×
Register Here to Apply for Jobs or Post Jobs. X

Specialist Information Security

Job in Montréal-Est, Montréal, Province de Québec, Canada
Listing for: Canadian National Railway Company
Full Time position
Listed on 2026-08-04
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 90000 - 120000 CAD Yearly CAD 90000.00 120000.00 YEAR
Job Description & How to Apply Below
Location: Montréal-Est

Specialist Information Security

At CN, everyday brings new and exciting challenges. You can expect an interesting environment where you’re part of making sure our business is running optimally and safely – helping keep the economy on track. We provide the kind of paid training and opportunities that long‑term careers are built on and we recognize hard workers who strive to make a difference. You will be able to thrive in our close‑knit, safety‑focused culture working together as ONE TEAM.

The careers we offer are meaningful because the work we do matters. Join us!

Job Summary

CN is looking for a Cybersecurity GRC (Governance, Risk & Compliance) analyst to help sustain and grow our Cybersecurity Governance team.

Reporting to the Cybersecurity Governance, Risk & Compliance Manager, this role supports CN’s cybersecurity governance objectives by translating security, risk, and compliance requirements into practical processes, evidence, reporting, and guidance for I&T and business stakeholders, with a primary focus on maintaining, supporting, and operating the CN IS Management System.

Key Responsibilities
  • Maintain, support, and operate CN’s Cybersecurity GRC framework, including information security classification, risk management processes, security-related policies, dissemination activities, and ongoing improvements to reflect business needs.
  • Communicate and support security recommendations that meet business objectives in a proactive and pragmatic manner, leveraging Service Now workflows and maintaining appropriate engagement with clients to support successful outcomes.
  • Support control testing, documentation, and maintenance activities to help ensure security controls remain adequate, effective, and aligned with regulatory and cybersecurity requirements.
  • Collaborate with the compliance team to ensure controls and compliance metrics are properly integrated into dashboards and reports that support overall metrics and KPIs.
  • Track cybersecurity issues, risks, and remediation actions in the Service Now Integrated Risk Management (IRM) module, including follow‑up on risk assessments, security testing outcomes, and related business impacts.
  • Provide guidance during the assessment or review of new IT solutions and new or existing technologies to maintain alignment with regulatory requirements, such as Sarbanes‑Oxley, PCI, and SWIFT, and security requirements using the Service Now Third Party Risk Management workflow.
  • Interact with other cybersecurity teams and I&T stakeholders to understand, apply, and support the enforcement of security requirements.
Requirements Experience
  • Knowledge of CN IT operations and business units is an asset.
  • 3+ years of experience in cybersecurity, compliance, IT audit, or a related role.
  • Practical experience with KPIs/KRIs.
  • Previous experience in risk management is an asset.
  • Experience with a GRC tool is an asset.
Education/Certification/Designation
  • Bachelor’s degree in an IT discipline or a related field –or– equivalent work experience.
Cybersecurity certifications
  • Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), or other related certifications are an asset.
Technical Skills/Knowledge
  • Knowledge of cybersecurity risk management practices.
  • Cybersecurity governance and compliance frameworks.
  • Knowledge of industry standards and frameworks, including the ISO/IEC 27000 series, ISF, NIST Special Publications, risk management methodologies, and security evaluation methodologies.
  • Understanding of security and privacy regulations and legislative compliance requirements, such as the Sarbanes‑Oxley Act, PCI DSS, and PIPEDA.
  • Knowledge of Service Now, including its landscape & workflows.
General Skills and Competencies
  • Integrity with a high ethical standard.
  • Client-focused mindset with the ability to provide practical guidance to business and I&T stakeholders.
  • Effective communication and interaction with others.
  • Teamwork and collaboration to achieve common goals.
  • Flexibility to manage multiple assignments effectively and adapt to changing priorities.
About CN

CN is a world‑class transportation leader and trade‑enabler. Essential to the economy, to the…

Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary