Specialist Information Security
At CN, everyday brings new and exciting challenges. You can expect an interesting environment where you’re part of making sure our business is running optimally and safely―helping keep the economy on track. We provide the kind of paid training and opportunities that long-term careers are built on and we recognize hard workers who strive to make a difference. You will be able to thrive in our close-knit, safety-focused culture working together as ONE TEAM. The careers we offer are meaningful because the work we do matters. Join us!
CN is looking for a Cybersecurity GRC (Governance, Risk & Compliance) analyst to help sustain and grow our Cybersecurity Governance team.
Reporting to the Cybersecurity Governance, Risk & Compliance Manager, this role supports CN’s cybersecurity governance objectives by translating security, risk, and compliance requirements into practical processes, evidence, reporting, and guidance for I&T and business stakeholders, with a primary focus on maintaining, supporting, and operating the CN IS Management System.
Maintain, support, and operate CN’s Cybersecurity GRC framework, including information security classification, risk management processes, security-related policies, dissemination activities, and ongoing improvements to reflect business needs.
Support control testing, documentation, and maintenance activities to help ensure security controls remain adequate, effective, and aligned with regulatory and cybersecurity requirements.
Track cybersecurity issues, risks, and remediation actions in the ServiceNow Integrated Risk Management (IRM) module, including follow-up on risk assessments, security testing outcomes, and related business impacts.
Provide guidance during the assessment or review of new IT solutions and new or existing technologies to maintain alignment with regulatory requirements, such as Sarbanes-Oxley, PCI, and SWIFT, and security requirements using the ServiceNow Third Party Risk Management workflow.
Education/Certification/Designation
Technical Skills/Knowledge
Knowledge of industry standards and frameworks, including the ISO/IEC 27000 series, ISF, NIST Special Publications, risk management methodologies, and security evaluation methodologies.
Understanding of security and privacy regulations and legislative compliance requirements, such as the Sarbanes-Oxley Act, PCI DSS, and PIPEDA.
General Skills and Competencies
About CN
CN is a world-class transportation leader and trade-enabler. Essential to the economy, to the customers, and to the communities it serves, CN safely transports more than 300 million tons of natural resources, manufactured products, and finished goods throughout North America every year. As the only railroad connecting Canada’s Eastern and Western coasts with the Southern tip of the U.S. through a 19,500 mile rail network, CN and its affiliates have been contributing to community prosperity and sustainable trade since 1919. CN is committed to programs supporting social responsibility and environmental stewardship. At CN, we work as ONE TEAM, focused on safety, sustainability and our customers, providing operational and supply chain excellence to deliver results.
About CN
CN is a premium railroad that sustainably generates value for our customers, shareholders, employees, and stakeholders with an unwavering commitment to safety and service. Essential to the economy, to the customers, and to the communities it serves, CN safely transports more than 300 million tons of natural resources, manufactured products, and finished goods throughout North America every year. CN's network connects Canada's Eastern and Western coasts with the U.S. South through a 20,000-mile rail network. CN and its affiliates have been contributing to community prosperity and sustainable trade since 1919. CN powers the North American economy and is committed to programs supporting social responsibility and environmental stewardship.
At CN, we are dedicated to building North America's safest, most inclusive and sustainable railroad, which includes reflecting the communities in which we operate. Research shows that candidates often don't apply unless they feel they fit the job posting at 100%. To all potential applicants, even if you don't meet every job requirement listed in a posting, we still encourage you to apply. If you require an accommodation for the recruitment process (including alternate formats of materials, accessible meeting rooms or other accommodations), please get in touch with our team at [email protected].
As an equal opportunity employer, qualified candidates will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, and other protected status as required by applicable law.
Please monitor your email on a regular basis as communication to applicants is done via email.