IT Security Compliance and Risk Specialist
2 weeks ago
I.T. Solutions
Important Notices & AmendmentsThis position currently falls within our hybrid model, allowing the employee to typically work a minimum of 50% of your time at your regular work location and the other 50% of time at home.
As an employer of choice, Niagara Region offers competitive salaries and benefits, a defined benefit pension plan, a corporate wellness centre, access to the Employee and Family Assistance Program (EFAP), mentorship and training programs, employee recognition programs, and more. In addition, the Region recognizes the value of having flexible work arrangements to support better work-life balance for our employees. Hybrid work arrangements may vary from one employee to another and may also differ in the number of remote workdays. These opportunities remain subject to the alignment of operational needs, business requirements, and customer service expectations.
Temporary DurationApproximate Duration: 12 months
About UsServing a diverse urban and rural population of more than 475,000, Niagara Region is focused on building a strong and prosperous Niagara. Working collaboratively with 12 local area municipalities and numerous community partners, the Region delivers a range of high-quality programs and services to support and advance the well-being of individuals, families and communities within its boundaries. Nestled between the great lakes of Erie and Ontario, the Niagara peninsula features some of Canada's most fertile agricultural land, the majesty of Niagara Falls and communities that are rich in both history and recreational and cultural opportunities. Niagara boasts dynamic modern cities, Canada's most developed wine industry, a temperate climate, extraordinary theatre, and some of Ontario's most breathtaking countryside. An international destination with easy access to its binational U.S. neighbour New York State, Niagara attracts over 14 million visitors annually, as well as a steady stream of new residents and businesses.
At Niagara Region, we value diversity - in background and experience. We are proud to be an equal opportunity employer. We aspire to hire and grow a workforce reflective of the diverse community we serve. By doing so, we can deliver better programs and services across Niagara.
We welcome all applicants For more information about diversity, equity, and inclusion at Niagara Region, Diversity, Equity and Inclusion - Niagara Region, Ontarioor email related questions to To send input on reducing barriers in the current hiring process, please email
For the Region's full employee equity statement, Working at Niagara Region - Niagara Region, Ontario.
While specific qualifications are important for certain roles, we invite individuals from diverse backgrounds to apply. Our recruiters will evaluate your suitability for the role.
Job DescriptionJob Summary
Salary under Review
Reporting to the IT Security Manager, the IT Security Compliance and Risk Specialist is responsible for analyzing, interpreting and developing solutions and strategies to manage the internal and external IT security audits and assessments. Acting as the liaison between potential auditors and technical teams, this role leads conversations with, and collaborates with key invested parties to identify risks and to ensure IT implemented solutions are compliant with corporate policies, regulations, and standards. The role is also responsible for monitoring remediation of audit findings up to completion, as well ensuring any mitigation strategies and security controls for all IT related findings are completed and documented.
Education- Bachelor's degree in Information Technology, Computer Science, related discipline or equivalent combination of education and experience.
- A minimum of 5 years of experience managing IT audits, risk and compliance is required preferably within the public sector or medium to large-sized organization;
- A security certification through an accredited organization
- Addition Information security certifications (CRISC, CISM, CGEIT, CISSP, CCSP or GIAC) are considered an asset
- Experience working with auditors and the evidence collection process
- Knowledge of regulatory and industry standards such as ISO, NIST, COBIT, GDPR and other security frameworks
- Understanding of information systems and networks and all areas of Information Security including data protection, incident management, and vulnerability management
- Experience working with Security training tools, including creating and launching phishing campaigns, and remedial training
- Knowledge of development and management of business continuity and disaster recovery planning
- Previous experience with IT systems threat/risk assessments, IT audits and regulatory compliance such as SOX and GDPR would be an asset
- Experience with cloud security controls and administration such as AWS and Azure would be an asset
Responsibilities
Compliance and Risk Auditing. (40% of time).
- Assesses risks and internal control dependency on systems by identifying areas of non-compliance and evaluating risks related to key technology processes.
