Information Security, GRC Analyst

Bennett Jones

Toronto

On-site

CAD 102,640 - 153,960

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Bennett Jones in Toronto seeks a Information Security GRC Analyst to support the governance, risk and compliance program. You will focus on third-party security, due diligence, and maintaining a formal risk-based security framework aligned with ISO standards.

The role requires at least three years of information security experience and excellent communication skills, with a collaborative approach across IT and business functions.

Qualifications

  • Bachelor's degree in information technology, computer science, cybersecurity, or related field.
  • Minimum three years of IT compliance, risk management, or information security experience.
  • Knowledge of ISO/27001, ISO/22301 and NIST security frameworks.
  • Experience with security risk management processes and compliance tools.
  • Outstanding oral and written communication skills with strong interpersonal abilities.
  • High attention to detail and personal initiative with minimal supervision.
  • Ability to prioritize tasks, meet deadlines and work effectively under pressure.
  • Professional certifications such as CISSP, CISA, CISM, CRISC or SANS/GIAC are assets

Responsibilities

  • Oversee the cybersecurity compliance program for third parties, including client/auditor requests for security questionnaires.
  • Manage vendor security due diligence, annual re-certification, and continuous monitoring of vendor security profiles.
  • Maintain security dashboards, metrics, and reports for senior management.
  • Suggest improvements to security standards and procedures.
  • Perform internal security audits and remediation of compliance gaps; maintain related documentation.
  • Stay current with threats, regulations, standards, and industry trends.

Skills

Security frameworks knowledge
Security risk management
Executive communication
Interpersonal skills
Attention to detail
Initiative
Time management
Prioritization

Education

Bachelor's degree in IT / CS / cybersecurity or related field

Job description

Ranked a Best Employer in Canada for 25 years, Bennett Jones is one of Canada’s premier business law firms and home to 450 lawyers and business advisors. With deep experience in complex transactions and litigation matters, and offices in Calgary, Edmonton, Montréal, Toronto, Vancouver and New York, the firm is well equipped to advise businesses and investors with Canadian ventures and connect Canadian businesses and investors with opportunities around the world. Serving clients since 1922, we are proud to be the firm that businesses trust with their most complex legal matters.

We are currently recruiting for the following role in our Toronto office:

Information Security, GRC Analyst

The Role

The Information Security GRC analyst, reporting to the Director Information Security GRC, will support the implementation and maintenance of the organization’s Governance, Risk, and Compliance (GRC) program, with a strong focus on third party security compliance, security governance, and internal controls. This role will contribute to maintaining a formally structured, risk-based security framework aligned with industry standards such as ISO 27001 and ISO 22301. The position requires a minimum of three years of information security experience in a similar position and excellent communication skills.

Essential Functions
  • Oversee the cybersecurity compliance program for third parties, including:
    • Managing requests from clients, prospects, auditors, cyber-insurers, or others, related to our security program, to ensure the timely and accurate response to security questionnaires and associated requests.
    • Managing the compliance of the Firm's key IT vendors with information security, including a comprehensive initial security due diligence, an annual security re-certification, and a continuous monitoring of the vendors' security profile.
  • Assist with the performance of important internal security processes and controls, including:
    • Tracking the status of key internal security tasks and following up with the responsible person to ensure these tasks are conducted in time and as per the annual schedule.
    • Maintaining security dashboards, metrics, and reports as required for the team, the IT Department and senior management.
    • Making suggestions, and improving existing security standards and procedures.
  • Conduct security tasks as required to maintain the Firm's ISO 27001 and ISO 22301 certifications: Perform limited internal security audits; Collaborate with IT and business functions to remediate compliance gaps; Maintain documentation related to compliance activities, controls, and audit findings; Assist with ad-hoc security investigations; Stay up to date with emerging threats, current regulations, existing standards, and industry trends.
Qualifications
  • Bachelor's degree in information technology, computer Science, cybersecurity, or related field
  • Minimum three years of experience in IT compliance, risk management, or information security
  • Knowledge of commonly used security frameworks (e.g., ISO 27001, ISO 22301, NIST)
  • Experience with security risk management processes and compliance tools
  • Outstanding oral and written communication skills
  • Excellent interpersonal relationship skills
  • High-level of attention to detail and accuracy
  • High degree of personal initiative and maturity with an ability to work with minimal supervision
  • Ability to prioritize tasks effectively, respect deadlines, and report any issues, conflict or roadblock in the performance of operational activities, and the planning and scheduling of tasks and projects

Professional certifications as follows are an asset

  • CISSP, CISA, CISM, CRISC
  • SANS/GIAC, CompTIA Security+, CEH
Additional Details
  • Compensation: $102,640 to $153,960 per annum based on experience
  • Vacancy: This position is for an existing vacancy
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Analyst - GRC
Security Analyst - GRC

Quantum Technology Recruiting Inc. (QTR) • Toronto

Hybrid
CAD 75,000 - 85,000
GRC & InfoSec Analyst - ISO 27001 Focus
GRC & InfoSec Analyst - ISO 27001 Focus

Bennett Jones • Toronto

On-site
CAD 102,000 - 154,000
Senior Cyber Security Analyst - GRC
Senior Cyber Security Analyst - GRC

Metro Supply Chain • Mississauga

On-site
CAD 105,000 - 125,000
Information Security Compliance Analyst
Information Security Compliance Analyst

Gowling WLG • Vancouver

Hybrid
CAD 100,000 - 115,000
100% employer-paid health and dental coverage
15+ vacation days
Parental leave top-up for 26 weeks
+2
Information Security Compliance Analyst
Information Security Compliance Analyst

Gowling WLG • Calgary

Hybrid
CAD 100,000 - 115,000
100% employer-paid health, dental, and mental health coverage
15+ vacation days
Parental leave top-up for 26 weeks
+2
Information Security Compliance Analyst
Information Security Compliance Analyst

Gowling WLG • Hamilton

Hybrid
CAD 100,000 - 115,000
100% employer-paid health, dental, and mental health coverage
15+ vacation days and hybrid work flexibility
Parental leave top-up for 26 weeks
Cyber Security Manager
Cyber Security Manager

Akkodis • Toronto

Hybrid
CAD 120,000 - 180,000
Performance-based bonuses
Defined contribution pension plan
Professional growth opportunities
+4
Senior Analyst - IT Security
Senior Analyst - IT Security

EECOL Electric • Calgary

On-site
CAD 90,000 - 120,000
Comprehensive insurance options
Generous paid time off
Flex benefits
+3
IT Risk and Compliance Analyst
IT Risk and Compliance Analyst

Experis • Mississauga

Hybrid
CAD 70,000 - 100,000
Bonus program
Flexible hybrid work
Professional development
+1
Senior Security Analyst, Third Party Risk
Senior Security Analyst, Third Party Risk

Insight Global • Vancouver

On-site