Senior Governance, Risk & Compliance; GRC) Analyst
Listed on 2026-09-06
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Business Analyst
Ready to build a rewarding career in an industry that is growing?
Who We AreWe are a global mining company dedicated to safely delivering nickel, copper, cobalt, and platinum group metals essential for the world’s energy transition.
Our mission is to improve lives and shape a better future together.
From utensils to cellphones to satellites, our operations simplify daily life and enhance connectivity. Our metals are integral to life‑saving medical equipment and the electric vehicles driving the fight against climate change – our work truly matters.
Join our diverse team of 15,000 talented individuals committed to transforming critical minerals into prosperity and sustainable development in countries like Canada, Brazil, Indonesia, the United Kingdom, and Japan. We invite you to use your skills with us and contribute to something meaningful and enduring.
The OpportunityWe are currently seeking a Senior Governance, Risk & Compliance (GRC) Analyst (Global Cybersecurity) to join our Global Cyber Risk, Governance, Risk & Compliance team in Toronto, Ontario
.
Reporting to the Senior Manager, Cyber Risk, Audit, Compliance & Data Privacy
, you will play a critical role in advancing our global cybersecurity governance, risk management, compliance, audit readiness, privacy governance, and third‑party risk programs.
This role partners with stakeholders across Cybersecurity, IT, Operational Technology (OT), Legal, Privacy, Procurement, Internal Audit, Finance, and Business Operations to assess risk, strengthen controls, support compliance efforts, and provide executive‑ready reporting that enables informed decision‑making across our global organization.
Key Responsibilities Cyber Governance & Control Framework- Support the development, maintenance, and continuous improvement of global cybersecurity policies, standards, controls, and governance processes.
- Align cybersecurity control frameworks with industry standards including NIST CSF, ISO 27001, COBIT, CIS Controls, and ITGC requirements.
- Coordinate governance activities and prepare materials for leadership reviews, risk committees, audits, and executive reporting.
- Promote consistent control ownership, accountability, and evidence management practices globally.
- Lead cybersecurity risk assessments across applications, infrastructure, cloud services, SaaS platforms, identity and access management, OT/ICS environments, and strategic projects.
- Identify control gaps and recommend remediation, compensating controls, and risk treatment strategies.
- Advise project teams and technology stakeholders on integrating cybersecurity requirements into design and implementation activities.
- Prepare risk documentation and executive summaries to support informed business decisions.
- Support internal and external audits, control testing, evidence collection, and remediation tracking activities.
- Coordinate cybersecurity compliance programs and control self‑assessments.
- Monitor regulatory, privacy, cybersecurity, and governance developments and assess their impact on the organization.
- Maintain audit‑ready documentation, risk registers, and management action plans.
- Conduct security and risk reviews of suppliers, contractors, SaaS providers, and managed service partners.
- Evaluate security questionnaires, due diligence assessments, control evidence, and contractual security obligations.
- Partner with Procurement, Legal, Privacy, and Technology teams to strengthen supplier security governance.
- Track supplier risks, remediation commitments, exceptions, and risk acceptance decisions.
- Develop dashboards and reporting on cyber risk posture, compliance status, remediation progress, and control health.
- Translate technical findings into business‑focused insights for leadership and stakeholders.
- Drive improvements in GRC processes, methodologies, reporting, and governance effectiveness.
- Mentor and support stakeholders on cybersecurity risk management and control expectations.
- Minimum 7-10 years of progressive experience in cybersecurity GRC, IT audit, technology risk,…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: