Governance, Risk, and Compliance
2 weeks ago
Location: Fredericton - Knowledge Park, CanadaIn fast changing markets, customers worldwide rely on Thales. Thales is a business where brilliant people from all over the world come together to share ideas and inspire each other. In aerospace, transportation, defence, security and space, our architects design innovative solutions that make our tomorrow's possible.Fredericton, N.B., (CAN.), HybridPosition SummaryAt Thales, we are proud to work together to imagine innovative solutions that contribute to building a future that is safer, greener and more inclusive. A future that we can all trust. But these technologies don't just come from anywhere. At Thales, it all starts with Human Intelligence. That is why our ambition is to create the best possible experience for you. We strive to create the conditions that enable your growth, to facilitate your work-life balance and daily work, and to broaden your prospects.In Canada, Thales is relied on to innovate for customers with high-stakes goals, critical missions and big ambitions. Our commitment to mastering digital capabilities in Canada strengthens the nation's economy – through high-technology jobs, investments in domestic research and technology, and solutions for the aerospace, defence, digital identity and security sectors.Driven by purpose, values, innovation, and a commitment to building a future we can all trust, Thales Canada seeks to increase digital trust and resilience, offering integrated digital solutions to organizations, mission critical systems and critical infrastructure in both the commercial and the defence community.Thales is seeking an Intermediate levelGovernance, Risk, and Compliance (GRC) Specialistto deliver advisory and hands-on execution across CPCSC, CMMC, ISO 2700x, and other compliance frameworks. This role will lead readiness assessments, design and improve control of environments, guide clients through audits/certifications, and translate complex requirements into pragmatic, business-aligned roadmaps. This role is ideal for a consultant who is comfortable working directly with stakeholders, facilitating workshops, and building sustainable GRC solutions built on customer intimacy.Key Areas of ResponsibilityAdvisory and Client EngagementLead discovery sessions, stakeholder interviews, and workshops to understand business context, scope, and compliance objectives.Translate regulatory and framework requirements into actionable program plans, control designs, and implementation roadmaps.Present findings and recommendations to technical and executive audiences; prepare high-quality client deliverables.Framework Readiness and ImplementationCPCSC: Conduct gap assessments, control mapping, and remediation planning against the applicable CPCSC requirements (or equivalent regional compliance scheme). Provide guidance on scoping, data flows, and evidence requirements.CMMC (v2): Perform NIST SP /CMMC readiness assessments; develop SSPs and POA&ms; define enclaves and scoping; establish evidence collection processes; support clients through RPO/RP-led journeys.ISO 27001/ x family): Build or mature ISMS programs; conduct risk assessments; develop the Statement of Applicability; support internal audits and management reviews; prepare for external certification.Control Design, Testing, and Continuous ImprovementDesign and document policies, standards, procedures, and control narratives aligned to applicable frameworks.Build crosswalks/control catalogs across CPCSC, CMMC, ISO 27001/27002, and related frameworks (e.g., NIST Perform control testing, sampling, and evidence reviews; track remediation and validate closure.Define and operationalize KRIs/KPIs and compliance metrics dashboards.Risk Management and Security GovernanceFacilitate formal risk assessments and treatment plans using recognized methods (ISO 27005, NIST 800-30, FAIR optional).Advise on secure configurations, IAM, vulnerability and patch management, logging/monitoring, and incident response alignment with compliance needs.Support third-party/vendor risk assessments and continuous monitoring activities.Audit and Certification SupportPrepare clients for external audits/assessments; coordinate evidence, walkthroughs, and sampling with assessors/certification bodies.Guide remediation and readiness sprints; develop playbooks for recurring audit cycles.Training and EnablementDeliver targeted training and awareness for control owners, process owners, and stakeholders.Create reusable templates, accelerators, and best practices to scale program delivery.Minimum QualificationsBachelor's degree in Information Security, Information Systems, Computer Science, Risk/Compliance, or related field; or equivalent experience.3–6 years of experience in GRC, cybersecurity compliance, or IT audit, with hands-on work in at least two of: CMMC/NIST , ISO 27001/27002, CPCSC or a similar regional cybersecurity compliance scheme.Demonstrated consulting/advisory experience: client-facing communication, facilitation, slideware, and report