Lead Security Analyst, Grc
3 days ago
Cronos Group is an innovative global cannabinoid company with international production and distribution across five continents. Cronos Group is committed to building disruptive intellectual property by advancing cannabis research, technology and product development. With a passion to responsibly elevate the consumer experience, Cronos Group is building an iconic brand portfolio. Cronos Group’s portfolio includes PEACE NATURALS, a global health and wellness platform and adult-use brand Spinach.
The Lead Security Analyst plans, monitors and executes compliance on all Cronos Group’s North American IT controls in alignment with requirements from the Security Operations Center (SOC). They play a critical role in identifying, escalating, and guiding remediation efforts with a heavy focus on continuous improvement in control processes.
**What you'll be doing**:
- Lead and execute the annual internal NIST CSF risk assessment
- Develop and implement a risk register process; perform quarterly risk register reviews and manage and monitor remediation and exceptions of risk
- Perform third party vendor security risk assessments
- Perform ITGC and NIST CSF security controls review, testing, and validation
- Initiate and assist with semi-annual and annual user access reviews for SAP, collecting evidence of necessary approvals to verify access levels are provided appropriately
- Drive a continuous improvement mentality, identifying opportunities to improve, standardize, and strengthen internal controls and compliance
- Build and maintain strong partnerships throughout the business to proactively identify existing and emerging risks and develop and update internal controls and corresponding documentation
- Collaborate with process owners to ensure controls testing is executed timely and accurately including updating master data files, evaluating test results, and developing remediation plans as needed In partnership with the Director, GRC and Internal Audit team, support efforts to raise awareness and knowledge of internal controls throughout the company, providing training to employees related to their controls responsibilities
- Perform user account reviews and privileged account reviews
- Develop and report metrics to measure the effectiveness of the GRC program
**You’ll need to have**:
- Bachelor's degree in information security, technology, risk management, business management or other related field
- 7+ years of IT audit, risk management, technology, compliance or other directly related experience
- In-depth knowledge in various key areas including Information Security, Identity and Access Management, Data Governance, Application Development and IT infrastructure principles, policies and procedures
- Knowledge of data and cyber technical control formation and implementation practices
- Knowledge of regulatory frameworks such as SOX, SOC 2, SEC, HIPAA, PCI and GDPR
- Experience using GRC tools such as AuditBoard to execute and manage audits, risk assessments, vendor security assessments, and risk register reviews Knowledge of industry security frameworks such NIST CSF, ISO 27001, and HITRUST CISA or CRISC certification highly desired
- Working knowledge with enterprise solutions including SAP and Onestream a plus
- Exceptional communication skills to articulate technical possibilities and limitations of systems to non-technical colleagues
- A knack for identifying and tackling “hard problems”, thinking creatively, and getting things done. You stay current on technology and are passionate about figuring out how to make processes, systems, functions, and experiences better
- Roll up the sleeves attitude with comfort transitioning between tactical execution and strategic thinking
- Capable of building trust with stakeholders, positioning yourself as a trusted advisor to your business partners
- Sound decision making skills; can swiftly assess risks, analyze complex situations and determine next course of action
- Adaptable and organized; capable of managing efforts and dynamically prioritizing multiple work-streams with a positive attitude
-
Principal Grc Technology Analyst
1 week ago
Remote, Canada opentext Full time**OPENTEXT - THE INFORMATION COMPANY** As the Information Company, our mission at OpenText is to create software solutions and deliver services that redefine the future of digital. Be part of a winning team that leads the way in Enterprise Information Management. **Life At Opentext** At OpenText and in IT, we believe in every employee having meaningful,...
-
Security Analyst
3 days ago
Remote, Canada Resolute Technology Solutions Inc Full time**About us** Resolute is a Full-Service IT firm with a multi-disciplined team that can handle every aspect of business IT. The two sides of our business are Professional Services and Managed Services. We are a trusted partner for growing, mid-sized, and enterprise organizations to enable them to achieve their business goals to scale up operations, reduce...
-
SAP Security Consultant
3 days ago
Remote, Canada Excel Gens Consulting services Full timePosition: SAP Security Analyst (Mid–Senior Level)Location and Work model : Remote, CanadaType: Full-Time / ContractRole OverviewWe are looking for SAP Security professionals with strong hands-on experience in RBAC (Role-Based Access Control) and SoD (Segregation of Duties). These resources will be responsible for designing and maintaining secure role...
-
Principal Security Compliance Analyst
5 days ago
Remote, Canada Open Text Corporation Full time**Principal Security Compliance Analyst**: - Req id: 37918- Virtual, CA Virtual, US**OPENTEXT - THE INFORMATION COMPANY** As the Information Company, our mission at OpenText is to create software solutions and deliver services that redefine the future of digital. Be part of a winning team that leads the way in Enterprise Information Management. **The...
-
Intermediate Security Analyst
7 days ago
Remote, Canada Devengine Full timeIntermediate Security AnalystRemote - Canada | Permanent / Full TimeOur client in Toronto, a financial services organization, is seeking a Security Analyst to help protect the organization's information systems and data by operating security controls, monitoring threats, leading incident response, and supporting compliance in a regulated environment....
-
IT Cyber Security Analyst
1 week ago
Remote, Canada KF Aerospace Full time**IT Cyber Security Analyst** **We’re all about the craft.** KF Aerospace is proud to deliver innovative aircraft services for corporate, commercial, and military customers worldwide. Launched in 1970 out of British Columbia’s beautiful city of Kelowna, KF Aerospace has grown to specialize in a wide range of aviation services including maintenance and...
-
Security Engineer I
2 weeks ago
Remote, Canada Cision Full timeAt Cision, we believe in empowering every individual to make an impact. Here, your voice is heard, your ideas are valued, and your unique perspective fuels our collective success. As part of our global team, you'll thrive in an environment that champions curiosity, collaboration, and innovation, all while making meaningful contributions to the brands we...
-
Governance, Risk, and Compliance
2 weeks ago
Remote, Canada Wellstar Full timeWho we areAt WELLSTAR, we are committed to reshaping Canadian healthcare by leveraging technology to address the administrative burdens that pull physicians away from their true calling—patient care. Our mission is focused on supporting providers and patients, shifting the emphasis back to quality, time, and positive outcomes. With a comprehensive suite of...
-
Remote, Canada Maplesoft Group Full timeTitleSenior IT Security Threat and Risk Assessment AnalystLocationRemote, within CanadaStart Date LanguageEnglishSalaryNegotiableSecurity ClearanceEnhanced Reliability ClearanceDuration4 MonthsDate Posted Job ID14032Recruiter EmailMaplesoft Group is currently seeking a Remote Senior IT Security Threat and Risk Assessment Analyst for our Federal Government...
-
Governance, Risk, and Compliance
7 days ago
Remote, Canada Wellstar Full timeWho we areAt WELLSTAR, we are committed to reshaping Canadian healthcare by leveraging technology to address the administrative burdens that pull physicians away from their true calling—patient care. Our mission is focused on supporting providers and patients, shifting the emphasis back to quality, time, and positive outcomes. With a comprehensive suite of...