Our client, a prominent leader in the Canadian financial services sector, is seeking a high-caliber Cybersecurity Governance & Policy Subject Matter Expert for an impactful consulting engagement. In this role, you will lead the strategic modernization and complete overhaul of the enterprise cybersecurity policy, standard, and technical guideline framework.
...
Moving away from legacy, purely compliance-driven documentation, your goal is to transition the organization toward a modern, pragmatic, and security-first model. You will be responsible for creating accessible, high-value guidance that simplifies compliance for general business users while delivering precise, technically rigorous standards for IT, Cloud, and Information Security engineering teams.
Advantages
Strategic Impact: Directly shape and modernize the cybersecurity foundation of a major financial institution.
Competitive Compensation: Hourly rate tailored to senior-level expertise (up to $141/hr based on candidate profile).
Flexible Location: Remote/hybrid flexibility across major Canadian hubs (Montreal, Laval, Quebec City, Toronto, Calgary, Edmonton, Vancouver, St. John's).
Collaborative Environment: Engage closely with cross-functional experts in security architecture, risk management, and upcoming GRC technology initiatives.
Responsibilities
Framework Overhaul: Direct the full lifecycle—from design to deployment—of modernized cybersecurity policies, technical standards, and operational guidelines.
Dual-Tier Documentation: Author clear, accessible high-level guidance for non-technical employees alongside deep-dive, actionable technical baselines for IT and Cyber Operations.
Regulatory Translation: Interpret and map key financial sector mandates (such as OSFI B-13, SOX, and OSC 52-109) and industry frameworks (NIST CSF, NIST SP 800-53, ISO 27001) into practical, non-bureaucratic controls.
Cross-Functional Alignment: Collaborate with Security Architecture, Cloud Engineering, Application Security, and Risk Advisory to ensure technical feasibility and real-world applicability.
Process Enhancement: Refine the formal Security Exception Process to ensure non-standard configurations are effectively evaluated, documented, and risk-tracked.
Adoption & Usability: Partner with internal teams to deploy modern content delivery mechanisms (e.g., interactive decision trees, quick-reference playbooks, and dynamic knowledge management tools like Jira, Confluence, and SharePoint) ahead of a broader GRC platform integration.
Reporting & Audit Support: Interface with regulatory, audit, and leadership stakeholders to demonstrate policy coverage, adherence metrics, and framework maturity.
Qualifications
Experience: Minimum of 10 years in IT/Cybersecurity, including at least 3 years explicitly focused on designing and managing enterprise security policy and governance frameworks within a regulated financial environment.
Regulatory Mastery: Proven, practical knowledge of Canadian financial regulations and standards (e.g., OSFI regulatory guidelines, SOX, NIST CSF, ISO 27001).
Technical Depth: Solid understanding of technical domains (including Identity & Access Management, Web Application Firewalls, Server Group Policies, Cloud Infrastructure, and Network Security) to ensure technical requirements are accurately articulated.
Dual Audience Communication: Outstanding ability to translate complex technical/regulatory requirements into plain, user-friendly language for general staff while providing explicit engineering details for technical specialists.
Tooling Proficiency: Experience utilizing dynamic collaboration tools (Confluence, Jira, SharePoint) to structure and manage interactive policy documentation.
Education & Certifications: Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent experience. Industry certifications (CISSP, CISM, CRISC, CISA, CCSP, SABSA) are highly desirable assets.
Our client operates in Canada. The company takes all reasonable steps to limit the number of positions in Quebec that require knowledge of a language other than French, and only requires it when necessary and its existing bilingual employees are unable to perform these duties. Based on an assessment conducted by our client, it has been determined that this position requires candidates to be fluent in English (both spoken and written). In particular, this position will require the employee to interact with centralized internal departments (e.g., Operations / HR / Finance / Legal / Contracts / Sales) that support the organization in Canada and that do not speak French.
Summary
Location: Canada (Flexible across Montreal, Laval, Quebec City, Toronto, Calgary, Edmonton, Vancouver, St. John's)
Contract Duration: October 5, 2026 – February 28, 2027
Position Type: Contract / Mandate
Language Requirement: English (Mandatory)
Randstad Canada is committed to fostering a workforce reflective of all peoples of Canada. As a result, we are committed to developing and implementing strategies to increase the equity, diversity and inclusion within the workplace by examining our internal policies, practices, and systems throughout the entire lifecycle of our workforce, including its recruitment, retention and advancement for all employees. In addition to our deep commitment to respecting human rights, we are dedicated to positive actions to affect change to ensure everyone has full participation in the workforce free from any barriers, systemic or otherwise, especially equity-seeking groups who are usually underrepresented in Canada's workforce, including those who identify as women or non-binary/gender non-conforming; Indigenous or Aboriginal Peoples; persons with disabilities (visible or invisible) and; members of visible minorities, racialized groups and the LGBTQ2+ community.
Randstad Canada is committed to creating and maintaining an inclusive and accessible workplace for all its candidates and employees by supporting their accessibility and accommodation needs throughout the employment lifecycle. We ask that all job applications please identify any accommodation requirements by sending an email to accessibility@randstad.ca to ensure their ability to fully participate in the interview process.
show more
Our client, a prominent leader in the Canadian financial services sector, is seeking a high-caliber Cybersecurity Governance & Policy Subject Matter Expert for an impactful consulting engagement. In this role, you will lead the strategic modernization and complete overhaul of the enterprise cybersecurity policy, standard, and technical guideline framework.
Moving away from legacy, purely compliance-driven documentation, your goal is to transition the organization toward a modern, pragmatic, and security-first model. You will be responsible for creating accessible, high-value guidance that simplifies compliance for general business users while delivering precise, technically rigorous standards for IT, Cloud, and Information Security engineering teams.
Advantages
Strategic Impact: Directly shape and modernize the cybersecurity foundation of a major financial institution.
Competitive Compensation: Hourly rate tailored to senior-level expertise (up to $141/hr based on candidate profile).
Flexible Location: Remote/hybrid flexibility across major Canadian hubs (Montreal, Laval, Quebec City, Toronto, Calgary, Edmonton, Vancouver, St. John's).
...
Collaborative Environment: Engage closely with cross-functional experts in security architecture, risk management, and upcoming GRC technology initiatives.
Responsibilities
Framework Overhaul: Direct the full lifecycle—from design to deployment—of modernized cybersecurity policies, technical standards, and operational guidelines.
Dual-Tier Documentation: Author clear, accessible high-level guidance for non-technical employees alongside deep-dive, actionable technical baselines for IT and Cyber Operations.
Regulatory Translation: Interpret and map key financial sector mandates (such as OSFI B-13, SOX, and OSC 52-109) and industry frameworks (NIST CSF, NIST SP 800-53, ISO 27001) into practical, non-bureaucratic controls.
Cross-Functional Alignment: Collaborate with Security Architecture, Cloud Engineering, Application Security, and Risk Advisory to ensure technical feasibility and real-world applicability.
Process Enhancement: Refine the formal Security Exception Process to ensure non-standard configurations are effectively evaluated, documented, and risk-tracked.
Adoption & Usability: Partner with internal teams to deploy modern content delivery mechanisms (e.g., interactive decision trees, quick-reference playbooks, and dynamic knowledge management tools like Jira, Confluence, and SharePoint) ahead of a broader GRC platform integration.
Reporting & Audit Support: Interface with regulatory, audit, and leadership stakeholders to demonstrate policy coverage, adherence metrics, and framework maturity.
Qualifications
Experience: Minimum of 10 years in IT/Cybersecurity, including at least 3 years explicitly focused on designing and managing enterprise security policy and governance frameworks within a regulated financial environment.
Regulatory Mastery: Proven, practical knowledge of Canadian financial regulations and standards (e.g., OSFI regulatory guidelines, SOX, NIST CSF, ISO 27001).
Technical Depth: Solid understanding of technical domains (including Identity & Access Management, Web Application Firewalls, Server Group Policies, Cloud Infrastructure, and Network Security) to ensure technical requirements are accurately articulated.
Dual Audience Communication: Outstanding ability to translate complex technical/regulatory requirements into plain, user-friendly language for general staff while providing explicit engineering details for technical specialists.
Tooling Proficiency: Experience utilizing dynamic collaboration tools (Confluence, Jira, SharePoint) to structure and manage interactive policy documentation.
Education & Certifications: Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent experience. Industry certifications (CISSP, CISM, CRISC, CISA, CCSP, SABSA) are highly desirable assets.
Our client operates in Canada. The company takes all reasonable steps to limit the number of positions in Quebec that require knowledge of a language other than French, and only requires it when necessary and its existing bilingual employees are unable to perform these duties. Based on an assessment conducted by our client, it has been determined that this position requires candidates to be fluent in English (both spoken and written). In particular, this position will require the employee to interact with centralized internal departments (e.g., Operations / HR / Finance / Legal / Contracts / Sales) that support the organization in Canada and that do not speak French.
Summary
Location: Canada (Flexible across Montreal, Laval, Quebec City, Toronto, Calgary, Edmonton, Vancouver, St. John's)
Contract Duration: October 5, 2026 – February 28, 2027
Position Type: Contract / Mandate
Language Requirement: English (Mandatory)
Randstad Canada is committed to fostering a workforce reflective of all peoples of Canada. As a result, we are committed to developing and implementing strategies to increase the equity, diversity and inclusion within the workplace by examining our internal policies, practices, and systems throughout the entire lifecycle of our workforce, including its recruitment, retention and advancement for all employees. In addition to our deep commitment to respecting human rights, we are dedicated to positive actions to affect change to ensure everyone has full participation in the workforce free from any barriers, systemic or otherwise, especially equity-seeking groups who are usually underrepresented in Canada's workforce, including those who identify as women or non-binary/gender non-conforming; Indigenous or Aboriginal Peoples; persons with disabilities (visible or invisible) and; members of visible minorities, racialized groups and the LGBTQ2+ community.
Randstad Canada is committed to creating and maintaining an inclusive and accessible workplace for all its candidates and employees by supporting their accessibility and accommodation needs throughout the employment lifecycle. We ask that all job applications please identify any accommodation requirements by sending an email to accessibility@randstad.ca to ensure their ability to fully participate in the interview process.
show more