Search jobs > Toronto, ON > Analyst compliance

Senior Analyst, Governance, Risk & Compliance

Ladders
Toronto, ON
$122K-$158.1K a year (estimated)
Full-time

Purpose of the Job

In this role, you will play a pivotal part in ensuring the maintenance of governance and compliance documents, managing our control library, and supporting various audit and assessment activities.

This role requires a subject matter expertise in Cyber Risk & Compliance management as this role will be responsible for building processes and capabilities that align with organization structure and culture while ensuring sufficient maturity of Cyber Risk management practices.

Your primary responsibilities will include Cyber Risk exceptions management and risk appetite and tolerance limit monitoring and reporting, facilitating security exceptions and risk acceptance process, operationalizing EQB's Cyber Control Framework management processes, aiding in internal and external audits, and supporting the due diligence process for third-party onboarding.

Additionally, you will contribute to annual PCI-DSS activities and play a key role in the tracking and reporting of team metrics.

Main Activities :

  • Support the maintenance of governance and compliance documents.
  • Manage the control library to ensure up-to-date and accurate information.
  • Perform Cyber Risk quantification and analysis to drive risk-informed business decision making.
  • Develop and apply statistical and quantitative models to assess cyber threats' likelihood and potential financial impact.
  • Contribute to developing risk mitigation strategies by identifying and prioritizing high-risk areas.
  • Support the security exception process by documenting, tracking, monitoring, and reporting on exceptions, with integrated quantitative analysis.
  • Assist in internal and external audits by gathering and organizing evidence.
  • Follow up on audit activities to ensure timely resolution.
  • Support the due diligence process for third-party onboarding activities.
  • Manage security risks for assigned portfolio to ensure that action / mitigation plans are defined and actioned in-time.
  • Escalate outstanding risks as required.
  • Assist in running annual PCI-DSS assessment activities.
  • Play a vital role in tracking and reporting team metrics.
  • Actively contribute to the continual improvement of security governance, risk, and compliance.
  • Participate in activities to identify improvements, including internal measurement practices, security practice reviews, and internal / external audits.
  • Stay current on the cyber security threat landscape, including the latest attacker tactics, techniques and procedures, and the controls that may serve as effective countermeasures.

Knowledge / Skill Requirements :

  • A college diploma or university degree is required. Higher accreditation (e.g. Bachelor of Computer Science) is preferred.
  • Minimum of 5-7 years of relevant work experience.
  • Hands on experience in supporting internal and external audits.
  • Relevant certifications in governance, risk, and compliance are preferred.
  • The following certifications are preferred : Open FAIR certification, CCSP, CCSK, CISM, CISSP, or CRISC.
  • Solid understanding and experience with PCI DSS.
  • Solid understanding of security threats and the security practices that are employed to defend against those threats.
  • Experience working in a banking or financial services environment is an asset.
  • Familiarity with security metrics and quantitative analysis tools (e.g. FAIR, Monte Carlo Analysis).

Communication Skills :

  • Excellent interpersonal skills, with proven track record of developing relationships and communicating conceptual information effectively to individuals unfamiliar with subject material.
  • Strong organizational skills : demonstrated ability to manage time and adhere to tight deadlines.

Accountability :

  • Reporting to and responsible for supporting the Cyber, Governance and Compliance manager and indirectly to the Chief Information Security Officer.
  • Makes decisions independently and contributes to the overall long-term performance of the security team.
  • Accountable for the day-to-day operations and performance within the Cyber Governance, Risk and Compliance domain.
  • Prioritize multiple competing priorities within restricted time constraints.
  • Decisions made by the incumbent impact on the security of the bank.
  • The incumbent will be required to work with suppliers who provide solutions, services and / or support to the bank.
  • 30+ days ago
Related jobs
Promoted
S I Systems
Toronto, Ontario

Reporting to the Senior Manager of the ETC – Compliance Testing Team, the Senior Compliance Testing Analyst will focus on providing support for the testing and monitoring program. Senior Compliance Testing Analyst - 52786. The Senior Compliance Testing Analyst models strong ethics, integrity, and le...

Promoted
ICONMA
Toronto, Ontario

Reporting to the Senior Manager of the ETC – Compliance Testing Team, the Senior Compliance Testing Analyst will focus on providing support for the testing and monitoring program. Senior Compliance Testing Analyst. The Senior Compliance Testing Analyst models strong ethics, integrity, and leadership...

Jobber
Canada
Remote

This role is ideal for entry-to-intermediate level candidates in the security, governance, risk and compliance space. Our Security Analyst, GRC, focuses on the governance side of security and is not a technical security operations position requiring specific technical certifications or experience. D...

KPMG
Canada, Canada

Our Governance, Risk and Compliance (GRCS) professionals provide a range of assurance and advisory services to enhance the efficiency and effectiveness of internal audit functions, enterprise risk management programs, third-party relationships, regulatory compliance, governance and sustainability in...

Raise
Toronto, Ontario

Senior Analyst, IT Risk & Control. We are looking for Senior Analyst, IT Risk & Control. We at Raise are hiring a Senior Analyst, IT Risk & Control for one of our top clients. Internal Risk Consultation: support TI Infrastructure teams with risk management. ...

Deloitte
Toronto, Ontario

The salary range for the Analyst position is $62,000 - $92,000 and $75,000 - $113,000 for the Senior Associate position, and individuals may be eligible to participate in our bonus program. Develop/validate/review Credit Risk models (e. Minimum 1-2 years of relevant experience spent within a credit ...

Royal Bank of Canada
Toronto, Ontario

Work collaboratively with the 2nd line GRM team to imbed understanding of the security risk profile and risk appetite into strategic decisioning with Senior Leadership at RBC; challenge executive decisioning that contradicts the risk profile and risk appetite. This involves supporting the 2nd Line o...

CB Canada
Toronto, Ontario

Our client in Toronto, is seeking a Senior Analyst, Risk Advisory to join their team. The engagements range from process optimization, data analytics and visualization, risk and controls assessments, assurance, and special high-priority consulting projects as requested by Senior Management and the B...

Royal Bank of Canada
Toronto, Ontario

As a Senior IT Risk Analyst, you will be a member of our Access Control Group (ACG) team supporting RBC's global Wealth Management (WM) and Investor Services (IS) businesses. Do you thrive at the intersection of business, technology, and risk management, and embrace new challenges? Are you passionat...

Deloitte
Toronto, Ontario

Minimum 6 years (Manager) / 8 years (Senior Manager) of professional experience in data and AI, with a primary focus on responsible AI, data & AI risk management, and regulatory compliance. We are seeking an experienced professional with an experience in Data and AI, with a strong focus on respo...