Senior GRC Specialist

OCS Ontario Cannabis Store

Toronto

On-site

CAD 100,000 - 120,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

The Ontario Cannabis Store in Toronto, ON is seeking a Senior GRC Specialist to drive IT governance, risk, and compliance initiatives. You will leverage ServiceNow GRC to strengthen controls, support audits, and work with stakeholders across the business.

The ideal candidate has 7+ years in GRC, IT risk, or related fields, with strong knowledge of NIST/ISO 27001 and risk methodologies. This permanent role offers a competitive package and room to evolve in a fast-growing industry.

Qualifications

  • Bachelor's degree in Information Security, IT, CS or related field.
  • 7+ years of experience in GRC, IT risk, or related discipline.
  • Experience with risk management, vulnerability remediation, and security operations.

Responsibilities

  • Develop, maintain, and guide IT policies, standards, procedures, playbooks, plans and SOPs to align with regulatory requirements and governance frameworks.
  • Coordinate reviews, assess control effectiveness, identify gaps, and implement improvements.
  • Support Data Governance and Records & Information Management initiatives as required.
  • Execute IT risk management activities: risk identification, assessment, documentation, monitoring and reporting.
  • Assess risks against industry frameworks and communicate findings to technical and non-technical audiences.
  • Support audits and prepare assessment reports with leadership.
  • Administer compliance activities within the ServiceNow GRC platform.
  • Coordinate internal and external audits and liaison with auditors.

Skills

GRC expertise
IT risk & compliance
Policy development
Audit coordination
Stakeholder management
ServiceNow GRC
Risk assessment
Threat Risk Assessment
Vendor risk management
Communication skills

Education

Bachelor's degree in Information Security/IT/CS

Tools

ServiceNow GRC

Job description

About Us

The Ontario Cannabis Store provides safe, responsible access to recreational cannabis for adults 19 and older. We operate the sole legal online store for recreational cannabis in Ontario and are the provincial wholesaler of cannabis for private retail stores.

About Us

The Ontario Cannabis Store provides safe, responsible access to recreational cannabis for adults 19 and older. We operate the sole legal online store for recreational cannabis in Ontario and are the provincial wholesaler of cannabis for private retail stores. Working at the OCS is a unique opportunity to be part of an agile start-up in a ground-breaking new industry. We're a diverse team passionate about delivering a great customer experience, working together with mutual respect and building value out of our differences. We're an inclusive organization that understands that delivering great results comes out of ensuring every voice is heard.

About The Role

We're looking for a Senior GRC Specialist to join our team. In this role, you'll support the execution and continuous improvement of OCS's Information Technology (IT) Governance, Risk, and Compliance (GRC) program. Working closely with business stakeholders and cross-functional teams, you'll provide expertise across IT governance, risk management, compliance, and audit activities while leveraging ServiceNow GRC capabilities to strengthen program effectiveness. As a trusted advisor, you'll identify opportunities to enhance controls, improve processes, and mitigate risk through practical, risk-informed recommendations. You'll also play a key role in supporting internal and external audits, helping ensure compliance with regulatory and organizational requirements. The ideal candidate brings a strong understanding of IT risk and compliance practices, stays current on emerging technologies, industry standards, and evolving threats, and is passionate about building and maintaining a GRC program that is both effective and adaptable in a changing technology landscape.

About Your Day
  • Develop, maintain, and provide guidance on IT policies, standards, procedures, playbooks, plans, and SOPs, ensuring alignment with regulatory requirements, industry standards, and organizational governance frameworks.
  • Coordinate policy reviews, assess control effectiveness, identify governance gaps, and recommend or implement improvements.
  • Support Data Governance and Records & Information Management initiatives as required.
  • Execute all aspects of the IT risk management program, including risk identification, assessment, documentation, monitoring, and reporting.
  • Assess risks against industry frameworks and organizational risk appetite, documenting findings in business-friendly language for technical and non-technical audiences.
  • Review mitigation plans, maintain third-party risk processes, and conduct vendor, service, and Threat Risk Assessments (TRAs).
  • Prepare assessment reports, present findings and recommendations to leadership, and support continuous improvement initiatives.
  • Draft risk acceptance documentation and facilitate risk discussions with IT leadership, Enterprise Risk Management, and Privacy teams.
  • Administer compliance activities within the ServiceNow GRC platform, ensuring controls are appropriately mapped, documented, attested, reviewed, and approved.
  • Monitor compliance coverage, strengthen control effectiveness, and implement new compliance controls where required.
  • Support ongoing monitoring, reporting, and continuous improvement of the IT compliance program.
  • Coordinate internal and external audits, ensuring accurate and timely delivery of required documentation and evidence.
  • Build strong relationships with auditors and provide guidance to stakeholders throughout audit and remediation activities.
  • Participate in cross-training initiatives and provide support across Information Security and GRC functions to maintain operational resilience and team coverage.
About You
  • . Bachelor's degree in Information Security, Information Technology, Computer Science, Engineering, or a related field, or an equivalent combination of education and experience.
  • One or more industry certifications such as CISSP, CISA, CRISC, CISM, GRCP, CGRC, or GIAC; CISSP, CGRC, or equivalent advanced security and governance certifications are considered an asset.
  • 7+ years of progressive experience in Governance, Risk, and Compliance (GRC), Information Security, or a related discipline.
  • Experience supporting risk management, vulnerability management, remediation activities, and/or security operations.
  • Experience across multiple security domains, including cloud security, security operations, vulnerability management, security architecture, and GRC program administration is preferred.
  • Experience administering or supporting ServiceNow Integrated Risk Management (IRM/GRC) solutions is an asset.
  • Strong knowledge of governance and security frameworks, including NIST, ISO 27001, CIS Controls, COBIT, and related industry standards.
  • Knowledge of Threat Risk Assessment (TRA) methodologies and practices; advanced TRA experience is preferred.
  • Strong analytical, documentation, communication, and stakeholder management skills.
  • Ability to assess risk, communicate complex concepts effectively, and collaborate with technical and business stakeholders.
About The Job
  • Location: Toronto, ON near York Mills and Yonge Street
  • Hours of Work: 36.25 a week
  • Employment Type: Permanent, Full-Time
  • Required Travel: Rare, usually within the GTA
Compensation

The target hiring range for this position is $100,000 - $120,000. This is a pay grade 7 role, with a salary range of $82,623.96 - $123,507.59. Placement in the salary range will be based on factors such as market conditions, internal equity, and candidate experience, skills, and qualifications relevant to the role. We are committed to providing an accessible, equitable and inclusive candidate and employee experience. We provide reasonable accommodation throughout the recruitment process and in employment. If you require an accommodation, please let us know, we will work with you to meet your needs.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Specialist
Senior GRC Specialist

OCS • Toronto

On-site
CAD 100,000 - 120,000
Senior Support Analyst
Senior Support Analyst

OCS Ontario Cannabis Store • Toronto

On-site
CAD 93,000 - 103,000
Senior Support Analyst
Senior Support Analyst

StratCann Services Inc. • Toronto

On-site
CAD 93,000 - 103,000
Security Analyst - GRC
Security Analyst - GRC

Quantum Technology Recruiting Inc. (QTR) • Toronto

Hybrid
CAD 75,000 - 85,000
Senior Cyber Security Analyst - GRC
Senior Cyber Security Analyst - GRC

Metro Supply Chain • Mississauga

On-site
CAD 105,000 - 125,000
Data Governance Specialist
Data Governance Specialist

OCS • Toronto

On-site
CAD 72,000 - 107,000
Cyber Security Manager
Cyber Security Manager

Akkodis • Toronto

Hybrid
CAD 120,000 - 180,000
Performance-based bonuses
Defined contribution pension plan
Professional growth opportunities
+4
Senior Policy Advisor
Senior Policy Advisor

OCS Ontario Cannabis Store • Toronto

On-site
CAD 85,000 - 95,000
Senior System Analyst
Senior System Analyst

OCS Ontario Cannabis Store • Toronto

On-site
CAD 71,000 - 108,000
Data Governance Specialist
Data Governance Specialist

OCS Ontario Cannabis Store • Toronto

On-site
CAD 85,000 - 100,000