1

Information Systems Security Officer Jobs in Quebec

Systems engineering, systems security engineering, System Development Life Cycle processes in the context of information systems and information technology and requirements management and ...

Systems engineering, systems security engineering, System Development Life Cycle processes in the context of information systems and information technology and requirements management and ...

Systems engineering, systems security engineering, System Development Life Cycle processes in the context of information systems and information technology and requirements management and ...

Systems engineering, systems security engineering, System Development Life Cycle processes in the context of information systems and information technology and requirements management and ...

Professional security certification such as CISSP (Certified Information Systems Security Professional). * Cisco CCNP Security or CCIE. * Experience with business continuity planning, auditing, and ...

... fournir un retour d'information ouvert, honnête et direct à nos employés. Promouvoir la ... système de risque et de sécurité de la station, des procédures d'assurance qualité et de ...

Reporting to the Security Supervisor, the Security Systems Technician will be responsible for ... Additional Information What we offer : * Competitive salary + other benefits * Group insurance and ...

next page

Showing results 1-20

Information Systems Security Officer information

See Quebec salary details

$51.5K

$112.9K

$161.5K

How much do information systems security officer jobs pay per year?

As of Sep 3, 2026, the average yearly pay for information systems security officer in Quebec is $112,885.00, according to ZipRecruiter salary data. Most workers in this role earn between $97,000.00 and $130,500.00 per year, depending on experience, location, and employer.

What does an information systems security officer do?

An Information Systems Security Officer (ISSO) is responsible for ensuring the security of an organization's information systems. This includes developing, implementing, and monitoring security policies and procedures to protect data from unauthorized access, breaches, and other cyber threats. ISSOs conduct risk assessments, coordinate security audits, and provide guidance on security best practices to staff. They also ensure compliance with relevant laws and regulations, such as NIST or ISO standards, and respond to security incidents when they occur.

What does an information systems security officer do?

An information systems security officer (ISSO) protects the IT infrastructure of companies, organizations, or agencies. Your duties include taking proactive security measures, assessing risks, and responding to security breaches. You monitor networks, databases, and computer systems and create a risk management plan for IT systems. You perform security updates and build firewalls and other security features. Your responsibilities also include assessing security practices and procedures. You may coordinate penetration tests to test the effectiveness of current security systems. Based on the results of this assessment, you implement changes and train employees in secure computer practices.

What skills and qualifications are needed to be an information systems security officer?

To thrive as an Information Systems Security Officer, you need a strong understanding of cybersecurity principles, risk management, and regulatory compliance, typically supported by a degree in information technology or cybersecurity and relevant certifications such as CISSP or CISM. Familiarity with security tools like intrusion detection systems, SIEM platforms, and vulnerability assessment software is essential. Exceptional analytical thinking, attention to detail, and strong communication skills help you proactively address threats and effectively enforce security policies. These abilities are crucial to protect organizational data, ensure compliance, and minimize security risks in a constantly evolving threat landscape.

What are common challenges information systems security officers face when implementing new security protocols?

Information Systems Security Officers often encounter challenges such as gaining buy-in from various departments, managing resistance to change, and ensuring that new protocols do not disrupt existing workflows. They must communicate the importance of security measures clearly and collaborate with IT, management, and end-users to provide training and support. Balancing robust security with user convenience while meeting compliance standards requires strong project management and interpersonal skills.

What is the difference between Information Systems Security Officer vs Network Security Analyst?

AspectInformation Systems Security OfficerNetwork Security Analyst
CertificationsCISSP, CISA, Security+CompTIA Security+, CISSP, CEH
Work EnvironmentOversees security policies, manages security teams, works across IT departmentsMonitors network traffic, analyzes security breaches, implements network defenses
Employer & Industry UsageUsed in government, finance, healthcare for security oversightCommon in tech firms, ISPs, and corporate IT for network protection

While both roles focus on cybersecurity, the Information Systems Security Officer has a broader responsibility for overall security policies and compliance, whereas the Network Security Analyst concentrates on protecting network infrastructure through monitoring and analysis.

