Talent.com
CoreFactor Inc.
Cybersecurity GRC Consultant (Contract)CoreFactor Inc. • Mississauga (Lisgar / Meadowvale), ON, ca
Cybersecurity GRC Consultant (Contract)

Cybersecurity GRC Consultant (Contract)

CoreFactor Inc. • Mississauga (Lisgar / Meadowvale), ON, ca
16 hours ago
Job type
  • Full-time
Job description

CoreFactor is searching for Cybersecurity GRC Consultant on a contract basis for a client in the GTA.


This position is hybrid and will require the successful incumbent to go into the Mississauga office four (4) times per week.


The Opportunity:

As our Governance, Risk Management, and Compliance (GRC) Analyst, you will report to the Director of Security Strategy and Architecture to help us build and grow our cyber practice from the ground up. This is a rare opportunity to join us on our journey on the forefront of cybersecurity, grow with us, and shape the future of the organization.

This role requires a motivated self-starter, someone who has strong analytical and problem-solving skills, a deep understanding of risk and compliance management principles, excellent communication and report-writing abilities, and foundational knowledge of industry-specific regulations, standards, and frameworks. You are passionate about security and compliance and believe in due diligence.

Snapshot of a Day-in-the-Life:

  • Work with leaders (such as CIO, CISO, GRC Manager, Infrastructure Managers) and assist them in strengthening the organization-wide Cybersecurity program
  • Work with stakeholders and implement Governance Risk and Compliance (GRC) related initiatives aligned with the organizations vision and strategy
  • Conduct risk assessments as per requirements within industry leading standards and frameworks (such as NIST CSF), identify gaps and assist in coordination of activities among other information security functions to resolve the gaps
  • Be the primary point of contact for external assessments, audits and participate in interviews, walkthroughs and requirements gathering process
  • Lead internal assessments (GRC) and audits, and conduct interviews, documentation review and controls assessment
  • Assist in implementation of requirements defined within Cybersecurity related policies and procedures throughout the organization
  • Collaborate with other information security functions (such as IAM, PAM, Resilience etc.) and collect Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs), and periodically report it to GRC Manager
  • Prepare information security reports for senior leaders (such as CIO, CISO and the Cybersecurity Committee)
  • Assist in Implementation of cyber security controls and management of the Cyber Controls Framework (NIST CSF)
  • Assist in development of cyber security related training and awareness initiatives
  • Keep track of risks within the organization. Ensure risks are appropriately addressed by risk owners within the determined timeline.
  • Work with required teams to collect and prepare audit data for C3 audits.

What You’ll Bring:

  • Understand Information Security Concepts (such as Risk Management, Governance, Data Protection, Incident Management etc.)
  • Knowledge of information security standards and regulations such as NIST CSF, NIST SP Series (800-53, 800-82, 800-207), NIST RMF (Risk Management Framework), C3, and CIS Critical Security Controls framework
  • Quick learner, strategic thinker, strong team player with ability to multi-task
  • Organize, prioritize, and track project activities on a day-to-day basis
  • Identify and communicate project risks to managers and IT leads
  • Analytical and problem-solving mindset
  • Clear verbal/written communication
  • Proficiency in Excel, PowerPoint
  • Risk assessment and risk analysis
  • Risk register management and remediation tracking
  • Control design and operating effectiveness assessment
  • Audit evidence review and audit readiness
  • Third-party risk management and vendor due diligence
  • Policy, standard, and procedure interpretation
  • Security control framework mapping, including NIST CSF, CIS Controls, ISO 27001, SOC 2, and NIST 800-53
  • KRI/KPI development, tracking, and reporting
  • Executive reporting and dashboard preparation
  • Exception, issue, and risk acceptance management
  • Data classification and data protection risk analysis
  • Cloud, IAM, infrastructure, and resilience risk assessment
  • Strong documentation and report-writing skills
  • Stakeholder management and cross-functional coordination
  • GRC tool proficiency, such as ServiceNow GRC/IRM, Archer, OneTrust, AuditBoard, MetricStream, or similar platforms
  • People
  • Ability to work collaboratively with members across other functions (such as Infrastructure, Cloud, Data etc.) to collaboratively solve problems and build strong processes
  • Track risks assigned to members within other functions (such as Infrastructure, Cloud, Data etc.)


