Senior Analyst, Information Security (GRC) And Crisis Management
Full-time
PSP Investments
Reference Code: NQ-08-JO-13-TT-20
ABOUT US We're one of Canada's largest pension investors, with CAD$299.7 billion of net assets as of March 31, 2025. We invest funds for the pension plans of the federal public service, the Canadian Forces, the Royal Canadian Mounted Police and the Reserve Force. Headquartered in Ottawa, PSP Investments has its principal business office in Montreal and offices in New York, London and Hong Kong. Capturing and leading complex global investments requires us to work as one to seize valuable opportunities, in close collaboration with some of the world's top companies. At PSP Investments, you'll join a team of motivated and engaged professionals, dedicated to propelling our organization further than ever before. ABOUT YOUR ROLE As a Senior Analyst, Security GRC & Crisis Management, you will report to the Manager, Security GRC and be part of the broader Information Security group. You will contribute to PSP's information security governance, risk, and compliance (GRC) program as well as to its enterprise crisis management capabilities. You will support the execution and continuous improvement of security frameworks, risk assessment processes, compliance activities, and crisis preparedness planning. You will: Security Governance, Risk & Compliance - Support the maintenance and evolution of PSP's security governance framework, policies, standards, and procedures in alignment with ISO 27001, NIST CSF, and COBIT
- Conduct security risk assessments across business units, technology platforms, and third-party vendors; maintain the corporate security risk register
- Support internal and external audit activities related to information security; track compliance requirements, remediation activities, and control gaps
- Support the vendor risk management program, including security assessments and follow-up on outstanding action items
- Prepare security KPI/KRI reporting materials and contribute to briefings for the CISO and senior leadership
- Stay current on the evolving threat landscape and regulatory developments; share relevant findings with the team and cross-functional partners in Internal Audit, Legal, and Enterprise Risk Crisis Management & Resilience - Support the maintenance and improvement of PSP's Crisis Management Plan, Cyber Incident Response Plan, and related operational playbooks across all crisis scenarios - cyber, operational, reputational, and physical
- Assist in coordinating and facilitating crisis simulations and tabletop exercises across crisis types; document findings and track remediation actions
- Participate in the operational response to incidents and crisis events, including documentation, coordination across teams, and post-incident review
- Contribute to maintaining crisis communication protocols and contact lists for internal and external stakeholders
- Monitor threat intelligence feeds and sector information sources; collaborate with Business Continuity and other stakeholders to align business continuity/ disaster recovery objectives and identify synergies across programs, plans, and exercises within the broader crisis management framework WHAT YOU'LL NEED - Bachelor's degree in Information Security, Computer Science, Engineering, or a related field
- Three (3) to five (5) years of experience in information security, with significant exposure to security GRC activities
- Experience with and awareness of incident preparedness and crisis management processes
- Familiarity with security frameworks such as ISO 27001, NIST CSF, or COBIT
- Ability to organize and work either autonomously or collaboratively, manage competing priorities, and deliver quality work with minimal supervision in a fast-paced environment
- Strong analytical and writing skills; able to translate technical information into clear documentation for non-technical audiences
- Relevant certification or active pursuit thereof considered a strong asset; experience in financial services or a regulated industry an asset
- Bilingualism: English and French (frequent interactions in English with PSP employees based in our offices in Hong Kong, London and New York, and interactions in French with employees in our local offices in Montreal and Ottawa)We offer a tailored employee experience and competitive total rewards and benefits package* designed to attract and retain global diverse talent, reward performance, and reinforce business strategies and priorities. Beyond salary and incentive pay eligibility, you have access to: - Investment in career development
- Comprehensive group insurance plans
- Competitive pension plans
- Unlimited access to virtual healthcare services and wellness programs
- Gender-inclusive paid family leave policy: up to 26 weeks for primary caregivers, 5 weeks for secondary caregivers
- A personalized family-building support, from pre-pregnancy to menopause, with available financial assistance
- Vacation days available on day one with additional days on milestone service anniversaries, and summer Friday afternoons off
- A hybrid work model with a mix of in-office and remote days *Benefits package may vary based on your employee type. At PSP Investments, we aim to provide a workplace where everyone feels valued, safe, respected and empowered to grow. As part of this leadership commitment, we strongly encourage applications from all qualified applicants and strive to offer an inclusive and accessible candidate experience. If you require any accommodation for any part of the recruitment process, please let us know. Visit us on
Follow us on LinkedIn
Languages: English, French
To apply: Click Apply Now!
