Security GRC Specialist

Aviso

Toronto

On-site

CAD 105,000 - 125,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive compensation package
Excellent health, dental and insurance
Generous vacation time
Matching retirement contributions
Education assistance and learning &amp
Regular social events

Job summary

Aviso is seeking an experienced Security GRC Specialist to govern risk management lifecycle, remediation tracking, and reporting metrics for senior leadership. You will oversee risk assessments, policy alignment, audits, and third-party risk while leveraging GRC tools to enhance governance processes.

With 5–8 years of IT risk, cybersecurity, or compliance experience and knowledge of NIST/ISO frameworks, you will collaborate across teams and communicate in English.

Qualifications

  • Bachelor's Degree in Information Security, Computer Science, Business, Risk Management or a related field.
  • CRISC, CISA, CISSP certifications are an asset.
  • 5-8 years of IT risk, cybersecurity risk, audit, compliance or equivalent roles.
  • Working knowledge of IT governance frameworks and standards (e.g., NIST CSF, ISO 27001, ITIL).
  • Familiarity with regulatory and compliance requirements.
  • Experience with GRC platforms and tools.
  • Ability to work in a fast-paced environment and stay updated on emerging threats and vulnerabilities.
  • Proactiveness, curiosity, adaptability, and strong problem-solving mindset.
  • Ability to collaborate across multiple business units.
  • Fluent English; bilingual French an asset.

Responsibilities

  • Conduct risk assessments of IT infrastructure, applications, third parties, and critical processes.
  • Track and manage mitigation plans and ensure timely resolution.
  • Support development and maintenance of cybersecurity risk register KPI monitoring and reporting.
  • Assist in development, review and maintenance of Technology & Cybersecurity Policies, Standards, and procedures.
  • Ensure alignment of internal policies with industry frameworks (NIST, ISO, COBIT).
  • Support audits and board level reporting including preparing key metrics.
  • Monitor compliance with external regulatory and internal control requirements.
  • Support internal and external audits.
  • Conduct periodic control testing including design and operating effectiveness.
  • Support vendor risk assessments, including reviewing response to questionnaire.
  • Maintain and enhance governance process through GRC tools (e.g., Archer, ServiceNow GRC, Resolver).
  • Support reporting, dashboard creation and automation of risk and compliance processes.

Skills

Risk assessment
Governance
Regulatory compliance
Stakeholder collaboration
Analytical thinking
English communication

Education

Bachelor's degree in Information Security / related field

Tools

Archer
ServiceNow GRC
Resolver

Job description

At Aviso, we are dedicated to improving the financial well-being of Canadians. As a leading wealth management organization, we are committed to leadership, innovation, partnership, responsibility, and community. Working with talented and energetic professionals who exemplify our values every day, you will quickly notice that our people and dynamic ‘oneaviso' culture sets us apart. If you are looking for interesting and challenging work, at a company committed to its people, find out more about what Aviso has to offer at www.aviso.ca.

The Opportunity

We’re looking to fill an opening with an experienced Security GRC Specialist to join our growing Security GRC team.

Reporting to the Director of Security Governance, Risk & Compliance (GRC), the Security GRC Specialist will be responsible to govern the risk management lifecycle, including monitoring findings remediation, assurance programs and reporting appropriate metrics to the senior leadership.

One Aviso
  • We Care - You do the right thing for clients, partners and colleagues. You build trusted relationships, champion service excellence, and contribute to a culture where people feel valued and supported
  • We Dare -You challenge the status quo with bold ideas and fresh perspectives. You embrace change, seek opportunities to innovate and are comfortable exploring new ways of working
  • We Share - You collaborate openly and build meaningful relationships. You seek out diverse perspectives, share your knowledge and work together to help colleagues, clients and partners succeed
  • We Deliver - You take ownership of your work, honour your commitments and focus on delivering meaningful results. You hold yourself accountable and continuously look for ways to improve
What your day looks like
Risk Management
  • Conduct risk assessments of IT infrastructure, applications, third parties, and critical processes to identify, assess and report on technology and cybersecurity risks
  • Track and Manage mitigation plans and ensure timely resolution
  • Support the development and maintenance of cybersecurity risk register KPI monitoring and reporting
Governance
  • Assist in development, review and maintenance of Technology & Cybersecurity Policies, Standards, and procedures
  • Ensure alignment of internal policies with industry frameworks (NIST, ISO, COBIT)
  • Support audits and board level reporting including preparing key metrics
Assurance
  • Monitor compliance with external regulatory and internal control requirements
  • Support internal and external audits
  • Conduct periodic control testing including design and operating effectiveness
Third Party Risk
  • Support vendor risk assessments, including reviewing response to questionnaire
GRC Tools
  • Maintain and enhance governance process through GRC tools (e.g., Archer, ServiceNow GRC, Resolver etc.)
  • Support reporting, dashboard creation and automation of risk and compliance processes
Requirements
Your experience and skills
  • Bachelor's Degree in Information Security, Computer Science, Business, Risk Management or a related field
  • Relevant certifications such as CRISC, CISA, CISSP are an asset
  • 5-8 years of experience in IT risk, cybersecurity risk, audit, compliance or equivalent roles
  • Working knowledge of IT governance frameworks and standards (e.g., NIST CSF, ISO 27001, ITIL)
  • Familiarity with regulatory and compliance requirements
  • Experience with GRC platforms and tools
  • Ability to work in a fast-paced environment and stay updated on emerging threats and vulnerabilities
  • Proactiveness, natural curiosity, a willingness to learn, adaptability in an evolving environment, and a strong problem-solving mindset
  • Ability to work across multiple business units and collaborate across teams
  • Fluent communication skills in English are required and bilingual skills in French are an asset
Benefits
  • Competitive compensation package that rewards and recognizes individual contributions
  • Excellent health, dental and insurance benefits to meet the diverse needs of our employees
  • Generous vacation time, fitness benefit, parental leave top-up options
  • Matching contributions to our retirement program
  • Commitment to the continuous improvement of our staff through learning & development and an education assistance program
  • Regular social events to foster teamwork
Why Aviso?

