Security GRC Specialist
Listed on 2026-07-31
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Business Analyst, IT Support
At Aviso, we are dedicated to improving the financial well-being of Canadians. As a leading wealth management organization, we are committed to leadership, innovation, partnership, responsibility, and community. Working with talented and energetic professionals who exemplify our values every day, you will quickly notice that our people and dynamic ‘oneaviso' culture sets us apart. If you are looking for interesting and challenging work, at a company committed to its people, find out more about what Aviso has to offer at
The OpportunityWe’re looking to fill an opening with an experienced Security GRC Specialist to join our growing Security GRC team.
Reporting to the Director of Security Governance, Risk & Compliance (GRC), the Security GRC Specialist will be responsible to govern the risk management lifecycle, including monitoring findings remediation, assurance programs and reporting appropriate metrics to the senior leadership.
One Aviso- We Care
- You do the right thing for clients, partners and colleagues. You build trusted relationships, champion service excellence, and contribute to a culture where people feel valued and supported - We Dare
-You challenge the status quo with bold ideas and fresh perspectives. You embrace change, seek opportunities to innovate and are comfortable exploring new ways of working - We Share
- You collaborate openly and build meaningful relationships. You seek out diverse perspectives, share your knowledge and work together to help colleagues, clients and partners succeed - We Deliver
- You take ownership of your work, honour your commitments and focus on delivering meaningful results. You hold yourself accountable and continuously look for ways to improve
Risk Management
- Conduct risk assessments of IT infrastructure, applications, third parties, and critical processes to identify, assess and report on technology and cybersecurity risks
- Track and Manage mitigation plans and ensure timely resolution
- Support the development and maintenance of cybersecurity risk register KPI monitoring and reporting
- Assist in development, review and maintenance of Technology & Cybersecurity Policies, Standards, and procedures
- Ensure alignment of internal policies with industry frameworks (NIST, ISO, COBIT)
- Support audits and board level reporting including preparing key metrics
- Monitor compliance with external regulatory and internal control requirements
- Support internal and external audits
- Conduct periodic control testing including design and operating effectiveness
- Support vendor risk assessments, including reviewing response to questionnaire
- Maintain and enhance governance process through GRC tools (e.g., Archer, Service Now GRC, Resolver etc.)
- Support reporting, dashboard creation and automation of risk and compliance processes
- Bachelor's Degree in Information Security, Computer Science, Business, Risk Management or a related field
- Relevant certifications such as CRISC, CISA, CISSP are an asset
- 5-8 years of experience in IT risk, cybersecurity risk, audit, compliance or equivalent roles
- Working knowledge of IT governance frameworks and standards (e.g., NIST CSF, ISO 27001, ITIL)
- Familiarity with regulatory and compliance requirements
- Experience with GRC platforms and tools
- Ability to work in a fast-paced environment and stay updated on emerging threats and vulnerabilities
- Proactiveness, natural curiosity, a willingness to learn, adaptability in an evolving environment, and a strong problem-solving mindset
- Ability to work across multiple business units and collaborate across teams
- Fluent communication skills in English are required and bilingual skills in French are an asset
- Competitive compensation package that rewards and recognizes individual contributions
- Excellent health, dental and insurance benefits to meet the diverse needs of our employees
- Generous vacation time, fitness benefit, parental leave top-up options
- Matching contributions to our retirement program
- Commitment to the continuous improvement of our staff through learning & development and an education assistance program
- Regular social…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: