IT Governance, Risk, and Compliance Analyst (Quebec City)

IT Governance, Risk, and Compliance Analyst (Quebec City)

13 Sep
|
Jobtailor
|
Quebec City

13 Sep

Jobtailor

Quebec City

Conduct cybersecurity compliance reviews throughout the Lightspeed system lifecycle, including TRR, PDR, CDR, and other program milestones
Gather, analyze, and maintain compliance evidence through interviews, documentation reviews, walkthroughs, and control validation activities
Interpret cybersecurity and regulatory requirements and translate them into actionable compliance activities
Collaborate with Engineering, Product Security, IT, and testing teams to verify cybersecurity controls are implemented and effective
Track compliance activities, findings, remediation efforts, and action items
Support implementation and maintenance of cybersecurity controls required to meet applicable obligations
Monitor changes to cybersecurity standards and regulations and support compliance updates
Prepare and maintain compliance documentation, assessment records, evidence repositories, and reports
Provide guidance to cross-functional teams on compliance requirements, control implementation, and evidence collection
Monitor and report on compliance activities, findings, and risks, escalating significant risks as appropriate
Requirements Diploma or Bachelor's Degree in Computer Science, Engineering, IT, Cybersecurity, or related field, or equivalent experience
3+ years supporting cybersecurity, compliance, governance, risk management, audit, assurance, or information security programs
Experience assessing cybersecurity controls and compliance requirements
Experience with NIST 800-53, NIST 800-171, ISO 27001, CMMC, or similar frameworks




Experience coordinating with technical and business stakeholders
Strong analytical, organizational, and communication skills
Knowledge of cybersecurity governance, risk management, compliance, and control assurance principles
Experience reviewing technical documentation, system designs, security controls, and implementation evidence
Certifications such as CISA, CRISC, Security+, CGRC, or ISO 27001 Lead Auditor are assets
Knowledge of CNSSP-12 or CAIQ is an asset
Experience with GRC, audit management, evidence management, or compliance tracking tools is an asset
Core Competencies Demonstrates expertise in cybersecurity compliance, risk management, and governance, with a solid ability to analyze and implement controls based on frameworks such as NIST and ISO. Proficient in collaborating with cross-functional teams to ensure effective compliance and documentation practices.
Highest-signal resume keywords Cybersecurity Compliance
NIST 800-53
ISO 27001
Risk Management
CISA
Hard Skills Cybersecurity Governance
Compliance Assessment
Control Validation
Technical Documentation Review
Evidence Collection
Soft Skills Analytical Skills
Organizational Skills
Communication Skills
Certifications & Qualifications CISA
CRISC
Security+
CGRC
ISO 27001 Lead Auditor
Industry Keywords Cybersecurity Standards
Compliance Documentation
Control Assurance
Governance Frameworks
Risk Assessment
Tools & Technologies GRC Tools
Audit Management Tools
Compliance Tracking Tools

#J-18808-Ljbffr

📌 IT Governance, Risk, and Compliance Analyst (Quebec City)
🏢 Jobtailor
📍 Quebec City

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: it governance, risk, and compliance analyst (quebec city) / quebec city

Subscribe to this job alert:

Get the latest job offers by email for: it governance, risk, and compliance analyst (quebec city) / quebec city