At Aviso, you will find a dynamic and inclusive culture that rewards innovation and celebrates success.

Here are a few things that set us apart:

Your Information

By submitting your application, you consent to the collection, use, and disclosure of your provided personal information for the purposes of assessing your qualifications and suitability for employment with Aviso. Your information will be handled in accordance with applicable Canadian privacy laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and relevant provincial legislation. Your data may be shared with authorized personnel involved in the recruitment process and retained only as long as necessary to fulfill these purposes or as required by law.

Further information is available on the Privacy link on our Career Page - Privacy Policies

Equal Employment Opportunity

Aviso welcomes and encourages applications from all qualified individuals including persons with disabilities. If you require an accommodation, we will work with you to meet your needs in all stages of the hiring process.

We thank all applicants for their interest, however, only those selected for further consideration will be contacted.

Company Overview

Aviso is a leading wealth management and investment services provider for the Canadian financial industry, with approximately $145 billion in total assets under administration and management, and over 1,000 employees. We're building a comprehensive, technology-enabled, client-centric wealth services ecosystem. Our clients include our partners, advisors, and investors. We're a trusted partner for nearly all credit unions across Canada, in addition to a wide range of portfolio managers, investment dealers, insurance and trust companies, and introducing brokers. Our partners depend on Aviso for specific solutions that give them a competitive edge in a rapidly evolving, highly competitive industry. Our investment dealer and mutual fund dealer and our insurance services support thousands of investment advisors. Our asset manager, NEI Investments, specializes in investing responsibly. Our online brokerage, Qtrade Direct Investing®, empowers self-directed investors, and our fully automated investing service, Qtrade Guided Portfolios®, serves investors who prefer a hands‑off approach. Aviso Correspondent Partners provides custodial and carrying broker services to a wide range of firms. We have offices in Toronto, Vancouver, and Montreal. Aviso is backed by the collective strength of our owners: the credit union Centrals, Co-operators/CUMIS, and Desjardins.

Salary

This position is posted with an expected salary range of $105000 - $125,000 CAD annually. Individual compensation packages are based on various factors unique to each candidate and the requirements of the position.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

System Access Administrator
System Access Administrator

Aviso Wealth Inc. • Toronto

On-site
CAD 55,000 - 65,000
Competitive compensation
Health and dental benefits
Generous vacation
+3
Director, Infrastructure Operations
Director, Infrastructure Operations

Aviso • Vancouver

On-site
CAD 155,000 - 165,000
Competitive compensation
Health, dental and insurance benefits
Generous vacation time
+3
Senior Business Operations Manager
Senior Business Operations Manager

Aviso Wealth Inc. • Toronto

On-site
CAD 115,000 - 135,000
Competitive compensation package
Excellent health, dental and insurance
Generous vacation time
+3
Senior Manager, Talent Management
Senior Manager, Talent Management

Aviso • Montreal (administrative region)

On-site
CAD 115,000 - 135,000
Competitive compensation
Health benefits
Generous vacation time
+4
Registered Plans Administrator, Temporary
Registered Plans Administrator, Temporary

Aviso Wealth Inc. • Toronto

On-site
CAD 46,000 - 55,000
Competitive compensation package
Benefits package
Vacation & wellness
+3
Senior Manager, Talent Management
Senior Manager, Talent Management

Aviso • Toronto

On-site
CAD 115,000 - 135,000
Competitive compensation
Health & dental benefits
Generous vacation
+3
AI Engineer - Gen AI & Agentic Solutions
AI Engineer - Gen AI & Agentic Solutions

Aviso • Toronto

On-site
CAD 125,000 - 135,000
Competitive compensation
Health & dental benefits
Generous vacation
+3
Supervisor, Client Solutions
Supervisor, Client Solutions

Aviso • Montreal (administrative region)

On-site
CAD 83,000 - 90,000
Competitive compensation
Health & dental benefits
Generous vacation and parental leave
Relationship Manager
Relationship Manager

Aviso • Toronto, Vancouver, Montreal (administrative region), Winnipeg

On-site
CAD 83,000 - 100,000
Competitive compensation
Health & dental benefits
Vacation & parental leave
+3
Senior Manager, Service Center
Senior Manager, Service Center

Aviso • Vancouver

On-site
CAD 115,000 - 135,000
Competitive compensation package
Excellent health, dental, and insurance benefits
Generous vacation time and parental leave options
+2