Cybersecurity Metrics and Controls Specialist
The specialist will define and document control and risk metrics for technology controls by collaborating with stakeholders and the policy team. They will also partner with data acquisition teams to implement these metrics and establish reporting frameworks for consumers.
- On-site
- Montréal, QC
- Posted Aug 24, 2026
- Apply by Sep 23, 2026
- 1 position
More jobs you can apply to directly
Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.
Job summary
Cybersecurity Metrics and Controls Specialist "Cybersecurity Metrics and Controls Specialist The successful candidate will join the Continuous Controls Monitoring (CCM) team and be part of the Metric Design & Architecture team. The team quantifies and reports on the implementation correctness and operating efficiency of Technology controls. • Establish and document Control/Risk metric definition for Technology controls by engaging with various Stakeholders, understanding processes and analyzing data for accurate measure. • Engage with Technology Policy team to ensure Control Measurement/Metric requirements are met through Policy design/update process. • Partner with various Metric consumers to establish Reporting framework meeting their requirements. • Partner closely with CCM Data acquisition and tooling team for successful implementation of metrics • 10+ years of experience in information security or/and information technology • 5+ years hands-on experience with technology or cybersecurity control implementations. • Ability to define metrics/ Key Control Indicators to show control implementation completeness • Strong business acumen and a strategic mindset • Experience working with and understanding the needs of customers or clients • Strong interpersonal skills, to interact at all levels and be effective as part of a broader team • Ability to manage expectations and handle high-pressure situations with tight deadlines • Proven analytical skills decision-making ability based on quantitative and qualitative data?Knowledge of various domains of Technology control / Cybersecurity • Knowledge of Public cloud technology • Knowledge of security concepts and tools around Identity &Authentication, Data Security, System security, Network Security and Application security. • Knowledge of security logging, monitoring, and incident response • Cybersecurity certifications is preferred "
What you’ll do
The specialist will define and document control and risk metrics for technology controls by collaborating with stakeholders and the policy team. They will also partner with data acquisition teams to implement these metrics and establish reporting frameworks for consumers.
Requirements
Candidates need over 10 years of experience in information security or IT, with at least 5 years of hands-on experience in cybersecurity control implementations. Knowledge of public cloud, security domains, and professional cybersecurity certifications are preferred.
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Cybersecurity Metrics
- Control Implementation
- Risk Metric Definition
- Public Cloud Technology
- Identity & Authentication
- Data Security
- Network Security
- Application Security
- Security Logging
- Incident Response
- Analytical Skills
- Stakeholder Management
- Strategic Mindset
- Business Acumen
- Continuous Controls Monitoring
- Reporting Frameworks
Job areas
- Security & Safety
- Technology
- Engineering
- Data & Analytics
- Consulting
Additional details
- Minimum education
- Professional degree
- Minimum experience
- 10+ years
- Apply by
- Sep 23, 2026
- Posting language
- English
- Working hours
- 40 hours per week
- Seniority
- Mid-Senior level
- Application method
- Direct apply is available
