FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Security Risk Management Specialist
WealthsimpleSpecialist in Security Risk Management supporting Wealthsimple's enterprise IT and security risk management program. Collaborating with various teams to manage and mitigate risks in a fast-moving fintech environment.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in IT and security risk management, including risk assessment, compliance frameworks, and risk reporting. Proficient in maintaining risk registers and collaborating with stakeholders to enhance risk mitigation strategies.
Highest-signal resume keywords
IT Risk ManagementRisk AssessmentCompliance FrameworksRisk Register MaintenanceVendor Risk Management
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Risk IdentificationRisk Treatment TrackingRisk ReportingCloud InfrastructureAccess ManagementApplication SecurityNIST CSFISO 27001FAIRVulnerability Management
Soft Skills
Analytical SkillsWritten CommunicationCross-Functional CollaborationSelf-StarterIndependent Management
Tools & Technologies
GRC ToolsRisk Management PlatformsJiraDrata
Certifications & Qualifications
CRISCCISACISSP
Industry Keywords
Financial ServicesFintechPCI DSSSOC 2Third-Party Risk Management
Tech Stack
Tools & technologiesAWSCloud
About the role
Key responsibilities & impact- Support the end-to-end IT and security risk management lifecycle, including risk identification, assessment, treatment tracking, and reporting
- Maintain and continuously improve the enterprise IT/security risk register, ensuring risks are accurately documented, rated, and assigned to appropriate owners
- Perform risk assessments across technology domains (cloud infra, access management, application security) and third-party assessments using the appropriate methodology for each
- Partner with control owners and business stakeholders to evaluate the effectiveness of risk mitigation controls and identify gaps
- Integrate vendor and technology risk findings into the risk register to facilitate tracking and remediation across both IT/Security and Third-Party Risk Management.
- Contribute to the development and maintenance of risk policies, standards, and procedures
- Assist in preparing risk reporting and dashboards for senior leadership and committee-level audiences
- Monitor the threat and vulnerability landscape and help translate emerging risks into actionable insights for the business
- Support security and compliance initiatives, including PCI DSS, SOC 2, and NIST, from a risk lens, ensuring risk findings are integrated into broader compliance activities
- Participate in risk-related work streams tied to new product launches, infrastructure changes, and strategic initiatives
Requirements
What you’ll need- 3–5 years of experience in IT risk management, information security, or a related GRC function, ideally within financial services or fintech
- Solid understanding of IT and security risk frameworks such as NIST CSF, ISO 27001, or FAIR
- Familiarity with key technology risk domains including cloud (AWS preferred), identity and access management and vulnerability management
- Experience conducting third-party and vendor reviews, with knowledge of due diligence review methodology, is an asset
- Experience maintaining risk registers and supporting risk assessment processes
- Working knowledge of compliance frameworks such as SOC 2, PCI DSS, and/or NIST is a strong asset
- Strong analytical and written communication skills, with the ability to translate technical risk findings into clear business language
- Comfortable working cross-functionally with both technical and non-technical stakeholders
- Experience with GRC tools and risk management platforms (e.g.Jira, Drata) is an asset
- Self-starter who can operate independently, manage competing priorities, and drive work to completion
- Relevant certifications are an asset (CRISC, CISA, CISSP, or equivalent)
Benefits
Comp & perks- Top-tier health benefits and life insurance
- Long-term group savings with employer match, through Wealthsimple for Business
- 20 vacation days, 4 wellness days, and unlimited sick and mental health days per year
- 90 days away: work outside Canada for up to 90 days per year
- Employee resource groups, including Rainbow (2SLGBTQ), Women of WS, and Black at WS