GRC Risk Consultant

4 weeks ago


Ottawa, Ontario, Canada VenorTalent Full time
Venor is proud to partner with Prevalent in their search for a GRC Risk Consultant. Named a 2022 Gartner Peer Insights Customers' Choice for IT Vendor Risk Management Tools, Prevalent's Canadian engineering team is growing in response to record-breaking growth. The Prevalent Third-Party Risk Management (TPRM) platform is a unified SaaS solution that combines automated, standardized risk assessment with continuous risk monitoring, assessment workflow, and remediation management across the entire third-party lifecycle. Their software and services enable you to eliminate the security and compliance exposures that come from working with vendors, suppliers, and other third parties – from sourcing to offboarding.

With over 120 employees between the US, UK, and across Canada, the ideal candidate will work in a hybrid-remote-first work environment from Ottawa, Ontario.

Prevalent is seeking a highly skilled GRC Risk Consultant with extensive experience in ISO 27001, NIST, SOC 2, and other related risk frameworks. The ideal candidate will have a strong background in information security, risk assessment, and compliance, and will advise clients on best practices to mitigate risks and ensure compliance with relevant standards. As a Risk Consultant, you will conduct risk assessments and gap analyses using frameworks like ISO 27001, NIST, and SOC 2, while developing and maintaining information security management systems (ISMS) to meet ISO 27001 standards. You will also guide clients through the implementation of NIST frameworks (CSF, SP 800-53), SOC 2 Trust Service Criteria, SOC1, HITRUST, and ESG standards.

Key responsibilities include:

- Performing security and risk audits.
- Creating reports for client third parties.
- Developing content for surveys related to Information Security, ESG, and Financial and Business frameworks.
- Developing customized risk management strategies.
- Monitoring the effectiveness of security controls.
- Staying up-to-date with industry trends.

While the role is 80% home-based remote work, there will be occasional requirements for onsite visits or office attendance in Ottawa, as well as collaboration with teams to integrate risk management into business operations.

What we are looking for:

- Bachelor's degree in Information Security, Computer Science, or a related field. Advanced degree preferred.
- Professional certifications such as CISSP, CISM, CRISC, or similar are highly desirable.
- Minimum of 5 years of experience in risk management, information security, or compliance consulting.
- In-depth knowledge of ISO 27001, NIST CSF, NIST SP 800-53, SOC 2, and other relevant frameworks and standards.
- Proven experience in developing and implementing ISMS and cybersecurity frameworks.
- Strong analytical, problem-solving, and decision-making skills.
- Excellent communication and presentation skills, with the ability to explain complex concepts to non-technical stakeholders.
- Ability to manage multiple projects and meet deadlines in a fast-paced environment.
- High level of integrity, professionalism, and attention to detail.

What's in it for you:

- Hybrid Working Model with 80% home-based work
- Unlimited PTO
- RRSP matching
- Health and dental coverage
- A talented team of peers and leaders to collaborate with and learn from
- Personal and professional growth opportunities

At Venor, we embrace a culture of belonging in the workplace. No matter who you are, where you're from, how you think, what you believe in, or who you love, we welcome your application. We all come from different backgrounds and different walks of life, bringing in unique perspectives and experiences. We encourage applications from 2SLGBTQ+, Black, Indigenous, and People of Colour (BIPOC), women, newcomers to Canada, and people with disabilities. If you require any accommodation in the application and interview process, please let us know (including different materials or otherwise).
For more information on this exciting opportunity, please reach out to Craig Coady at craig@venor.ca or Anna Bryant via anna@venor.ca.

#J-18808-Ljbffr
  • GRC Operations Lead

    2 days ago


    Ottawa, Ontario, Canada Barracuda Networks Full time

    Job DescriptionBarracuda Networks is seeking a GRC Operations Lead to support the development of global compliance initiatives. The ideal candidate will lead compliance-focused programs, collaborate with cross-functional teams, and define strategies to ensure adherence to regulatory requirements.Key ResponsibilitiesDevelop and implement compliance-related...


  • Ottawa, Ontario, Canada Resolver, a Kroll Business Full time

    Risk Intelligence Expertise Wanted    As a key member of our Governance, Risk & Compliance (GRC) Sales team, you will be responsible for driving business growth through strategic sales planning and execution. Your expertise in risk management and compliance solutions will help us deliver exceptional value to our clients.


  • Ottawa, Ontario, Canada Malleum Full time

    About Us We are a premier cybersecurity consultancy, blending advanced offensive and defensive strategies to safeguard our customers.With a team known for its contributions to cybersecurity research at platforms like Black Hat and DEF CON, we excel at identifying and mitigating sophisticated threats.Large enterprises from a range of industries trust us for...

  • Senior GRC Analyst

    3 days ago


    Ottawa, Ontario, Canada Barracuda Networks Full time

    Job ID 25-602Come join our passionate team Barracuda is a leading cybersecurity company providing complete protection against complex threats. Our platform protects email, data, applications, and networks with innovative solutions, and a managed XDR service, to strengthen cyber resilience. Hundreds of thousands of IT professionals and managed service...


  • Ottawa, Ontario, Canada Barracuda Networks Full time

    About the RoleBarracuda Networks is seeking a highly experienced Compliance Risk Manager to join our Security team. As a key member of the team, you will be responsible for leading compliance-focused programs and ensuring adherence to regulatory requirements.ResponsibilitiesCollaborate with cross-functional teams to integrate compliance requirementsDevelop...