Requirements

  • A minimum of 3 years of security related experience within GRC function
  • A minimum of 7 years of security related experience in total within various information security functions (GRC, MITRE ATT&CK, Resilience etc.)
  • Experience in conducting risk assessments as per requirements in industry leading standards and frameworks (such as NIST CSF) is a must.
  • Experience in conducting ITGC (IT General Controls) controls testing (Preferred)
  • Experience in Data Protection, Third-party Risk Management and Resilience (Preferred)
  • Prior experience in working in Consumer or Food & Beverage Industry (Preferred)
  • Risk register ownership and lifecycle management — documenting risks, assigning owners, tracking remediation, validating closure, and preparing risk status updates.
  • Control testing and evidence review — assessing control design and operating effectiveness, reviewing audit evidence, and identifying gaps.
  • Third-party/vendor risk assessments — reviewing security questionnaires, SOC 2 reports, ISO 27001 certificates, penetration test summaries, and remediation plans.
  • Risk reporting for leadership — preparing executive-level dashboards, KRIs/KPIs, risk summaries, and remediation progress updates.
  • Framework mapping — mapping risks and controls to NIST CSF, CIS Controls, ISO 27001, SOC 2, or internal control frameworks.
  • Exception and risk acceptance management — documenting exceptions, residual risk, compensating controls, expiry dates, and approval workflows.
  • Experience with GRC tools — such as Archer, ServiceNow GRC/IRM, OneTrust, AuditBoard, MetricStream, or similar platforms.
  • Data classification and privacy/security risk — evaluating how sensitive data is collected, stored, transmitted, retained, and protected.
  • Cloud and infrastructure risk assessments — assessing risks related to cloud platforms, IAM, network security, endpoint controls, backup/recovery, and resilience.
  • Audit readiness and compliance support — preparing teams for audits, collecting evidence, coordinating responses, and tracking findings to closure.

Education

  • Bachelor's degree in Information Technology, Engineering or Computer Science (Preferred)
  • Professional certifications in Information Security such as CISSP, CISM, CRISC, CC or equivalent (Preferred)


Create a job alert for this search

Cybersecurity GRC Consultant (Contract) • Mississauga (Lisgar / Meadowvale), ON, ca

Similar jobs

Principal Telecom Digital Consultant

Infosysmississauga, peel region, Canada
Full-time

In this role, you will anchor the engagement effort for assignments, from business process consulting and problem definition to solution design, development, and deployment.You will be pivotal to p... Show more

 • Promoted

Remote Oracle Financials Consultant - FAR Compliance

LeverageTek Staffing SolutionsMississauga, Peel Region, CA
Remote
Full-time

A staffing solutions company is seeking a Senior Oracle Functional Consultant for a 6-month remote contract.The role focuses on aligning Oracle implementation with US Government FAR compliance and ... Show more

 • Promoted

Senior Grc Security Analyst: Risk & Compliance Leader - C$105,000 - C$125,000 A Year

Metro Supply ChainMississauga, Canada
Full-time

A logistics company in Mississauga seeks a Senior Cybersecurity Analyst overseeing governance, risk management, and compliance aspects of the security program.The role involves developing policies,... Show more

 • Promoted

Senior Cyber Security Architect - Enterprise Risk & TRA

ResonaiteMississauga, Peel Region, CA
Full-time

A cybersecurity consulting firm is seeking a Senior Cyber Security Architect in Mississauga to provide enterprise-level security architecture leadership.The ideal candidate will possess 8-12 years ... Show more

 • Promoted

Director of FinTech Analytics & Risk

JobberMississauga, Peel Region, CA
Full-time

Join Jobber as a Director where you will elevate the integration of FinTech analytics and risk management.This key position makes a significant impact on financial product strategies.Reporting to t... Show more

 • Promoted

Remote GRC & Cybersecurity Compliance Consultant

MalleumMississauga, Peel Region, CA
Remote
Full-time

A leading cybersecurity consultancy in Montreal is seeking a Governance, Risk & Compliance Consultant.The role requires 5-8 years of experience in IT security and risk management, with a deep under... Show more

 • Promoted

Senior DFIR Consultant for Complex Cybersecurity Investigations

New Value SolutionsMississauga, Peel region, Canada
Full-time

Become a pivotal force in cybersecurity as a Senior DFIR Consultant.Lead forensic investigations and incident responses in a contract capacity across enterprise systems.This senior role requires yo... Show more

