Talent.com
TEEMA
IT Security Analyst GRCTEEMA • Toronto, Ontario
IT Security Analyst GRC

IT Security Analyst GRC

TEEMA • Toronto, Ontario
11 hours ago
Salary
CA$50.00–CA$65.00 hourly
Job type
  • Full-time
Job description


What you will be doing:
Governance & Compliance

  • Support development, maintenance, and periodic review of information security policies, standards, procedures, and guidelines.

  • Coordinate compliance evidence collection for internal audits, external audits, ISO 27001 activities, and other assurance requirements.

  • Maintain accurate governance documentation, control records, exception records, and supporting artifacts in approved repositories or GRC platforms.

  • Assist in preparing security metrics, dashboards, management summaries, and committee materials.

  • Track policy review cycles, control attestations, audit requests, and management action items to closure.

Risk Management

  • Conduct or support information security risk assessments for systems, applications, cloud services, vendors, projects, and business initiatives.

  • Document risks, likelihood, impact, existing controls, treatment plans, residual risk, and ownership in the risk register.

  • Facilitate risk reviews with risk owners, process owners, technology teams, and business stakeholders.

  • Track risk treatment plans, remediation actions, security exceptions, and risk acceptance decisions.

  • Support reporting of risk posture, key risk indicators, and remediation status to management.

Third-Party & Vendor Risk Management

  • Perform vendor security due diligence and third-party risk assessments using questionnaires, interviews, and document reviews.

  • Review SOC 1/SOC 2 reports, ISO certifications, penetration test summaries, policies, and other vendor assurance documentation.

  • Identify vendor control gaps, document risks, and recommend practical mitigation actions.

  • Monitor vendor remediation commitments, reassessment timelines, and security review outcomes.

  • Maintain vendor security assessment records and provide concise reporting to stakeholders.

Audit & Control Assurance

  • Support audit planning, evidence gathering, control walkthroughs, and responses to auditor requests.

  • Perform control testing and compliance reviews against internal security requirements and recognized frameworks.

  • Track audit observations, corrective actions, root cause analysis outcomes, and remediation evidence.

  • Validate closure and effectiveness of corrective actions where assigned.

  • Support continuous monitoring of key information security controls.

Security Awareness & Governance Support

  • Support security awareness, compliance training, and reporting activities.

  • Assist with Information Security Steering Committee or governance meeting materials, minutes, and action tracking.

  • Prepare clear executive summaries, status updates, and decision materials for security leadership.

  • Promote a risk-aware culture by helping business teams understand security obligations in practical terms.


What you must have:
Education

  • Bachelor's degree in Information Security, Cybersecurity, Information Technology, Risk Management, Business Administration, or a related discipline.

  • Equivalent combination of education, training, and professional experience will be considered.

Experience

  • 3–5 years of experience in Information Security, IT Risk, Compliance, Internal Audit, Technology Assurance, or a related governance role.

  • Experience supporting enterprise control frameworks, audit readiness, risk assessments, and compliance programs.

  • Experience conducting vendor security reviews or third-party risk assessments is strongly preferred.

  • Experience working in regulated or global enterprise environments is an asset.

Preferred Certification

  • CISA, CRISC, CISM, CISSP, ISO 27001 Lead Implementer or Lead Auditor, Security+, or equivalent certification.

  • Candidates actively pursuing relevant certifications may also be considered.

Technical Knowledge

  • Information Security Governance ISO/IEC 27001:2022, Security risk assessment methodologies NIST Cybersecurity Framework, SOC 2 reporting

Third-party risk management

  • GRC Tools Any GRC tools and workflow tracking platforms

  • Cloud security concepts, including Microsoft 365 and Azure

Skills & Competencies

  • Strong analytical and critical thinking skills.

  • Excellent written and verbal communication skills, with the ability to prepare concise, business-ready documentation.

  • Ability to translate technical findings, control gaps, and risk scenarios into clear business impact statements.

  • Strong attention to detail and commitment to evidence quality.

  • Effective stakeholder management and ability to coordinate across IT, business, audit, legal, privacy, and vendor teams.

  • Ability to manage competing priorities and meet deadlines in a dynamic enterprise environment.

  • Practical mindset focused on balancing security, risk reduction, and business enablement.


Salary/Rate Range: $50.00 -$65.00/hr Incorporated


Thank you for your interest in this opportunity. If you are selected to move forward in the process, we will contact you directly. If you do not hear from us, we encourage you to continue visiting our website for other roles that may be a good fit.


Create a job alert for this search

IT Security Analyst GRC • Toronto, Ontario

Similar jobs

IT Security Analyst - Vulnerability & Risk (Hybrid, 8-Mo Contract)

TekStaff IT SolutionsToronto, ON, CA
Full-time

A leading IT solutions provider is seeking an IT Security Analyst for an 8-month hybrid contract based in Scarborough, ON.Candidates should have 5-8 years of experience in cybersecurity concepts in... Show more

 • Promoted

Senior Consultant - Oracle Application Security & GRC

EYToronto
Full-time

EY is looking for dynamic individuals in the Oracle Applications Security and GRC space for on premise and cloud applications.These professionals will know how to help clients identify, design, imp... Show more

 • Promoted

Senior Cyber Security Analyst - Grc - C$105,000 - C$125,000 A Year

Metro Supply ChainEast York, Canada
Full-time

Senior Cyber Security Analyst for GRC, responsible for implementing and maintaining information security governance programs.Requires 5+ years of experience, proficiency in security domains, and st... Show more

 • Promoted • New!

Remote Senior Grc Consultant: Governance & Security Risk - C$86,000 - C$136,000 A Year - Remote

A technology solutions firmNorth York, Canada
Remote
Full-time

Seeking an experienced GRC Consultant to lead cybersecurity audits and assessments for clients, enhancing their security posture.Requires over 10 years of IT/security experience. Show more

 • Promoted

Cybersecurity GRC Analyst

Ontario Medical AssociationToronto
Full-time +1

The Ontario Medical Association (OMA) advocates for and supports doctors, seeking to strengthen their leadership role in caring for patients.We continually seek to be the trusted voice in transform... Show more

 • Promoted

Bilingual IT Security Analyst - LATAM Risk & DLP (Hybrid)

Infotek Consulting Inc.Toronto, Ontario, Canada
Full-time

A consulting firm based in Toronto seeks an IT Security Analyst 3 (Bilingual Spanish) to support an enterprise-level information security team.The ideal candidate will have extensive hands-on exper... Show more

 • Promoted

Senior Infrastructure Security Analyst: Enterprise Security & Risk - C$95,000 - C$110,000 A Year

Global Financial Services CompanyToronto County, Canada
Full-time

Seeking a Senior Infrastructure Security Analyst to enhance enterprise security and protect systems and data in Toronto. Show more

 • Promoted

Security Analyst - Security & Governance Compliance

TVET CollegeRichmond Hill, York region, Canada
Full-time

Security Analyst - Security & Governance Compliance.The Security Analyst, Security Risk & Compliance will support the management and continuous improvement of Staples Canada’s PCI compliance progra... Show more

 • Promoted

Senior Infrastructure Security Analyst: Enterprise Security & Risk - C$95,000 - C$110,000 A Year

Global financial services companyToronto County, Canada
Full-time

Senior Infrastructure Security Analyst needed to enhance enterprise security, design, and implement measures to protect systems and data in a financial services company. Show more

 • Promoted

Infrastructure Security Analyst - C$92,712 - C$109,056 A Year

City of North VancouverToronto, Canada
Full-time

Seeking an Infrastructure Security Analyst to support daily security operations, detect and mitigate cyber threats, analyze suspicious activity, respond to incidents, and provide security awareness... Show more

 • Promoted

IT/Information Security Risk / Security Analyst III (Gen AI OR AI Technologies)

Compunnel Inc.Toronto, Ontario, Canada
Full-time

The Opportunity: This role is part of the Information Risk team, within the Group Functions (GF) Information Technology First Line of Defense.The team is responsible for performing risk-based infor... Show more

 • Promoted

Senior Grc Security Analyst: Risk & Compliance Leader - C$105,000 - C$125,000 A Year

Logistics CompanyToronto, Canada
Full-time

A logistics company in Mississauga seeks a Senior Cybersecurity Analyst overseeing governance, risk management, and compliance aspects of the security program.The role involves developing policies,... Show more

 • Promoted

Senior IT Security Analyst at ERCO Worldwide

ERCO WorldwideToronto, ON, CA
Full-time

Take the next step in your career as a Senior IT Security Analyst with ERCO Worldwide in a hybrid work environment in Mississauga.Play a key role in safeguarding our digital assets and infrastructu... Show more

 • Promoted

IT Security R&D Specialist / Cyber Threat Intelligence Analyst

Rubicon PathToronto, Ontario, Canada
Full-time

IT Security R&D Specialist / Cyber Threat Intelligence Analyst.Job Openings IT Security R&D Specialist / Cyber Threat Intelligence Analyst.About the job IT Security R&D Specialist / Cyber Threat In... Show more

 • Promoted

It Grc Leader (Hybrid) – Icfr, Pci-Dss, Nist Csf - $125,000 - $135,000 A Year

Leading Retail CompanyMarkham, Canada
Full-time

IT Governance, Risk, and Compliance Manager sought for a retail company to oversee controls and frameworks like ICFR and PCI-DSS.Requires 8+ years of experience. Show more

 • Promoted

Director, It Technical Services & Cyber Security Toronto - C$137,009 - C$175,000 A Year

BaycrestNorth York, Canada
Full-time

Director responsible for IT infrastructure, network, helpdesk, and cybersecurity in a healthcare setting. Show more

 • Promoted

Senior Analyst, IT Risk Analytics & Reporting (Global Security)

RBCToronto, ON, CA
Full-time

What is the opportunity? As the Senior Analyst, IT Risk Analytics & Reporting, you work with data enhancement, and governance of enterprise technology risk metrics.This role serves as a critical br... Show more

 • Promoted

It Security Leader: Strategy, Policy & Risk | Hybrid - C$84,000 - C$105,000 A Year

Health Solutions ProviderNorth York, Canada
Full-time

Manage IT security strategy, policy, and risk for a health solutions provider, overseeing the information security program and ensuring compliance. Show more

 • Promoted

Manager It Security - C$84,000 - C$115,000 A Year

DynacareToronto, Canada
Full-time +1

Life is precious and every moment matters.Dynacare is helping Canadians achieve a healthy future with care and wellness solutions that are convenient, understandable, and accessible.When you join o... Show more

 • Promoted

IT Security Analyst

ROSSToronto
Full-time

Assist in providing IT security services to the company and it’s customers.Assist management and its customers in defining their IT Security requirements to meet their business needs.Assess, provid... Show more