GRC Analyst – Cybersecurity Specialist
Location: Remote – must work from Alberta
Contract: 6 months, October 2026 – March 2027
Hours: 35 hours/week, 7 hours/day
Equipment: Laptop provided
About the Role
We are looking for an experienced GRC / Cybersecurity Analyst to support security risk assessments, vulnerability management, third-party/vendor risk, and security awareness initiatives .
This is a hands-on role requiring someone who can independently assess security risks, operate vulnerability-management tools, work with vendors and internal technology teams, and drive security issues through remediation.
Key Responsibilities
- Conduct security risk assessments for applications, systems, projects, and technology initiatives.
- Perform third-party/vendor security assessments , including reviewing security questionnaires, SOC reports, certifications, and security documentation .
- Identify, document, track, and prioritize security risks and recommend remediation or mitigation strategies.
- Use vulnerability-management tools such as Rapid7 to identify, validate, prioritize, and report vulnerabilities.
- Work with technical teams to track vulnerabilities and security issues through remediation.
- Plan and execute phishing simulation campaigns and analyze results.
- Develop security awareness and training materials , including phishing awareness, security tips,
and employee communications.
- Prepare clear reports covering security risks, vulnerabilities, vendor assessments, remediation progress, and awareness activities.
- Support continuous improvement of GRC, vulnerability management, third-party risk, and security awareness processes .
Must-Haves
- Strong experience in cybersecurity GRC / security risk management .
- Hands-on experience conducting security risk assessments .
- Experience with third-party/vendor security risk assessments .
- Ability to review SOC reports, security questionnaires, certifications, and related security documentation .
- Hands-on experience with Rapid7 or similar vulnerability-management tools .
- Experience with vulnerability assessment, prioritization, tracking, and remediation .
- Experience planning or supporting phishing simulations and security awareness campaigns .
- Strong understanding of cybersecurity risks, vulnerabilities, controls, and common security frameworks.
- Excellent communication, documentation, and stakeholder-management skills.
- Ability to work independently in a fully remote environment.
Robust Assets
- Previous post-secondary or public-sector cybersecurity experience .
- Relevant cybersecurity/GRC certifications.
- Experience working directly with technical, business, and external vendor teams.
📌 Cyber Security Specialist (Alberta)
🏢 TEEMA
📍 Alberta