
Security Risk Management Specialist
Posted Jul 20

Posted Jul 20
This is a fully remote position, open to applicants in Canada.
β’ Facilitate the complete IT and security risk management lifecycle, encompassing risk identification, assessment, treatment tracking, and reporting.
β’ Sustain and enhance the enterprise IT/security risk register, ensuring that risks are accurately recorded, evaluated, and assigned to the correct owners.
β’ Conduct risk assessments across various technology domains (cloud infrastructure, access management, application security) and third-party assessments utilizing the suitable methodology for each case.
β’ Collaborate with control owners and business stakeholders to assess the effectiveness of risk mitigation controls and pinpoint any gaps.
β’ Incorporate vendor and technology risk findings into the risk register to streamline tracking and remediation efforts across both IT/Security and Third-Party Risk Management.
β’ Aid in the creation and upkeep of risk policies, standards, and procedures.
β’ Assist in the preparation of risk reports and dashboards for senior leadership and committee-level audiences.
β’ Monitor the threat and vulnerability landscape, aiding in the translation of emerging risks into actionable insights for the organization.
β’ Support security and compliance initiatives, including PCI DSS, SOC 2, and NIST, from a risk perspective, ensuring that risk findings are integrated into broader compliance efforts.
β’ Engage in risk-related work streams associated with new product launches, infrastructure modifications, and strategic initiatives.
β’ 3β5 years of experience in IT risk management, information security, or a related GRC function, preferably in the financial services or fintech sectors.
β’ Comprehensive understanding of IT and security risk frameworks such as NIST CSF, ISO 27001, or FAIR.
β’ Familiarity with essential technology risk domains, including cloud (preferably AWS), identity and access management, and vulnerability management.
β’ Experience in conducting third-party and vendor assessments, with knowledge of due diligence review methodology being an advantage.
β’ Proven experience in maintaining risk registers and supporting risk assessment processes.
β’ Working knowledge of compliance frameworks including SOC 2, PCI DSS, and/or NIST is a significant asset.
β’ Excellent analytical and written communication skills, capable of translating technical risk findings into clear business language.
β’ Comfortable collaborating cross-functionally with both technical and non-technical stakeholders.
β’ Experience with GRC tools and risk management platforms (e.g., Jira, Drata) is beneficial.
β’ Self-motivated individual capable of operating independently, managing competing priorities, and driving tasks to completion.
β’ Relevant certifications are advantageous (CRISC, CISA, CISSP, or equivalent).
β’ Comprehensive health benefits and life insurance coverage.
β’ Long-term group savings plan with employer match, facilitated through Wealthsimple for Business.
β’ 20 vacation days, 4 wellness days, and unlimited sick and mental health days annually.
β’ Opportunity to work outside Canada for up to 90 days each year.
β’ Access to employee resource groups, including Rainbow (2SLGBTQ), Women of WS, and Black at WS.
Staffing For Doctors
Circle
Lincoln Financial
Affirm
Get handpicked remote jobs straight to your inbox weekly.