Talent.com
Lumentum
IT Governance, Risk & Compliance (GRC) Analyst 1Lumentum • Ahuntsic North, ca
IT Governance, Risk & Compliance (GRC) Analyst 1

IT Governance, Risk & Compliance (GRC) Analyst 1

Lumentum • Ahuntsic North, ca
2 days ago
Job type
  • Full-time
Job description
It's fun to work in a company where people truly BELIEVE in what they're doing!

We're committed to bringing passion and customer focus to the business.

If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!

Lumentum Canada was awarded the 2022 National Capital Region’s Top Employers for the 6th consecutive year and the 2022 Career Directory Canada’s Best Employers for Recent Graduates for the 5th consecutive year.

Position Title: IT Governance, Risk & Compliance (GRC) Analyst 1

Employment Type:

Full-time, Existing vacancy

Location:

Ottawa (On-Site)

About Lumentum At Lumentum, we’re building the tech behind the world’s fastest networks and most advanced systems. Our optical and photonic solutions power everything from AI and cloud computing to data centers, telecom, and advanced manufacturing.

We’re a global team of innovators working where light meets technology, solving big challenges that keep the world connected and moving forward. If shaping the future of connectivity excites you, you’ll fit right in.

Why You’ll Love This Role At Lumentum, we are searching for Canada’s brightest young minds engineers and innovators who want to build the next generation of optical technology. If you are driven by curiosity, eager to solve real-world challenges, and excited about developing groundbreaking optical systems, this is your opportunity.

Join us in designing the future of optical cloud & networking technology our advanced photonic modules power the world’s voice and internet traffic, and we need your expertise to take them to the next level. This is not just another job; this is your chance to define & design what’s next in photonics.

What You’ll Be Doing The IT Governance, Risk & Compliance (GRC) Analyst I supports the organization’s information security governance, risk management, compliance, audit, and third-party risk management (TPRM) programs. This role assists in maintaining security policies, conducting risk assessments, supporting internal and external audits, evaluating third‑party security risks, and ensuring compliance with applicable regulatory and industry frameworks. This role works closely with IT, Security, Legal, Procurement, Privacy, Internal Audit, and business stakeholders to ensure that information systems, processes, and controls align with organizational policies, industry standards, and regulatory requirements.

The ideal candidate is a proactive, detail‑oriented professional with strong analytical and organizational skills and a strong understanding of cybersecurity, governance, risk management, and compliance principles. They communicate effectively with both technical and non-technical stakeholders, demonstrate a collaborative mindset, and are committed to continuous learning and professional growth in cybersecurity governance and risk management.

Governance & Policy Management

Assist with maintaining information security policies, standards, and procedures.

Help keep governance documentation and policy records up to date.

Support governance initiatives and promote security best practices.

Track policy exceptions and follow up on remediation activities.

Risk Management

Assist with IT and cybersecurity risk assessments.

Help identify, document, and track security risks and remediation efforts.

Maintain the IT risk register and support periodic risk reporting.

Work with stakeholders to monitor risk mitigation activities.

Compliance & Regulatory Support

Support compliance activities for frameworks such as ISO 27001, NIST CSF, SOC 2, GDPR, and CMMC.

Assist with compliance assessments, evidence collection, and documentation.

Help track remediation activities to address compliance findings.

Support internal and external compliance reviews and audits.

Third‑Party Risk Management

Assist with vendor security assessments during onboarding and periodic reviews.

Review vendor security documentation, including questionnaires and audit reports.

Track vendor risk findings and remediation activities.

Maintain third‑party risk records on the GRC platform.

Audit Support

Coordinate audit evidence requests and documentation.

Track audit findings and remediation activities.

Help maintain audit readiness across teams.

Program Improvement

Support governance, risk, and compliance initiatives across IT and Security.

Help monitor compliance metrics, risks, and remediation progress.

Assist with identifying process improvements and updating documentation.

Perform other duties in support of the Information Security team.

What We’re Looking For

Bachelor’s degree in information technology, Cybersecurity, Information Systems, Risk Management, Business Administration, or a related field.

Equivalent combination of education and experience may be considered.

Preferred Certifications One or more of the following certifications (or willingness to obtain) is preferred:

CompTIA Security+

Certified Information Systems Auditor (CISA) (or pursuing)

Certified in Risk and Information Systems Control (CRISC) (or pursuing)

Certified Information Security Manager (CISM)

ISO 27001 Lead Implementer or Lead Auditor

Security+ or equivalent cybersecurity certification

Experience

2 – 5 years of internship or entry-level experience in IT governance, risk management, compliance, cybersecurity, IT audit, or related fields.