writing.Practical knowledge of:CMMC (v2) practices, NIST SP requirements, SSP/POA&M, scoping/enclave concepts, evidence management.ISO 27001:2022 and ISO 27002:2022 controls, ISMS lifecycle, risk assessment, SoA, internal audit, and certification processes.Control design and testing, governance documentation (policies, standards, procedures), and audit readiness.Strong understanding of core security domains: asset/configuration management, access control, vulnerability management, logging/monitoring, business continuity, incident response, and change management.Excellent communication skills and ability to translate technical concepts into business outcomes.Key CompetenciesAdvisory mindset: structured problem-solving, stakeholder management, and clear executive communication.Project delivery: scoping, planning, tracking, and on-time delivery of milestones and artifacts.Analytical rigor: evidence-based assessment, root-cause analysis, and pragmatic recommendations.Collaboration: ability to work with cross-functional teams (Security, IT, Legal, Engineering, Procurement).Adaptability: comfortable with evolving standards and working across multiple client environments.Preferred QualificationsSkills and Abilities:Exposure to additional frameworks/requirements: NIST 800-53, SOC 2, PCI DSS, privacy regimes (e.g., GDPR/CCPA), secure SDLC/DevSecOps integration.Experience working within the defense industrial base or regulated sectors (e.g., aerospace/defense, critical infrastructure, fintech, healthcare).Familiarity with compliance and GRC platforms and ticketing/ITSM tools (e.g., Jira, ServiceNow).Experience building control crosswalks and maintaining control libraries.Comfort with data classification and handling requirements, encryption key management guidance, and cloud security controls (ISO 27017/27018).Education:One or more relevant certifications preferred: CISM, CISA, CISSP, ISO 27001 Lead Implementer/Lead Auditor, CC (for CMMC), CRISC, PMP, or comparable.For CMMC advisory, current/eligible CMMC related credentials (e.g., RP/RPO affiliation, CCP/CCA when applicable) are a plus.Special Position RequirementsSchedule:Core business hours Monday-Friday; eight-hour work-day.Physical Environment:Access to R&D facilities, cyber-ranges, and Cyber Security Operations Centres.Travel:Travel required in supported of customer requirements regionally and nationally. Travel expected 25% of time.Customer Location Based or Site Visits:Travel will be required to customer location.What We OfferThales provides an extensive benefits program for all full-time employees working 24 or more hours per week and their eligible dependents, including the following:Company paid Extended Health, Dental, HSA, Life, AD&D, Short-term Disability, Cancer Care Program, travel insurance, Employee Assistance Plan and Well-Being program.Retirement Savings Plans (RRSP, DCPP, TFSA) with a company contribution and a match to a DCPP, with no vesting period.Company paid holidays, vacation days, and paid sick leave.Voluntary Life, AD&D, Critical Illness, Long-Term Disability.Employee Discounts on home, auto, and gym membership.Why Join Us?Say HI and learn more about working at Thalesclick here.The reference Total Target Compensation(TTC) market range for this position, inclusive of annual base salary and the variable compensation target, is betweenTotal Target Cash (TTC) 89, ,564.53 CAD AnnualThales provides an extensive benefits program for all full-time employees working 24 or more hours per week and their eligible dependents, including the following:Company paid Extended Health, Dental, HSA, Life, AD&D, Short-term Disability, Cancer Care Program, travel insurance, Employee Assistance Plan and Well-Being program.Retirement Savings Plans (RRSP, DCPP, TFSA) with a company contribution and a match to a DCPP, with no vesting period.Company paid holidays, vacation days, and paid sick leave.Voluntary Life, AD&D, Critical Illness, Long-Term Disability.Employee Discounts on home, auto, and gym membership.Thales is an equal opportunity employer which values diversity and inclusivity in the workplace. Thales is committed to providing accommodations in all parts of the interview process. Applicants selected for an interview who require accommodation are asked to advise accordingly upon the invitation for an interview. We will work with you to meet your needs. All accommodation information provided will be treated as confidential and used only for the purpose of providing an accessible candidate experience.This position requires direct or indirect access to hardware, software or technical information controlled under the Canadian Export Control List, the Canadian Controlled Goods Program, the Canadian Industrial Security Program, the US International Traffic in Arms Regulations (ITAR) and/or the US Export Administration Regulations (EAR). All applicants must be eligible or able to obtain authorization for such access including eligibility to the Canadian Controlled Goods Program and able to obtain a Canadian NATO Secret clearance.
