board, Office of the Superintendent of Financial Institutes, etc.