GM Financial Canada logo

Associate Cybersecurity Analyst - Bilingual

Hiring from
United States
Work type
Hybrid
Posted
Sep 24, 2026
Is this job info correct?

Why GMF Cybersecurity?

Innovation isn’t just a talking point at GM Financial; it’s how we operate. By joining our team, you’ll work in a mission-focused environment with specialized teams, including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall, Governance, Risk, Architecture and Offensive Security. These teams collaborate to identify, manage and respond to threats, all while driving innovation across the environment.

Cybersecurity is central to our strategic vision, so you’ll benefit from exceptional leadership visibility, with direct reporting lines to the CEO. This structure ensures your work is recognized and supported at the highest levels, while also enabling bold innovation and the adoption of cutting-edge technologies.

Shape the future of Cybersecurity at GM Financial, with the freedom to explore, the tools to build and the support to thrive.

This position will be posted until filled.

About the role

The Associate Cybersecurity Analyst supports cybersecurity policy governance and regulatory compliance activities across multiple international authorities. This entry-level to early-career role assists in monitoring regulatory developments, conducting research and analysis, maintaining policy documentation, and supporting compliance initiatives. The Associate Cybersecurity Analyst works closely with Cybersecurity, Legal, Compliance, Privacy, Risk Management, Technology, and business stakeholders to help maintain alignment between cybersecurity policies, standards, and applicable regulatory requirements.

This position requires professional fluency in both English and Spanish to support global regulatory monitoring activities, communicate compliance requirements, and collaborate with stakeholders across diverse regions.

In this role you will:

Cybersecurity Policy Governance

  • Support cybersecurity policy governance activities to help maintain alignment with regulatory requirements, legal obligations, organizational objectives, and industry frameworks.

  • Assist with the full policy lifecycle, including development, review, approval, publication, communication, implementation, and periodic recertification.

  • Coordinate policy reviews and stakeholder engagement across Cybersecurity, Legal, Compliance, Privacy, Risk Management, Technology, and business teams.

  • Maintain policy governance documentation, repositories, implementation trackers, compliance evidence, milestones, action items, and remediation activities.

  • Participate in governance meetings, working groups, and review sessions; document outcomes, track follow-up actions, and support implementation efforts.

  • Prepare policy governance metrics, compliance summaries, management reports, and other governance-related communications.

  • Provide guidance on policy requirements and implementation expectations to support organizational compliance.

Regulatory Monitoring and Analysis

  • Research, monitor, and analyze cybersecurity regulations, regulatory guidance, compliance requirements, and industry standards.

  • Assist in translating regulatory requirements into cybersecurity policies, standards, procedures, controls, and implementation plans.

  • Support regulatory impact assessments, gap analyses, compliance initiatives, and remediation activities across applicable regulatory authorities.

  • Coordinate stakeholder engagement, evidence collection, and implementation activities related to regulatory compliance efforts.

  • Track regulatory implementation progress, including risks, dependencies, issues, corrective actions, and compliance outcomes.

  • Prepare regulatory updates, executive summaries, compliance metrics, and implementation status reports for leadership and stakeholders.

  • Partner with Legal, Compliance, Privacy, Risk Management, Technology, and business teams to support regulatory interpretation and implementation.

  • Identify opportunities to improve regulatory monitoring, reporting, and compliance processes through standardization, automation, and operational efficiencies.

What makes you an ideal candidate?

  • Professional fluency in English and Spanish (written and verbal).

  • Foundational knowledge of cybersecurity governance principles, regulatory compliance, and information security frameworks.

  • Sound analytical, organizational, communication, and documentation skills.

  • Ability to prioritize multiple assignments and collaborate effectively with cross-functional teams.

  • Proficiency with Microsoft Office applications, including Word, Excel, PowerPoint, and Teams.

  • Must have a high-level understanding of financial services industry, security, risk and privacy

  • Must have current knowledge and stay up-to-date on the latest Cybersecurity legislation, regulations, advisories, alerts and vulnerabilities

  • Must have knowledge of Information Security and Cybersecurity frameworks

  • Proficiency with Microsoft Office applications, including Word, Excel, PowerPoint, and Teams.

  • Knowledge of security methodologies, policies, standards and industry practices

  • Knowledge of information technology systems, infrastructure and operations

  • Understanding of cloud technologies and concepts

  • Familiarity with DevOps and Agile development process

  • Ability to initiate, facilitate and promote Cybersecurity within the organization and monitor adherence to Cybersecurity policies, standards and controls

  • Ability to clearly explain and articulate technical concepts using non-technical language

  • Foundational knowledge of cybersecurity governance principles, regulatory compliance, and information security frameworks.

  • Familiarity with cybersecurity frameworks and standards preferred, including:

  • NIST Cybersecurity Framework (CSF)

  • NIST SP 800-53

  • NIST SP 800-171

  • ISO 27001

  • Exposure to policy management platforms, workflow tools, or regulatory tracking solutions preferred

Additional Knowledge and Skills

Working effectively within an AI enabled environment:

  • Ability to use AI tools (e.g., Microsoft Copilot) to support daily work

  • Skills in evaluating AI outputs for accuracy, compliance, and bias

  • Experience integrating AI into workflows to improve efficiency or insights

  • Familiarity with AI assisted research, summarization, and content generation

  • Understanding of responsible AI use, including ethics and data protection

Experience and Education:

  • 0-2 years of experience in large and complex business environments with a successful track record working directly with senior level management with working knowledge in one or more of the following domains: Access Control, Telecom and Network Security, Cybersecurity Governance, Risk Management, Software Development Security, Cryptography, Security Architecture and Design, Operational Security, Business Continuity & Disaster Recovery, Legal Regulations, Investigations and Compliance, Physical (Environmental) Security, IT or Security Audit, IT or Security Compliance preferred

  • 0-2 years of experience in the financial services industry preferred

  • 0-2 years of demonstrable experience leading collaborative programs and projects with senior level management required

  • High School Diploma or equivalent required

  • Bachelor’s Degree or equivalent experience strongly preferred

What We Offer: Generous benefits package available on day one to include: 401K matching, bonding leave for new parents (12 weeks, 100% paid), tuition assistance, training, GM employee auto discount, community service pay and nine company holidays.

Our Culture: Our team members define and shape our culture — an environment that welcomes innovative ideas, fosters integrity, and creates a sense of community and belonging. Here we do more than work — we thrive.

Compensation: Competitive pay and bonus eligibility.

Work Life Balance: Flexible hybrid work environment, 4-days a week in office.

NOTE: We are unable to consider candidates who require visa sponsorship for this position

This position is not open to agency submissions

#GMFJobs #LI-Hybrid #LI-SC1

Similar jobs

Apply for this job