Talent.com
Cybersecurity GRC Analyst
Cybersecurity GRC AnalystOntario Medical Association • Hybrid - Toronto, ON, CA
Cybersecurity GRC Analyst

Cybersecurity GRC Analyst

Ontario Medical Association • Hybrid - Toronto, ON, CA
3 hours ago
Job type
  • Permanent
  • Quick Apply
Job description

Are you looking to join one of Greater Toronto’s Top 2026 Employers ?

The Ontario Medical Association (OMA) advocates for and supports doctors, seeking to strengthen their leadership role in caring for patients.

We continually seek to be the trusted voice in transforming Ontario’s health-care system by courageously pursuing best practices, new ideas, solutions, and opportunities to improve.

Job summary This position is responsible for strengthening the Ontario Medical Association’s (OMA) information security governance, risk, and compliance program by operating within the second line of defense to provide oversight, independent validation, and risk-based advisory.

Working within the Technology department and in close collaboration with the Information Security team, enterprise risk management, service providers, and business stakeholders, the role ensures cybersecurity risks are effectively identified, assessed, and managed across the organization.

It supports audit and regulatory readiness while embedding strong security practices and enabling the secure adoption of technology, including emerging areas such as artificial intelligence (AI).

The Cybersecurity GRC Analyst advances the OMA’s strategic vision by fostering cross-functional collaboration, promoting business agility, and influencing stakeholders to safeguard sensitive information.

How you will make a difference Governance, Risk, Compliance (GRC): Maintaining and continuously improving cybersecurity policies, standards, and controls, ensuring alignment with recognized frameworks such as CIS, NIST, and ISO 27001.

Serving as the primary point of contact for cybersecurity-related audits, coordinating activities including evidence collection and remediation tracking.

Overseeing security exception and risk acceptance processes.

Integrating governance for artificial intelligence (AI) and emerging technologies into existing frameworks, including assessing associated organizational risks and providing guidance on regulatory and ethical considerations.

Cyber Risk Governance & Reporting: Maintaining the enterprise cybersecurity risk register, including risk ratings, remediation expectations, and escalation thresholds.

Assessing and documenting risks arising from vulnerabilities, incidents, third-party findings, and control gaps.

Developing and maintaining cybersecurity dashboards, key risk indicators (KRIs), and key performance indicators (KPIs).

Providing regular reporting to senior leadership on emerging cybersecurity risks and overall security posture.

Vulnerability and Application Risk Oversight: Maintaining visibility of vulnerabilities across infrastructure, cloud, and applications, assessing business impact, particularly related to sensitive data exposure.

Tracking remediation progress, escalate overdue critical items, and document residual risk and risk acceptance where remediation is deferred.

Application and data security oversight: Overseeing controls protecting sensitive data, including personal and health information (PII/PHI).

Collaborating on data governance initiatives, including data classification and data loss prevention (DLP), and report on application and data-related risks.

Work closely with the Senior Security Architect to conduct threat modeling for new and existing applications and validate secure coding practices, SAST/DAST scanning, and remediation effectiveness.

Reviewing and reporting on application risks related to identity and access management, API security, data protection, and third-party dependencies.

Identity, Incident & Operational Control Oversight: Overseeing quarterly privileged access and identity certification reviews.

Reviewing major incident reports, validating root cause analysis and corrective actions.

Monitoring recurring control failures and systemic weaknesses across infrastructure, applications, and AI systems. Third-Party Risk & Security Awareness: Conducting third-party cybersecurity risk assessments, including vendors providing AI-enabled services.

Monitoring remediation commitments and risk acceptance documentation.

Facilitating periodic technical and management tabletop exercises.

Supporting phishing simulations and broader cybersecurity awareness initiatives.

Requirements that are important to us University degree in Information Technology, Computer Science, Computer Engineering, or an equivalent Six to nine years of relevant experience in information security and IT, including experience in a GRC-focused role supporting enterprise environments (endpoint and identity security).

