IT audit and GRC Consultant (Toronto)

IT audit and GRC Consultant (Toronto)

09 Aug
|
SPECTRAFORCE
|
Toronto

09 Aug

SPECTRAFORCE

Toronto

Job Title – Security Specialist V

Duration: 6 months (Possibility of extension)

Location: Toronto, ON (Hybrid - 2 days in office but will be going in 4 days eventually)

Scope of Project: Both project and day to day operations

Team Size/Culture: 15ppl

Required Degree/Level of Education:

- University degree or relevant field / equivalent experience.
- CRISC certification or equivalent experience.
- CISA certification or equivalent experience.
- CISSP certification or equivalent experience a plus.

Certifications Required: CISA certification Years of Overall Experience: 10 year plus

Preferred/Ideal Candidate Background: IT Audit and GRC, very strong comms written and verbal

Must-Have Skills:

IT audit - IT Governance Controls and Standards – 10 years

2.) Quality insurance as it relates to remediation plans – 10 years

3.) Very strong comms – written and verbal- key

4.) IT governance experience in information security and controls risk frameworks – 10 Years

1. Experience with assessing evaluation of audit and regulatory remediation – 10 years

1. governance frameworks

7.Team player – collaborate well with other team members
1. Knowledge and experience with various technology tools including, but not limited to, RSA Archer, JIRA, Confluence, Sharepoint, MS Office, Excel. SERVICENOW
2. IOR methodology OR comparable audit validation approaches.

3. Strong auditor mindset
4. Experience developing sample-based test plans – 10 years

5. CISA certification

Soft Skills: 1.) attention to detail

Nice-To-Have

1.) CISSP certification or equivalent experience a plus. – nice to have

Department Overview

Building a World-Class, Diverse and Inclusive Technology Team at Client

We can't afford to be boring. Neither can you. The scale and scope of what Client does may surprise you. The rapid pace of change makes it a business imperative for us to be smart and open-minded in the way we think about technology. Client’s technology and business teams become more intertwined as new opportunities present themselves. This new era in banking does not equal boring. Not at Client, anyway.

Client Global Security & Defense is home to a team of highly valued professionals, who support all Global Technology Solutions related Regulatory and support interactions, which includes business, 2nd, or 3rd LOD led exams. They provide oversight and governance,



independently challenging High / Med severity issues tied to Regulatory, Audit and ORM. Includes issue escalations tied to potential overdue and validation failures, issue support for insight, governance reporting and exams.

Also, provides demand management support assurance functions.

There's room to grow in all of it.

Job Specific Accountabilities

We are looking for someone who is well-versed at providing governance, risk, compliance and issue remediation oversight and control best practices that meet client’s overarching Global Technology Solutions strategy and objectives. The individual will be responsible for partnering with Technology segments to support independent challenge and oversight of issue remediation plans impacting our information security control workplace. Here's some of what you may be asked to perform:

- Lead assessments of audit and regulatory finding remediations required to mitigate risk within technology infrastructure and applications, working with stakeholders across the three lines of defense to ensure effective risk mitigation and remediation
- Provide advice and guidance to Technology segments and Technology Risk Services on various areas requiring subject matter expertise and interpretation: Audit & Assurance Standards; IT Risk Governance Control Frameworks, and GRC (Governance, Risk, and Compliance) frameworks.
- Contribute to the development of mature Governance Oversight & Control practices, through improvement of Risk Identification, Control Design and Operating Effectiveness.
- Identify emerging themes, understand trends, and provide specialized business management advice to senior management and respective teams while raising industry, external and internal, enterprise and business awareness.
- Lead continuous improvement projects, leveraging agile / lean continuous improvement practices/methods that demonstrate sustainable and leading edge solutions (e.g. Artificial Intelligence (AI), Machine Learning (ML), Power BI/Apps, Python, etc.)

Job Requirements





What can you bring to Client? Share your credentials and your relevant experience and knowledge. It helps if you have:

Confidential

Internal

:

Information Security Specialist - Challenge & QA Remediation

- Expert knowledge of IT Audit and Control methodology, IT Governance Controls and Standards, and associated tools to ascertain the quality and effectiveness of technology remediation plans.
- Competencies in technology controls, emerging threats, and technology risk disciplines and practices.
- Strengthen the independent assurance, governance and oversight operations, utilizing lean continuous improvement practices and tools.
- Apply core Agile frameworks (e.g. Scrum, Kanban) to execute operational workplan projects.
- Collaborate with data scientists, engineers, information security specialists, and business stakeholders to align AI initiatives with strategic objectives.
- Ability to train colleagues and team members related to risk and compliance of issue remediations.
- Excellent verbal and written business communication skills; meticulous documentation.
- Ability to manage multiple efforts simultaneously, priority demands and strong organizational skill.
- Ability to effectively interact with individuals across the organization and at various levels (technical, business, Senior & Executive Management).
- Stay current with the latest research and trends in AI/ML and recommend relevant tools, frameworks and methodologies.

Specific Educational Requirements / Accreditations:

- 10+ years as an IT Risk Specialist with relevant experience in governance, risk and compliance management within regulated industries.
- Information Security or technology risk and controls background (financial industry experience a plus).
- IT governance experience in information security and controls risk frameworks (i.e., ITIL, NIST, COBIT).
- Knowledge and experience with various lifecycle methodologies / frameworks, i.e., Agile, Project Management, IT Processes, Risk Management frameworks and process / operations.
- Knowledge and experience with various technology tools including, but not limited to, RSA Archer, JIRA, Confluence, Sharepoint, MS Office, Excel.
- CRISC certification or equivalent experience.
- CISA certification or equivalent experience.
- CISSP certification or equivalent experience a plus.
- University degree or relevant field / equivalent experience.

📌 IT audit and GRC Consultant (Toronto)
🏢 SPECTRAFORCE
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: it audit and grc consultant (toronto) / toronto