Intern - IT Governance, Risk & Compliance
Job in
Windsor, Ontario, N8H, Canada
Listed on 2026-06-02
Listing for:
Tilray Brands
Full Time, Apprenticeship/Internship
position Listed on 2026-06-02
Job specializations:
-
IT/Tech
Cybersecurity, IT Business Analyst, IT Consultant, Information Security
Job Description & How to Apply Below
Duration: June 8 – August 14, 2026
Work Schedule:
5 days/ 8 hours
Tilray Brands, Inc. (“Tilray”) (Nasdaq: TLRY; TSX: TLRY) is a leading global lifestyle and consumer packaged goods company with operations in Canada, the United States, Europe, Australia, and Latin America that is leading as a transformative force at the nexus of cannabis, beverage, wellness, and entertainment, elevating lives through moments of connection. Tilray’s mission is to be a leading premium lifestyle company with a house of brands and innovative products that inspire joy, wellness and create memorable experiences.
Tilray’s unprecedented platform supports over 40 brands in over 20 countries, including comprehensive cannabis offerings, hemp-based foods, and craft beverages.
Internship Summary
The IT GRC Intern will support the organization’s IT Governance, Risk, and Compliance (GRC) program by executing day-to-day activities that ensure IT operations align with business objectives, regulatory requirements, and internal policies. This role is critical in strengthening the organization’s risk posture and compliance readiness, working closely with stakeholders across IT, security, and business units.
Key Responsibilities
Conduct IT risk assessments, identify control gaps, and recommend remediation plans
Maintain and update the enterprise risk register and track mitigation activities
Ensure proper risk is identified and managed throughout Tilray IT environments, systems, applications, and throughout IT Projects
Assist in the design, technical writing, testing, and maintenance of Tilray’s Disaster Recovery, Business Continuity, and other planning efforts
Control Testing & Compliance
Perform IT control testing for frameworks such as SOX, GDPR, PIPEDA, and NIS2
Support internal and external audits by preparing evidence and responding to requests
Monitor compliance with IT policies, standards, and regulatory requirement
Governance & Policy Support
Assist in drafting, reviewing, and maintaining IT policies and procedures
Support awareness and training initiatives to promote a compliance culture
Provide input into the design and implementation of standards, policies, guidelines, and appropriate architectural principles to ensure the company’s cyber security goals continue to be met
Prepare regular reports on risk, compliance status, and control effectiveness for management
Provide insights and recommendations to improve the GRC programme
Work closely with the IT team to ensure that appropriate security guidance is provided to support project delivery
Support a culture of in-depth understanding as to why security testing is required at both business and internal team level
Vendor & Third-Party Risk
Conduct security and compliance assessments of third-party vendors
Track remediation of identified vendor risks
Collaborate with IT and the business to properly consider vendor and risk management in new and on-going projects and endeavors
Work closely with Legal and the business to help review IT specific contractual information
This is a great 3-month paid internship opportunity for third or fourth-year students, as well as new graduates looking for real-world experience.
Qualifications
Bachelor’s degree in Business Administration, or fields relating to Risk Management, Cybersecurity, Information Technology
Familiarity with regulatory frameworks (SOX, GDPR, PIPEDA, NIS2) and industry standards (ISO 27001, NIST, CIS) is considered an asset
Strong analytical and problem-solving skills with attention to detail
Excellent communication skills for engaging with technical and non-technical stakeholders
Proficiency in Microsoft Office Suite of tools is mandatory
Outstanding communication skills written and verbal
Experience in creating information security documentation, policies, and procedures is considered a plus
Experience in IT Disaster Recovery and Business Continuity planning is considered a plus
Ability to build and earn trust of co-workers and clients quickly
Tilray welcomes applications from all qualified individuals and is committed to employment equity and diversity in the workplace. Tilray does not use artificial…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×