GRC Analyst
- Hiring from
- Canada
- Work type
- Hybrid
- Posted
508,688 remote jobs, straight from company career pages
100% free · New jobs every hour
Show job descriptionHide job description
Job Description
Engagement Details
Estimated Start Date: October 20, 2026
Estimated End Date: June 20, 2027
Hours: 7 Hrs/day
Work Arrangement: Hybrid (2-3 days per week in office)
Location: Winnipeg, MB
Role Description
• Support the Cybersecurity GRC framework, including related services, standards, and awareness activities.
• Conduct and support cybersecurity risk, third-party, control, audit, regulatory, and compliance assessments, including assisting with the transition to a GRC tool.
• Maintain the cybersecurity risk register and track risks, control deficiencies, and exemptions, including supporting the transition to a GRC tool.
• Work with the existing GRC team to develop the compliance framework and the corresponding processes and procedures required for monitoring, including collaboration with control owners.
• Develop and analyze cybersecurity metrics and key risk indicators to assess program effectiveness and recommend risk treatment strategies.
Expected Deliverables
• Risk assessments
• Compliance program documentation
• GRC tool outputs
Qualifications
• 5-7 years of experience in cybersecurity, risk, compliance, and/or governance.
• University or college education, preferably in Computer Science or a related field, or an equivalent combination of education and experience.
• Professional certifications in IT risk, compliance, or security, such as CISA, CISM, CRISC, or CISSP, are considered assets.
• Experience with risk assessment methodologies and IT control frameworks such as NIST, ISO, PCI, CIS, and COBIT.
• Demonstrated ability to translate policies into actionable operational standards and procedures.
• Strong critical thinking and problem-solving skills.
• Demonstrated leadership experience and ability to work both independently and in a team environment.
• Experience in IT auditing and technology risk management is an asset.
• Previous experience using GRC tools.
• Experience facilitating and influencing discussions with diverse stakeholder groups.
• Ability to manage multiple priorities and adapt quickly to changing requirements.
• Excellent organizational, verbal, and written communication skills.
• Knowledge of the lottery and gaming industry is an asset.