Senior Governance, Risk & Compliance (GRC) Analyst

Socket.dev

Toronto

On-site

CAD 107,000 - 131,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Pension plan
Health insurance
Paid time off
Career development
Safety culture

Job summary

Vale Base Metals seeks a Senior Governance, Risk & Compliance (GRC) Analyst to join our Global Cyber Risk, Governance, Risk & Compliance team in Toronto, Ontario. You will advance cybersecurity governance, risk management, and compliance programs, collaborating with Cybersecurity, IT, Legal, Privacy, Procurement, and Internal Audit to strengthen controls and provide executive-ready reporting.

The role requires 7–10 years of GRC/IT risk experience, strong knowledge of NIST CSF, ISO 27001, and

Qualifications

  • Minimum 7-10 years of progressive experience in cybersecurity GRC, IT audit, technology risk, compliance, control assurance, privacy, or related advisory roles.
  • Experience supporting global or multinational organizations.
  • Proven experience conducting risk assessments, audit support, compliance reviews, and third‑party risk assessments.
  • Experience working across clouds, infrastructure, identity management, applications, and OT/ICS environments.
  • Strong stakeholder management and influencing skills without direct authority.

Responsibilities

  • Develop global cybersecurity policies, standards, controls, and governance processes.
  • Align cybersecurity control frameworks with NIST CSF, ISO 27001, COBIT, CIS Controls, and ITGC requirements.
  • Lead cybersecurity risk assessments across applications, infrastructure, cloud services, SaaS platforms, IAM, OT/ICS environments, and strategic projects.
  • Identify control gaps and recommend remediation, compensating controls, and risk treatment strategies.
  • Advise project teams on integrating cybersecurity requirements into design and implementation activities.
  • Prepare risk documentation and executive summaries for informed decisions.
  • Support internal and external audits, control testing, and remediation tracking.
  • Monitor regulatory, privacy, cybersecurity, and governance developments and impact.
  • Maintain audit-ready documentation, risk registers, and management action plans.
  • Conduct security and risk reviews of suppliers, contractors, SaaS providers, and MSPs.
  • Evaluate security questionnaires, due diligence, control evidence, and contractual obligations.
  • Partner with Procurement, Legal, Privacy, and Technology teams to strengthen supplier security governance.
  • Track supplier risks, remediation commitments, exceptions, and risk acceptance decisions.
  • Develop dashboards and reporting on cyber risk posture, compliance status, remediation progress, and control health.
  • Translate technical findings into business-focused insights for leadership.
  • Drive improvements in GRC processes, methodologies, reporting, and governance effectiveness.
  • Mentor and support stakeholders on cybersecurity risk management and control expectations.

Skills

NIST CSF
ISO 27001
COBIT
CIS Controls
ITGC/IT SOX
Cybersecurity risk management
Risk assessments
Audit readiness
Third‑party risk management
Stakeholder management

Education

Undergraduate degree

Tools

GRC tools
Microsoft 365
Excel
PowerPoint
SharePoint

Job description

Ready to build a rewarding career in an industry that is growing?

Who We Are

We are a global mining company dedicated to safely delivering nickel, copper, cobalt, and platinum group metals essential for the world’s energy transition.

Our mission is to improve lives and shape a better future together.

From utensils to cellphones to satellites, our operations simplify daily life and enhance connectivity. Our metals are integral to life‑saving medical equipment and the electric vehicles driving the fight against climate change – our work truly matters.

Join our diverse team of 15,000 talented individuals committed to transforming critical minerals into prosperity and sustainable development in countries like Canada, Brazil, Indonesia, the United Kingdom, and Japan. We invite you to use your skills with us and contribute to something meaningful and enduring.

The Opportunity

We are currently seeking a Senior Governance, Risk & Compliance (GRC) Analyst (Global Cybersecurity) to join our Global Cyber Risk, Governance, Risk & Compliance team in Toronto, Ontario.

Reporting to the Senior Manager, Cyber Risk, Audit, Compliance & Data Privacy, you will play a critical role in advancing our global cybersecurity governance, risk management, compliance, audit readiness, privacy governance, and third‑party risk programs.

