Specialist, IT Security Risk Management

CMHC - SCHLMontreal, QC
CA$86,817 - CA$108,521Hybrid

About The Position

Join the Technology and Business Transformation team, in the Specialist, IT Security Risk Management position, where you will help identify, assess, monitor, and report cybersecurity and information security risks across CMHC. The role supports risk-informed decisions by working with business, technology, security, and governance stakeholders to understand risk exposure, treatment options, and control effectiveness. The Specialist also supports cyber risk registers, remediation tracking, exception and acceptance processes, key risk indicators, and executive-level reporting aligned with CMHC’s risk appetite, enterprise risk practices, regulatory expectations, and recognized frameworks. This role works closely with cross-functional teams to assess threats, respond to incidents, ensure regulatory compliance, and enhance the overall cybersecurity maturity of the organization. This is a temporary position of a duration of 18 months.

Requirements

  • A bachelor’s degree in Information Security, Computer Science, or a related field, or an equivalent combination of education and experience.
  • At least 5+ years of experience in IT security, risk management, or related roles.
  • Experience conducting security risk assessments, evaluating controls, documenting residual risk, and supporting treatment plans.
  • Knowledge of recognized frameworks such as NIST CSF, ITSG-33, COBIT, or similar.

Nice To Haves

  • Certifications such as CISSP, CISM, CRISC, CGRC, ISO 27001, CISA, or similar (an asset).
  • Experience in a regulated, financial services, Crown corporation, or public-sector environment is considered an asset.

Responsibilities

  • Advise business, technology, and security stakeholders on information security risks, including impacts, mitigation strategies, remediation priorities, and risk acceptance requirements.
  • Promote and apply consistent information security risk management practices across projects, technologies, vendors, and operational processes.
  • Conduct, document, and communicate risk assessments, control effectiveness, residual risks, treatment options, and escalation requirements to support informed decision-making.
  • Maintain comprehensive risk documentation, including risk registers, exceptions, acceptances, remediation plans, and supporting evidence.
  • Monitor remediation activities by tracking commitments, target dates, dependencies, and progress with accountable risk owners.
  • Identify, analyze, and escalate high-priority, overdue, emerging, or systemic risks, control weaknesses, and issues requiring management or governance attention.
  • Develop cyber risk metrics, trends, dashboards, and reporting, and prepare clear updates for management, executives, governance committees, auditors, and regulators.
  • Enhance the organization's risk management maturity by improving methodologies, templates, taxonomies, scoring, quality assurance practices, and contributing to policies, standards, procedures, and regulatory impact assessments.

Benefits

  • Accrued vacation.
  • Annual individual performance bonus.
  • Group insurance coverage to support your well-being from day one.
  • Support towards your personal and professional growth with training, mentorship and more.
  • An inclusive workplace culture and environment.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service