- Co-ordinates timely activities as it relates to internal, external and regulatory audit requests including SOX, SOC1, SOC2;
- Conducts and reviews business impact analysis, implements and coordinates disaster recovery planning and disaster recovery exercises where required;
- Conducts risk assessments and supports the invested parties in determining the appropriate treatment of identified risks; identify appropriate action plans for risk remediation;
- Inventory, assess significance, assign accountability, and develop appropriate monitoring for the control environment;
- Conducts IT compliance reviews including user access reviews, risk assessments, control objectives monitoring, and third party assessments;
- Liaises with Information Privacy Assessment Office and identify IT compliance requirements and assist with creation and maintenance and coordinate IT responses to regulatory audits;
- Works with and supports the development of the risk and compliance practice with IT management and the leadership team.
- Assists in the creation and maintenance of the information security risk register, audit requests, and third party consultant/vendor assessments.
- Assist in gathering information asset inventory, including identification and valuation, including any strategies and methodologies around loss scenarios
- Leads complex analysis, develops and generates KRIs/KPIs, validates compliance and develops actionable recommendations.
- Works with and supports the existing IT Security training platforms to identify high risk business users within the organization.
- Conducts information systems controls assessments.
- Reviews and administers the Incident Response Process, and ensures updates to and ongoing assessments are coordinated as required.
- Reviews and actions the latest Indicators/Endpoints of Compromise as required, ensuring issues are addressed in a timely fashion to mitigate any potential attack(s).
- Performs the necessary technical support as required, in order to support the Corporate Security strategy and processes, such as remediation actions and/or tactics that may be deployed as a result of a security scan result.
- Documents, tracks and investigates information security events, requests, and incidents;
- Implements and reviews information security policies, guidelines, procedures, training materials, awareness campaigns, internal bulletins and portal contents.
Development, administration, and implementation of IT risk policies, procedures, guidelines and standards (20% of time)
- Supports the invested parties in understanding and applying IT risks, security best practices and processes framework;
- Performs consultation and development of the IT objectives and requirements of the risk program;
- Partners with IT managers and team members to ensure risk and compliance issues are identified, defined, communicated, and addressed.
- Provides effective mentoring and guidance to other IT personnel and may assist in developing policy, standards and procedures.
- Collaborates in change management communications and processes, with focus on facilitating risk and compliance training for all affected staff.
- Business Continuity and Disaster Recovery program administration including conducting impact assessments, disaster recovery plans development and coordinating disaster recovery exercises;
- Ensures Business Continuity, Disaster Recovery, and Incident Response plans are current, and supporting documentation is actioned by engaging with peers and other business supports where required;
- Assists in conducting tabletop and resiliency exercises with corporate teams.
Perform other related duties and responsibilities as assigned or required.
Special Requirements- In accordance with the Corporate Criminal Record Check Policy, the position requires the incumbent to undergo a Criminal Records Check and submit a Canadian Police Clearance Certificate.
- Must maintain ability to travel in a timely manner to other offices, work locations or sites as authorized by the Corporation for business reasons.
- Regional staff strive to enable the strategic priorities of council and the organization through the completion of their work. Staff carry out their work by demonstrating the corporate values.
Uncover the wonder of the Niagara Region and join a team dedicated to meeting tomorrow's challenges TODAY
Let us know why you would be an excellent team member by submitting your online application.
We thank all candidates for their interest however, only those candidates selected for an interview will be contacted.
We confirm that we do not use AI in screening of applicants, and this position is an existing vacancy.
If you require an accommodation for the application process in accordance with the Ontario Human Rights Code and the Accessibility for Ontarians with Disabilities Act, the alternate formats for contacting us are as follows:
- Email:
- Phone: or
- Bell Relay:
- In-person: Sir Isaac Brock Way, Thorold, ON L2V 4T7 – Human Resources Department
-
Toronto, Ontario, Canada Alquemy Full timeJob DescriptionThis role focuses on Governance, Risk, and Compliance (GRC), involving policy development, risk assessment, compliance audits, and alignment with industry standards and regulations.Key Responsibilities:Governance: Develop, update, and maintain security policies, standards, and procedures. Ensure alignment with frameworks like ISO 27001, NIST,...
