Lead Security Analyst, Grc
5 months ago
Cronos Group is an innovative global cannabinoid company with international production and distribution across five continents. Cronos Group is committed to building disruptive intellectual property by advancing cannabis research, technology and product development. With a passion to responsibly elevate the consumer experience, Cronos Group is building an iconic brand portfolio. Cronos Group’s portfolio includes PEACE NATURALS, a global health and wellness platform and adult-use brand Spinach.
The Lead Security Analyst plans, monitors and executes compliance on all Cronos Group’s North American IT controls in alignment with requirements from the Security Operations Center (SOC). They play a critical role in identifying, escalating, and guiding remediation efforts with a heavy focus on continuous improvement in control processes.
**What you'll be doing**:
- Lead and execute the annual internal NIST CSF risk assessment
- Develop and implement a risk register process; perform quarterly risk register reviews and manage and monitor remediation and exceptions of risk
- Perform third party vendor security risk assessments
- Perform ITGC and NIST CSF security controls review, testing, and validation
- Initiate and assist with semi-annual and annual user access reviews for SAP, collecting evidence of necessary approvals to verify access levels are provided appropriately
- Drive a continuous improvement mentality, identifying opportunities to improve, standardize, and strengthen internal controls and compliance
- Build and maintain strong partnerships throughout the business to proactively identify existing and emerging risks and develop and update internal controls and corresponding documentation
- Collaborate with process owners to ensure controls testing is executed timely and accurately including updating master data files, evaluating test results, and developing remediation plans as needed In partnership with the Director, GRC and Internal Audit team, support efforts to raise awareness and knowledge of internal controls throughout the company, providing training to employees related to their controls responsibilities
- Perform user account reviews and privileged account reviews
- Develop and report metrics to measure the effectiveness of the GRC program
**You’ll need to have**:
- Bachelor's degree in information security, technology, risk management, business management or other related field
- 7+ years of IT audit, risk management, technology, compliance or other directly related experience
- In-depth knowledge in various key areas including Information Security, Identity and Access Management, Data Governance, Application Development and IT infrastructure principles, policies and procedures
- Knowledge of data and cyber technical control formation and implementation practices
- Knowledge of regulatory frameworks such as SOX, SOC 2, SEC, HIPAA, PCI and GDPR
- Experience using GRC tools such as AuditBoard to execute and manage audits, risk assessments, vendor security assessments, and risk register reviews Knowledge of industry security frameworks such NIST CSF, ISO 27001, and HITRUST CISA or CRISC certification highly desired
- Working knowledge with enterprise solutions including SAP and Onestream a plus
- Exceptional communication skills to articulate technical possibilities and limitations of systems to non-technical colleagues
- A knack for identifying and tackling “hard problems”, thinking creatively, and getting things done. You stay current on technology and are passionate about figuring out how to make processes, systems, functions, and experiences better
- Roll up the sleeves attitude with comfort transitioning between tactical execution and strategic thinking
- Capable of building trust with stakeholders, positioning yourself as a trusted advisor to your business partners
- Sound decision making skills; can swiftly assess risks, analyze complex situations and determine next course of action
- Adaptable and organized; capable of managing efforts and dynamically prioritizing multiple work-streams with a positive attitude
-
SAP Security and Grc Consultant
5 months ago
Remote, Canada Stream-Flo Full time**Primary Accountability**: - Implement the new Security design for Stream-Flo users, support teams and system users - Design and Implement Governance, Risk and Compliance System(GRC) - Define and configure Segregation of Duties(SODs) and risk library - Advice on SAP Security policy and procedures - Cutover planning and roll out to users **Key Position...
-
Staff Security Awareness and Culture Analyst
6 months ago
Remote, Canada Okta Full time**Get to know Okta** Okta is The World's Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transforms how people move through the digital world, putting Identity at the heart of business security...
-
Principal Security Compliance Analyst
5 months ago
Remote, Canada Open Text Corporation Full time**Principal Security Compliance Analyst**: - Req id: 37918- Virtual, CA Virtual, US**OPENTEXT - THE INFORMATION COMPANY** As the Information Company, our mission at OpenText is to create software solutions and deliver services that redefine the future of digital. Be part of a winning team that leads the way in Enterprise Information Management. **The...
-
Cyber Security Analyst
6 months ago
Remote, Canada Dawn InfoTek Inc. Full timeDawn InfoTek Inc. is a professional IT consulting team that partners with major financial institutions, investment firms and government sectors. We have been dedicated to delivering cutting-edge consulting services and recruiting all levels of IT positions for our clients. We are currently seeking competent individuals to fulfill the role of **Cyber...
-
Network Analyst
5 months ago
Remote, Canada Dacaro Software Services Inc Full time**Network Analyst** **Position Overview**: **Responsibilities**: - Design, implement, and manage the organization's network infrastructure. - Monitor network performance and troubleshoot connectivity issues. - Collaborate with IT teams to ensure the integration of network systems with other technologies. - Evaluate and recommend network hardware and...
-
Intermediate Application Support Analyst, IT
5 months ago
Remote, Canada WestJet Full time**Why WestJet**: Every WestJet journey has the potential to enrich lives; a career with us is no exception. WestJet arrived on the Canadian airline scene in 1996 and changed the industry for the better. We made air travel more affordable for Canadians and now we're going global. **Join us and love where you’re going.** **Remote Work**: This position is...
