Talent.com
TEEMA
IT Security Analyst GRCTEEMA • Toronto, Ontario
IT Security Analyst GRC

IT Security Analyst GRC

TEEMA • Toronto, Ontario
Il y a 22 jours
Salaire
50,00 $CA –65,00 $CA par heure
Type de contrat
  • Temps plein
Description de poste


What you will be doing:
Governance & Compliance

  • Support development, maintenance, and periodic review of information security policies, standards, procedures, and guidelines.

  • Coordinate compliance evidence collection for internal audits, external audits, ISO 27001 activities, and other assurance requirements.

  • Maintain accurate governance documentation, control records, exception records, and supporting artifacts in approved repositories or GRC platforms.

  • Assist in preparing security metrics, dashboards, management summaries, and committee materials.

  • Track policy review cycles, control attestations, audit requests, and management action items to closure.

Risk Management

  • Conduct or support information security risk assessments for systems, applications, cloud services, vendors, projects, and business initiatives.

  • Document risks, likelihood, impact, existing controls, treatment plans, residual risk, and ownership in the risk register.

  • Facilitate risk reviews with risk owners, process owners, technology teams, and business stakeholders.

  • Track risk treatment plans, remediation actions, security exceptions, and risk acceptance decisions.

  • Support reporting of risk posture, key risk indicators, and remediation status to management.

Third-Party & Vendor Risk Management

  • Perform vendor security due diligence and third-party risk assessments using questionnaires, interviews, and document reviews.

  • Review SOC 1/SOC 2 reports, ISO certifications, penetration test summaries, policies, and other vendor assurance documentation.

  • Identify vendor control gaps, document risks, and recommend practical mitigation actions.

  • Monitor vendor remediation commitments, reassessment timelines, and security review outcomes.

  • Maintain vendor security assessment records and provide concise reporting to stakeholders.

Audit & Control Assurance

  • Support audit planning, evidence gathering, control walkthroughs, and responses to auditor requests.

  • Perform control testing and compliance reviews against internal security requirements and recognized frameworks.

  • Track audit observations, corrective actions, root cause analysis outcomes, and remediation evidence.

  • Validate closure and effectiveness of corrective actions where assigned.

  • Support continuous monitoring of key information security controls.

Security Awareness & Governance Support

  • Support security awareness, compliance training, and reporting activities.

  • Assist with Information Security Steering Committee or governance meeting materials, minutes, and action tracking.

  • Prepare clear executive summaries, status updates, and decision materials for security leadership.

  • Promote a risk-aware culture by helping business teams understand security obligations in practical terms.


What you must have:
Education

  • Bachelor's degree in Information Security, Cybersecurity, Information Technology, Risk Management, Business Administration, or a related discipline.

  • Equivalent combination of education, training, and professional experience will be considered.

Experience

  • 3–5 years of experience in Information Security, IT Risk, Compliance, Internal Audit, Technology Assurance, or a related governance role.

  • Experience supporting enterprise control frameworks, audit readiness, risk assessments, and compliance programs.

  • Experience conducting vendor security reviews or third-party risk assessments is strongly preferred.

  • Experience working in regulated or global enterprise environments is an asset.

Preferred Certification

  • CISA, CRISC, CISM, CISSP, ISO 27001 Lead Implementer or Lead Auditor, Security+, or equivalent certification.

  • Candidates actively pursuing relevant certifications may also be considered.

Technical Knowledge

  • Information Security Governance ISO/IEC 27001:2022, Security risk assessment methodologies NIST Cybersecurity Framework, SOC 2 reporting

Third-party risk management

  • GRC Tools Any GRC tools and workflow tracking platforms

  • Cloud security concepts, including Microsoft 365 and Azure

Skills & Competencies

  • Strong analytical and critical thinking skills.

  • Excellent written and verbal communication skills, with the ability to prepare concise, business-ready documentation.

  • Ability to translate technical findings, control gaps, and risk scenarios into clear business impact statements.

  • Strong attention to detail and commitment to evidence quality.

  • Effective stakeholder management and ability to coordinate across IT, business, audit, legal, privacy, and vendor teams.

  • Ability to manage competing priorities and meet deadlines in a dynamic enterprise environment.

  • Practical mindset focused on balancing security, risk reduction, and business enablement.


Salary/Rate Range: $50.00 -$65.00/hr Incorporated


Thank you for your interest in this opportunity. If you are selected to move forward in the process, we will contact you directly. If you do not hear from us, we encourage you to continue visiting our website for other roles that may be a good fit.


Créer une alerte emploi pour cette recherche

IT Security Analyst GRC • Toronto, Ontario

Offres similaires

IT Security Analyst - Vulnerability & Risk (Hybrid, 8-Mo Contract)

TekStaff IT SolutionsToronto, ON, CA
Temps plein

A leading IT solutions provider is seeking an IT Security Analyst for an 8-month hybrid contract based in Scarborough, ON.Candidates should have 5-8 years of experience in cybersecurity concepts in... Voir plus

 • Offre sponsorisée

Senior Consultant - Oracle Application Security & GRC

EYToronto
Temps plein

EY is looking for dynamic individuals in the Oracle Applications Security and GRC space for on premise and cloud applications.These professionals will know how to help clients identify, design, imp... Voir plus

 • Offre sponsorisée

It Application Security Manager

Randstad DigitalToronto, Canada
Temps plein

OverviewCandidates MUST be located in Toronto, ON / GTA --- This is a HYBRID Role --- 3 days a week work from officeSeniority Level - 10+ Years (Senior)Required SkillsPeople Management Experience i... Voir plus

