Manager, Global Technology Governance, Risk and Compliance; GRC
Permanent Full Time
The Technology GRC initiative is a strategic program aimed at establishing a Global Governance, Risk, and Compliance (GRC) framework across Great‑West Lifeco on behalf of the Global Information Security Office. As part of the key initiative to implement the Service Now IRM solution, the Information Security & Technology Risk (ISTR) team requires a dedicated manager to ensure the platform effectively supports business, regulatory, and operational needs.
This role will lead cross‑segment alignment, drive automation efforts, and enable the development and reporting of the Global Technology Risk Profile.
- Lead and support the implementation, optimization, and ongoing management of Service Now IRM, ensuring alignment with GRC processes, regulatory expectations, and segment needs.
- Align and evolve information security policies and standards with industry frameworks (ISO 27001/2, COBIT, NIST) and regulatory requirements.
- Partner with Canada, Europe, and US to harmonize governance practices and support consistent adoption of policies, standards, and controls.
- Provide governance expertise and risk‑based guidance to senior leaders, balancing business needs with security considerations to support informed decision‑making.
- Drive change management, communication, training, and stakeholder engagement to support adoption of GRC practices and process workflows.
- Prepare and deliver governance updates, executive presentations, and risk insights for senior leadership and oversight committees.
- Use Service Now IRM to aggregate and interpret enterprise outcome data, including risks, issues, controls, remediation updates, and Key Risk Indicators (KRIs), for Lifeco‑level dashboards, metrics, and reporting.
- Aggregate and analyze segment‑level risk assessment outputs (technology, cyber, operational, regulatory, emerging) to support consolidated oversight.
- Support regulatory engagements (e.g., OSFI), including preparing responses, evidence, and submissions.
- Identify opportunities to streamline and automate GRC processes, reporting, and workflows across segments.
- Contribute to broader information security and technology risk governance activities, including Risk Taxonomy Engineering, Emerging Technology Risk Management, Third Party Risk Assessments, Frameworks and Policy Management, Cybersecurity Maturity, etc.
- 7–12 years of experience in Information Security, Technology Risk, or GRC roles within large complex organizations.
- Degree or Diploma in Information Technology and/or business, or combined relevant field experience and certifications CISSP, CGRC, CISA, CISM, CRISC, CGEIT.
- Experience supporting or implementing Service Now IRM.
- Experience in designing, building, integrating, and maintaining technology products, automation, and data structures that enable an organization’s GRC processes.
- Strong knowledge of frameworks (NIST CSF, ISO 27001, COBIT, CIS Controls) and regulatory expectations (OSFI B‑10, DORA, SOC 2, GDPR).
- Skilled at articulating technical risks in business language and influencing stakeholders across regions, lines of defence, and leadership levels.
- Excellent collaboration skills across global teams and multi‑segment environments.
The base salary for this position is between $119,300 and $169,300 annually. This represents base salary only and does not include other variable compensation components of our total compensation (i.e., annual bonus, commission, etc.). If you are selected to move forward in our recruitment process, your recruiter will be able to discuss additional details of our total rewards program with you.
Career opportunities will be open a minimum of 5 business days from the date of posting; closing dates will vary depending on the search activity. All applications received will be reviewed on a rolling basis.
It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Canada Life policies. To request a reasonable accommodation in the application process, contact talentacq
#J-18808-LjbffrTo Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: