обновлено 5 дней назад
Leader, Governance, Risk & Compliance (Fintech)
150 000 - 180 000CAD
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Leader, Governance, Risk & Compliance (Fintech): Establishing and maturing an enterprise GRC program for a Canadian digital payments platform with an accent on information security risk, regulatory compliance, and control effectiveness. Focus on implementing ISMS and security frameworks, managing audits and remediation, strengthening business continuity, and leading a GRC team.
Location: Toronto, Canada; flexible hybrid work model
Salary: CAD 150,000–180,000 annually, plus eligibility for a short-term incentive plan.
Company
operates a Canadian digital payments and identity verification network with secure payment, fraud protection, and financial ecosystem services.
What you will do
- Establish and mature the enterprise Governance, Risk & Compliance mandate, goals, policies, standards, and reporting metrics.
- Lead information security risk management, including risk treatment, remediation tracking, risk portfolio reporting, and control-gap reduction.
- Operate and maintain the Information Security Management System and support alignment with ISO 27000, NIST, PCI, SOC 2, and ISO 27001 requirements.
- Coordinate internal and external audits, security certifications, compliance activities, and continuous control monitoring.
- Provide leadership for incident response documentation, disaster recovery, and business continuity activities related to security standards.
- Coach and manage the GRC team while collaborating with Internal Audit, Legal, Enterprise Risk, Data Governance, Privacy, Vendor Management, and business units.
Requirements
- Degree, diploma, or equivalent relevant experience and certifications, with 8–10 years of experience in information systems, law, or policy management.
- Progressive leadership experience in information security Governance, Risk & Compliance.
- Experience implementing an ISMS; ISO 27001 certification experience is beneficial.
- Strong knowledge of technology risk, regulatory requirements, and frameworks including ISO 27000, NIST, and PCI.
- Security certifications such as CISM, CISA, or CRISC, along with strong communication, writing, analytical, and problem-solving skills.
- Ability to acquire secret clearance.
Nice to have
- Experience leading GRC platforms, technologies, and solutions.
- ISO 27001 certification experience.
Culture & Benefits
- Flexible hybrid work model.
- Vacation and wellness days, employer-paid benefits, and a funded RRSP program.
- 24/7 confidential employee and family assistance program.
- Pregnancy and parental leave top-up.
- Charitable donation matching and an inclusive, collaborative work environment.
Hiring process
- Successful candidates complete background checks, which may include Canadian criminal, identity, employment, education, credit, and social media verification.
- Accommodation is available during the application and recruitment process.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
12 дней назад
Governance, Risk & Compliance (GRC) Manager (SaaS)
140 000 - 165 000CAD
5 дней назад
Data Protection Specialist
79 000 - 113 000CAD
10 дней назад
Audit Manager, Technology Operations & Security (Cybersecurity)
Mercury
11 дней назад
Senior Cloud Security Engineer - InfoSec (Fintech)
166 600 - 208 300$
9 дней назад
Technical Program Management, Guidewire Security (AI)
120 000 - 150 000CAD
11 дней назад