Maintains one or more active, industry-recognized certifications (e.g., CISSP, CRISC, CISA, Certified Ethical Hacker, or equivalent) Additional certifications considered an asset include CISM, ISACA Advanced in AI Security Management (AAISM), ITIL, PMP, or an MBA (or equivalent) Experience working with Microsoft Security and Compliance solutions Strong experience in identity governance and conditional access (e.g., Entra ID) Hands-on experience with XDR tools and familiarity with SIEM/SOAR platforms, including automated workflows/playbooks Solid understanding of Zero Trust security principles and modern security architectures Knowledge of MITRE ATT&CK and experience with threat modeling methodologies Exposure to or experience with AI-driven security tools and controls is an asset Experience with API-based integrations and automation (e.g., REST, Microsoft Graph API).

Strong knowledge of cyber risk management, cybersecurity frameworks, and business continuity practices, including BCP and Disaster Recovery (DR) Demonstrated business acumen with strong analytical, problem-solving, and decision-making skills Excellent communication and presentation skills, with the ability to effectively influence and collaborate with both technical and non-technical stakeholders The OMA has moved to a permanent hybrid work environment.

As such, the individual in this position will be required to work a minimum number of days in our Toronto office.

What do we have to offer you?

A work environment whose values are to be respectful, bold, responsive, and transparent in our work and our behaviours A fantastic opportunity to grow with the team and help shape the strategic direction of the OMA, its members and the health-care system An organization that is committed to the equity, diversity and inclusion principles of humility, accountability, collaboration, courage and integrity A commitment to growth and development through paid professional development and continuous in-house learning A friendly and flexible hybrid work environment Competitive total rewards package including a hiring salary range of $92,835 - $98,640 plus pension plan and a bonus program Exceptional group benefits package, including a spending account and a robust wellness program An organization that has been recognized as a Greater Toronto’s Top Employers for six consecutive years.

As a condition of employment, OMA conducts background checks and reference checks for all open positions.

  • Facebook | Twitter | Instagram | YouTube | LinkedIn ­­ We're excited to share this opportunity, which is for a newly created position on our team.

Kindly be advised that our recruitment process does not involve the use of Artificial Intelligence.

The Ontario Medical Association is strongly committed to diversity within its community and welcomes applications from racialized persons/persons of colour, women, Indigenous People of North America, persons with disabilities, LGBTQ2S+ persons, and others who may contribute to the further diversification of ideas.

In accordance with the AODA Act, accommodation will be provided throughout the recruitment process to applicants with disabilities.

  • Powered by JazzHR

Create a job alert for this search

Cybersecurity GRC Analyst • Hybrid - Toronto, ON, CA

Similar jobs

Cybersecurity Analyst

Discovery Silver CorpToronto, ON, CA
Full-time

A growing North America Precious Metals Company, Discovery is committed to combining high-quality gold producing assets in Canada with the world’s largest undeveloped silver deposit in Mexico.Disco...Show more

 • Promoted

Manager, Cybersecurity, Risk

Investment Management Corporation of Ontario (IMCO)Toronto, ON, CA
Full-time

At IMCO, our talent is among the best! IMCO offers a uniquely stimulating and rewarding environment where you can help build and drive organizational transformation, all while seeking to challenge ...Show more

 • Promoted

Senior Cybersecurity Governance & Risk Lead

Société Financière ManuvieToronto, ON, CA
Full-time

Une entreprise de services financiers à Toronto recherche un expert en cybersécurité senior pour renforcer son équipe.Vous serez responsable du développement de frameworks de gouvernance, de la réa...Show more

 • Promoted

Cybersecurity Analyst

Visfuture Inc.Markham, York Region, CA
Full-time +1

IT services and solutions provider, is a forward-looking technology company dedicated to delivering innovative digital solutions.We prioritize the highest standards of security to safeguard our sys...Show more

 • Promoted

Cybersecurity Threat & Compliance Analyst

CAA Club GroupMarkham, York Region, CA
Full-time

A leading automobile association in Canada is seeking an experienced IT Security professional to ensure the security of their systems and data.You will be responsible for monitoring network traffic...Show more

