Ontario Cannabis Store logo
Ontario Cannabis StorePosted 2 weeks ago

Senior GRC Specialist

$100,000–$120,000 year

On-siteToronto, Ontario, Canada

Full TimeSenior LevelMedium

Job Summary

Develop, maintain, and provide guidance on IT policies, standards, procedures, playbooks, plans, and SOPs to ensure alignment with regulatory requirements and organizational governance frameworks. Coordinate policy reviews, assess control effectiveness, and identify gaps to recommend or implement improvements across the IT risk management program. Execute risk identification, assessment, documentation, monitoring, and reporting, documenting findings in business-friendly language for diverse audiences. Administer compliance activities within the ServiceNow GRC platform, ensuring controls are mapped, documented, attested, and approved while supporting internal and external audits. Prepare assessment reports, present findings to leadership, and facilitate risk discussions with IT, Enterprise Risk Management, and Privacy teams. Monitor compliance coverage, strengthen control effectiveness, and implement new controls where required.

Required Qualifications

  • Bachelor's degree in Information Security, Information Technology, Computer Science, Engineering, or a related field, or an equivalent combination of education and experience
  • 7+ years of progressive experience in Governance, Risk, and Compliance (GRC), Information Security, or a related discipline
  • Experience supporting risk management, vulnerability management, remediation activities, and/or security operations
  • Strong knowledge of governance and security frameworks, including NIST, ISO 27001, CIS Controls, COBIT, and related industry standards
  • Knowledge of Threat Risk Assessment (TRA) methodologies and practices
  • Strong analytical, documentation, communication, and stakeholder management skills
  • Ability to assess risk, communicate complex concepts effectively, and collaborate with technical and business stakeholders
  • Rare, usually within the GTA

Desired Qualifications

  • One or more industry certifications such as CISSP, CISA, CRISC, CISM, GRCP, CGRC, or GIAC
  • CISSP, CGRC, or equivalent advanced security and governance certifications
  • Experience across multiple security domains, including cloud security, security operations, vulnerability management, security architecture, and GRC program administration
  • Experience administering or supporting ServiceNow Integrated Risk Management (IRM/GRC) solutions
  • Advanced TRA experience

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce