Information Security Consultant
Hybrid · Toronto, Ontario, Canada or Waterloo, Ontario, Canada
Job Summary
Information Security Consultant to lead Risk Control Self Assessments (RCSA) and Risk Governance across technology, data, and information/operational risk. Responsibilities include designing and testing controls, performing internal control testing for RCSA and regulatory/audit activities, coordinating data analytics and compliance monitoring, identifying gaps and remediation needs, driving process improvements, and serving as an internal SME for escalations and governance reporting. Requires knowledge of risk programs, regulatory standards, and tools such as Archer, ServiceNow, or Fusion; familiarity with ISO/NIST/COBIT/CSA/CCM and OSFI; experience with AI/automation and continuous monitoring; and ability to communicate effectively with senior technology/data leaders.
Required Qualifications
- 3-5 years of experience in Information Risk, Technology Risk, Cyber Risk, GRC, or Operational Risk
- Experience performing independent L1B oversight or audit-style review activities
- Strong understanding of technology, data, cloud, infrastructure, and operational resilience risks
- Ability to evaluate complex risk scenarios
- Experience with risk programs (RCSA, third-party risk, issues, incidents, BC/DR, change risk)
- Familiarity with GRC platforms such as Archer, ServiceNow, or Fusion
- Knowledge of regulatory frameworks and standards (ISO, NIST, COBIT, CSA/CCM, OSFI, etc.)
- Exposure to Generative AI, Agentic AI, automation tools, or continuous monitoring technologies
Apply with one swipe on Sorce. We auto-fill applications and apply on your behalf — no cover letters, no 40-minute forms.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.