Back to Jobs
Data Science & Analytics Just now

Security GRC Specialist, IT/Security Risk Management

CanadaCanada
Full-time
Not Disclosed
Mid-Level

Job Description

Key Skills Required

Master these to land this role

ComplianceCloud SecurityGRCRisk ManagementVulnerability ManagementIT Security

Want to know if you're a match for this job?

Calculate My Match Score

In this role, you'll have the opportunity to

  • Support the end-to-end IT and security risk management lifecycle, including risk identification, assessment, treatment tracking, and reporting

  • Maintain and continuously improve the enterprise IT/security risk register, ensuring risks are accurately documented, rated, and assigned to appropriate owners

  • Perform risk assessments across technology domains (cloud infra, access management, application security) and third-party assessments using the appropriate methodology for each

  • Partner with control owners and business stakeholders to evaluate the effectiveness of risk mitigation controls and identify gaps

  • Integrate vendor and technology risk findings into the risk register to facilitate tracking and remediation across both IT/Security and Third-Party Risk Management.

  • Contribute to the development and maintenance of risk policies, standards, and procedures

  • Assist in preparing risk reporting and dashboards for senior leadership and committee-level audiences

  • Monitor the threat and vulnerability landscape and help translate emerging risks into actionable insights for the business

  • Support security and compliance initiatives, including PCI DSS, SOC 2, and NIST, from a risk lens, ensuring risk findings are integrated into broader compliance activities

  • Participate in risk-related work streams tied to new product launches, infrastructure changes, and strategic initiatives

What you'll bring

  • 3–5 years of experience in IT risk management, information security, or a related GRC function, ideally within financial services or fintech

  • Solid understanding of IT and security risk frameworks such as NIST CSF, ISO 27001, or FAIR

  • Familiarity with key technology risk domains including cloud (AWS preferred), identity and access management and vulnerability management

  • Experience conducting third-party and vendor reviews, with knowledge of due diligence review methodology, is an asset

  • Experience maintaining risk registers and supporting risk assessment processes

  • Working knowledge of compliance frameworks such as SOC 2, PCI DSS, and/or NIST is a strong asset

  • Strong analytical and written communication skills, with the ability to translate technical risk findings into clear business language

  • Comfortable working cross-functionally with both technical and non-technical stakeholders

  • Experience with GRC tools and risk management platforms (e.g.Jira, Drata) is an asset

  • Self-starter who can operate independently, manage competing priorities, and drive work to completion

  • Relevant certifications are an asset (CRISC, CISA, CISSP, or equivalent)

How would you rate this job post?

See what other professionals think about this role.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More