ABOUT US We're one of Canada's largest pension investors, with CAD$299.7 billion of net assets as of March 31, 2025. We invest funds for the pension plans of the federal public service, the Canadian Forces, the Royal Canadian Mounted Police and the Reserve Force. Headquartered in Ottawa, PSP Investments has its principal business office in Montreal and offices in New York, London and Hong Kong. Capturing and leading complex global investments requires us to work as one to seize valuable opportunities, in close collaboration with some of the world's top companies. At PSP Investments, you'll join a team of motivated and engaged professionals, dedicated to propelling our organization further than ever before. ABOUT YOUR ROLE As a Senior Analyst, Security GRC & Crisis Management, you will report to the Manager, Security GRC and be part of the broader Information Security group. You will contribute to PSP's information security governance, risk, and compliance (GRC) program as well as to its enterprise crisis management capabilities. You will support the execution and continuous improvement of security frameworks, risk assessment processes, compliance activities, and crisis preparedness planning. You will: Security Governance, Risk & Compliance - Support the maintenance and evolution of PSP's security governance framework, policies, standards, and procedures in alignment with ISO 27001, NIST CSF, and COBIT
- Conduct security risk assessments across business units, technology platforms, and third-party vendors; maintain the corporate security risk register
- Support internal and external audit activities related to information security; track compliance requirements, remediation activities, and control gaps
- Support the vendor risk management program, including security assessments and follow-up on outstanding action items
- Prepare security KPI/KRI reporting materials and contribute to briefings for the CISO and senior leadership
- Stay current on the evolving threat landscape and regulatory developments; share relevant findings with the team and cross-functional partners in Internal Audit, Legal, and Enterprise Risk Crisis Management & Resilience - Support the maintenance and improvement of PSP's Crisis Management Plan, Cyber Incident Response Plan, and related operational playbooks across all crisis scenarios - cyber, operational, reputational, and physical
- Assist in coordinating and facilitating crisis simulations and tabletop exercises across crisis types; document findings and track remediation actions
- Participate in the operational response to incidents and crisis events, including documentation, coordination across teams, and post-incident review
- Contribute to maintaining crisis communication protocols and contact lists for internal and external stakeholders
- Monitor threat intelligence feeds and sector information sources; collaborate with Business Continuity and other stakeholders to align business continuity/ disaster recovery objectives and identify synergies across programs, plans, and exercises within the broader crisis management framework WHAT YOU'LL NEED - Bachelor's degree in Information Security, Computer Science, Engineering, or a related field
- Three (3) to five (5) years of experience in information security, with significant exposure to security GRC activities
- Experience with and awareness of incident preparedness and crisis management processes
- Familiarity with security frameworks such as ISO 27001, NIST CSF, or COBIT
- Ability to organize and work either autonomously or collaboratively, manage competing priorities, and deliver quality work with minimal supervision in a fast-paced environment
- Strong analytical and writing skills; able to translate technical information into clear documentation for non-technical audiences
- Relevant certification or active pursuit thereof considered a strong asset; experience in financial services or a regulated industry an asset
- Bilingualism: English and French (frequent interactions in English with PSP employees based in our offices in Hong Kong, London and New York, and interactions in French with employees in our local offices in Montreal and Ottawa)We offer a tailored employee experience and competitive total rewards and benefits package* designed to attract and retain global diverse talent, reward performance, and reinforce business strategies and priorities. Beyond salary and incentive pay eligibility, you have access to: - Investment in career development
- Comprehensive group insurance plans
- Competitive pension plans
- Unlimited access to virtual healthcare services and wellness programs
- Gender-inclusive paid family leave policy: up to 26 weeks for primary caregivers, 5 weeks for secondary caregivers
- A personalized family-building support, from pre-pregnancy to menopause, with available financial assistance
- Vacation days available on day one with additional days on milestone service anniversaries, and summer Friday afternoons off
- A hybrid work model with a mix of in-office and remote days *Benefits package may vary based on your employee type. At PSP Investments, we aim to provide a workplace where everyone feels valued, safe, respected and empowered to grow. As part of this leadership commitment, we strongly encourage applications from all qualified applicants and strive to offer an inclusive and accessible candidate experience. If you require any accommodation for any part of the recruitment process, please let us know. Visit us on
Follow us on LinkedIn
Languages: English, French
To apply: Click Apply Now!
