Enable job alerts via email!

Senior GRC Analyst - Governance & Risk

Marqeta

Toronto

Hybrid

CAD 89,000 - 112,000

Full time

Yesterday
Be an early applicant

Job summary

A leading fintech company in Toronto is seeking a Senior GRC Analyst - Governance & Risk to enhance security policies and ensure compliance with regulatory frameworks. The ideal candidate will have at least 5 years of experience in cybersecurity and risk management, along with strong analytical and communication skills. This role offers a competitive salary and flexible working options.

Benefits

Multiple health insurance options
Flexible time off
Retirement savings program
Monthly stipend for remote work

Qualifications

  • 5+ years of experience in Cybersecurity or IT Risk Management.
  • Strong understanding of cybersecurity regulations and compliance standards.
  • Experience conducting risk assessments in an enterprise environment.

Responsibilities

  • Develop and enhance cybersecurity policies and standards.
  • Conduct risk assessments and manage security risks.
  • Support audits by providing documentation and coordination.

Skills

Cybersecurity frameworks
Risk management
Compliance standards
Analytical skills
Communication skills
Problem-solving skills

Education

Bachelor’s or Master’s degree in Computer Science, Information Security, or related field

Tools

OneTrust
ServiceNow

Job description

Join to apply for the Senior GRC Analyst - Governance & Risk role at Marqeta

Join to apply for the Senior GRC Analyst - Governance & Risk role at Marqeta

The Senior GRC Analyst - Governance & Risk will play a critical role in strengthening Marqeta’s cybersecurity governance, risk management, and compliance programs. This role will focus on enhancing security policies, standards, risk assessments, and governance frameworks to align with regulatory requirements, industry best practices, and Marqeta’s security strategy. The ideal candidate will work closely with cross-functional teams to track and mitigate security risks, improve cybersecurity governance structures, and ensure compliance with regulatory obligations.

The Impact You'll Have

Governance, Policies & Standards

  • Develop, maintain, and enhance cybersecurity policies, standards, and control frameworks to align with industry regulations (e.g., PCI DSS, ISO 27001, SOC 2, SOX, DORA & NIST).
  • Work with cross-functional teams to ensure cybersecurity policies are embedded in business processes.
  • Establish documentation and approval processes for cybersecurity policies, ensuring consistency and transparency.
  • Maintain a centralized inventory of cybersecurity controls, ensuring alignment with regulatory and internal security requirements.

Risk Management & Assessments

  • Conduct cybersecurity risk assessments to identify, evaluate, and prioritize security risks across Marqeta.
  • Develop risk classification and treatment plans to guide security decision-making.
  • Monitor and track risk remediation efforts, providing guidance on mitigation strategies.
  • Work with business and technical teams to ensure risk treatment plans align with company objectives and security standards.
  • Drive continuous improvement of risk management processes by identifying emerging threats and adapting security strategies accordingly.
  • Compliance & Audit Support

  • Support external and internal audits (ISO 27001, SOC 2, PCI DSS, SOX, etc.) by providing necessary documentation, evidence, and coordination.
  • Ensure control validation activities are conducted regularly to maintain compliance with security frameworks and regulatory requirements.
  • Collaborate with compliance, internal audit, and legal teams to maintain a strong cybersecurity compliance posture.
  • Track and manage cybersecurity exceptions, risk acceptance, and remediation activities.
  • Advisory & Awareness

  • Provide guidance to business units on risk management best practices, security policy implementation, and compliance requirements.
  • Work with leadership to develop risk-based security strategies that align with Marqeta’s business objectives.
  • Support security awareness initiatives by contributing to training programs, guidelines, and best practices for employees and partners.
  • Who You Are

  • 5+ years of experience in Cybersecurity, IT Risk Management, Governance, Compliance, or Information Security roles.
  • Strong understanding of cybersecurity frameworks, regulations, and compliance standards (e.g., ISO 27001, ISO 27002, ISO 27005, NIST, SOC 2, PCI DSS, SOX, etc.).
  • Hands-on experience conducting risk assessments and managing security risks in an enterprise environment.
  • Experience working with GRC tools (e.g., OneTrust, ServiceNow) to track and manage security governance activities.
  • Familiarity with risk management strategies.
  • Strong analytical, communication, and problem-solving skills.
  • Ability to work cross-functionally with technical and non-technical stakeholders.
  • Holding at least one industry certifications such as CISM, CRISC, CISSP, ISO 27001 Lead Auditor, Security+ or equivalent.
  • Nice-To-Haves

  • Bachelor’s or Master’s degree in Computer Science, Information Security, Information Technology, or a related field (or equivalent experience).
  • Experience in the fintech or financial services industry.
  • Knowledge of third-party risk management and vendor security assessment processes
  • Familiarity with cloud security
  • Your Manager

  • Ben Pournader
  • Recruiter For This Role

  • Kayla Osuna
  • Compensation And Benefits

    Marqeta is a Flex First company which allows you to choose your best working environment, whether that be from home or at a company office. To support Flex First, we calibrate pay to a competitive value according to working location.