Experience supporting audits and compliance assessments.

Familiarity with risk assessment methodologies and control frameworks.

Technical Knowledge

Working knowledge of:

Information Security principles

Risk assessment methodologies

Governance and compliance processes

Security frameworks such as NIST CSF, ISO 27001, and SOC 2

Microsoft Office Suite (Excel, Word, PowerPoint) or similar

Preferred experience with GRC platforms such as:

ServiceNow GRC

Archer

OneTrust

AuditBoard

Key Competencies

Analytical and problem-solving skills

Attention to detail and organizational skills

Effective written and verbal communication

Ability to work independently and as part of a team

Basic understanding of risk, compliance, and governance principles

Customer-focused with strong stakeholder relationship skills

Ability to manage multiple priorities in a fast-paced environment

Willingness to learn and continuously develop GRC knowledge

Success Measures

Timely completion of assigned risk assessments, compliance activities, and vendor reviews.

Accurate, organized, and complete documentation and reporting.

Effective support of internal and external audits, including timely evidence collection.

Consistent tracking and follow-up of risk, audit, and compliance remediation activities.

Positive collaboration with business and technical stakeholders.

Demonstrated growth in GRC knowledge, skills, and professional development.

Perks You’ll Love

Flexible time off

Health and wellness benefits (physical and mental)

Tuition reimbursement and career growth support

A workplace built for you: free gym, games room, prayer room

Subsidized meals, free coffee/tea

Employee stock options and incentive plans

A collaborative, innovative, and inclusive culture

Working Conditions

May require coordination across multiple time zones and business units.

Salary Range: $55,000 - $80,000 CAD (flexible).

Final compensation will be determined based on factors such as experience, skills, and qualifications. In line with our commitment to being a great place to work, Lumentum offers competitive total rewards which may include annual bonus, equity, and comprehensive health and welfare benefits.

Join a Team That’s Shaping the Future At Lumentum, we’re more than just a workplace—we’re a launchpad for creativity and innovation. We’re committed to celebrating your unique talents and helping you grow. Our guiding principles—Innovate, Engage, Deliver, Excel, and Win—aren’t just words; they’re the heart of what we do.

Let’s Build a Brighter Future Together! We’re committed to building an inclusive workplace where everyone feels valued and empowered. We welcome applicants from all backgrounds and provide accommodations for individuals with disabilities throughout the hiring process. Your uniqueness makes us stronger, sparks creativity, and drives our success.

Please contact us at talentacquisition@lumentum.com to request accommodation.

Join us—your future starts here!

#J-18808-Ljbffr
Create a job alert for this search

IT Governance, Risk & Compliance (GRC) Analyst 1 • Ahuntsic North, ca

Similar jobs

Senior Analyst, Information Security (GRC) and Crisis Management

PSP’s Private Debt & Credit Investment (PDCI) groupMontreal (administrative region), QC, CA
Full-time

We’re one of Canada’s largest pension investors, with CAD$299.We invest funds for the pension plans of the federal public service, the Canadian Forces, the Royal Canadian Mounted Police and the Res... Show more

 • Promoted

Senior Auditor - IT Governance Specialist

Groupe Dynamite, Inc GarageMount Royal, Montreal (administrative region), CA
Full-time

Shape IT compliance practices with Groupe Dynamite as a Senior IT Auditor.This role is essential for overseeing risk management and governance in a dynamic retail environment.This Senior IT Auditor... Show more

 • Promoted

Director of FinTech Analytics & Risk

JobberMontreal (administrative region), QC, CA
Full-time

Join Jobber as a Director where you will elevate the integration of FinTech analytics and risk management.This key position makes a significant impact on financial product strategies.Reporting to t... Show more

 • Promoted

Interactive Brokers Compliance Analyst Role

Interactive BrokersMontreal (administrative region), QC, CA
Full-time

Become part of Interactive Brokers as a Compliance Analyst in their Montreal office.This hybrid role combines the analysis of financial crimes with proactive client activity monitoring to uphold re... Show more

 • Promoted

Strategic IT Risk & Governance Analyst

ALLTECH CONSULTING SVC INCMontreal
Full-time

A consulting firm based in Canada is seeking an experienced individual to manage technology risk initiatives effectively.The role involves developing strong relationships with stakeholders, monitor... Show more

 • Promoted

Analytical Expert for Digital Regulatory Assurance

PathlionMontreal (administrative region), QC, CA
Full-time

Harness your analytical abilities as a Business Intelligence Analyst for the Government of Alberta’s Digital Regulatory Assurance System.Your role will be instrumental in delivering high-quality da... Show more

