Specialist Information Security

Canadian National Railway CompanyMontréal-Est, QC

About The Position

The role of Specialist Information Security is responsible for defining, maintaining and supporting the Information Security framework and related processes. He / She is a specialist in information security management matters, including but not limited to understanding business risks, settings security requirements, associated metrics, compliance requirements, project support, GRC processes consulting and integration of regulatory requirements. The Specialist is charged with gaining widespread support of and compliance with information security requirements and policies.

Requirements

  • B.S. degree in Computer Science, Information Systems or equivalent degree & experience
  • Knowledge of Information Security Risk practices and frameworks
  • Knowledge of Information Security Governance and Compliance frameworks
  • Knowledge of various industry standards and frameworks including ISO/IEC 27000 series, ISF, NIST Special Publications, Risk Management methodologies, and security evaluations methodologies
  • Knowledge of security regulations, Sarbanes-Oxley Act, PCI-DSS standard, OWASP.
  • Knowledge of UNIX/Linux environments
  • Knowledge of cryptography
  • Programming experience in Python, PHP, Perl, Ruby, or other interpreted or compiled languages
  • Detail-oriented self-starter with a high level of commitment and personal motivation
  • Knack for prioritizing tasks and working in a fast-paced environment
  • Strong oral and written language skills in French and English
  • Relationship management skills
  • Minimum 5-10 years overall work experience
  • Minimum 5 years experience in information security discipline such as GRC, architecture or operation
  • Experience performing security analysis and assessment
  • Experience with Agile development

Nice To Haves

  • Certifications in ITIL, CISSP, CISM, CISA, desirable
  • Previous experience in Security Governance, Risk and Compliance

Responsibilities

  • Perform threat analysis, risk evaluations and security assessments, recommendations and ensure adherence to regulatory and information security requirements
  • Develop and maintain policy, standards and processes to assess, report and remediate risk and compliance related issues
  • Support the business initiatives, while making sure any I&T security risk introduced is properly managed
  • Identify I&T risks, communication and development of “best practice” solutions, and implementation of mitigating controls consistent with company strategy
  • Identify compliance risks and in implement plans to monitor and address those findings with relevant and feasible remediation plans
  • Responsible to ensure that CN’s internal technological processes and services comply with community expectations, laws, and regulations for privacy, security, and social responsibility
  • Work with security and architecture teams to establish and review policies
  • Implement and manage governance around security management both internally and externally in multiple vendor environments
  • Perform process and control reviews to ensure that they align to CN’s information security requirements
  • Plan, coordinate and oversee activities related to the design, development and integration of information systems, operations systems and reporting systems in a security or risk context
  • Monitor emerging IT security threats and trends
  • Respond to vulnerabilities and threats
  • Define hardening configurations
  • Assist our full stack development and DevOps teams in building secure software and infrastructure
  • Work as an integral part of the DevOps team
  • Provide guidance on emerging IT security threats and trends
  • Provide guidance on compliance with laws, and regulations for privacy, security, and social responsibility

Benefits

  • paid training
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service