Lead Security Analyst, Grc
7 months ago
Cronos Group is an innovative global cannabinoid company with international production and distribution across five continents. Cronos Group is committed to building disruptive intellectual property by advancing cannabis research, technology and product development. With a passion to responsibly elevate the consumer experience, Cronos Group is building an iconic brand portfolio. Cronos Group’s portfolio includes PEACE NATURALS, a global health and wellness platform and adult-use brand Spinach.
The Lead Security Analyst plans, monitors and executes compliance on all Cronos Group’s North American IT controls in alignment with requirements from the Security Operations Center (SOC). They play a critical role in identifying, escalating, and guiding remediation efforts with a heavy focus on continuous improvement in control processes.
**What you'll be doing**:
- Lead and execute the annual internal NIST CSF risk assessment
- Develop and implement a risk register process; perform quarterly risk register reviews and manage and monitor remediation and exceptions of risk
- Perform third party vendor security risk assessments
- Perform ITGC and NIST CSF security controls review, testing, and validation
- Initiate and assist with semi-annual and annual user access reviews for SAP, collecting evidence of necessary approvals to verify access levels are provided appropriately
- Drive a continuous improvement mentality, identifying opportunities to improve, standardize, and strengthen internal controls and compliance
- Build and maintain strong partnerships throughout the business to proactively identify existing and emerging risks and develop and update internal controls and corresponding documentation
- Collaborate with process owners to ensure controls testing is executed timely and accurately including updating master data files, evaluating test results, and developing remediation plans as needed In partnership with the Director, GRC and Internal Audit team, support efforts to raise awareness and knowledge of internal controls throughout the company, providing training to employees related to their controls responsibilities
- Perform user account reviews and privileged account reviews
- Develop and report metrics to measure the effectiveness of the GRC program
**You’ll need to have**:
- Bachelor's degree in information security, technology, risk management, business management or other related field
- 7+ years of IT audit, risk management, technology, compliance or other directly related experience
- In-depth knowledge in various key areas including Information Security, Identity and Access Management, Data Governance, Application Development and IT infrastructure principles, policies and procedures
- Knowledge of data and cyber technical control formation and implementation practices
- Knowledge of regulatory frameworks such as SOX, SOC 2, SEC, HIPAA, PCI and GDPR
- Experience using GRC tools such as AuditBoard to execute and manage audits, risk assessments, vendor security assessments, and risk register reviews Knowledge of industry security frameworks such NIST CSF, ISO 27001, and HITRUST CISA or CRISC certification highly desired
- Working knowledge with enterprise solutions including SAP and Onestream a plus
- Exceptional communication skills to articulate technical possibilities and limitations of systems to non-technical colleagues
- A knack for identifying and tackling “hard problems”, thinking creatively, and getting things done. You stay current on technology and are passionate about figuring out how to make processes, systems, functions, and experiences better
- Roll up the sleeves attitude with comfort transitioning between tactical execution and strategic thinking
- Capable of building trust with stakeholders, positioning yourself as a trusted advisor to your business partners
- Sound decision making skills; can swiftly assess risks, analyze complex situations and determine next course of action
- Adaptable and organized; capable of managing efforts and dynamically prioritizing multiple work-streams with a positive attitude
-
Principal Grc Technology Analyst
2 weeks ago
Remote, Canada opentext Full time**OPENTEXT - THE INFORMATION COMPANY** As the Information Company, our mission at OpenText is to create software solutions and deliver services that redefine the future of digital. Be part of a winning team that leads the way in Enterprise Information Management. **Life At Opentext** At OpenText and in IT, we believe in every employee having meaningful,...
-
SAP Security and Grc Consultant
6 months ago
Remote, Canada Stream-Flo Full time**Primary Accountability**: - Implement the new Security design for Stream-Flo users, support teams and system users - Design and Implement Governance, Risk and Compliance System(GRC) - Define and configure Segregation of Duties(SODs) and risk library - Advice on SAP Security policy and procedures - Cutover planning and roll out to users **Key Position...
-
Security Analyst
1 week ago
Remote, Canada Resolute Technology Solutions Inc Full time**About us** Resolute is a Full-Service IT firm with a multi-disciplined team that can handle every aspect of business IT. The two sides of our business are Professional Services and Managed Services. We are a trusted partner for growing, mid-sized, and enterprise organizations to enable them to achieve their business goals to scale up operations, reduce...
-
Grc Risk Consultant
7 months ago
Remote, Canada Prevalent Full timeThe Prevalent GRC Risk Consultant will be working as part of a dynamic and multi-skilled team providing client-facing professional services across a range of deliverables. Key deliverables will focus on risk remediation, audit and risk advisory activities. You will also be required to support other business functions in the delivery of Prevalent services. -...
-
Staff Security Awareness and Culture Analyst
7 months ago
Remote, Canada Okta Full time**Get to know Okta** Okta is The World's Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transforms how people move through the digital world, putting Identity at the heart of business security...
-
Principal Security Compliance Analyst
7 months ago
Remote, Canada Open Text Corporation Full time**Principal Security Compliance Analyst**: - Req id: 37918- Virtual, CA Virtual, US**OPENTEXT - THE INFORMATION COMPANY** As the Information Company, our mission at OpenText is to create software solutions and deliver services that redefine the future of digital. Be part of a winning team that leads the way in Enterprise Information Management. **The...
-
IT Cyber Security Analyst
2 weeks ago
Remote, Canada KF Aerospace Full time**IT Cyber Security Analyst** **We’re all about the craft.** KF Aerospace is proud to deliver innovative aircraft services for corporate, commercial, and military customers worldwide. Launched in 1970 out of British Columbia’s beautiful city of Kelowna, KF Aerospace has grown to specialize in a wide range of aviation services including maintenance and...
-
Application Security Analyst
58 minutes ago
Remote, Canada ATB Financial Full time**Our bottom line is different.** There’s something special about working at ATB, and it’s been recognized on every top employer list that matters. Maybe it’s our exceptional culture where your total wellness is supported through market-leading benefits and you’re free to bring your whole self to work. Maybe it’s our commitment to a growth mindset...
-
Iam Security Analyst
2 weeks ago
Remote, Canada ATB Financial Full time**Our bottom line is different.** There’s something special about working at ATB, and it’s been recognized on every top employer list that matters. Maybe it’s our exceptional culture where your total wellness is supported through market-leading benefits and you’re free to bring your whole self to work. Maybe it’s our commitment to a growth mindset...
-
Cyber Security Analyst
7 months ago
Remote, Canada Dawn InfoTek Inc. Full timeDawn InfoTek Inc. is a professional IT consulting team that partners with major financial institutions, investment firms and government sectors. We have been dedicated to delivering cutting-edge consulting services and recruiting all levels of IT positions for our clients. We are currently seeking competent individuals to fulfill the role of **Cyber...
-
Remote, Canada TGT Solutions Inc Full time**About us** For the past 26 years, TGT (_The Genesis Team_) has worked to create an industry-leading team of professionals who develop new products and deliver world-class services internally and externally. We are visionary in our leadership and work very closely with our clients to help them to Profit Through Technology®. To facilitate our client’s...
-
Network Security Analyst
4 days ago
Remote, Canada Maplesoft Group Full timeMaplesoft Group is currently seeking a L3 Network Security Analyst for one of our Federal Government clients in the National Capital Region. This work can be done remotely. The following responsibilities are associated with the “Statement Of Work” but are not limited to: 1. Analyze identified network and/or telecom problems, identify resolution...
-
IT Security Analyst, Penetration Tester
7 days ago
Remote, Canada iON United Full timeiON United Inc. is one of Canada’s most trusted cybersecurity solution providers. Founded in 2003, our experienced team delivers best-in-class advisory, technology, and managed services for securing IT, OT, and cloud environments. With consecutive year-over-year growth, we foster meaningful relationships through meaningful work by helping organizations...
-
SAP Hana Security Analyst
4 days ago
Remote, Canada Nucleo Digital Full timeWe are searching for an SAP HANA Security Analyst to join our Canadian Technology Team. We offer a high energy, professional yet casual work environment with the opportunity to make a difference every day. It's an environment where everyone’s contribution is rewarded and valued. We take pride in our ability to have fun and celebrate our successes together....
-
Network Analyst
7 months ago
Remote, Canada Dacaro Software Services Inc Full time**Network Analyst** **Position Overview**: **Responsibilities**: - Design, implement, and manage the organization's network infrastructure. - Monitor network performance and troubleshoot connectivity issues. - Collaborate with IT teams to ensure the integration of network systems with other technologies. - Evaluate and recommend network hardware and...
-
Intelligence Analyst
4 days ago
Remote, Canada Sqope SA Full timeSqope is looking for an intelligence analyst to join our expanding global team. The analyst will work on a variety of in-depth due diligence-oriented reports tailored for the financial sector and with a focus on uncovering potential risks of money laundering, sanctions evasion, terror financing, and reputational damage, among others. - Proven analytical...
-
Intermediate Application Support Analyst, IT
7 months ago
Remote, Canada WestJet Full time**Why WestJet**: Every WestJet journey has the potential to enrich lives; a career with us is no exception. WestJet arrived on the Canadian airline scene in 1996 and changed the industry for the better. We made air travel more affordable for Canadians and now we're going global. **Join us and love where you’re going.** **Remote Work**: This position is...
-
Business Analyst
7 months ago
Remote, Canada eCapital Full time**About Us**: eCapital supports small and mid-sized companies throughout the United States, Canada, and the United Kingdom by providing alternative financial solutions like invoice factoring, factoring lines of credit, and asset-based lending to accelerate their access to capital. Through its Commercial Finance, Freight Factoring and ABL divisions, eCapital...
-
Secops Analyst
4 days ago
Remote, Canada Triton Digital Canada Inc. Full timeWe’re looking for a SecOps Analyst to join our Triton Platform team to operate and improve our privacy and security by design environment that is robust, high-quality, and blazingly performant. Reporting into our Specialist, SecOps, you’ll work with a highly skilled and motivated team where your efforts and expertise will have a direct impact on framing...
-
Technical Analyst
3 days ago
Remote, Canada Ignite Technical Resources. Full timeTechnical Analyst - 6-month Contract position in Burnaby: On behalf of our client in **Burnaby, Ignite Technical Resources** is looking for a **Technical Analyst** with our client for a **6-month contract** **opportunity**. **Responsibilities**: **Qualifications**: - 3+ year’s work experience with the server, storage, network, and core infrastructure...