-
Compliance Audit Rep
2 days ago
Fredericton, New Brunswick, Canada Merchandising Consultants Associates Full timeMerchandising Consultants Associates Location: North York, ONHours: Flexible, Part-Time Pay: $25 per completed visitEarning Potential: Up-to $375 per shift About MCA MCA is a 100% Canadian owned and operated Merchandising Company that services Retailers and CPG companies across Canada. MCA is currently hiring Retail Compliance Shoppers to visit different...
-
Manager Pipeline Operational Compliance
1 week ago
Fredericton, New Brunswick, Canada Enbridge Full time US$113,500 - US$155,000Posting End Date:December 02, 2025Employee Type:Regular-Full timeUnion/Non: This is a non-union positionWe are looking for a leader to help ensure the safety and integrity of gas transmission pipeline systems. This role is vital in interpreting Federal and State pipeline safety regulations and partnering with multiple departments to maintain full compliance....
-
Scrum Master
1 week ago
Fredericton, New Brunswick, Canada Cosqube Full timePosition: Scrum MasterLocation: Saint John New Brunswick (OR) Moncton/FrederictonDuration: 6- 12 monthsOnsite WorkRole OverviewSeeking an experienced Scrum Master to lead agile delivery for a large-scale data engineering initiative. This role will be pivotal in enabling cross-functional teams to deliver high-quality, compliant, and scalable data solutions...
-
Senior Automation Consultant
2 weeks ago
Fredericton, New Brunswick, Canada Greenlight Consulting Full timeSenior Consultant (Project Manager) Location: Flexible / Hybrid (Canada) Type: Full-time, Consulting Level 3 About usGreenlight was founded on a simple idea: deliver real value wins to our customers and build a culture where great people can do their best workWe've evolved into a trusted partner in intelligent automation, helping organizations reimagine...
-
Digital Health Technical Project Director
2 weeks ago
Fredericton, New Brunswick, Canada Russell Tobin Full timeDigital Health Technical Project Director Location: Fredericton,NB (Onsite)Pay Rate: CAD$100/hr - CAD$110/hrRole SummarySeeking an experienced Digital Health Technical Project Director to lead and oversee the technical delivery of a large-scale Clinical Information System (CIS) transformation program. The role is responsible for coordinating complex...
-
Product Owner
4 days ago
Fredericton, New Brunswick, Canada Anglophone School District Full timeDescriptionAbout the teamService New Brunswick (SNB) is building a new, dynamic team to transform how we deliver IT services across the province. As one of the largest IT employers in New Brunswick, with over 700 technology professionals located across the province, we are dedicated to having an agile, client-focused approach, acting as a strategic partner...
-
ITSM Administrator
3 days ago
Fredericton, New Brunswick, Canada Bulletproof, a GLI Company Full timeWho We AreHeadquartered in Canada with locations across the United States and around the globe with a footprint on six continents, Bulletproof, a GLI company has decades of technology, security, and compliance expertise. Bulletproof's work in the security space has been recognized nationally and globally with Microsoft's global Security Partner of the...
-
Director of Technology
2 weeks ago
Fredericton, New Brunswick, Canada Affinity Full timeJob Description:On behalf of our Healthcare Client, Affinity Healthcare Solutions is looking for a Health Technical Project Director who will lead and manage the technical workstream within a large-scale digital health program. This role ensures seamless integration across technical, clinical, and business streams, driving execution against delivery...
-
Digital Health Technical Project Director
1 week ago
Fredericton, New Brunswick, Canada Anglophone School District Full timeDescriptionService New BrunswickDigital Health Technical Project DirectorSymbioR85-2025/ Open Competition - Pay Band 93 year contract with possibility of extensionFlexible Work Location within New BrunswickAbout the teamJoin Service New Brunswick (SNB) and help shape the future of healthcare in New Brunswick SNB is one of the largest IT employers in the...
-
Digital Health Technical Project Director
2 weeks ago
Fredericton, New Brunswick, Canada Workiy Full timeClient requires a Digital Health Technical Project Director. Requirements Client seeks a resource who demonstrate the following Mandatory Requirements: Education:Bachelor's degree in computer science, Engineering, Health Informatics, or a related field. Experience:Minimum 9 years of progressive leadership experience in health IT or large-scale CIS...