Senior Cybersecurity GRC Analyst/ Security Specialist

Randstad

Toronto

On-site

CAD 120,000 - 160,000

Full time

14 days+
Application generator

Get a reply from this recruiter — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Randstad Canada is seeking a Senior Cybersecurity GRC Analyst (Security Specialist) for a 24-month hybrid contract based in Toronto. You will lead governance, risk, and compliance initiatives across IT, cloud, and OT, aligning with Canadian privacy regulations.

This role requires CISSP or CRISC, 7+ years GRC experience, and deep knowledge of NIST CSF, ISO/IEC 27001/27002, and other standards. You will collaborate with stakeholders to implement risk controls and drive assurance programs.

Qualifications

  • 7+ years of GRC cybersecurity experience.
  • Active CISSP or CRISC certification.
  • 10+ years of progressive IT experience.
  • 5+ years of Privacy Impact Assessments (PIAs).
  • Knowledge of NIST CSF, ISO/IEC 27001/27002, ISA/IEC 62443, NERC CIP, CIS Controls, SOC2.

Responsibilities

  • Conduct security and privacy risk assessments across IT, cloud, network, and OT.
  • Analyze existing controls, identify threats, and propose mitigations.
  • Develop and refresh governance frameworks, policies, standards, and procedures.
  • Lead vendor risk assessments and contract risk reviews.
  • Ensure compliance with PHIPA, MFIPPA, CASL, CCSPA and related laws.
  • Provide GRC advisory across IT projects and modernization programs.

Skills

GRC governance
Risk management
Cybersecurity
Policy governance
Analytical skills
Communication

Education

CISSP
CRISC
University degree in CS/InfoSec

Tools

GRC tooling

Job description

Senior Cybersecurity GRC Analyst (Security Specialist)

We are seeking a highly accomplished Senior Cybersecurity GRC Analyst (Security Specialist) for an enterprise-level contract opportunity based in Toronto. In this role, you will take on a premier strategic capacity within cybersecurity governance, risk management, and regulatory compliance streams, specializing in identifying vulnerabilities, evaluating security architectures, and enforcing enterprise risk controls.

As a principal GRC specialist, you will bridge the gap between technical infrastructure, privacy legislation, and enterprise security frameworks. Operating within a hybrid work model, you will lead comprehensive security and privacy impact assessments (PIAs/TRAs), develop and refresh corporate cybersecurity policies, manage third-party vendor risk programs, and ensure strict alignment with industry security standards and Canadian privacy regulations. This position is tailored for a certified security authority (CISSP or CRISC) who can deliver actionable risk analytics, evaluate third-party vendor contracts, and govern compliance across IT, cloud, and operational technology (OT) environments.

Location: Toronto, ON

Assignment Type: Hybrid (2 to 3 days per week onsite)

Contract Duration: 24-month contract (with potential for extension)

Advantages
  • High-Impact Risk Leadership: Drive enterprise-wide Security Risk Assessments, Privacy Impact Assessments (PIAs), and Threat and Risk Assessments (TRAs).
  • Broad Framework Exposure: Govern compliance across leading cybersecurity standards, including NIST CSF, ISO/IEC 27001/27002, ISA/IEC 62443, NERC CIP, CIS Controls, and SOC2.
  • Complex Multi-Environment Scope: Evaluate risk profiles across enterprise IT, cloud platforms, hybrid networks, and industrial/OT infrastructure.
  • Long-Term Enterprise Engagement: Secure a foundational multi-year contract runway with options for further extension.
Responsibilities
  • Conduct comprehensive security and privacy risk assessments across new and existing information systems, network infrastructure, cloud environments, and operational technologies.
  • Analyze existing security controls, perform vulnerability evaluations, and assess technical architectures to identify threats and operational risks.
  • Formulate, document, and recommend actionable security controls to mitigate identified risks and communicate findings effectively to technical and business stakeholders.
  • Identify, assess, and monitor cybersecurity and privacy risks, providing predictive analytics to support strategic business decisions.
  • Develop, refresh, enhance, and communicate enterprise cybersecurity governance frameworks, policies, standards, and operational procedures.
  • Design technical, administrative, and physical security controls to ensure organizational compliance with Canadian privacy and cyber security legislation (PHIPA, MFIPPA, CASL, CCSPA).
  • Execute periodic gap assessments across the information security program, validate ongoing control compliance, facilitate remediation plans, and elevate critical issues to leadership.
  • Manage the security exception review and approval lifecycle, ensuring all risk acceptances are documented and re-evaluated on a defined schedule.
  • Perform initial and ongoing third-party vendor security due diligence, vendor risk monitoring, and maintain the enterprise supplier risk inventory.
  • Review information security and privacy clauses within procurement documents (RFIs, RFPs, MPSAs, contracts, and purchase orders) to identify gaps and enforce data protection terms.
  • Provide expert GRC advisory services across enterprise projects, IT initiatives, and technology modernization programs.
Core Requirements & Mandatory Certifications
  • Education: University degree in Computer Science, Information Security, Cybersecurity, or a related field (or an equivalent combination of education and professional experience).
  • Mandatory Professional Certification: Active credential in at least one of the following:
    • Certified Information Systems Security Professional (CISSP)
    • Certified in Risk and Information Systems Control (CRISC)
  • GRC Experience: 7+ years of relevant cybersecurity experience focused on Governance, Risk, and Compliance (GRC).
  • Privacy Impact Assessments: 5+ years of hands-on experience conducting Privacy Risk Assessments and Privacy Impact Assessments (PIAs).
  • Enterprise IT Experience: 10+ years of progressive Information Technology experience.
  • Security Framework Depth: Significant experience applying enterprise security frameworks and standards, such as NIST CSF, ISO/IEC 27001/27002, ISA/IEC 62443, NERC CIP, CIS Controls, and SOC2.
  • Policy & Governance Development: Demonstrated experience developing, refreshing, and implementing cybersecurity policies, standards, guidelines, and procedures.
  • Canadian Regulatory Mastery: In-depth understanding and practical application of Canadian privacy and security legislation, including PHIPA, MFIPPA, CASL, Critical Cyber Systems Protection Act (CCSPA), and related digital security acts.
Preferred Technical & Architecture Skills
  • Architecture & Infrastructure Depth: Strong background in enterprise IT and Security Architecture, spanning cloud, hybrid, and OT/industrial operational environments.
  • Networking & Protocols: Solid understanding of networking principles (TCP/IP, WAN/LAN) and core security/internet protocols (SMTP, HTTP, FTP, LDAP, SAMLv2, OAuth, SSL/TLS).
  • Vendor & Contract Risk: Direct experience evaluating vendor risk, reviewing RFP/contractual security terms, and utilizing GRC risk management tooling.
Soft Skills & Professional Attributes
  • Analytical Problem Solving: Superior diagnostic capabilities to evaluate complex risk scenarios, weigh costs versus benefits, and recommend pragmatic mitigations.
  • Consultative Communication: Exceptional written and verbal communication skills with meticulous attention to detail when presenting risk findings to diverse audiences.
  • Time Management & Adaptability: Proven ability to manage competing priorities, deliver under tight deadlines, and navigate fast-paced environments effectively.