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Senior Analyst, Information Security (GRC) And Crisis Management in Montréal, QC vacancy
- ...Description du poste Vous avez une base solide en sécurité des TI? Vous aimez résoudre des problèmes complexes... ...et votre collaboration ? L’équipe de sécurité de l’information veut vous rencontrer. L’Analyste en sécurité de l’information sera responsable de l’exploitation...SuggestedFull timeSeasonal workWork at office
- ...utilisation éthique et socialement acceptable de l’IA. Description du mandat Vous appliquez vos compétences en tant qu’analyste en sécurité de l’information au sein de l’équipe technologie de l’information de Mila dans un environnement en constante évolution. Vous continuez...SuggestedDaily paidContract workApprenticeshipRemote workFlexible hoursDay shift
$110k - $120k per year
...consolidés trimestriels et annuels, et assurer une première phase de révision Assurer le respect des exigences en matière d'information financière et de divulgation à travers le Groupe, incluant les nouvelles exigences à venir (ex : IFRS18) Participer activement...SeniorPermanent employment$47k - $78k per year
...Support Services team is looking for an analyst to provide on-site and virtual conferencing... ...candidate will report into the IT Manager of the Conferencing Solutions team. DT -... ...working with fellow technicians and with the Information Technology Services support teams who oversee...SuggestedPermanent employmentWork at officeRemote workFlexible hoursWeekend work$90k per year
...want to join a global trading firm’s cybersecurity team, helping to detect threats, respond to incidents, and strengthen the company’s security posture? Join a global proprietary trading firm that combines quantitative research, advanced algorithms, and high-performance...SuggestedPermanent employmentWorldwide- ...TEHORA est présentement à la recherche d’un(e) conseiller(ère) en gouvernance de la sécurité de l'information senior Sans être exhaustifs, voici les services et livrables que devra fournir la personne retenue : Définir les stratégies de sécurité; Réaliser des analyses...SeniorHourly payFull timeContract workApprenticeshipRemote workFlexible hours
- ...Threat Defense (CTD) au sein du département AMER Data and Cyber Security (ISR) et reporte au Directeur du CTD. Ce poste nécessite une forte... ...: (1) évaluer les dommages potentiels des failles de sécurité et aider à la mise en œuvre des actions correctives ; (2) identifier...Daily paid
- ...TEHORA est présentement à la recherche d ’un(e) analyste d’affaires TI pour accompagner les directions dans la définition de leurs besoins technologiques et dans l’évolution des systèmes applicatifs d’un organisme public de Montréal. La personne participera à des projets...Hourly payContract workApprenticeshipRemote workFlexible hours
- ...Analyste règlements et sécurité En tant qu'analyste règlements et sécurité, vous vous concentrez sur les mesures de protection de la communauté et du contenu, afin de protéger notre entreprise et notre clientèle contre diverses formes d'activités à haut risque. Nous recherchons...Daily paidFull timeRemote workHome officeWeekend workDay shiftAfternoon shift
- ...Genetec est à la recherche d’un(e) analyste de l'information expérimenté(e) pour se joindre à notre... ...Établir des politiques sur la qualité, la sécurité, la confidentialité et la gestion du... ...d’entreprise) CDMP (Certified Data Management Professional) Voilà ce que nous offrons...Flexible hours
$70k - $90k per year
...that enables companies to achieve certification in leading global security frameworks, including ISO 27001, SOC 2, PCI-DSS, GDPR, and more.... ...a move? Get in touch and apply today! Responsibilities: Manage a portfolio of clients and MSPs through the end-to-end SOC 2 and...Permanent employmentWork at officeFlexible hours2 days per week1 day per week- IT Security Manager Become the strategic cornerstone of our security! In this key role, you will be responsible for implementing our long... ...responsibility for defining and promoting best practices in information security across our entire ecosystem. This is a highly structured...Long term contractRemote work
- ...We're seeking someone to join our team as a Business Information Analytics Manager to oversee and transform the delivery of financial analytics work... ...demand. Implement strategic evolution roadmap for supporting Analyst workflows by incorporating AI platforms and building agents...Full timeWork at officeRemote work
- ...poste : Poste permanent ou de pigiste à titre d’architecte de sécurité senior pour des interventions à long terme au sein d’organismes... ...pertinente dans les TI dont 8 ans en architecture de sécurité de l’information numérique ; Avoir 3 mandats de plus de 300 j-p dans des...SeniorPermanent employmentFull timeFreelanceRemote work
- .... The position at a glance The senior associate – Accounting Analyst day-to-day maintenance and control... ...the Vice-President in terms of team management, project management and closing periods... ...requires working in/for the U.S. securities industry, you will be required to...SeniorBank staffWork at officeMonday to fridayFlexible hours3 days per week
$75k per year
