Salary
💰 CA$105,000 - CA$125,000 per year
Tech Stack
Cyber SecurityServiceNow
About the role
- Govern the risk management lifecycle, including monitoring findings remediation and assurance programs and reporting metrics to senior leadership
- Conduct risk assessments of IT infrastructure, applications, third parties, and critical processes to identify, assess and report on technology and cybersecurity risks
- Track and manage mitigation plans and ensure timely resolution
- Support the development and maintenance of cybersecurity risk register, KPI monitoring and reporting
- Assist in development, review and maintenance of Technology & Cybersecurity Policies, Standards, and procedures
- Ensure alignment of internal policies with industry frameworks (NIST, ISO, COBIT)
- Support audits and board level reporting including preparing key metrics
- Monitor compliance with external regulatory and internal control requirements
- Support internal and external audits and conduct periodic control testing including design and operating effectiveness
- Support vendor risk assessments, including reviewing responses to questionnaires
- Maintain and enhance governance process through GRC tools (e.g., Archer, ServiceNow GRC, Resolver)
- Support reporting, dashboard creation and automation of risk and compliance processes
Requirements
- Bachelor's Degree in Information Security, Computer Science, Business, Risk Management or a related field
- Relevant certifications such as CRISC, CISA, CISSP are an asset
- 5-8 years of experience in IT risk, cybersecurity risk, audit, compliance or equivalent roles
- Working knowledge of IT governance frameworks and standards (e.g., NIST CSF, ISO 27001, ITIL)
- Familiarity with regulatory and compliance requirements
- Experience with GRC platforms and tools
- Ability to work in a fast-paced environment and stay updated on emerging threats and vulnerabilities
- Proactiveness, natural curiosity, a willingness to learn, adaptability in an evolving environment, and a strong problem-solving mindset
- Ability to work across multiple business units and collaborate across teams
- Fluent communication skills in English are required and bilingual skills in French are an asset