  • Ottawa, Ontario, Canada Hydroone Full time

    Hiring at Hydroone Solutions, we need a skilled Cybersecurity and Risk Management Lead. The position involves overseeing the broader GRC function and driving structure for the team.This leadership role requires strong expertise in information security, risk assessment approaches, control testing activities, and maturity frameworks across multiple...


  • Ottawa, Ontario, Canada Nexus Systems Group Inc. Full time

    Nexus Systems Group Inc. is seeking a Risk Management Consultant to help us navigate the complex landscape of regulatory compliance. As a key member of our team, you will work closely with stakeholders to identify risks and develop strategies to mitigate these risks.About the Role:This is an exciting opportunity to join a dynamic team and contribute to the...


  • Ottawa, Ontario, Canada Moneris Solutions Corp Full time

    Senior Enterprise Risk Management Specialist (ERM, Hybrid)Apply locations Toronto Montreal time type Full time posted on Posted 3 Days Ago job requisition id JR104725Your Moneris Career - The OpportunityYou will develop, implement, and maintain Moneris' enterprise risk management program including frameworks, policies, standards, procedures, risk assessment...


  • Ottawa, Ontario, Canada ipss inc. Full time

    Division: Office of the Chief Information Security OfficerSalary Range: $122,305 to $163,639Work Location: 55 John Street, TorontoJob Type: Permanent Full TimeShift Information: Monday to Friday, 35 hours work weekJOB SUMMARY:To provide expert guidance, advice, and operational support for the City's cyber risk management program, ensuring robust protection...


  • Ottawa, Ontario, Canada ENGINEERINGUK Full time

    Inspirational, innovative and entrepreneurial - this is how we describe our empowered teams. Combine your passion with purpose and join a culture that is thriving in the face of change.Make an impact with our Enterprise Risk – IT Audit team as a Consultant. This diverse team of professionals utilizes leading-edge industry knowledge to assist clients in...


  • Ottawa, Ontario, Canada Hydroone Full time

    Company OverviewAcronym Solutions is a full-service information and communications technology company that provides scalable and secure solutions. With extensive experience in managing mission-critical systems, we understand the needs of businesses. We deliver innovative services to support rapid growth and digital transformation.Job DescriptionAs a key...


  • Ottawa, Ontario, Canada Behavox Full time

    About Behavox:Behavox is shaping the future for how businesses harness their most important raw material - data. Our mission is bold: Organize enterprise data into actionable information that protects and promotes the business growth of multinational companies around the world.From managing enterprise risk and compliance to maximizing revenue and value, our...


  • Ottawa, Ontario, Canada Nexus Systems Group Inc. Full time

    About this Role:\We are seeking an Operational Risk Management Consultant to join our team at Nexus Systems Group Inc. As a Business Analyst with 10+ years of experience, you will play a critical role in managing operational risk and ensuring compliance with regulatory requirements. Your primary responsibility will be to lead the implementation of trade...


  • Ottawa, Ontario, Canada Manulife Financial Full time

    At Manulife Financial, we are committed to delivering exceptional customer experiences through our Underwriting team. We are seeking highly skilled and experienced Senior Underwriting Consultants to join our High Net Worth team.We offer a comprehensive training program that will help you develop your skills and expertise in underwriting. Our team is...


  • Ottawa, Ontario, Canada Barracuda Networks Full time

    About Our TeamBarracuda Networks is committed to a candidate selection process and work environment that is inclusive and barrier-free. We are seeking a highly experienced Regulatory Compliance Expert to join our Security team.ResponsibilitiesCollaborate with cross-functional teams to integrate compliance requirementsDevelop and implement compliance-related...


  • Ottawa, Ontario, Canada Resolver, a Kroll Business Full time

    Job Description:We're looking for a talented sales professional to join our Resolver team as an Account Executive. In this role, you'll have the opportunity to drive sales growth, expand our customer base, and work closely with internal stakeholders to develop business cases and proposals.Responsibilities:Consultative and conceptual selling to drive revenue...


  • Ottawa, Ontario, Canada Barracuda Networks Full time

    Job OverviewBarracuda Networks seeks a seasoned Cybersecurity Governance Specialist to support the development of global compliance initiatives. The ideal candidate will lead compliance-focused programs, collaborate with cross-functional teams, and define strategies to ensure adherence to regulatory requirements.Key ResponsibilitiesConduct detailed risk...


  • Ottawa, Ontario, Canada S&P Global Full time

    About the Role: Grade Level (for internal use): 08 The Team: Financial Risk Analytics (FRA) delivers enterprise risk solutions to some of the largest firms in the financial services industry, and is part of S&P Global, a dynamic entrepreneurial company listed on the New York Stock Exchange. FRA is currently investing in their technology platform to...


  • Ottawa, Ontario, Canada TD Bank Full time

    Job Summary:We are seeking an experienced Information Security Specialist to join our team at TD Bank. This role will be responsible for managing security incidents, providing technical expertise, and overseeing project consultations. The ideal candidate will have a strong technical background, excellent communication skills, and the ability to work...


  • Ottawa, Ontario, Canada TD Bank Full time

    Job DescriptionThis Senior IT Risk Manager position is responsible for overseeing and managing a team of experts in technology risk management. The job involves providing technical expertise and consultation to partners and/or stakeholders on a broad range of Technology Controls / Information Security programs / policies / standards and incidents for own...