    When determining salaries, we consider several factors including, but not limited to, skills, prior experience, and work location. The new-hire base salary range for this position, reflected in CAD, is : 89,600 - 112,000.

    We also believe in recognizing the contributions of our people. That's why we award annual bonuses to eligible employees, rewarding both individual performance and the success of the entire company.

    Along with monetary compensation, Marqeta offers

  • Multiple health insurance options
  • Flexible time off – take what you need
  • Retirement savings program with company contribution
  • Equity in a publicly-traded company
  • Monthly stipend to support our remote work model
  • Annual “development dollars” to support our people growth and development
  • Family-forming benefits and up to 20 weeks of Parental Leave
  • About Marqeta

    Marqeta is on a mission to change the way money moves. We’re one of the earliest enablers of embedded finance, a market opportunity sized up in the trillions. Our card issuing platform provides unprecedented flexibility and control for companies to issue cards, authorize transactions, and manage payment operations in real time. Marqeta is powering the most well known brands in the new economy (Block, Cash App, Affirm, Instacart, Doordash, Uber, Walmart, etc). You don’t need to be a Payments expert to join the Marqeta Team, let us help you with that. This is the opportunity of a lifetime to work with innovators around the world and unlock equitable financial access for all.

    Marqeta’s Values

    Solve for the Customer : With a deep understanding of our customers' business and empathy for their needs, we deliver products and services that drive their success. Earning and keeping their trust guides everything we do.

    Do What's Right : Knowing businesses and livelihoods depend on us, we pursue solutions that disrupt responsibly and deliver high-quality results that our customers count on. We own our work from start to finish.

    Simplify and Innovate : We approach challenges with curiosity and take smart risks. Innovation comes from finding better, simpler ways to achieve extraordinary outcomes.

    Win as a Team : We succeed together by embracing diverse perspectives and pushing each other to raise the bar. We lead with humility and set aside hierarchy to work as a team.

    Make it Count : We drive forward with focus and agility. With a sense of urgency and purpose, we get the job done, and done right.

    Equal Employment Opportunity, Accommodations and Privacy

    Marqeta is proud to be an equal opportunity employer that gives consideration to all qualified applicants regardless of race, ancestry, national origin, color, Indigenous, citizenship, religion / creed, sex, sexual orientation, gender identity, gender expression marital status, family status, disability, veteran status, criminal histories consistent with legal requirements, or any other characteristic protected by applicable law.

    Our dedication to diversity and inclusion extends beyond the categories above. Review Marqeta’s ESG Report to see that dedication in action. Fostering an environment where everyone feels valued and respected creates a stronger and more innovative team at Marqeta. We celebrate the unique contributions of each individual and empower all members of our organization. Join us in building a company where diversity thrives and everyone can be their authentic selves.

    If you require reasonable accommodation for the application process and beyond (including due to a disability), please submit this form and we will be more than happy to assist you. Marqeta will make reasonable accommodations for candidates when needed in accordance with applicable law. The Applicant and Candidate Privacy Notice applies to the personal data that you directly provide to us or that we collect during the application and candidate recruitment process.

    Seniority level

    Seniority level

    Mid-Senior level

    Employment type

    Employment type

    Full-time

    Job function

    Job function

    Information Technology and Engineering

    Referrals increase your chances of interviewing at Marqeta by 2x

    Sign in to set job alerts for “Senior Analyst” roles.

    Payments Risk Analyst I, Operations (Platform)

    Senior Governance, Risk & Compliance Analyst

    Senior Manager, Risk Initiatives, Monitoring and Testing

    Senior Manager, Operational Risk and Resilience Program

    Analyst / Consultant / Senior Consultant, Credit Risk Models - Financial Engineering & Modeling

    Cyber Security Risk and Controls Manager

    Senior Analyst, Conflict of Interest - Risk Management

    Senior Analyst, Conflict of Interest - Risk Management

    Manager, Plan Operations Risk & Controls

    Analyst, Enterprise Risk - Internal Audit & Controls

    We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

    J-18808-Ljbffr

    Get your free, confidential resume review.
    or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.