Security Assurance TPRM, Lead

Interac Corp. Head Office

Interac Corp.

Discover more about everyday conveniences Interac can provide to make your life easier and payment solutions that can drive your business.

View all jobs at Interac Corp.

Apply now Apply later

Security Assurance & TPRM Lead

At Interac, we design and deliver products and solutions that give Canadians control over their money so they can get more out of life. But that’s not all. Whether we’re leading real-time money movement, driving innovative commerce solutions like open payments for transit systems, or making advancements in new areas like verification and open banking, we are playing a key role in shaping the future of the digital economy in Canada.

Want to make a lasting impact amongst a community of creative thinkers, problem solvers, technical virtuosos, and high-performance application developers? We want to hear from you.

HIGH-LEVEL ROLE DESCRIPTION

The Security Assurance and TPRM Lead is a key resource to ensuring Interac Corp. “Security First” principles are embedded in all environments. The successful candidate will have expert knowledge of assurance principles in security policies and standards and modern practices and a good understanding of security aspects of the various technologies. As a member a dedicated Information Security team, the Security Assurance and TPRM Lead works closely with senior leadership, team members and staff across Risk, Audit, Vendor Management, Legal, IT Operations, and Infrastructure teams to ensure the organization is operating securely.

In this role, you are working with the various teams to maintain security posture of the organization. You will design and manage a Security Assurance and Program to ensure that our organization's people, process, and technology are secure and resilient against various threats. You want to know as much about the state of the environment as you can, and you can think outside the box when it comes to proposing solutions which will benefit the organization.

You’re great at…

  • Implementation and ongoing management of a cyber security assurance testing program to ensure the effectiveness of security processes and procedures, compliance with organizational cyber security framework and industry best practices.

  • Conduct continuous security control testing exercises at defined intervals, collect evidence, and collaborate with business units to identify areas for improvement and resolution.

  • Develop and maintain security assurance KRI’s and KPI’s to assess the effectiveness and adherence to security requirements and technical controls.

  • Experience managing risk throughout the risk lifecycle and effectively managing risk within organizational risk appetite.

  • Weigh business needs against security concerns to help guide the business to make practical and informed risk decisions.

  • Conducting vendor risk assessments via vendor security risk tooling capabilities.

  • Evaluate and monitor third party vendors including strategic partners for security compliance.

  • Participate and support security related engagements and serve as a key interface with external and internal auditors for security compliance related activities.

  • Expert knowledge of industry best practices, pertinent regulations and standards bodies such as ISO 27001/2, PCI DSS, CIS, and NIST Series.

Who are you?

  • You have a You have excellent knowledge information security with Degree or Diploma in Information Technology and/or business, or combined relevant field experience and certifications CISSP, CISA, CRISC, CISM

  • You have 7+ years of experience managing an Information Security Assurance and Third-Party Security Risk Management Program within medium to large sized organizations.

  • You have strong and proven leadership capabilities with communication, coaching, influence, negotiation and conflict resolution.

  • You have experience implementing and managing TPRM and Security Tooling Capabilities.

  • You have experience with Information Security practice and processes including vendor threat and risk assessments.

  • You have experience managing risk throughout the risk lifecycle

  • You are highly motivated, and results oriented with an ability to handle high pressure situations with key stakeholders.

  • You have strong service management and service delivery orientation.

  • You have excellent presentation and communication (written and verbal) skills and an ability to present complex information in a manner suitable for technical and non-technical audiences.

  • You have excellent knowledge in several areas of information security (domain knowledge

  • Eligibility to work for Interac Corp. in Canada in a full-time capacity.

Interac requires employees to complete a background check that is completed by one of our service providers.  We use this service to complete the following checks:

  • Canadian criminal record check;
  • Public safety verification;
  • Canadian ID cross-check;
  • 5-year employment verification;
  • Education verification; and
  • If applicable, Credit Inquiry and Social Media Check

How we work
We know that exceptional people have great ideas and are passionate about their work.  Our culture encourages excellence and actively rewards contributions with:

Connection: You’re surrounded by talented people every day who are driven by their passion of a common goal.

Core Values:  They define us. Living them helps us be the best at what we do.

Compensation & Benefits: Pay is driven by individual and corporate performance and we provide a multitude of benefits and perks.

Education: To ensure you are the best at what you do we invest in you

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0
Category: Leadership Jobs

Tags: Banking CISA CISM CISSP Compliance CRISC ISO 27001 KPIs NIST PCI DSS Risk assessment Risk management Vendor management

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.