EDUCATION AND EXPERIENCE
The requirements of this role are typically acquired though completion of a university degree in Computer Science, Computer Engineering, Information Security, or equivalent plus (6) six years of related experience in Cybersecurity risk management. Requires relevant certifications such as CISSP, CISM, or CRISC
KNOWLEDGE SKILLS
Advanced understanding of cybersecurity principles and access control best practices.
Advanced understanding and experience with risk assessment process including identifying, evaluating, and prioritizing potential threats and vulnerabilities within an organization’s systems and networks.
Solid knowledge of risk prioritization based on criticality, resource availability, and business impact.
Solid knowledge with the evaluation, security posture and compliance of external vendors, partners, and supply chain risk.
In-depth knowledge of cybersecurity principles, risk management frameworks, and industry best practices.
Good understanding of threat models, attack vectors, risk assessment frameworks and drivers of offensive operations such as tactics, techniques, and procedures (TTPs) used by cyber adversaries.
Excellent leadership and communication skills for effective strategy implementation.
Ability to explain complex concepts to senior leadership non-technical stakeholders.
Ability to assess cybersecurity risks and devise effective mitigation strategies.
Ability to conceptualize, evaluate, and synthesize information to make unbiased judgments and relevant recommendations.
Ability to stay updated on emerging threats and risk assessment and management best practices.
OTHER REQUIREMENTS
Solid knowledge of security frameworks the National Institute of Standards and Technology (NIST) Cybersecurity Framework, ISACA’s Control Objectives for Information Related Technology (COBIT), and PCI DSS (Payment Card Industry Data Security Standard) and BC’s Freedom of Information and Protection of Privacy Act (FOIPPA).
Advanced interpersonal and communication skills to influence others and provide specialized guidance and expertise to all levels of stakeholders internally and externally, peers and vendors as required.
Demonstrated ability to build trusted and collaborative working relationships with business and cross functional teams.
Advanced analytical and critical thinking skills to manage conflict resolution, facilitating discussion, and alternatives of different approaches.
Advanced decision-making and problem-solving skills, with a proven ability to weigh the relative costs, risks, and benefits of potential solutions and make sound recommendations to senior leaders and peers.
Solid planning, organization, and time management skills with strong ability to organize competing priorities.
Proven experience in managing and implementing cybersecurity risk management strategies.
Strategic mindset with the ability to adapt practices to evolving security landscapes.
Proficient in developing and maintaining metrics, KPIs and KRIs.
High level of integrity and commitment to maintaining confidentiality in handling sensitive information