Senior Analyst – IT Governance, Risk and Compliance

1 month ago


Markham Ontario IP, CA Enercare Full time
Senior Analyst – IT Governance, Risk and Compliance

Markham, ON, Canada Req #2497

Proudly Canadian-owned, Enercare is committed to providing the best services, solutions and advice to make customer’s homes as comfortable as they can be. With Enercare Advantage, we provide affordable clean air and water solutions for homes and workplaces. We are committed to operating in an environmentally responsible way, including keeping as much waste out of landfills as possible, and giving back to the communities where we live and work. Enercare is about putting people first by listening to our customers, continuous improvement and making our organization a destination for building people’s careers.

Come and join one of North America's largest home and commercial services and energy solutions companies We offer comprehensive benefits, a DC Pension Plan and savings match plan. If you are passionate about joining an organization committed to delivering 5 Star Customer Service, we would love to hear from you.

Enercare has embraced a hybrid work environment for the time being as we try different options and technologies to determine what will work best for the future of our people and our organization. Join us with an open mind on the future of work

Role: Senior Analyst – IT Governance, Risk and Compliance

Status: Regular, Full-Time

Department: Information Technology

Reports: Director, IT Governance, Risk and Compliance

Location: Hybrid - Markham

Summary:

The Senior Analyst – IT Governance, Risk and Compliance (IT GRC) will manage activities within Canada and US, as part of the IT GRC team, and report directly to the Director, IT GRC. The person will be instrumental in collaborating across IT, business, and internal / external audit teams especially for the compliance process.

A great fit for this role is someone with working experience in the field and who has assisted in planning, testing, execution and reporting on IT Governance, Risk and Compliance, especially processes and controls for Sarbanes-Oxley (SOX), Payment Card Industry (PCI) Data Security Standards (DSS) and/or compliance programs.

Responsibilities :

IT Governance

  • Responsible for, where required, writing, or advising on IT Policies, Standards, Guidelines, Procedures, Plans, Playbooks & Standard Operating Procedures (SOPs) and ensure alignment to industry standards, best practices, regulatory requirements, IT enterprise policy framework & management requirements.
  • Ensuring policies are reviewed on schedule & communicated to all relevant parties in compliance with processes and at times could include reviewing and contributing to non-IT owned policies.
  • Ensure that IT procedures, controls and documentation are sufficient across IT, provide advice on gaps and support or guide teams in filling those gaps.
  • Responsible for performing gap analysis of IT governance and remediating gaps or working with department management to remediate gaps.
  • Supporting the Data Governance program and records information management programs
  • Performing all aspects of an IT risk management program. This includes assessing risk (to industry frameworks and in line with Enterprise risk tolerance and appetite), documenting technical details as well as documenting risk in a way that is easily understood by non-technical people.
  • Reviewing & assessing management responses, ensuring that risks are sufficiently mitigated, and documenting justification and reasoning.
  • Performing risk assessments of vendors that the Company works with and providing advice on any iterative improvements to that process.
  • Facilitating periodic risk review sessions with IT leadership, performing assessments and to ensure consistent patterns of risk management processes across the Company.
  • Manage the third-party risk management process for external vendors.

IT Compliance

  • Assist with the IT Compliance programs (e.g., SOX, PCI DSS) including planning, testing, execution, monitoring and reporting of new and existing processes and controls.
  • Participate in annual and ongoing IT Compliance (e.g., SOX) scoping to identify any changes to the systems, applications, and automated controls considered to be in-scope for the current fiscal year.
  • Manage IT Compliance readiness, such as control identification and testing for new systems, applications, and automated controls.
  • Lead IT General Control (ITGC), and application control (ITAC) (as applicable), walkthroughs for new or complex processes and systems
  • Develop, update and/or review IT process documentation for accuracy, completeness and relevance and update as necessary.
  • Coordinate IT SOX program testing for ITGC, and ITAC (as applicable) with co-sourced internal audit IT team members, external audit IT team members, control owners, managers and executive management.
  • Evaluate IT control deficiencies for impact and perform root cause analysis to determine appropriate management actions.
  • Monitor management’s remediation efforts to closure, including review of supporting evidence.
  • Provide regular IT Compliance program status reporting to the IT team, Internal Audit and Senior IT management (as needed)
  • Assisting with benchmarking and other initiatives to improve controls, make processes more efficient, effective, and/or reduce cycle time for IT SOX and PCI DSS compliance.
  • Work closely with cross-functional teams including IT Operations, Accounting/Finance, and Internal/External Audit.
  • Collaborate with internal and external auditors to ensure IT SOX and other compliance program requirements are being met.
  • Ensure new software programs meet compliance requirements before they are made operational.
  • Support and manage detailed testing of controls to ensure risks are appropriately identified, associated audit procedures are applied, and related controls are designed and operating to mitigate the identified risks.
  • Training of IT GRC to the IT and Business teams.
  • Build trust and positive working relationships with auditors, business stakeholders, IT teams, and senior management to ensure alignment between IT strategy and business objectives.
  • Collaborating with Project, IT development and operations teams to identify, collect and optimize IT resources to meet business requirements.

