Role Overview
KYYBA Inc is hiring a mid-level Cyber Security Risk Specialist. This is a contract role in Montreal. Full responsibilities, required qualifications, and the apply link are listed in the description below.
Resume Keywords to Include
Make sure these keywords appear in your resume to improve ATS scoring
Job Description
Purpose
The Cyber Security Supply‑Chain Risk Specialist ensures that third‑party services across North, Central, and South America business, regulatory, and security standards. The role partners with Relationship Managers, Vendor Management, and global security teams to translate global vendor‑due‑diligence findings into actionable local mitigations, run continuous‑monitoring programs, and lead third‑party security transformation projects.
Key Responsibilities
Supply‑Chain Risk Management
- Review and understand vendor services and define assessment scope using the Vendor Questionnaire.
- Conduct security assessments or work with global team to ensure appropriately scoped assessments are performed; deliver findings in both English and Spanish.
- Evaluate final assessment reports, define appropriate risk levels, taking into account local control environment (Low/Moderate/Notable, High), and develop implementable corrective actions.
- Discuss findings with business lines, come to agreement on next steps, and formalize action plans in the system of record
- Perform periodic outreach to service providers verifying mitigation steps for current treats and open action plans.
Transformation & Projects
- Understand business priorities, key initiatives, planned programs and aspirations; collaborate closely with cybersecurity leadership to ensure programs are aligned and communicated
- Lead initiatives and deliverables within information security domain environments
- Lead end‑to‑end delivery (design, development, testing, implementation, operation and maintenance) of new and existing Third Party and Information Security projects
- Assist in identifying opportunities for automation through data analysis
Operational Efficiency
- Support and promote automation of repetitive and complex data management tasks to improve efficiency across information security functional areas
- Extract, Transform, and Load(ETL) Data with a firm understanding of how to shape datasets using a mixed environment
- Design, maintain, and review KPI dashboards that monitor third‑party risk performance and drive continuous improvement.
Required Qualifications
Category
Minimum Requirements
Experience
≥ 6 years in information‑security or risk‑management roles, including ≥ 2 years delivering security projects.
Education
Bachelor’s degree in Computer Science, Information Security, Engineering, or equivalent work experience.
Technical Skills
- Vendor risk assessment frameworks (NIST CSF, ISO 27001, SIG).
- Proficiency with security questionnaires (SIG, CAIQ).
- Scripting – basic competency in PowerShell, Python, or equivalent.
- ETL tools (SQL, Alteryx, Python‑pandas).
Languages
Fluent written & spoken English and Spanish mandatory (French not required for this role).
Certifications (desired)
CISSP, CISA, CRISC, or Certified Third‑Party Risk Professional (CTPRP).
Soft Skills
Strong written & verbal communication; ability to convey complex security concepts concisely in both languages; excellent stakeholder‑management; adaptability to shifting priorities; rigorous documentation habits.
Other
Legally authorized to work in the Greater Montreal area (no sponsorship). Ability to work on‑site as an essential function of the role.
Preferred Qualifications
- Project‑management experience delivering IT products in a banking environment.
- Prior audit experience (internal or external).
- Additional language(s): Portuguese or French.
- Experience with cloud‑service security (IaaS/PaaS SaaS) assessments.
Frequently Asked Questions
How do I apply for the Cyber Security Risk Specialist position at KYYBA Inc?
Use the Apply button above to submit your application directly to KYYBA Inc. Most applications take less than 5 minutes if your resume and contact details are ready, and you'll be routed to the employer's official application system to finish.
Where is the Cyber Security Risk Specialist position at KYYBA Inc located?
This position is based in Montreal. KYYBA Inc has not indicated remote or hybrid options for this role, so candidates should plan for on-site work.
What does a Cyber Security Risk Specialist at KYYBA Inc earn?
KYYBA Inc has not disclosed a salary range in this posting. Many employers share specifics later in the interview process; you can also ask during a recruiter screen if compensation transparency is important to you.
When was the Cyber Security Risk Specialist role at KYYBA Inc posted?
This role was posted on April 27, 2026 (53 days ago). It's still listed as actively hiring; we re-confirm openings against the source system multiple times per day and remove closed roles.
AI-powered job search
Get every job scored to your resume
Upload your resume and get jobs ranked, your resume tailored, and employee contacts found automatically.
Get Started FreeNo credit card to start