 • Offre sponsorisée

Senior Security Analyst

MindlanceToronto, ON, CA
Temps plein

Global Cyber Security team, providing deep technical expertise and advisory support across endpoint and threat surface security platforms.This role focuses on maintaining and strengthening enterpri... Voir plus

 • Offre sponsorisée

Cybersecurity GRC Analyst

Ontario Medical AssociationToronto
Temps plein +1

The Ontario Medical Association (OMA) advocates for and supports doctors, seeking to strengthen their leadership role in caring for patients.We continually seek to be the trusted voice in transform... Voir plus

 • Offre sponsorisée

Bilingual IT Security Analyst - LATAM Risk & DLP (Hybrid)

Infotek Consulting Inc.Toronto, Ontario, Canada
Temps plein

A consulting firm based in Toronto seeks an IT Security Analyst 3 (Bilingual Spanish) to support an enterprise-level information security team.The ideal candidate will have extensive hands-on exper... Voir plus

 • Offre sponsorisée

Security Analyst - Security & Governance Compliance

TVET CollegeRichmond Hill, York region, Canada
Temps plein

Security Analyst - Security & Governance Compliance.The Security Analyst, Security Risk & Compliance will support the management and continuous improvement of Staples Canada’s PCI compliance progra... Voir plus

 • Offre sponsorisée

Security Analyst - Security & Governance Compliance

Staples CanadaRichmond Hill, York region, Canada
Temps plein

Some of what you will do: The Security Analyst, Security Risk & Compliance will support the management and continuous improvement of Staples Canada’s PCI compliance program and broader cybersecurit... Voir plus

 • Offre sponsorisée

Senior GRC Leader — Security & Compliance

AkkodisToronto
Temps plein

A leading technology firm in Toronto is seeking a Senior Manager, Security Governance, Risk, and Compliance (GRC) to lead enterprise-wide security initiatives.This role involves developing GRC stra... Voir plus

 • Offre sponsorisée

Senior It Security Analyst At Erco Worldwide

ERCO WorldwideToronto, Canada
Temps plein

Take the next step in your career as a Senior IT Security Analyst with ERCO Worldwide in a hybrid work environment in Mississauga.Play a key role in safeguarding our digital assets and infrastructu... Voir plus

 • Offre sponsorisée

It Security R&D Specialist / Cyber Threat Intelligence Analyst

Rubicon PathToronto, Canada
Temps plein

IT Security R&D Specialist / Cyber Threat Intelligence AnalystJob Openings IT Security R&D Specialist / Cyber Threat Intelligence AnalystAbout the job IT Security R&D Specialist / Cyber Threat Inte... Voir plus

 • Offre sponsorisée

It Risk & Controls Analyst — Dashboards & Governance

Compunnel, Inc.Toronto, Canada
Temps plein

A leading IT services company is hiring an Information Risk Management Analyst to manage IT risks through evaluation and documentation of controls.The role focuses on risk analysis and reporting, r... Voir plus

 • Offre sponsorisée

IT/Information Security Risk / Security Analyst III (Gen AI OR AI Technologies)

Compunnel Inc.Toronto, Ontario, Canada
Temps plein

The Opportunity: This role is part of the Information Risk team, within the Group Functions (GF) Information Technology First Line of Defense.The team is responsible for performing risk-based infor... Voir plus

 • Offre sponsorisée

IT Compliance Analyst — Drive IT Risk & Controls

The Citco Group LimitedToronto
Temps plein

A global leader in fund services is seeking an IT Compliance Analyst in Toronto.The role involves analyzing and improving IT compliance, coordinating controls testing, and supporting policy reviews... Voir plus

 • Offre sponsorisée

It/Information Security Risk / Security Analyst Iii (Gen Ai Or Ai Technologies)

Compunnel Inc.Toronto, Canada
Temps plein

Overview The Opportunity: This role is part of the Information Risk team, within the Group Functions (GF) Information Technology First Line of Defense.The team is responsible for performing risk-ba... Voir plus

 • Offre sponsorisée

Senior IT Security Analyst at ERCO Worldwide

ERCO WorldwideToronto, ON, CA
Temps plein

Take the next step in your career as a Senior IT Security Analyst with ERCO Worldwide in a hybrid work environment in Mississauga.Play a key role in safeguarding our digital assets and infrastructu... Voir plus

 • Offre sponsorisée

IT Security R&D Specialist / Cyber Threat Intelligence Analyst

Rubicon PathToronto, Ontario, Canada
Temps plein

IT Security R&D Specialist / Cyber Threat Intelligence Analyst.Job Openings IT Security R&D Specialist / Cyber Threat Intelligence Analyst.About the job IT Security R&D Specialist / Cyber Threat In... Voir plus

 • Offre sponsorisée

Director, It Technical Services & Cyber Security Toronto - C$137,009 - C$175,000 A Year

BaycrestNorth York, Canada
Temps plein

Director responsible for IT infrastructure, network, helpdesk, and cybersecurity in a healthcare setting. Voir plus

 • Offre sponsorisée

It Security Leader: Strategy, Policy & Risk | Hybrid - C$84,000 - C$105,000 A Year

Health Solutions ProviderNorth York, Canada
Temps plein

Manage IT security strategy, policy, and risk for a health solutions provider, overseeing the information security program and ensuring compliance. Voir plus

 • Offre sponsorisée

Cybersecurity Analyst - Threat Detection & Dlp (Hybrid)

LanceSoft, Inc.Toronto, Canada
Temps plein

A leading IT service provider is seeking a Mid-Senior IT Security Analyst for a hybrid role in Toronto.The ideal candidate will have over 5 years of experience in network and information security, ... Voir plus