Qualifications:

  • Bachelor’s degree or higher, preferably in Information Technology (IT), Information Security, Computer Science or other technical discipline; Finance/Accounting is acceptable.
  • 5+ years of progressive experience in IT Governance, Risk Management, Compliance and/or Audit (e.g., Operations, Financial, IT); Project management experience is desired.
  • Designations and Certifications in one or more of the following areas: CPA (CA, CMA, CGA), CISA, GRCP, CGRC, CIA is preferred
  • CISSP, GIAC, CGEIT, CRISC, CISM, CDPSE, ISO 27001 are an asset.
  • Demonstrate previous success working with IT GRC programs.
  • Advanced knowledge and experience with SOX, PCI DSS and related industry standards/frameworks is required.
  • Knowledge of CIS, ISO 27001, COBIT, NIST and related industry standards/frameworks is preferred.
  • Possess strong communication and collaboration skills, to provide solutions and translate in both technical and non-technical manners.
  • Illustrated ability to deliver projects on time and within budget in fast moving environment and competence in managing several projects.
  • Prior experience in large professional services, consulting, and audit companies, including Big 4 firms, is strongly desired.
  • Experience in supporting compliance with applicable privacy laws, is an asset.

Enercare is an equal opportunity employer. We are committed to equal employment opportunity regardless of race, colour, ancestry, national origin, religion, sex, age, sexual orientation, gender identity, citizenship, marital status, disability, pregnancy, military status, protected veteran status or other characteristics protected by applicable law. Enercare’s recruitment process includes accommodation for applicants with disabilities in accordance with applicable provincial accessibility laws and regulations. All accommodations will take into account the applicant’s accessibility needs due to disability and are available upon request.

#J-18808-Ljbffr

  • Old Toronto, Ontario, CA HOOPP Full time

    Senior Manager, Technology Governance, Risk and Compliance page is loaded Senior Manager, Technology Governance, Risk and Compliance Apply locations Toronto, Ontario, Canada time type Full time posted on Posted 4 Days Ago job requisition id JR101651 Why you’ll love working here:high-performance, people-focused cultureour commitment that equity, diversity,...


  • Markham, Ontario, I3P, CA Aviva Full time

    About Us Individually we are people, but together we are Aviva. Individually these are just words, but together they are our Values – Care, Commitment, Community, and Confidence. Position Overview We are seeking an upbeat and experienced Senior Underwriting Analyst. Reporting to the Senior Manager, Review Team, Aviva Connex, this role implements the...


  • Golden Horseshoe, Ontario, CA The Toronto-Dominion Bank Full time

    Senior Analyst, Compliance Governance & AssuranceWork Location: CanadaHours: 37.5Line of Business: CompliancePay Details: We’re committed to providing fair and equitable compensation to all our colleagues. As a candidate, we encourage you to have an open dialogue with a member of our HR Team and ask compensation related questions, including pay details for...


  • Golden Horseshoe, Ontario, CA ADP, Inc. Full time

    Note to ADP Associates An associate must be in his/her current position for a minimum of 18 months to apply for any internal openings. He/she must inform their manager have they been invited for a second interview. A little about ADP: We are a global leader in human resources technology, offering the latest AI and machine learning-enhanced payroll, tax,...


  • Old Toronto, Ontario, CA Women in Payments Full time

    Metrolinx is connecting communities across the Greater Golden Horseshoe. Metrolinx operates GO Transit and UP Express, as well as the PRESTO fare payment system. We are also building new and improved rapid transit, including GO Expansion, Light Rail Transit routes, and major expansions to Toronto’s subway system, to get people where they need to go,...

  • Legal Governance

    4 weeks ago


    Old Toronto, Ontario, CA TD Bank Full time

    Lieu de travail: CanadaHoraire: 37.5Secteur d’activité: Gestion des affaires, Stratégie et soutienDétails de la rémunération :Nous avons à cœur d’offrir une rémunération juste et équitable à tous nos collègues. En votre qualité de candidat ou de candidate, nous vous encourageons à avoir une conversation franche avec votre recruteur et à...


  • Old Toronto, Ontario, CA Scotiabank Full time

    Press Tab to Move to Skip to Content Link Select how often (in days) to receive an alert: Title: Senior Manager, Regulatory Risk & Governance Requisition ID: 205679Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture. Contributes to the overall success of the Global Finance, Regulatory Risk Governance...


  • Old Toronto, Ontario, CA Deciem Beauty Group Full time

    Senior Manager, Cybersecurity, Compliance & GovernanceKnown as “The Abnormal Beauty Company”, DECIEM is the parent company of The Ordinary, NIOD, and other beauty brands & is an industry disruptor with a science first approach to innovation. DECIEM was Co-Founded in 2013 by the late Brandon Truaxe, a visionary who set out to change the beauty industry...