What are popular job titles related to Information Systems Security Officer jobs in Quebec?

For Information Systems Security Officer jobs in Quebec, the most frequently searched job titles are:

What job categories do people searching Information Systems Security Officer jobs in Quebec look for?

The top searched job categories for Information Systems Security Officer jobs in Quebec are:

Infographic showing various Information Systems Security Officer job openings in Quebec as of August 2026, with employment types broken down into 1% As Needed, 75% Full Time, 21% Part Time, and 3% Contract. Highlights an 90% Physical, 2% Hybrid, and 8% Remote job distribution, with an average salary of $112,885 per year, or $54.3 per hour.

Information Security Officer

Societe Generale

Montreal, QC • On-site

Full-time

Re-posted 17 days ago


Job description

The Vulnerability Management Lead is responsible for the AMER region's vulnerability management and configuration management program. The position requires excellent communication skills (written and verbal) and a strong ability to influence others. The ideal candidate will be able to demonstrate practical and in-depth knowledge of running an effective vulnerability & / or configuration management program including dynamically responding to emerging threats in the financial services industry.

The role also calls for strong technical analysis and process improvement skills and the ability to present to senior management on the state of, and proposals to improve, the program.

Working knowledge of cybersecurity and risk assessment frameworks (e.g., NIST) and regulations applicable to the financial services industry (e.g., NYDFS 500, FINRA, SEC) is preferred.

The Vulnerability Management Lead is a member of the Cyber Threat Defense (CTD) team within the AMER Data and Cyber Security (ISR) department and reports to the Director of CTD. This position requires strong collaboration across GBSU and GTS departments in the Americas and globally with SG CERT, ISR and GTS teams.

ESSENTIAL JOB FUNCTIONS

Vulnerability & Configuration Management

  • Lead the AMER vulnerability & configuration management programs - Act as the main point of contact and expert in Vulnerability Management and configuration management; including overseeing the risk of zero-day vulnerabilities, oversee patching/remediation and risk acceptance of vulnerabilities where appropriate.

  • Oversee the discovery, evaluation, and implementation of vulnerability scanning, patch and configuration review, penetration testing.

  • Present operating and steering committees for projects to senior management on a quarterly basis.

  • Develop and oversee annual roadmaps of initiatives to align with overall InfoSec and business objectives/strategy.

  • Develop and manage detailed vulnerability reviews and assessments, and patching and configuration reviews: (1) Assess potential damage of security flaws and assist in the implementation of corrective actions; (2) Identify, document, and report security issues and concerns to management; and (3) Monitor corrective actions and recommending cost-effective preventive measures to preclude recurrences.

  • Review and sign-off on all recommendations on possible improvements resulting from the work performed as part of projects.

  • Draft and publish communications for management as new threats emerge.

  • Improve the reporting framework that will provide regular metrics and statistics about our business and IT environment; analyze trends in security events, activities, etc. to better understand risks, insufficiencies in our solutions, staffing shortages, etc.; report security metrics and statistics to the CISO and other key stakeholders such as the COO, CIO, and CTO.

LANGUAGE: 

Ability to communicate in English, both orally and in writing, is a requirement as the person in this position will need to collaborate regularly with colleagues and partners in the United States. 

KNOWLEDGE AND EXPERIENCE

       5-10 years related information security experience, in particular hands-on experience in vulnerability management.

       Excellent communications skills, both verbal and written. Comfortable presenting to all levels from technical to senior (C-level).

  • Proficiency with MS Office suite of productivity tools is required.
  • Strong analytical, problem solving, and process improvement skills are required.
  • Experience with Qualys, Windows Defender or equivalent tools to manage vulnerabilities, patching and configurations if preferred.
  • Solid understanding of common security best practices and risk assessment is preferred.

EDUCATION/CERTIFICATIONS

  • Bachelor's degree or equivalent business experience in Cybersecurity, Computer Science, or Business Management is required.
  • CISSP, CCSP, CISM, GSEC, CEH, or related security certification(s) is highly preferred.