...TITRE DU POSTE : Analyste financier senior Nom de l’employeur : Astaldi Canada Enterprises Inc.... ...directeur dans l’élaboration de rapports d’informations financières afin de fournir des... ...connaissances. Maintient les normes de sécurité et veille au respect des exigences du...SeniorPermanent employmentFull timeRemote workDay shift- ...est présentement à la recherche d’ un(e) architecte systèmes d’information senior ayant une solide expérience en architecture applicative, en... ...Collaborer avec les experts d’affaires, technologiques et sécurité afin d’assurer une vision intégrée; Formuler des recommandations...SeniorHourly payFull timeContract workApprenticeshipRemote workFlexible hours
$60k - $115k per year
Senior Financial Analyst Position Description We have a challenging and rewarding career opportunity... ...ensuring balance sheet integrity -Manage special requests and collaborate on in-... ...If you require an accommodation, please inform your recruiter. To learn more about...SeniorContract work- ...and talented Business Systems Analyst to join the team. You are... ...and integrate efficient information systems and operations systems... ..., and backlog breakdown into manageable stories. Develop strong relationships... ..., Global IT Operations & Security – Project Delivery and...SeniorPermanent employmentRemote work
- ...re seeking someone to join our team as a Senior Security Architecture Specialist in Cyber to be... ...impact. Visit morganstanley.com for more information. WHAT YOU CAN EXPECT FROM MORGAN STANLEY... ...: At Morgan Stanley, we raise, manage and allocate capital for our clients –...SeniorFull timeWork at officeRemote work
- ...Novipro est actuellement à la recherche d'un Analyste en sécurité pour joindre son équipe technique dans un poste permanent. Début: dès que possible Responsabilités: Implémente et administre des solutions de sécurité avancées Supervise la détection et la réponse...Permanent employmentFull time
- ...We currently have acontract role as a Senior Network Security Engineer with our large consulting... ...Bachelor's degree in Computer Science, Information Technology, or Network Engineering ~... ...support and project delivery ~ IT service management certifications (e.g., ITIL)...SeniorRemote jobLong term contractPermanent employmentFull timeWork at office
- ...primarily through partnerships with external managers, where the approach is to build... ...in our downtown Montreal office, the Senior Analyst, Public Markets will report directly to... ...ongoing basis, and report on relevant informative findings on a timely basis In relation...SeniorPermanent employmentFull timeWork at office
- ...and greener for all. Read more at: ROLE As Product Manager, Defence & Security, you will own and drive product roadmap and execution for... ...personal commitments. EQUITY, PRIVACY & APPLICATION INFORMATION We are committed to creating a sense of belonging amongst...Long term contractWork at officeRemote workFlexible hours
- ...TEHORA est présentement à la recherche d’un(e) analyste d'affaires, Technologie de l'information ayant d’excellentes aptitudes techniques, d’excellentes connaissances et qui souhaite mettre à profit ses compétences au sein d’une équipe polyvalente. Sans être exhaustifs,...Hourly payFull timeContract workApprenticeshipRemote workFlexible hours
- ...seeking a detail-oriented and analytical Senior Accounting Analyst to join our finance team. This role... ...supporting accurate accounting operations and informed business decisions. What you're... ...skills You have the Ability to manage multiple priorities and meet deadlines...SeniorFull timeWorldwide
$60k - $115k per year
Spécialiste Réseau et Sécurité Sénior Description de poste Nous recherchons un Spécialiste... ...CISSP ou équivalente en sécurité de l’information Qualités requises pour réussir dans... ...technologie de l’information (TI) et en management au monde. Network Security...Senior- ...Description Position Overview The Senior Business Analyst plays a key role in driving... ...including Finance, Human Resources, and Information Technology, while ensuring alignment around... ...assessments, impact analysis, change management, user adoption, and continuous...SeniorFull timeContract workPart timeWork from homeFlexible hours
- ...Job Description This position is a project manager role specializing in physical security, responsible for the planning, coordination, and delivery... ...asset) PMP certification (an asset) Additional Information What we offer! Competitive salary + other benefits...Full timeWork at officeWorldwide
$80k - $100k per year
...Senior Analyst, Affinity ~202601878 ~Montreal, Quebec, Canada ~Toronto, Ontario, Canada... ...) Support the overall project management for engagements across the client team... ...Ability to summarize and communicate complex information, insights, results and other data findings...SeniorFull timeTemporary workManual laborWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Analyst, Information Security (GRC) And Crisis Management. Be the first to apply!
Related searches
- geopolitical analyst Montréal, QC
- land analyst Montréal, QC
- statistical analyst Montréal, QC
- analyste d'inventaire Montréal, QC
- senior analyst Montréal, QC
- provisioning analyst Montréal, QC
- hris analyst Montréal, QC
- records analyst Montréal, QC
- asset analyst Montréal, QC
- health and safety analyst Montréal, QC