This role partners with stakeholders across Cybersecurity, IT, Operational Technology (OT), Legal, Privacy, Procurement, Internal Audit, Finance, and Business Operations to assess risk, strengthen controls, support compliance efforts, and provide executive‑ready reporting that enables informed decision‑making across our global organization.

Key Responsibilities
Cyber Governance & Control Framework
  • Support the development, maintenance, and continuous improvement of global cybersecurity policies, standards, controls, and governance processes.
  • Align cybersecurity control frameworks with industry standards including NIST CSF, ISO 27001, COBIT, CIS Controls, and ITGC requirements.
  • Coordinate governance activities and prepare materials for leadership reviews, risk committees, audits, and executive reporting.
  • Promote consistent control ownership, accountability, and evidence management practices globally.
Cyber Risk Assessment & Advisory
  • Lead cybersecurity risk assessments across applications, infrastructure, cloud services, SaaS platforms, identity and access management, OT/ICS environments, and strategic projects.
  • Identify control gaps and recommend remediation, compensating controls, and risk treatment strategies.
  • Advise project teams and technology stakeholders on integrating cybersecurity requirements into design and implementation activities.
  • Prepare risk documentation and executive summaries to support informed business decisions.
Compliance, Assurance & Audit
  • Support internal and external audits, control testing, evidence collection, and remediation tracking activities.
  • Coordinate cybersecurity compliance programs and control self‑assessments.
  • Monitor regulatory, privacy, cybersecurity, and governance developments and assess their impact on the organization.
  • Maintain audit‑ready documentation, risk registers, and management action plans.
Third‑Party Risk Governance
  • Conduct security and risk reviews of suppliers, contractors, SaaS providers, and managed service partners.
  • Evaluate security questionnaires, due diligence assessments, control evidence, and contractual security obligations.
  • Partner with Procurement, Legal, Privacy, and Technology teams to strengthen supplier security governance.
  • Track supplier risks, remediation commitments, exceptions, and risk acceptance decisions.
Reporting & Continuous Improvement
  • Develop dashboards and reporting on cyber risk posture, compliance status, remediation progress, and control health.
  • Translate technical findings into business‑focused insights for leadership and stakeholders.
  • Drive improvements in GRC processes, methodologies, reporting, and governance effectiveness.
  • Mentor and support stakeholders on cybersecurity risk management and control expectations.
About You
Experience
  • Minimum 7-10 years of progressive experience in cybersecurity GRC, IT audit, technology risk, compliance, control assurance, privacy, or related advisory roles.
  • Experience supporting global or multinational organizations.
  • Proven experience conducting risk assessments, audit support, compliance reviews, and third‑party risk assessments.
  • Experience working across clouds, infrastructure, identity management, applications, and operational technology environments.
  • Strong stakeholder management and influencing skills without direct authority.
Education
  • Undergraduate degree in Cybersecurity, Information Technology, Computer Science, Business, Engineering, Risk Management, Audit, or related discipline.
Skills & Competencies
  • Strong knowledge of NIST CSF, ISO 27001, COBIT, CIS Controls, ITGC/IT SOX, and cybersecurity risk management frameworks.
  • Experience with risk assessments, control testing, audit readiness, compliance programs, and third‑party risk management.
  • Strong analytical, problem‑solving, and documentation skills.
  • Ability to communicate effectively with technical and non‑technical audiences.
  • Advanced proficiency with Microsoft 365, Excel, PowerPoint, SharePoint, GRC tools, and reporting platforms.
  • Strong organizational skills with a high degree of professionalism, confidentiality, and business acumen.
Preferred Qualifications
  • CISA, CRISC, CISM, CISSP, ISO 27001 Lead Implementer/Lead Auditor, COBIT, ITIL, CCSP, CIPM/CIPP, or similar certifications.
  • Experience in mining, industrial, manufacturing, or critical infrastructure environments.
  • Knowledge of OT/ICS cybersecurity and cloud security governance.
  • Experience with OneTrust or similar GRC/privacy platforms.
  • Exposure to board‑level cyber risk reporting and audit committee presentations.
What We Offer You
  • Competitive compensation including a variable annual incentive plan
  • Participation in a competitive Defined Contribution Pension package
  • Comprehensive benefits package (company paid core coverage, health and dental coverage, flex accounts, disability plans, and optional insurances)
  • Leave for all of life’s reasons (vacation, personal, sick, parental)
  • Work culture dedicated to safety, diversity & inclusion, and career growth
  • Employee Family Assistance Program
  • Virtual Healthcare online
  • Online training and career development opportunities
Why Toronto

Toronto, Canada’s largest city and financial hub, is a center of innovation, commerce, and culture. Known for its diverse economy and vibrant urban environment, Toronto offers unparalleled access to talent, technology, and global connectivity.

