GRC Manager
2 weeks ago
Join to apply for the GRC Manager role at Exchange Technology Services About Us Exchange Technology Services is a leading IT consulting company in Winnipeg and part of the Exchange Income Corporation's family of companies. We provide a wide range of services, including Managed IT, Project Management, Business Intelligence, Cyber Security, Digital Transformation, Training Services, Installation Services, and Telecommunications across Canada and the US. If you are looking for a fast-paced career, serving enterprise customers and managing diverse IT projects, we invite you to join us. Our work environment is dynamic, filled with learning opportunities, exciting and challenging projects, and a chance to make a positive impact on clients’ businesses. We value teamwork, fun, and achieving amazing results together. Job Overview Reporting to the Director of Information Security, the Governance, Risk and Compliance (GRC) Manager is responsible for developing, implementing, and managing the organization’s GRC framework to ensure alignment with industry standards, regulatory requirements, and strategic business objectives. Key responsibilities include overseeing risk assessments, policy development, compliance audits, and enterprise risk reporting, while fostering a strong risk-aware culture across the organization. Key Responsibilities Governance: Develop, maintain, and enforce GRC policies, standards, and frameworks aligned with best practices (e.g., ISO 27001, SOC2, FAIR, NIST, CIS). Oversee the establishment and continuous improvement of information security, governance structures and risk management processes. Coordinate the development and maintenance of organizational policies, SOPs, and guidelines related to risk, compliance, and data protection. Lead GRC awareness and training programs for internal and external stakeholders. Lead and govern IT Risk Management, ensuring integration with organizational objectives. Develop and maintain the strategic IT Risk Framework to guide enterprise decision-making. Support the Information Security Director in implementing and maintaining the ETS Information Security Management System (ISMS). Manage processes and activities to sustain the ETS ISMS, including reporting on metrics that measure Information Security objectives. IT Risk Management: Identify, assess, and manage enterprise and IT risks through a structured risk management process. Conduct periodic risk assessments, threat modeling, and impact analysis to support decision-making. Maintain and update the enterprise risk register and ensure that mitigation plans are in place and monitored. Collaborate with business units and IT to embed risk management practices in daily operations and strategic planning. Monitor emerging risks and recommend appropriate responses. Assess enterprise-wide risk tolerance, risk appetite, and the quantification of risks. Manage the evolution of risk frameworks and processes to identify, measure, monitor, and report on the ETS risk environment. Ensure continuous improvement of the organization’s ability to manage priority risks, including technology risks. Oversee Supplier and Vendor Risk Management, including annual risk assessments, quarterly KRI reporting, and updates to corporate recovery plans. Direct the development and maintenance of Business Continuity Plans (BCP), ensuring accuracy and completeness through plan reviews, exercises, and compliance signoffs. Monitor and manage action plans to address gaps in BCPs. Compliance: Monitor regulatory and legal compliance requirements relevant to the organization’s industry (e.g., data protection, cybersecurity, financial reporting). Lead internal and external audits related to compliance, including ISO certifications and regulatory inspections. Manage responses to compliance violations, audit findings, and risk incidents. Oversee third-party risk assessments and vendor compliance reviews. Ensure compliance with data privacy and protection frameworks (e.g., CMMC, CDP, GDPR, PIPEDA, or regional equivalents). Evaluate internal controls and conduct audits to ensure regulatory and policy adherence. Lead the internal audit team and support the maintenance of Information Security certifications and attestations. Manage oversight of policies, procedures, and systems that ensure ongoing compliance. Reporting and Communication: Provide periodic reporting to executive leadership and relevant committees on the status of risk, compliance, and governance initiatives. Develop dashboards, metrics, and KPIs for monitoring GRC performance. Additional responsibilities as assigned. Qualifications Education, Licenses, and/or Certification, Experience Required Bachelor’s or Master’s degree in Information Security, Risk Management, or a related field. Minimum 5 years of relevant experience in GRC, cyber security, audits, or enterprise risk. Professional certifications preferred: CRISC, CISM, CISA, ISO 27001 Lead Implementer/Auditor, or similar. Knowledge, Skills, and Abilities Required Strong knowledge of regulatory and compliance frameworks such as ISO 27001, NSIT, PCI-DSS, or regional standards. Strong communication skills to effectively interact with diverse groups of people at all levels of the organization. Exceptional writing skills to generate required reports. Experience in a fast-paced environment with multitasking responsibilities. Strong ability to prioritize tasks and meet deadlines. Strong attention to detail and accuracy. Working Conditions Must be able to obtain and maintain a clear criminal record check. Work performed primarily in an office environment. Manual dexterity required to use desktop computer and telephone. High visibility role that requires regular interaction with stakeholders, clients, and vendors. What We Offer Competitive salary and benefits package Registered Retirement Savings Plan with Company Matching Employee Share Purchase Plan Subsidized Gym Membership Subsidized Phone Plan Opportunities for professional development and career growth Collaborative and innovative work environment Seniority Level Mid-Senior level Employment Type Full-time Job Function Other Industries IT Services and IT Consulting Please note, Exchange Technology Services is an equal opportunity employer. We are committed to building a diverse and inclusive workplace and encourage applications from all qualified individuals. Accommodations are available upon request throughout the recruitment process. Please reach out to careers@exchangetech.ca if you have any questions. #J-18808-Ljbffr
-
GRC Manager
2 weeks ago
Winnipeg, Canada Exchange Technology Services Full timeJoin to apply for the GRC Manager role at Exchange Technology Services About Us Exchange Technology Services is a leading IT consulting company in Winnipeg and part of the Exchange Income Corporation's family of companies. We provide a wide range of services, including Managed IT, Project Management, Business Intelligence, Cyber Security, Digital...
-
GRC Manager
2 weeks ago
Winnipeg, Canada Exchange Technology Services Full timeJoin to apply for the GRC Manager role at Exchange Technology Services About Us Exchange Technology Services is a leading IT consulting company in Winnipeg and part of the Exchange Income Corporation's family of companies. We provide a wide range of services, including Managed IT, Project Management, Business Intelligence, Cyber Security, Digital...
-
Senior Security Engineer, GRC Automation
4 weeks ago
Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Victoria, Surrey, Halton Hills, London, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada 1Password Full timeSenior Security Engineer, GRC AutomationThis role designs and implements automation, dashboards, and integrations that power Governance, Risk, and Compliance (GRC) operations. It is a remote opportunity within the US or Canada.What You’ll DoLead the implementation and integration of the GRC platform, ensuring it is fully operational across key systems and...
-
ServiceNow GRC Developer-Fully Remote
3 weeks ago
Ajax, Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Victoria, Surrey, Halton Hills, London, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Onta, Canada Wholepoint Systems Full timeThe role of a ServiceNow GRC Developer at WholePoint involves crafting tailored Governance, Risk, and Compliance (GRC) solutions on the ServiceNow platform for our diverse clientele. Success in this role is defined by the ability to create GRC solutions that align seamlessly with each client's distinct regulatory framework, risk assessment methodologies, and...
-
Governance, Risk, and Compliance
3 weeks ago
Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Victoria, Surrey, Halton Hills, London, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada WELLSTAR Full timeWho we are At WELLSTAR, we are committed to reshaping Canadian healthcare by leveraging technology to address the administrative burdens that pull physicians away from their true calling—patient care. Our mission is focused on supporting providers and patients, shifting the emphasis back to quality, time, and positive outcomes. With a comprehensive suite...
-
Remote GRC Lead: ISO 27001
4 weeks ago
Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Victoria, Surrey, Halton Hills, London, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada WELLSTAR Full timeA technology-enabled healthcare company in Toronto seeks a Governance, Risk, and Compliance (GRC) Lead to define and drive GRC efforts. The role involves maintaining compliance frameworks, managing risk assessments, and leading cross-functional collaborations. Ideal candidates have 8+ years in GRC and familiarity with compliance tools. This remote-friendly...
-
Senior Manager, Governance, Risk, and Compliance
3 weeks ago
Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Victoria, Surrey, Halton Hills, London, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada D-Wave Quantum Inc. Full timeSenior Manager, Governance, Risk, and Compliance (GRC) D-Wave (NYSE: QBTS) , D-Wave is a leader in the development and delivery of quantum computing systems, software, and services. We are the world’s first commercial supplier of quantum computers, and the only company building both annealing and gate-model quantum computers. Our mission is to help...
-
Senior GRC Analyst, Security — Remote
4 weeks ago
Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Victoria, Surrey, Halton Hills, London, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada KOHO Full timeA fintech company is seeking a Senior Governance, Risk and Compliance (GRC) Analyst to develop compliance programs and manage cybersecurity risks. The role is remote and focuses on automation and communication within cross-functional teams. Ideal candidates will have a background in risk management, experience with PCI DSS, and possess strong communication...
-
Senior GRC Strategist
4 weeks ago
Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Victoria, Surrey, Halton Hills, London, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada Mozilla Full timeA technology organization in Toronto is seeking a Governance, Risk and Compliance expert to define and implement a comprehensive GRC framework. The ideal candidate will have extensive experience in regulatory compliance and risk management, playing a pivotal role in ensuring security across various product and enterprise functions. The role offers...
-
Senior GRC Leader—Remote, Automate Compliance
3 weeks ago
Toronto, Montreal, Calgary, Vancouver, Edmonton, Old Toronto, Ottawa, Mississauga, Quebec, Winnipeg, Halifax, Saskatoon, Burnaby, Hamilton, Victoria, Surrey, Halton Hills, London, Regina, Markham, Brampton, Vaughan, Kelowna, Laval, Southwestern Ontario, R, Canada D-Wave Quantum Inc. Full timeA quantum computing leader is seeking a Senior Manager, Governance, Risk, and Compliance (GRC) to lead their global risk strategy. The role requires expertise in multiple regulatory frameworks and strong leadership skills. Responsibilities include defining compliance roadmaps, modernizing through automation, and collaborating with various departments to...