In this role, you will provide information security consulting services for BMO overall and businesses/groups and partner with stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs. Also, you will help lead the development of information security strategy by understanding business processes, policies, information and information systems, and build exceptional relationships with internal and external stakeholders. You will ensure that requirements and solutions align to a real business need, are approved by all relevant stakeholders, and meets essential information security standards. and provide thought leadership, promotes new processes and methodologies and emerging technologies, with the flexibility to align to the unique requirements of the business/group and deliverables.
- Promotes process improvements and methodologies; keeps emerging information security issues and trends in mind and ensures standards are followed.
- Supports the execution of strategic initiatives in collaboration with internal and external stakeholders.
- Builds credibility and influences/negotiates effectively to drive business performance through development and delivery of information security solutions.
- Acts as a trusted advisor to assigned business/group.
- Assists in the development of strategic plans.
- Understands the strategy, plans, activities and needs of all stakeholders and translates those business needs into solutions and makes recommendations.
- Facilitates discussions and follows a disciplined approach to plan, elicit, analyse, document, communicate and manage initiatives and issues with stakeholders by applying a variety of elicitation techniques to probe, challenge and understand associated risks.
- Helps determine business priorities and best sequence for execution of business/group strategy.
- Provides advice, counsel and support on information security matters and recommends solutions to assigned business/group leaders on principles, frameworks, programs, approaches, trends, legislation and regulatory requirements including interpretation of policy and identification and management of risk.
- Acts as the day to day contact for vendors; supports the implementation, maintenance, and sustainment of vendor solutions.
- Breaks down strategic problems, and analyses data and information to provide insights and recommendations.
- Tracks metrics and milestones, providing recommendations for resolution and escalating as appropriate when issues arise.
- Understands and can explain to others the core processes, risks and mitigation techniques for designated areas.
- Knowledge of information security processes, procedures and controls – In-depth.
- Understanding of and problem solving ability for information security issues within their business group – Working.
- Collaboration & team skills – In-depth.
- Understanding of industry standards and frameworks e.g. NIST Cyber Security Framework (CSF), ISO 27001 and 27002, Payment Card
- Industry (PCI) Data Security Standard (DSS), etc. – In-depth.
- Deep knowledge and technical proficiency gained through extensive education and business experience.
- Knowledge of business analysis, project delivery practices and standards across the project lifecycle – In-depth.
- Verbal & written communication skills – In-depth.
- Preference for candidates who have at least one certification in a related field, with strong preference for Information security certifications from a well-recognized institution (e.g. (ISC)2, ISACA, SANS).
- Understanding of information security risk and regulatory requirements – Working.
Qualification & Experience:
- Experience in information security concepts and methodology.
- Min of 1-3 years of knowledge in the Software Development Lifecycle (SDLC) (i.e. Agile, Waterfall, DevOps)
- Min of 1-3 years of experience in Application Security
- Min of 3 years of experience in Governance, Risk, or Advisory Services within Cyber Security or Information Security
- Typically between 4 – 7 years of relevant experience and a post-secondary degree in Information Security, Computer Science, Engineering, and/or Information Systems or a related field of study or an equivalent combination of education and experience.
Vacancy Type: Full Time
Job Functions: Sales
Job Location: Chicago, IL, US
Application Deadline: N/A