We are seeking a Defence Compliance Specialist to support defence procurement, cybersecurity compliance, and federal security requirements within a complex naval defence environment in Dartmouth, Nova Scotia.
In this role, you will lead compliance initiatives to ensure IT systems, digital infrastructure, and supplier integrations align with Government of Canada defence procurement directives, DND and federal security guidelines, and cybersecurity frameworks including NIST SP 800-171 and NIST SP 800-53.
You will work closely with security, IT, engineering, procurement, and supplier teams to translate Security Requirements Check Lists (SRCLs) and other federal security requirements into actionable IT controls, documentation, and risk mitigation activities.
This position requires full-time on-site presence in Dartmouth, Nova Scotia, five days per week.
Your future duties and responsibilities
- Support compliance of IT architectures, systems, and vendor procurement processes with applicable Public Services and Procurement Canada (PSPC), Department of National Defence (DND), and Canadian industrial security requirements.
- Lead cybersecurity readiness assessments, security control mapping, gap analysis, and remediation activities against NIST SP 800-171, NIST SP 800-53, and CMMC frameworks.
- Partner with internal security, IT, engineering, procurement, and supplier teams to interpret, document, and operationalize Security Requirements Check Lists (SRCLs) for IT systems, networks, and subcontractor environments.
- Support the protection and appropriate handling of Controlled Unclassified Information (CUI), Controlled Goods, and other security-sensitive information.
- Conduct formal Threat and Risk Assessments (TRAs) and develop associated risk mitigation strategies.
- Coordinate Vulnerability Assessment and Penetration Testing (VAPT) activities and support remediation of identified security findings.
- Develop and maintain System Security Plans (SSPs), Plans of Action and Milestones (POA&M), compliance documentation, and remediation roadmaps.
- Author, maintain, and review IT security policies, standard operating procedures, and defence data-handling protocols.
- Support continuous audit readiness and provide documentation and evidence for applicable federal and defence security reviews.
- Communicate technical security and compliance requirements to technical teams, business stakeholders, leadership, suppliers, and federal auditors.
Required qualifications to be successful in this role
- 5 to 7+ years of progressive experience in IT security, information assurance, defence regulatory compliance, or a closely related field.
- Strong operational experience with NIST SP 800-171 and NIST SP 800-53.
- Experience working with Canadian federal IT security guidance, including ITSD and CCCS requirements.
- In-depth working knowledge of the Canadian Federal Government procurement lifecycle, industrial security requirements, and SRCL administration.
- Experience interpreting and implementing Security Requirements Check Lists (SRCLs) within IT, network, or supplier environments.
- Experience authoring System Security Plans (SSPs) and conducting Threat and Risk Assessments (TRAs).
- Experience developing and managing security remediation roadmaps, including Plans of Action and Milestones (POA&M).
- Must be able to work on-site in Dartmouth, Nova Scotia, five days per week.
- Must hold or be eligible to obtain Government of Canada Secret (Level II) security clearance and meet the stated requirement for 10 years of verifiable Canadian residency.
- Must be eligible for and able to obtain Controlled Goods Program (CGP) clearance.
Assets
- CISSP, CISA, CRISC, CMMC-RP/PA, or equivalent industry certification.
- Experience working within Canadian defence prime contractors, major Crown projects, the National Shipbuilding Strategy, or DND/CAF programs.
- Experience with CMMC cybersecurity requirements and assessment activities.
- Strong stakeholder management skills, including experience translating technical security and compliance requirements for executive leadership and federal auditors.
CGI is providing a reasonable estimate of the pay range for this role. The determination of this range includes factors such as skill set level, geographic market, experience and training, and licenses and certifications. Compensation decisions depend on the facts and circumstances of each case. A reasonable estimate of the current range is $75000–$145000. This role is a future opportunity.
#LI - OA1
Together, as owners, let’s turn meaningful insights into action.
Life at CGI is rooted in ownership, teamwork, respect and belonging. Here, you’ll reach your full potential because…
You are invited to be an owner from day 1 as we work together to bring our Dream to life. That’s why we call ourselves CGI Partners rather than employees. We benefit from our collective success and actively shape our company’s strategy and direction.
Your work creates value. You’ll develop innovative solutions and build relationships with teammates and clients while accessing global capabilities to scale your ideas, embrace new opportunities, and benefit from expansive industry and technology expertise.
You’ll shape your career by joining a company built to grow and last. You’ll be supported by leaders who care about your health and well-being and provide you with opportunities to deepen your skills and broaden your horizons.
At CGI, we value the strength that diversity brings and are committed to fostering a workplace where everyone belongs. We collaborate with our clients to build more inclusive communities and empower all CGI partners to thrive. As an equal-opportunity employer, being able to perform your best during the recruitment process is important to us. If you require an accommodation, please inform your recruiter.
That same commitment to fairness extends to how we use technology. To support our recruitment team, AI tools may be used to help assess applications though they never replace human judgement. All hiring decisions remain entirely in the hands of our recruitment professionals.
To learn more about accessibility at CGI, contact us via email. Please note that this email is strictly for accessibility requests and cannot be used for application status inquiries.
Come join our team—one of the largest IT and business consulting services firms in the world.