-
Business Analyst
5 months ago
Remote, Canada eCapital Full time**About Us**: eCapital supports small and mid-sized companies throughout the United States, Canada, and the United Kingdom by providing alternative financial solutions like invoice factoring, factoring lines of credit, and asset-based lending to accelerate their access to capital. Through its Commercial Finance, Freight Factoring and ABL divisions, eCapital...
-
Kyc Analyst
5 months ago
Remote, Canada BlazeSoft Full timeThis is a remote position. As a KYC Analyst, you will play a crucial role in ensuring the integrity and security of our platform. Your responsibilities will include: - Conducting thorough customer risk assessments by meticulously reviewing account documentation and identifying potential risks associated with individual customers. - Collaborating closely...
-
HR Analyst
5 months ago
Remote, Canada VC3 Full timeThe HR Analyst with experience in systems implementation is responsible for supporting the Human Resources Information Systems (HRIS) implementation project while also fulfilling traditional HR Analyst responsibilities. This role involves a dual focus on managing day-to-day HRIS activities, data analysis, and taking a lead role in the successful...
-
Technical Business Analyst
5 months ago
Remote, Canada INVENT.us Full time**About INVENT.us** INVENT is an innovative software development consulting firm founded by industry veteran, Oleg Tishkevich and an elite team of Cloud technologists. Purpose built to assist financial organizations to modernize their advisor technology stack, INVENT is transforming how financial services operate. For years, financial organizations have...
-
IT Helpdesk Analyst
5 months ago
Remote, Canada Flexis Full timeIT Help Desk Analyst will report to the Service Delivery Manager and provide remote technical guidance, assistance, coordination and follow-up on customer questions, problems or malfunctions of all PC, MAC-related, Office 365, Network issues with a goal of first contact resolution. 1+ years of experience working for a Managed Service Provider, MSP or...
-
Servicenow Itsm Techno Functional Analyst
5 months ago
Remote, Canada Compest Solutions Inc Full time**ServiceNow ITSM techno functional Analyst** **(Mobile domain) Business Analyst** **Location: Remote work EST hour** **CAD$90 - 100K/Annum** **Please reply** with your **expected Salary range--** **ServiceNow ITSM techno functional Analyst**, Experience in Requirement gathering for **ITSM and integrations.** Develop and document the ITSM requirements...
-
Clinical Data Analyst
6 months ago
Remote, Canada Pulse Infoframe Full time**Clinical Data Analyst / Visualization Specialist** Pulse Infoframe is a global health technology company focused on cancer and rare/orphan diseases. We believe that medical advances are made when data is shared across boundaries, and we are leaders in Real World Data / Evidence. Our customers include leading global pharmaceutical and biotechnology...
-
National IT Support Analyst
5 months ago
Remote, Canada Baker Tilly Canada Full time**National IT Support Analyst** **Canada**: Current Opportunities Are you an accomplished technology professional who is organized, detail oriented, a great communicator, and comfortable working remotely? Baker Tilly Canada’s National office is hiring a National IT Support Analyst to work as part of our collaborative national team and to proactively...
-
Chief Security Officer
6 months ago
Remote, Canada High Tech Genesis Full timeLocation: Ottawa, ON Canada Hybrid Term: Permanent High Tech Genesis is currently looking to hire a Chief Security Officer (CSO), you will play a pivotal role in safeguarding our organization's assets, mitigating risks, and ensuring compliance with regulatory standards. With your strategic vision and leadership, you will lead our security efforts, from...
-
Manager, Security Operations
6 months ago
Remote, Canada Jobber Full timeJobber exists to help people in small businesses be successful. We work with small home service businesses, like your local plumbers, painters, and landscapers, to transform the way service is delivered through technology. With Jobber they can quote, schedule, invoice, and collect payments from their customers, while providing an easy and professional...
-
Information System Analyst
7 months ago
Remote, Canada Absorb Software Full time"Two years have flown by since I started as an IT Support Analyst at Absorb Software. My role is challenging and rewarding, filled with strategic projects that stretch my technical skills and problem-solving abilities. There's a unique satisfaction in resolving issues for colleagues, making their workdays smoother._ - The people at Absorb truly make it...
-
IT Security and Compliance Manager
5 months ago
Remote, Canada Mogo Finance Technology Inc. Full timeWe are looking for a capable IT Security and Compliance Manager, who enjoys remote security work and possesses both deep and wide expertise in the information security space. The base salary for this role is: $90,000-$130,000 **Job Summary**: As the IT Security and Compliance Manager at Mogo and its subsidiaries, you are entrusted with spearheading the...
-
Operations Coordinator
5 months ago
Remote, Canada Lyrical Security Full time**Responsibilities** Executive Assistant (50%) - Act as a trusted partner to the CEO and executive leadership team, managing an array of administrative tasks and facilitating smooth communication. - Track incoming requests and create a list of daily priorities based on urgency, importance, and deadlines. Follow-up to ensure any delays are communicated to...
-
Technical Business Analyst, Digital Services
5 months ago
Remote, Canada Granicus Inc. Full time**The Company** **Serving the People Who Serve the People** - Granicus is driven by the excitement of building, implementing, and maintaining technology that is transforming the Govtech industry by bringing governments and their constituents together. We are on a mission to support our customers by meeting the needs of their communities and implementing our...