Senior Cybersecurity Advisor
Company | Aviva |
---|---|
Location | Toronto, ON, Canada, Markham, ON, Canada |
Salary | $Not Provided – $Not Provided |
Type | Full-Time |
Degrees | Bachelor’s |
Experience Level | Senior |
Requirements
- Minimum 5 years’ experience in Cybersecurity Threat Risk Assessments on new applications and systems being introduced in the environment as well as cloud based solutions.
- Lead experience in at least one key area that the team is responsible for.
- 3rd Party Supplier Assurance and Risk Assessments experience including issue remediation.
- Leading the pen test program with external vendor and IT teams.
- Access Management reviews including Privileged access, processes and tools.
- Experience related to Dev Ops, microservices, application migration to cloud, SAAS based solutions.
- Experience working in a Security or IT Audit team, IT Developer, System Administration or network experience is an asset.
- Demonstrated ability to establish effective working relationships and collaborative work approaches with both internal and external contacts.
- Knowledge of PCI Compliance requirements including Compliance Attestation process.
- Knowledge of Ariba, Archer GRC or equivalent platforms.
- Post-secondary education in Computer Science, Computer Engineering, IT security, risk management, or comparable professional training.
Responsibilities
- Lead one or more of the key team responsibilities.
- Lead sophisticated projects providing security advice to ensure Cybersecurity risks are mitigated.
- Excel in reviewing architecture documents and crafting security assessment documents.
- Collaborate with various business lines, IT support functions.
- Promote awareness to Aviva’s Cybersecurity Standards and Policies.
- Provide the required support to management on matters related to Cybersecurity efficiently.
- Address daily requests from IT and business users on security related matters and take ownership of the same to conclusion and satisfaction.
Preferred Qualifications
- Professional designation relating to cybersecurity or IT risk (e.g. CISSP, CISA, CISM, CCSP/CCSK, GIAC) preferred.