Our Toronto office serves as a strategic hub for corporate functions, technology development, and business operations. Here, we drive initiatives that support Vale Base Metals’ global operations, leveraging advanced analytics, digital transformation, and strategic planning to ensure operational excellence across all regions.

Toronto’s dynamic ecosystem enables collaboration with leading technology partners, universities, and research institutions, fostering innovation in mining and metals processing. This location is integral to shaping the future of sustainable mining and advancing our commitment to responsible resource development.

Include to Transform

At Vale Base Metals, we are committed to ensuring an inclusive work environment where people feel comfortable to be themselves. Vale encourages everyone to express their ideas and opinions and values the plurality of individual profiles. We want our people to feel that all.

We want our people to feel that all voices are heard, all cultures respected and that a variety of perspectives are not only welcome – they are critical to our success. We treat each other

fairly and with dignity regardless of race, gender, nationality, ethnic origin, religion, age, sexual orientation, or any other personal consideration that makes us different.

Vale is an equal opportunity employer seeking to increase diversity across our operations and improve equal opportunity at Vale and in the mining industry.

Accommodation is available throughout our recruitment process for applicants with disabilities.

Vale uses artificial intelligence to screen, assess, and/or select applicants for this position.

Pay Grade: F2T

Minimum Starting Salary: CAD $119000

Apply by: Friday, Sep 18, 2026

#ValeBaseMetals

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Legal Counsel - Global Commercial and Operations
Senior Legal Counsel - Global Commercial and Operations

Vale Base Metals • Toronto

On-site
CAD 120,000 - 180,000
Competitive compensation
Pension package
Comprehensive benefits
+1
Senior Specialist, Base Metals Market
Senior Specialist, Base Metals Market

Vale Base Metals • Toronto

Hybrid
CAD 117,000 - 143,000
Business Analyst Mining Operations
Business Analyst Mining Operations

Vale Base Metals • Greater Sudbury

On-site
Competitive compensation including a variable annual incentive plan
Vacation pay
Flexible work arrangements
+3
Business Analyst Support Commercial
Business Analyst Support Commercial

Vale Base Metals • Greater Sudbury

Hybrid
Competitive compensation
Flexible work arrangements
Employee Family Assistance Program
+1
Analyst II, IT
Analyst II, IT

Vale Base Metals • Labrador City

On-site
Competitive compensation
Defined Contribution Pension package
Comprehensive benefits package
+4
Geologist/Senior Geological Technologist
Geologist/Senior Geological Technologist

Vale Base Metals • Northeastern Ontario

On-site
CAD 80,000 - 97,000
Competitive compensation
Defined contribution pension
Comprehensive benefits
+6
Senior Geologist
Senior Geologist

Vale Base Metals • Northeastern Ontario

On-site
CAD 84,653 - 103,464
Incentive plan
Pension plan
Benefits package
+5
Sr Advisor, Reliability
Sr Advisor, Reliability

Vale Base Metals • Thompson

On-site
CAD 110,000 - 160,000
Competitive compensation
Pension plan
Health and dental benefits
+2
Supervisor, Maintenance (Mobile)
Supervisor, Maintenance (Mobile)

Vale Base Metals • Greater Sudbury

On-site
CAD 90,000 - 120,000
Competitive compensation
Defined Contribution Pension package
Comprehensive benefits package
+5
Supervisor, Maintenance (Ps)
Supervisor, Maintenance (Ps)

Vale Base Metals • Greater Sudbury

On-site
CAD 84,000 - 102,000
Variable incentive
Defined contribution pension
Benefits package
+5