Governance Risk and Compliance Specialist

3 weeks ago


Toronto ON CA, Ontario LeverageTek IT Solutions Full time
Opportunity Details

LeverageTek is actively seeking a Governance Risk and Compliance Specialist (GRC) – Technology and Enterprise Risk for a permanent position with its Ottawa-based customer.

Work Location

Hybrid preferred (1x/week onsite) or Remote (ON/QC)

Key Tasks

Deliver new security program capabilities by leading IT security, GRC, and cloud technology projects; scope of projects may include IT selection and procurement, development of detailed project, resource, and communications plans, coordination with both IT and organizational change management, and providing task direction to other senior project team members
Deliver daily operations for IT security risk and compliance management programs and associated governance frameworks, including but not limited to:
Complete IT security risk assessments and associated reporting
Perform GRC monitoring, reporting, and policy enforcement by making maximum effective use of automated available from Azure, Microsoft 365, and associated tools
Perform supply chain security assessments across IT products, SaaS and hosted services, and other 3rd party support services partners to ensure security controls are appropriate for business needs and the sensitivity of data involved
Develop and maintain reporting of key measures and metrics for IT security risk, prepare monthly, quarterly, and annual risk reporting artifacts, and support presentation of relevant material to management and executive stakeholders
Develop, implement, and maintain effective monitoring of external and internal cybersecurity threat context and impacts to risk posture
Conduct assessments of security posture, control implementation maturity, and conformance to security policies, standards, and guidelines – including coordination of 3rd party assessments and security penetration testing
Prepare reports, policies, standards, and other documentation of a high standard regarding cyber security guidance and/or requirements
Provide business impact context assessment and guidance related to IT resiliency for service continuity and disaster recovery
Participate in security incident responses as a member of the incident response team and support post-event root cause and risk analysis, providing recommendations towards continuous improvement and risk reduction
Develop security policies and operational procedures, including for cybersecurity incident response processes and playbooks, security configuration management, security in system development lifecycle, etc.
Provide IT security, risk, and compliance advisory support:
Within Technology Solutions to ensure security needs are addressed for all IT domains and to support the integration and continuous improvement of IT security risk and compliance management into IT architecture, engineering, software, system integration, and system development lifecycle processes
To the enterprise, including for domains of vendor and supply-chain security, project threat risk assessments, and operational risk inputs to enterprise risk management
Provide high quality and customer-focused support to both IT and user/stakeholder clients by responding to requests and assignments in a timely, respectful, constructive, and responsive manner
Perform other related duties as needed

Key Qualifications

Recent experience in a Governance Risk and Compliance role supporting Enterprise Risk with a focus on Technology and IT Security
Experience with Microsoft Purview supporting Enterprise-wide initiatives related to data protection (data loss and data leakage)
Experience in a GRC capacity leading the Technology and IT Security risk function while also working very closely with other business stakeholders such as HR, Legal, Finance, Procurement, Vendor Management, Supply Chain etc.

Qualifications

University degree in the field of Computer Science, Information Technology, or in a related discipline
2+ years of experience in security program implementation
Delivering security and technology projects involving the implementation and deployment of new capabilities, transition of services to production operations, and successful adoption by users
Developing effective IT security policy, standard, and guideline documentation
Developing governance frameworks and associated documentation for IT security risk management or compliance programs
Preparing risk, compliance, and/or security program reporting for senior management and/or Board stakeholders
Selecting, implementing, and ensuring conformance with IT Security industry best practices and relevant standards and regulations (e.g., NIST Cybersecurity Framework, ISO/IEC 27001/2, COBIT, SOC 2, Information Security Forum, PCI-DSS, Cloud Security Alliance, SANS, CIS Benchmarks, etc.)
Assessing current state compliance against selected IT security and control frameworks, standards, or audit charter objectives
Conducting security maturity and gap assessments against a desired target control posture state
Conducting IT security threat and risk assessments (TRA) and preparing formal TRA reporting documentation
Selecting, applying, and assessing security control implementation for:
Azure infrastructure services including virtual machines, network security groups, and network zoning
Azure native services, such as backup, encryption, and monitoring
Microsoft 365 services
On premise network infrastructures, including boundary protections, monitoring, and network zoning
Portable and mobile computing devices, including Windows and Mac laptops, and mobile iOS platforms
Implementing, monitoring, and reporting from Azure and M365 portals and tools, such as Security Center, for supporting compliance, vulnerability management, and security score posture optimization
Ability to lead complex IT and security implementation projects involving organization-wide rollout and that rely on successful adoption by key stakeholders and/or large user audiences
Ability to deliver daily operational tasks that must be prioritized effectively around competing project and incident response demands
Ability to successfully deliver a broad program of responsibilities and projects according to a multi-year implementation roadmap
Expertise with Azure and Microsoft 365 security and compliance capabilities for control implementation and current state reporting of posture and compliance
Ability to use critical thinking and problem-solving skills to find out root causes of problems or opportunities
General knowledge of networking and IT security concepts and technologies
Results oriented with excellent time and project management skills
Strong ability to handle multiple concurrent and time-sensitive priorities, able to own and guide projects from beginning to end
Demonstrated leadership skills with an ability to influence and positively inspire others to act
Strategic thinking; creative, innovative, and collaborative out of the box thinker
Leading and managing change