 • Promoted

IT Risk Oversight Analyst Focusing on Cybersecurity and Governance

Haventree BankToronto, ON, CA
Full-time

Lead IT risk management initiatives as a Senior Analyst with a focus on cybersecurity governance.Enhance frameworks, conduct assessments, and collaborate with teams to mitigate operational risks.In...Show more

 • Promoted

Cybersecurity Analyst

Porter Airlines Inc.Toronto, ON, CA
Full-time

We are seeking someone who is passionate about making a big impact in our cybersecurity operations.In this position, you will help drive important initiatives like identity and access management, t...Show more

 • Promoted

Cybersecurity Governance & Risk Analyst - Hybrid

Aviva CanadaMarkham, York Region, CA
Full-time

A leading insurance company seeks a Cybersecurity Governance Analyst to support its Cybersecurity Program.The role involves developing governance and compliance solutions, managing risks, and colla...Show more

 • Promoted

Remote GRC & Cybersecurity Compliance Consultant

MalleumToronto, ON, CA
Remote
Full-time

A leading cybersecurity consultancy in Montreal is seeking a Governance, Risk & Compliance Consultant.The role requires 5-8 years of experience in IT security and risk management, with a deep under...Show more

 • Promoted • New!

Cybersecurity Risk Governance Director

MQ Referrals OnlyToronto, ON, CA
Full-time

Lead innovative governance initiatives as a Director of Cybersecurity Risk.Drive the development and implementation of comprehensive cybersecurity policies while ensuring regulatory compliance and ...Show more

 • Promoted • New!

Cybersecurity Engineer

EdealerToronto, ON, CA
Full-time

E INC is the parent company of EBlock and EDealer, unifying our approach to products, services, and strategies under one Vision and one Mission: to create the best digital auction and retailing pla...Show more

 • Promoted

Strategic GRC & Cybersecurity Advisor

ElastifyToronto, ON, CA
Full-time

A cybersecurity consultancy firm in Toronto is seeking a GRC & Cybersecurity Consultant to help clients strengthen their security posture and meet regulatory obligations.This role combines strategi...Show more

 • Promoted

Remote Cybersecurity Advisor - Enterprise Risk & GRC

NES FircroftToronto, ON, CA
Remote
Full-time

A leading global technical recruitment company is seeking a Cybersecurity Advisor to provide expert advisory services across the enterprise in Calgary, AB.This role entails working closely with IS ...Show more

 • Promoted • New!

Manager, Cybersecurity, Risk

Investment Management Corporation of OntarioToronto, ON, CA
Full-time

Manager, Cybersecurity, Risk page is loaded## Manager, Cybersecurity, Risklocations: Toronto - 16 York Sttime type: Full timeposted on: Posted Yesterdayjob requisition id: R26-58At IMCO, our talent...Show more

 • Promoted

Lead Cybersecurity Analyst Focused on Threat Response and Policy

DialogueToronto, ON, CA
Full-time

Elevate your cybersecurity career as a Staff Cybersecurity Analyst leading threat detection and incident management.Shape security culture, policies, and strategies in a hybrid working environment....Show more

 • Promoted

Senior Cybersecurity Governance & Risk Lead

Manulife FinancialToronto, ON, CA
Full-time

A leading financial services provider is seeking a Senior Cybersecurity Specialist in Toronto to enhance its cybersecurity posture.The role involves developing governance frameworks, conducting vul...Show more

 • Promoted

Cyber GRC Analyst: Risk, Compliance & Incident Response

Warner Music GroupToronto, ON, CA
Full-time

A global music organization in Toronto is seeking a Cybersecurity Risk Manager to lead GRC functions and coordinate cybersecurity initiatives.This role involves performing risk assessments, managin...Show more

 • Promoted

Senior GRC Architect: Cloud Risk & Compliance Leader

KPMG LLP CanadaToronto, ON, CA
Full-time

A leading professional services firm is seeking a Manager, GRC in Toronto to drive IT audit and risk advisory engagements.The role involves defining enterprise GRC architecture, implementing cloud ...Show more