  • Legal governance

    3 weeks ago


    Old Toronto, Ontario, CA TD Full time

    Lieu de travail:CanadaHoraire:37.5Secteur d’activité:Gestion des affaires, Stratégie et soutienDétails de la rémunération :Nous avons à cœur d’offrir une rémunération juste et équitable à tous nos collègues. En votre qualité de candidat ou de candidate, nous vous encourageons à avoir une conversation franche avec votre recruteur et à poser...


  • Old Toronto, Ontario, CA Quantum Technology Recruiting Inc. Full time

    Position: Third Party Risk AnalystLocation: Remote (EST hours) in Ontario onlyType: Permanent – Full TimeOur Toronto-based client, consistently ranked as one of Canada’s top employers, is looking for a Third Party Risk Analyst, who has done full-cycle 3rd party vendor risk assessments to support their Information Security Risk Management and Governance...


  • Old Toronto, Ontario, CA Deciem Beauty Group Full time

    Known as “The Abnormal Beauty Company”, DECIEM is the parent company of The Ordinary, NIOD, and other beauty brands & is an industry disruptor with a science-first approach to innovation. DECIEM was Co-Founded in 2013 by the late Brandon Truaxe, a visionary who set out to change the beauty industry through authenticity and transparency. He developed...


  • Golden Horseshoe, Ontario, CA The Toronto-Dominion Bank Full time

    Senior Analyst, AML Risk AssessmentWork Location: CanadaHours: 37.5Line of Business: Financial Crime Risk ManagementJob Description:The Senior Analyst, FCRM Risk Assessment, position reports directly to the Manager, FCRM Risk Assessment, and supports the FCRM Risk Assessment team with their technology, methodology execution, and relationship management...


  • Old Toronto, Ontario, CA TD Bank Full time

    Senior AML Financial Crime Risk AnalystLieu de travail: CanadaHoraire: 37.5Secteur d’activité: Lutte blanchiment d’argentDétails de la rémunération: Nous avons à cœur d’offrir une rémunération juste et équitable à tous nos collègues. En votre qualité de candidat ou de candidate, nous vous encourageons à avoir une conversation franche avec...


  • Old Toronto, Ontario, CA TD Bank Full time

    Senior Market Risk Analyst Lieu de travail: Canada Horaire: 37.5 Secteur d’activité: Gestion des risques Détails de la rémunération: Nous avons à cœur d’offrir une rémunération juste et équitable à tous nos collègues. En votre qualité de candidat ou de candidate, nous vous encourageons à avoir une conversation franche avec votre recruteur et...


  • Golden Horseshoe, Ontario, CA The Toronto-Dominion Bank Full time

    Senior Market Risk Analyst page is loaded Senior Market Risk Analyst Apply remote type Hybrid locations Toronto, Ontario time type Full time posted on Posted 8 Days Ago job requisition id R_1361933 Work Location:CanadaHours:37.5Line of Business:Risk Management Pay Details: We’re committed to providing fair and equitable compensation to all our...


  • Markham, Ontario, I3P, CA Aviva plc Full time

    Senior Actuarial Analyst, Personal Insurance page is loaded Senior Actuarial Analyst, Personal Insurance Apply locations Markham posted on Posted 30+ Days Ago job requisition id R-137887 Are you passionate about data and not afraid of searching for a needle in a stack of hay? Does developing pricing techniques give you goosebumps? Do you get excited when...


  • Markham, Ontario, I3P, CA Miipe Quality Solutions Full time

    Miipe is a dynamic organization that fosters creativity and growth. We offer opportunities to learn and challenge yourself in a fast-paced software consulting firm, working alongside large Fortune 500 clients in a myriad of industries, such as banking, telecommunications, insurance, utilities, and technology.As a leader in our field, we are rapidly growing...


  • Old Toronto, Ontario, CA EQ Bank | Equitable Bank Part time

    Senior Manager, RCM Program Governance and ReportingPart Time / Full TimePurpose:The Senior Manager, Governance and Reporting is responsible for developing and coordinating governance activities associated with the Bank’s Regulatory Compliance Management (RCM) program as well as the development and coordination of compliance reporting. This role ensures...


  • Old Toronto, Ontario, CA EQ Bank | Equitable Bank Full time

    Purpose:The Senior Manager, Governance and Reporting is responsible for developing and coordinating governance activities associated with the Bank’s Regulatory Compliance Management (RCM) program as well as the development and coordination of compliance reporting. This role ensures that the organization’s compliance framework is effectively communicated...


  • Old Toronto, Ontario, CA TMX Group Full time

    Senior Analyst, Enterprise Risk Management Venture outside the ordinary - TMX Careers The TMX group of companies includes leading global exchanges such as the Toronto Stock Exchange, Montreal Exchange, and numerous innovative organizations enhancing capital markets. United as a global team, we’re connecting cross-functionally, traversing industries and...