06 Sep
|
Resonaite
|
Toronto
Our client is seeking a contract based Senior IT Governance, Risk & Compliance (GRC) Manager to support the transformation of its IT GRC operating model.
This role is responsible for IT governance, modernizing the controls setting, improving risk-to-control alignment, and creating stronger integration across IT Risk, Enterprise Risk Management, Internal Controls, Internal Audit, Compliance, and Policy Management.
The successful candidate will combine hands-on GRC expertise with strong execution, organization, learning agility, and stakeholder management skills. They will lead key initiatives, navigate ambiguity, influence stakeholders across the organization, and help establish a more integrated and proactive approach to GRC and risk-informed decision making.
Location: Toronto - onsite
Duration: 16 months
Responsibilities
- Support the development, operationalization, and continued maturity of the organization’s IT Governance framework.
- Lead and support the next phase of the Controls Modernization program, including rationalizing and improving the IT control environment.
- Strengthen risk-to-control mapping and improve traceability across risks, controls, compliance requirements, attestations, and audit findings.
- Identify key controls and improve control ownership, accountability, documentation, monitoring, and reporting.
- Drive stronger integration between IT Risk Management, Enterprise Risk Management, Internal Controls, Internal Audit, Compliance, and other assurance functions.
- Lead and coordinate IT Governance awareness and adoption initiatives across the organization.
- Improve IT policy administration, including policy lifecycle management, governance,
ownership, reviews, approvals, and compliance monitoring.
- Develop reporting, metrics, and management insights that increase visibility into the organization’s IT risk and control environment.
- Identify GRC process gaps and develop practical future-state processes and improvements.
- Lead medium-to-large GRC initiatives from planning and stakeholder alignment through execution and implementation.
- Facilitate workshops and working sessions with technology, risk, compliance, controls, audit, and business stakeholders.
- Build trusted relationships and provide guidance to stakeholders ranging from practitioners and managers to senior executives.
- Develop governance documentation, procedures, templates, guidance, and knowledge-transfer materials to support sustainable adoption.
- Help evolve the organization toward an integrated GRC operating model that enables better governance and risk-informed decision making.
Requirements
- 8+ years experience in IT Governance, Risk & Compliance (GRC), including IT risk management, controls, compliance, and policy administration.
- Demonstrated experience leading medium-to-large IT governance, risk, controls, or transformation initiatives.
- Strong experience with IT control design, assessment, rationalization,
documentation, ownership, monitoring, and remediation.
- Experience with controls modernization and strengthening risk-to-control mapping and traceability.
- Experience developing, implementing, or operationalizing IT governance frameworks, processes, accountabilities, and decision structures.
- Experience integrating risk management with controls, compliance activities, attestations, audit findings, and enterprise risk processes.
- Experience with IT policy governance and policy lifecycle management.
- Strong understanding of recognized industry frameworks and practices, including COBIT and NIST.
- Working knowledge of COBIT 2019 is highly desirable but not mandatory.
- Understanding of Enterprise Risk Management, Internal Controls, Internal Audit, Compliance, and their relationship with IT GRC.
- Experience developing GRC reporting, metrics, dashboards, and management-level insights.
- Strong stakeholder management, influencing, facilitation, and communication skills, including experience working with senior leadership.
- Highly organized and detail-oriented with the ability to manage multiple priorities and navigate ambiguity.
- Strong learning agility with the ability to quickly absorb new concepts, processes, frameworks, and organizational requirements.
- Demonstrated ability to drive change and deliver results across cross-functional teams without relying solely on formal authority.
- Relevant certifications such as COBIT, CRISC, CISA, CGEIT, CISSP, or equivalent governance, risk, cybersecurity, or audit certifications are considered assets.
📌 IT GRC Manager (Toronto)
🏢 Resonaite
📍 Toronto