Assets
Prior experience with Microsoft Purview, Microsoft Information Protection, or Azure Information Protection
Developing future state security capability profiles and IT security strategy towards achieving desired future state
Developing Disaster Recovery and IT resiliency preparedness, including conducting business impact assessments, developing business and/or service continuity plans, and developing or exercising disaster recovery plans
Security operations and event investigations, security incident response, network or web application penetration testing, or digital forensics
Applying IT security and compliance concepts to Google Cloud Platform (GCP) environments.
Integrating IT security, compliance, and operations capabilities across multiple public cloud tenants

About LeverageTek IT Solutions

Thank you for taking the time to apply Since our company’s inception in March 2003, LeverageTek IT Solutions has worked resolutely to become one of the industry’s most recognized and trusted suppliers of technology staffing and business consulting services. With hundreds of successful engagements to our credit with many of Canada’s leading public and private sector organizations, we are the experts in identifying, deploying, and supporting IT and business talent on a contract, contract-to-hire, and permanent basis. We work with customers across all sectors including academia, aerospace, aviation, finance, government, health care, high tech, military, not-for-profit, and more.

Our responsive service and ability to deliver the right fit, on time and within budget, typically leads to repeat engagements and a long-standing relationship.

Accessibility accommodations are available upon request.

  • Toronto, Ontario, Canada Tucows Inc. Full time

    Tucows (NASDAQ:TCX, TSX:TC) is possibly the biggest Internet company you've never heard of. We started as a simple shareware site in 1993 and have since grown into a stable of businesses: Tucows Domains, Ting Internet and Wavelo.What's next at TucowsWe embrace a people-first philosophy that is rooted in respect, trust, and flexibility. We believe that...


  • Toronto, Ontario, Canada Tucows Inc. Full time

    Tucows (NASDAQ:TCX, TSX:TC) is possibly the biggest Internet company you've never heard of. We started as a simple shareware site in 1993 and have since grown into a stable of businesses: Tucows Domains, Ting Internet and Wavelo.What's next at TucowsWe embrace a people-first philosophy that is rooted in respect, trust, and flexibility. We believe that...


  • Toronto, ON, C6A, Ontario, Canada 7th Avenue Partners Inc. Full time

    Position Title : Data Governance Specialist with hands-on experience in Python (AML Focus)Location : Toronto, CanadaCompany Overview :7th Ave Partners provides state of the art business consulting and technology consulting services for the public sector, private corporations, and small ventures looking for digital and regulatory solutions to strategically...


  • Toronto, Ontario, Canada CN Rail Full time

    At CN, we work together to move our company-and North America-forward. Be part of our Information & Technology (I&T) team, a critical piece of the engine that keeps us in motion. From enterprise architecture to operational technology, our teams use the agile methodology to automate and digitize our railroad ensuring our operations run optimally and safely...


  • Toronto, Ontario, Canada Raymond James Ltd. Full time

    At Raymond James, we develop, we collaborate, we decide, we deliver, and we improve together.Raymond James Ltd. is Canada's leading independent investment dealers offering high quality investment products and services to Canadians seeking customized solutions to their wealth management needs.Manager, Compliance GovernanceHow does the role impact the...


  • Toronto, ON, C6A, Ontario, Canada National Bank Full time

    A career in the Insurance sector at National Bank means being part of a dynamic and diverse team that works to offer innovative protection solutions to the Bank's clients. As a Senior Advisor - Legal Affairs and Compliance, you will use your expertise to influence the risk culture and maintain the team's skills to the highest expected standard by...


  • Toronto, ON, C6A, Ontario, Canada Facility Association Full time

    Compliance manager, Claims.Facility Association (“FA”) is an unincorporated non-profit association of insurers. FA operates in Yukon, Nunavut, North West Territories, Alberta, Ontario, Nova Scotia, New Brunswick, Prince Edward Island and Newfoundland and Labrador. Every insurer licensed to write automobile liability insurance in these jurisdictions is a...


  • Toronto, Ontario, Canada OTT Financial Full time

    We are looking for Operations Specialist, Trading Analysis Specialist and Risk Control Specialist to support the growth of our business in North America and Asia. The Specialists will have the chance to be exposed to various aspects of business operations in payments, foreign exchange, financial technology and those related middle-office work, such as risk...


  • Toronto, Ontario, Canada OTT Financial Group Full time

    Salary: We are looking for Operations Specialist, Trading Analysis Specialist and Risk Control Specialist to support the growth of our business in North America and Asia. The Specialists will have the chance to be exposed to various aspects of business operations in payments, foreign exchange, financial technology and those related middle-office work, such...


  • Toronto, Ontario, Canada LifeWorks Inc. Full time

    TELUS Health and LifeWorks have recently come together to leverage the power of technology and our caring cultures to further progress our shared goal of building a healthier and friendlier future for all. As a global-leading health and well-being provider - encompassing physical, mental and financial health - TELUS Health is improving health outcomes for...


  • Toronto, Ontario, Canada FIS Global Full time

    Position Type : Full time Type Of Hire : Experienced (relevant combo of work and education) Education Desired : Bachelor of Business Administration Travel Percentage : 1 - 5%Are you ready to unleash your full potential? We're looking for people who are passionate about payments to chart Worldpay's path to being the largest and most-loved payments company in...


  • Toronto, Ontario, Canada Trade Compliance Recruiting Solutions Full time

    HIGH LEVEL OVERVIEWWill be the subject matter expert in Trade Compliance for this family owned Global Company working in the University of Toronto, Mississauga campus area. Will be 100% on site with flexible working hours.EXPECTATIONSHere are some of the responsibilities:SME for all Trade Compliance - #1 positionFull responsibility for all Customs/Gov't...


  • Toronto, Ontario, Canada Krissilasgroup Full time

    Our client is a leader in its industry and is considered one of the top 25 most engaged companies globally. Operational Technology - OT GRC Security Risk Analyst Contract Position: 6 months to start Hybrid The Information Security Risk and Governance Analyst supports the Information Security Risk Management and Governance programs. The candidate will...


  • Toronto, Ontario, Canada Definity Financial Full time

    Job DescriptionThe Model Risk Oversight function in Enterprise Risk Management (ERM) provides oversight for the Model Risk Management framework through which the model risks across the organization are identified, measured, managed, monitored, and reported. The scope and depth of model oversight activities across the organization will be significantly...


  • Toronto, Ontario, Ontario, Canada AIR MILES Reward Program Full time

    The AIR MILES Reward Program is one of Canada’s most recognized loyalty programs, with over 10 million active collector accounts, representing more than half of all Canadian households. AIR MILES collectors earn Reward Miles at more than 300 leading Canadian, global and online brands and at thousands of retail and service locations across the country. AIR...


  • Toronto, ON, C6A, Ontario, Canada National Bank Full time

    A career as a Senior Credit Manager in the credit risk team at National Bank means being a specialist and coach for credit approvals within the commercial sector. You will be called upon to play an important role as an expert in the development of the Ontario and Western Canadian market. This position allows you to leverage your expertise and influential...


  • Toronto, ON, C6A, Ontario, Canada HelpSeeker Technologies Full time

    HelpSeeker is a technology company leading the way in developing innovative solutions to tackle social, municipal, and governmental challenges. Our mission is to empower non-profits, charities, and government bodies with cutting-edge technology to drive significant social impact. We are looking for a Senior Social Sector Specialist with a strong background...


  • Toronto, ON, C6A, Ontario, Canada The Mirillion Group Full time

    Position Overview:We are actively looking for an accomplished Senior Underwriting Specialist or Senior Underwriter to join this fantastic Insurance Firm with a great reputation in the market. The right candidate will be responsible for underwriting and profitably growing a portfolio of property business including P&C Package within the Ontario and Atlantic...


  • Toronto, Ontario, Canada Royal Bank of Canada Full time

    Job SummaryJob DescriptionWhat is the opportunity?In this hands-on role, you will Manage and provide subject matter expertise on technology risk control and advisory services to Global Functions Technology (GFT) US portfolio. Services include Operational risk analysis, risk & compliance reporting, risk awareness & advisory, audit and regulatory liaison. You...


  • Greater Toronto Area, Canada, Ontario Robertson & Company Ltd. Full time

    Our Client:Our client is a leading residential mortgage insurer renowned for offering mortgage default insurance to Canadian residential mortgage lenders.What You Will Achieve in This Role:As the Manager of Enterprise Risk Management (ERM), you will play a pivotal role in developing and implementing elements to support the ERM program within our client’s...