 • Promoted

Security GRC Specialist — Remote-Ready & Metrics-Driven

Tecsys Inc.Mississauga, Peel Region, CA
Remote
Full-time

Join a forward-thinking company as a Security Governance, Risk, and Compliance Specialist, where your expertise will be pivotal in enhancing security measures and compliance frameworks.In this role... Show more

 • Promoted

Remote Change Lead — Cybersecurity Transformation

ARAGA SOLUTIONSMississauga, Peel Region, CA
Remote
Full-time

A technology solutions provider is seeking a Change Manager to develop and implement a change management strategy focused on cybersecurity modernization.The role involves stakeholder engagement, st... Show more

 • Promoted

Remote Cloud Security Architect: DevSecOps & Risk Leader

Intuitive.aiMississauga, Peel Region, CA
Remote
Full-time

A leading cybersecurity solutions company is seeking a Cybersecurity Specialist (GCP) to enhance their Cybersecurity Program.The role involves developing comprehensive security strategies in cloud ... Show more

 • Promoted

Senior OT Cybersecurity Leader — ICS Strategy & Risk

BBA ConsultantsVaughan
Full-time

A leading consulting engineering firm in Vaughan is seeking a Senior OT Cybersecurity Leader to enhance its industrial control systems cybersecurity team.This role involves managing client relation... Show more

 • Promoted

GCP Solutions Delivery Lead at BDO

BDO Canadaoakville, on, Canada
Full-time

Become a pivotal figure in BDO’s GCP practice as a Solutions Delivery Lead, enhancing client relationships and spearheading cloud innovation.This strategic role requires technical proficiency and l... Show more

 • Promoted

Remote Implementation Consultant - Compliance (FinTech ICM)

ConfluenceMississauga, Peel Region, CA
Remote
Full-time

A leading technology firm is seeking an experienced Implementation Consultant - Compliance to support clients in the FinTech space.This role focuses on Investment Compliance Monitoring and involves... Show more

 • Promoted

Cybersecurity Consultant – Azure & AI Governance

ConcentrixMississauga, Peel Region, CA
Full-time

Cybersecurity Consultant – Azure & AI Governance.Microsoft ecosystem to advise enterprise customers and lead strategic AI security initiatives.Lead customer workshops to assess AI readiness, focusi... Show more

 • Promoted

Lead DevOps Innovations in a Remote Crypto Trading Team

NewtonMississauga, Peel Region, CA
Remote
Full-time

Join a progressive team dedicated to reshaping crypto trading in Canada.As a DevOps Engineer, you’ll enhance system deployments and ensure robust AWS infrastructure from anywhere in Canada.This vit... Show more

 • Promoted

Principal Consultant Cybersecurity Zero Trust Advisory

Palo Alto NetworksMississauga, Peel Region, CA
Full-time

Join Palo Alto Networks as a Principal Consultant in Zero Trust Advisory.Your expertise will guide clients through comprehensive cybersecurity transformations with a focus on Zero Trust architectur... Show more

 • Promoted

Senior Solutions Specialist, Cybersecurity

Bell CanadaMississauga
Full-time

Senior Solutions Specialist, Cybersecurity.At Bell, we are dedicated to providing advanced digital solutions and secure connectivity for businesses across Canada.We are looking for an experienced S... Show more

 • Promoted

Insurance Broker with Builder's Risk Focus

TEEMA Solutions GroupOakville, ON, CA
Full-time

Drive your insurance career forward as a Broker at Ai Insurance Organization specializing in Builder's Risk.Enjoy remote work flexibility while serving the construction sector.We are looking for a ... Show more

 • Promoted

Oracle ERP Cloud Transformation Consultant

ArcLight ConsultingMississauga, Peel Region, CA
Full-time

A dynamic consulting firm in Canada is seeking an Oracle ERP Cloud Consultant.The role demands a minimum of 4 years of implementation experience with Oracle ERP Cloud Financials, along with knowled... Show more

 • Promoted

Director of IT Security for Directive Consulting

DirectiveMississauga, Peel Region, CA
Full-time

Enhance IT security as Director at Directive Consulting.Protect client data and manage risks within a fully remote framework.In this leadership role, you'll report to the Head of Finance and define... Show more