Security GRC Specialist, IT/Security Risk Management
CanadaJob Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
In this role, you'll have the opportunity to
Support the end-to-end IT and security risk management lifecycle, including risk identification, assessment, treatment tracking, and reporting
Maintain and continuously improve the enterprise IT/security risk register, ensuring risks are accurately documented, rated, and assigned to appropriate owners
Perform risk assessments across technology domains (cloud infra, access management, application security) and third-party assessments using the appropriate methodology for each
Partner with control owners and business stakeholders to evaluate the effectiveness of risk mitigation controls and identify gaps
Integrate vendor and technology risk findings into the risk register to facilitate tracking and remediation across both IT/Security and Third-Party Risk Management.
Contribute to the development and maintenance of risk policies, standards, and procedures
Assist in preparing risk reporting and dashboards for senior leadership and committee-level audiences
Monitor the threat and vulnerability landscape and help translate emerging risks into actionable insights for the business
Support security and compliance initiatives, including PCI DSS, SOC 2, and NIST, from a risk lens, ensuring risk findings are integrated into broader compliance activities
Participate in risk-related work streams tied to new product launches, infrastructure changes, and strategic initiatives
What you'll bring
3–5 years of experience in IT risk management, information security, or a related GRC function, ideally within financial services or fintech
Solid understanding of IT and security risk frameworks such as NIST CSF, ISO 27001, or FAIR
Familiarity with key technology risk domains including cloud (AWS preferred), identity and access management and vulnerability management
Experience conducting third-party and vendor reviews, with knowledge of due diligence review methodology, is an asset
Experience maintaining risk registers and supporting risk assessment processes
Working knowledge of compliance frameworks such as SOC 2, PCI DSS, and/or NIST is a strong asset
Strong analytical and written communication skills, with the ability to translate technical risk findings into clear business language
Comfortable working cross-functionally with both technical and non-technical stakeholders
Experience with GRC tools and risk management platforms (e.g.Jira, Drata) is an asset
Self-starter who can operate independently, manage competing priorities, and drive work to completion
Relevant certifications are an asset (CRISC, CISA, CISSP, or equivalent)
How would you rate this job post?
See what other professionals think about this role.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.