Randstad Canada is committed to fostering a workforce reflective of all peoples of Canada. As a result, we are committed to developing and implementing strategies to increase the equity, diversity and inclusion within the workplace by examining our internal policies, practices, and systems throughout the entire lifecycle of our workforce, including its recruitment, retention and advancement for all employees. In addition to our deep commitment to respecting human rights, we are dedicated to positive actions to affect change to ensure everyone has full participation in the workforce free from any barriers, systemic or otherwise, especially equity‑seeking groups who are usually underrepresented in Canada's workforce, including those who identify as women or non‑binary/gender non‑conforming; Indigenous or Aboriginal Peoples; persons with disabilities (visible or invisible) and; members of visible minorities, racialized groups and the LGBTQ2+ community.

Randstad Canada is committed to creating and maintaining an inclusive and accessible workplace for all its candidates and employees by supporting their accessibility and accommodation needs throughout the employment lifecycle. We ask that all job applications please identify any accommodation requirements by sending an email to accessibility@randstad.ca to ensure their ability to fully participate in the interview process.

This posting is for existing and upcoming vacancies.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cyber Security Analyst - GRC
Senior Cyber Security Analyst - GRC

Metro Supply Chain • Mississauga

On-site
CAD 105,000 - 125,000
Risk and Resilience Specialist
Risk and Resilience Specialist

University of Toronto • Toronto

On-site
CAD 90,000 - 120,000
CISO-Level Visibility
AI-Driven Governance
Broad Cybersecurity Scope
+1
Senior Information Security, GRC Analyst
Senior Information Security, GRC Analyst

Cassels Brock & Blackwell LLP • Toronto

On-site
CAD 100,000 - 125,000
Extended Health & Dental Care
RRSP Matching
Fitness Reimbursement
+6
Director, Governance, Risk & Compliance (GRC)
Director, Governance, Risk & Compliance (GRC)

Robertson & Company Ltd. • Toronto

On-site
CAD 170,000 - 190,000
Senior Specialist Risk Management
Senior Specialist Risk Management

TEEMA • Toronto

On-site
CAD 126,000 - 176,000
Sr. Cyber Security Analyst
Sr. Cyber Security Analyst

10 Percent Recruiting Ltd. • Canada

Hybrid
CAD 110,000 - 140,000
Cyber Security Manager
Cyber Security Manager

Akkodis • Toronto

On-site
CAD 120,000 - 180,000
Performance-based bonuses
Defined contribution pension plan
Professional growth opportunities
+4
Senior IT Security TRA & C&A Analyst
Senior IT Security TRA & C&A Analyst

Maplesoft Group, an SEB Company • Ottawa

Remote
CAD 11,021,000 - 13,776,000
Remote work within Canada
Contract extension potential
Enterprise security exposure
Specialist
Specialist

LTM • Mississauga

On-site
CAD 70,000 - 90,000
Comprehensive Medical Plan covering Medical, Dental, Vision
Health Care Spending Account
Short Term and Long Term Disability Coverage
+4
Information Security Specialist
Information Security Specialist

Ian Martin Group • Toronto

On-site
CAD 100,000 - 130,000