обновлено 5 дней назад
Leader, Governance, Risk & Compliance (Cybersecurity)
150 000 - 180 000CAD
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Leader, Governance, Risk & Compliance (Cybersecurity): Establishing and maturing Interac’s security governance, risk, and compliance program with an accent on ISMS operations, control effectiveness, regulatory alignment, and audit readiness. Focus on managing risk portfolios, closing control gaps, leading incident response and business continuity activities, and developing measurable security KPIs.
Location: Toronto, Canada; flexible hybrid work model
Salary: CAD 150,000–180,000 annually, plus eligibility for a short-term incentive plan
Company
is a Canadian fintech company providing secure digital payments, identity verification, and fraud protection services.
What you will do
- Establish and mature the organization’s Governance, Risk and Compliance mandate, goals, and operating practices.
- Develop, review, and communicate security policies aligned with ISO 27000, NIST, PCI, SOC 2, and other applicable standards.
- Coordinate information security risk management, risk treatment, remediation tracking, control monitoring, and reporting to management committees.
- Support internal and external audits, security certifications, compliance activities, and operation of the Information Security Management System.
- Lead security-related incident response, disaster recovery, and business continuity activities.
- Coach and manage a GRC team while collaborating with Internal Audit, Legal, Enterprise Risk, Data Governance, Privacy, Vendor Management, and business units.
Requirements
- 8–10 years of relevant experience in information systems, law, policy management, information security, or GRC, supported by a degree, diploma, work experience, or certifications.
- Progressive leadership experience in information security governance, risk, and compliance.
- Strong understanding of technology risk, ISO 27000, NIST, PCI, regulatory requirements, and industry best practices.
- Experience implementing an ISMS; ISO 27001 certification experience is beneficial.
- Security certifications such as CISM, CISA, or CRISC.
- Ability to acquire secret clearance, with successful completion of applicable Canadian background checks.
Nice to have
- Experience leading GRC platforms, technologies, and solutions.
- ISO 27001 certification experience.
Culture & Benefits
- Flexible hybrid work model.
- Vacation and wellness days.
- Employer-paid benefits coverage and an employer-funded RRSP program.
- 24/7 confidential employee and family assistance program.
- Pregnancy and parental leave top-up, plus charitable donation matching.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 дней назад
Data Protection Specialist
79 000 - 113 000CAD
12 дней назад
Governance, Risk & Compliance (GRC) Manager (SaaS)
140 000 - 165 000CAD
10 дней назад
Audit Manager, Technology Operations & Security (Cybersecurity)
11 дней назад
DLP Analyst (Cybersecurity)
9 дней назад
Technical Program Management, Guidewire Security (AI)
120 000 - 150 000CAD
10 дней назад
Cyber Defense Analyst – Data Loss Prevention
60 000 - 65 000CAD