 • Promoted

IAM Governance Analyst (SailPoint) Remote

Nexus Systems Group Inc.Montreal (administrative region), QC, CA
Remote
Full-time

A leading technology consulting firm is seeking an IT Security Analyst to support the IAM Governance team.The role involves overseeing access management and ensuring compliance with security measur... Show more

 • Promoted

Portfolio Integration Senior Operational Risk Advisor

Infotree Global SolutionsMontreal (administrative region), QC, CA
Full-time

A leading financial institution in Montreal seeks a Senior Operational Risk Advisor to integrate risk management frameworks and ensure compliance during portfolio integration.Candidates must have 1... Show more

 • Promoted

Analyste Réassurance / Reinsurance Analyst

Reinsurance Group of America, IncorporatedMontreal (administrative region), QC, CA
Full-time

RGA is a purpose-driven organization working to solve today’s challenges through innovation and collaboration.A Fortune 200 Company and listed among its.RGA is a purpose-driven organization working... Show more

 • Promoted

Remote IT Security Risk Analyst: Governance & Risk

Onico SolutionsMontreal (administrative region), QC, CA
Remote
Permanent

A leading IT security firm in Richmond Hill is looking for an IT Security Risk Analyst to support their Information Security Risk Management programs.The role requires expertise in risk assessments... Show more

 • Promoted

Manager, Governance Risk And Compliance - C$84,500 - C$125,500 A Year

KpmgLe Plateau, Canada
Full-time

The Manager will lead Governance, Risk, and Compliance services, overseeing internal controls, SOX 404 programs, and risk assessments.They will manage client engagements, mentor teams, and contribu... Show more

 • Promoted

Senior IT Compliance & Audit Lead — Remote

P2PMontreal (administrative region), QC, CA
Remote
Full-time

A leading crypto firm is seeking a senior IT audit professional.This fully remote role emphasizes managing SOC examinations and establishing audit rigor.Ideal candidates will have over 5 years of e... Show more

 • Promoted

Senior Analyst, Information Security (GRC) and Crisis Management

PSP Investments | Investissements PSPMontreal
Full-time

We’re one of Canada’s largest pension investors, with CAD$299.We invest funds for the pension plans of the federal public service, the Canadian Forces, the Royal Canadian Mounted Police and the Res... Show more

 • Promoted

Technology Risk Management Lead — Drive It Risk - $73,000 - $109,500 A Year

KPMG CanadaCandiac, Canada
Full-time

Overseeing technology risks and ensuring adherence to risk management processes. Show more

 • Promoted

Groupe Dynamite Senior IT Auditor Role

Groupe DynamiteMount Royal, Montreal (administrative region), CA
Full-time

Step into a vital role as a Senior IT Auditor at Groupe Dynamite in Montréal.Focus on comprehensive IT audits to drive compliance and enhance risk management strategies.In this position, you will s... Show more

 • Promoted

Montreal Technology Risk Governance Analyst

Compunnel, Inc.Montreal (administrative region), QC, CA
Temporary

Step into an impactful role as a Technology Risk Metrics Governance Analyst, located in Montreal.This intermediate, fixed-term contract requires onsite presence three days per week and focuses on r... Show more

 • Promoted

Senior Director, IT Compliance and Risk Management

IntactMontreal (administrative region), QC, CA
Full-time

Join Intact as a Senior Director of IT Financial Controls, where you will manage compliance and risk initiatives in a hybrid setting.Use your strategic insight to lead a high-performing team.In thi... Show more

 • Promoted

Analyste des risques et du contrôle de la gestion des actifs IT (IT Asset Management Risk & Con[...]

AstekMontreal
Full-time

Offre d’emploi : Analyste des risques et des contrôles en gestion des actifs TI (IT Asset Management Risk & Control Analyst).Mode de travail : Hybride (1ère journée en présentiel, ensuite en présen... Show more

 • Promoted

Advisor Technology Risk Governance

National Bank of CanadaMontreal
Full-time

A career as a risk Governance Advisor in the Technology, Cybersecurity and Data risk Management team at National Bank means acting as a technology, cybersecurity and data risk governance specialist... Show more

 • Promoted

Remote Information Risk & Security Analyst

DexianMontreal (administrative region), QC, CA
Remote
Full-time

A leading IT services firm is seeking an Information Control Testing Specialist to manage information risk and ensure compliance with security policies.You will work on global initiatives, conduct ... Show more