-
Security Specialist
3 days ago
Toronto, Ontario, Canada Global Technical Talent, an Inc. 5000 Company Full timePrimary Job TitleSecurity SpecialistAlternate / Related Job TitlesInformation Security SpecialistIT Risk & Governance SpecialistGRC Security SpecialistTechnology Risk & Compliance SpecialistInformation Security Assurance SpecialistLocation & Onsite FlexibilityToronto, ONHybrid(currently 2 days onsite; increasing to 4 days onsite)Contract DetailsPosition...
-
Senior Security Specialist
3 days ago
Toronto, Ontario, Canada Bevertec Full timeSecurity Specialist - SeniorLocation: Up to 3 days onsite Toronto, ONContract RoleMust Haves:Background InformationThe purpose of this request is to acquire a Sr. Security Specialist to support and deliver on multiple initiatives related to Security Governance, Risk and Compliance and Cyber Defence Operations. This includes leading multiple initiatives...
-
Compliance Lead
3 days ago
Toronto, Ontario, Canada TAC Security Full timeRole OverviewThe Compliance Lead will be responsible for building, managing, and scaling within TAC Security. This role is critical to ensuring regulatory compliance, risk governance, and trust assurance across TAC Security programs, including trust frameworks, security controls, and compliance operations aligned with enterprise and AI-driven platforms.The...
-
Governance, Risk
2 weeks ago
Toronto, Ontario, Canada Lyrical Security Full timePosition OverviewWe are seeking a Governance, Risk & Compliance (GRC) Analyst to join our GRC team on a temporary contract through December 2026. This role has the potential to transition to full-time based on performance, business needs, and mutual fit.This entry-level role is ideal for someone with foundational security experience looking to grow in a...
-
Microsoft Security Engineering Specialist
3 days ago
Toronto, Ontario, Canada TekStaff IT Solutions Full timeTitle- Microsoft Security Engineering SpecialistMax Pay rate: $66-80Contract - 6 MONTHSRequired Skills & Qualifications:5+ years of experience in IT security with at least 3 years in hands-on Microsoft security solution implementation.Proven experience deploying and configuring the following Microsoft E5 Security solutions:Microsoft Defender XDR (Endpoint,...
-
Senior Security Specialist
5 days ago
Toronto, Ontario, Canada StafinGo Full timeSenior Security Specialist – Governance, Risk & Compliance (GRC) / Cyber DefenceLocation:Toronto, ON (Hybrid – up to 3 days onsite)Contract Length: 2-3 months to start(with potential extension)Sector:Public Sector / HealthcareA leadingpublic-sector organization in Ontariois seeking a highly experiencedSenior Security Specialistto support multiple...
-
Security Specialist V
1 week ago
Toronto, Ontario, Canada Global Technical Talent, an Inc. 5000 Company Full timePrimary Job Title:Security SpecialistAlternate / Related Job Titles:IT Security SpecialistCyber Security Risk SpecialistTechnology Risk & Controls SpecialistInformation Security ConsultantLocation & Onsite Flexibility:Toronto, ON —Hybrid(2 days onsite initially, moving to 4 days onsite starting February)Office Address:320 Front Street West, Toronto, ONJob...
-
Toronto, Ontario, Canada Marsh Risk Full timeWe're excited to find a talented individual eager to make a meaningful impact and flourish in our dynamic and innovative environment Your journey to success starts here at Marsh McLennan —come join us and be part of something amazingJoin our team as a Senior Specialist in Identity Governance and Administration and play a pivotal role in managing and...
-
Sr IT Security Specialist
6 days ago
Toronto, Ontario, Canada BeachHead Full timeAre you a seasoned security professional ready to make a significant impact in a top-tier financial environment? Apply NowWorking with one of our top financial clients, this role calls for a Security Specialist to lead critical security initiatives, assess risks, and collaborate with stakeholders across the organization to ensure a robust security posture....