Manager, Security Governance, Risk and Compliance

4 days ago


Greater Toronto Area, Canada KUBRA Full time

Overview:
KUBRA is seeking a Manager, Security Risk Management and Compliance to lead our Compliance team

What you get to do every day:

- Develop and implement effective and reasonable policies and practices to secure protected and sensitive data, and ensure information security and compliance with relevant legislation and legal interpretation.
- Define and document business process responsibilities and ownership of the controls.
- Schedules regular assessments and testing of effectiveness and efficiency of controls and create GRC reports
- Update security controls and provide support to all stakeholders on security controls covering internal assessments, regulations, protecting Personally Identifying Information (PII) data, and Payment Card Industry Data Security Standards (PCI DSS).
- Lead the development and implementation of the organization-wide risk management function of the information security program to ensure information security risks are identified and monitored.
- Internally assess, evaluate and make recommendations to management regarding the adequacy of the security controls for the Company's information and technology systems.
- Lead the organization-wide information security compliance program, ensuring IT activities, processes, and procedures meet defined requirements, policies and regulations.
- Assist in the develop and implementation of effective and reasonable policies and practices to secure protected and sensitive data and ensure information security and compliance with relevant legislation and legal interpretation and alignment with business objectives.
- Execute strategy for dealing with increasing number of audits, compliance checks and external assessment processes from customers and external auditors relating to effective security & privacy practices, PCI-DSS, ISO 27001/2, SOC 1/2, SOX etc.
- Interacts in both oral and written communications with all levels of Company staff including; IT, HR, engineering, senior leadership, general counsel, auditors, customers, and technology vendors and contractors, in matters related to information security.
- Work with customers, external auditors, and outside consultants as appropriate on required security assessments and audits.
- Coordinate and track all information technology and security related audits including scope of audits, parties involved, timelines, auditing agencies and outcomes.
- Work with auditors as appropriate to keep audit focus in scope, maintain excellent relationships with audit entities and provide a consistent perspective that continually puts the organization in its best light. Provide guidance, evaluation, and advocacy on audit responses.

What kind of person should you be?:

- Ability to interact with a broad cross-section of personnel to explain and enforce security measures
- Excellent writing and verbal communication skills, interpersonal and presentation skills and proven ability to influence and communicate effectively with all levels of staff.
- Successful track record of effective project coordination, prioritization, collaboration, organization, and timely project delivery
- You are proactive and remain informed on evolving industry standards and practices, toward an ability to show forward thinking with new and innovative approaches to security while meeting overarching business objectives
- Ability to manage/oversee both internal and/or external resources, while also being able to nurture talent within assigned team.

What skills do you need?:

- A degree in Information Technology, Computer Science or related field.
- 10+ years of relevant GRC experience
- 5+ years of experience managing security teams
- Extensive experience in security and privacy standards, regulations, and laws e.g., PCIDSS, SOC 1/2, ISO 27001/2, GDPR, PIPEDA, CCPA etc
- Extensive experience in IT risk management practices with a focus on security, performance, and reliability
- Good understanding of current legislation and regulations pertaining to IT security
- Required certifications include: CISM, PCIP, CISA, CISSP

What can you expect from us?:

- Award-winning culture that fosters growth, diversity and inclusion for all
- Paid day off for your birthday
- Access to LinkedIn learning courses
- Continued education with our education reimbursement program
- Flexible schedules
- Two paid days for volunteer opportunities

KUBRA is a fast-growing company that delivers customer communications solutions to some of the largest utility, insurance, and government entities across North America. KUBRA offers billing and payments, mapping, mobile apps, proactive communications, and artificial intelligence solutions for customers. With more than 1.5 billion customer interactions annually, KUBRA services reach over 40% of households in the U.S. and Canada. KUBRA is an operating subsidiary of Hearst.

Our office is small enough to allow creative individuals to flourish, yet large enough to provide long-term stability. We place a tremendous amo


  • Governance, Risk

    2 months ago


    Greater Toronto Area, Canada AutoTrader.ca Full time

    **Summary** Governance, Risk and Compliance is accountable for the design and implementation of Trader Corporation’s GRC Framework that sets out the company's policies, processes and practices as well as executes on the identification, assessment, reporting, mitigation and control of operational and financial crimes risk. As an integral part of the team,...


  • Toronto, Canada Aecon Group Full time

    **Build Your Career at Aecon** Aecon is proud to build some of the most impactful infrastructure projects of this generation. From the roads and transit systems that connect our communities, to the communication networks that link us from coast-to-coast, and the water infrastructure that supplies our businesses and homes. Our integral work includes...


  • Toronto, Canada HashiCorp Full time

    **Manager, Governance, Risk & Compliance**: **About the Role**: We're looking for a GRC manager to lead, develop and mature the commercial compliance (SOC 2 Type 2, ISO 27001/17/18) and policy/controls programs at HashiCorp. This role will be heavily focused on scaling, automating, and managing compliance capabilities across HashiCorp. We're looking for a...


  • Toronto, Canada BMO Financial Group Full time

    250 Yonge Street Toronto Ontario,M5B 2L7 As Governance, Risk and Compliance specialist, you will support the Cyber Security Center of Excellence in the effective implementation, maintenance and administration of first line of defense (1st LOD) programs (e.g., operational risk, compliance, regulatory, etc. Contributes to a strong risk management culture...


