- Company Name
- ADM Aéroports de Montréal
- Job Title
- Conseiller Spécialiste Sécurité des projets (11781)
- Job Description
-
**Job title**
Cybersecurity Project Security Advisor
**Role Summary**
Senior specialist who integrates security requirements into technology‑enabled projects from inception to completion. Provides expert guidance on legal, regulatory, and risk aspects, designs and implements security controls, coordinates testing, and ensures compliance with industry standards.
**Expectations**
- Deliver expert security advice and measurable recommendations to project teams.
- Ensure integration of confidentiality, integrity, availability, and traceability requirements into project artefacts.
- Meet legal, contractual, and regulatory obligations, including personal data protection laws and PCI DSS.
- Maintain the highest level of security posture through continuous improvement of controls and risk mitigation.
**Key Responsibilities**
- Qualify internal client security needs and incorporate them into project scopes.
- Analyse legal, regulatory, contractual, business, threat, and vulnerability requirements.
- Identify applicable security controls and collaborate with project teams to plan and implement them.
- Work with architects to design controls for access, encryption, authentication, logging, monitoring, hardening, and anomaly detection.
- Coordinate with analysts to validate secure implementation of systems throughout the project life cycle.
- Facilitate privacy impact assessments and develop associated controls.
- Define and conduct cybersecurity test strategies, analyze results, and drive corrective actions.
- Gather security evidence, identify non‑conformities, assess cyber‑risk, and recommend mitigation measures.
- Produce professional security reviews, recommendations, and communicate findings to stakeholders.
**Required Skills**
- Minimum of 8 years’ experience in cybersecurity and cloud security.
- Deep knowledge of cloud security, risk management methodologies, privacy law, and PCI DSS.
- Proficiency in OWASP Top 10, NIST, ISO, SANS 25, and other security frameworks.
- Expertise in cryptography, CIAC, logging, monitoring, detection, penetration testing, and incident response.
- Strong analytical, problem‑solving, and communication skills in French (native) and English (working).
- Ability to work collaboratively in cross‑functional teams.
**Required Education & Certifications**
- Bachelor’s degree in Information Technology or a related discipline.
- Preferred certifications: CISSP, CISM, ISO 27001 Lead Implementer, CEH, CCSP, CCSK, AWS Security Specialty, or equivalent cloud security credential.
- Ability to obtain required security clearances after hire.