  • Old Toronto, Canada Homebase Full time

    About UsAt Homebase, we strive to make hourly work easier for local businesses and hourly shift workers. Our platform serves more than 100,000 small businesses with employee scheduling, time clocks, payroll, team communication, hiring, onboarding, and compliance solutions.We are committed to fostering a welcoming environment where every employee feels valued...


  • Toronto, Ontario, Canada BMO Financial Group Full time

    BMO Financial Group is a leading financial institution committed to making a positive impact in the lives of our customers, communities, and employees. As a key member of our team, you will play a vital role in shaping the future of risk management and governance within our organization.About the RoleAs an Enterprise Risk Manager, Governance and Compliance,...


  • Toronto, Canada Canada Goose Full time

    **_Emplacement _** Toronto Address: 100 Queens Quay East Toronto, Ontario M5E 1V3 Canada Job Title: Manager, Technology Governance, Risk & Compliance Canada Goose isn't like anything else. We've built something great, something special - an iconic lifestyle brand with an inspirational and authentic story. At the heart of it is our promise to inspire and...


  • Toronto, Canada KPMG Full time

    Overview: At KPMG, you’ll join a team of diverse and dedicated problem solvers, connected by a common cause: turning insight into opportunity for clients and communities around the world. Our **Governance, Risk and Compliance Services (GRCS)** professionals provide a range of assurance and advisory services to enhance the efficiency and effectiveness of...


  • Toronto, Canada KPMG Full time

    Overview: At KPMG, you’ll join a team of diverse and dedicated problem solvers, connected by a common cause: turning insight into opportunity for clients and communities around the world. Our **Governance, Risk and Compliance Services (GRCS)** professionals under **Advisory Risk Services** provide a range of assurance and advisory services to enhance the...


  • Toronto, Canada Loopio Full time

    Loopio is a workplace that unleashes learning & growth opportunities for our Loopers. We provide autonomous, challenging work that allows each employee to master their craft. We attract and retain people who are naturally curious, have grit and are eager to grow and build their careers. At Loopio, we genuinely support each other, because true success comes...


  • Toronto, Ontario, Canada Randstad Full time

    Randstad is seeking a highly skilled IT Internal Audit Assistant Manager to join their team. The ideal candidate will have a strong background in evaluating the integration of IT security controls with business systems and processes, ensuring the overall IT security and governance risk/control environment is strengthened for critical production systems used...


  • Old Toronto, Canada TD Bank Full time

    Senior Analyst, Governance & ControlSalary: $76,800 - $115,200 CAD per yearTD Securities' Governance & Control (G&C) team plays a vital role in managing risk across the organization. As a Senior Analyst, you will support all TD Securities businesses in reporting and issue management.The primary responsibilities of this role include:Preparation of monthly,...

  • Goverance, Risk

    3 weeks ago


    Toronto, Canada Teknion Corporation Full time

    The Information Technology Governance, Risk and Compliance Analyst is responsible for assessing and prioritizing risks for cyber security and data protection across the organization while helping Teknion meet its compliance obligations. The incumbent supports the risk mitigation efforts through conducting risk assessments, establishing and maintaining...

  • Manager, Cyber Risk

    7 months ago


    Toronto, Canada Coca-Cola Canada Bottling Limited Full time

    Facility Location - Toronto Employee Type - Regular Employee FT Salaried **About This Opportunity**: **Responsibilities**: - Oversee the risk team and manage additional projects within the cybersecurity division. - Lead the design, implementation, and management of the organization's risk program to ensure compliance with regulatory requirements, in...


  • Old Toronto, Canada Canada Mortgage and Housing Corporation Full time

    Canada Mortgage and Housing Corporation (CMHC) is a leading organization in the field of housing finance. We are seeking a highly skilled Risk Management Specialist - IT Security to join our team.**Job Summary:**The successful candidate will be responsible for assessing and interpreting data to determine the level of risk and other indicators of risk,...


  • Toronto, Canada Norton Rose Fulbright Full time

    Role The information security governance & compliance specialist takes responsibility for overseeing responses to support the client bids and client audit process, and the third-party supplier assessment process. The role is a key part of assuring our clients on the technical security measures NRF has in place for protecting client data. Providing...


  • Toronto, Canada Canada Life Assurance Company Full time

    Manager, Governance and Risk Reporting **Description: - Permanent Full Time- We are looking for a **_Manager, Governance and Risk Reporting._** - The Manager, Governance and Risk Reporting will work closely with the Director, Information Security Management System and Technology Risk Leaders to visualize and influence the governance and oversight of risks,...


  • Toronto, Ontario, Canada Randstad Full time

    About the OpportunityWe are seeking a highly skilled Senior Compliance Analyst to join our team at Randstad.As a key member of our Risk Governance department, you will assist in managing the renewal of various offering documents for SLGI and regulatory projects related to investment industry experience.Key ResponsibilitiesSupporting the Director, Risk...


  • Greater Toronto Area, Canada AutoTrader.ca Full time

    Responsible for overseeing the Cybersecurity function, leading identification, assessment, monitoring, remediation, and reporting of operational risk efforts within TRADER Corporation. The Director of Information Security establishes and administers the strategies and procedures for the information security function. Develops and implements information...


  • Toronto, Canada KPMG Full time

    Overview: At KPMG, you’ll join a team of diverse and dedicated problem solvers, connected by a common cause: turning insight into opportunity for clients and communities around the world. Our **Governance, Risk and Compliance Services** (GRCS) professionals provide a range of assurance and advisory services to enhance the efficiency and effectiveness of...