Senior Specialist, Risk Management

Tundra Technical Solutions

Toronto

On-site

CAD 120,000 - 180,000

Full time

11 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Tundra Technical Solutions is seeking a senior Risk Management professional to lead the Client-wide cybersecurity program and governance framework in Toronto. The role focuses on identifying, assessing, and mitigating enterprise risks across divisions, agencies, and partnerships.

You will oversee risk remediation, develop GRC policies, and advise senior leadership on risk decisions to strengthen the organization's security posture and regulatory alignment.

Qualifications

  • 10+ years of experience in Risk Management, focused on Cyber Risk Management.
  • Extensive knowledge of risk concepts: vulnerability, threat, likelihood, impact, mitigation, remediation.
  • Extensive expertise in Information Security or Governance, Risk & Compliance (GRC).
  • Experience with third party assessments, especially with SMEs.
  • Experience reviewing SOC 2 Type II reports and ISO 27001 certifications.
  • Experience PCI assessments or PCI audits preparation.
  • Experience developing and implementing cybersecurity policies and standards.
  • Experience risk assessments based on NIST Cybersecurity Framework.

Responsibilities

  • Oversee risk remediation plans and ensure timely implementation with stakeholders.
  • Lead the GRC program by developing policies, frameworks, and controls to manage enterprise risks.
  • Provide guidance on regulatory compliance, internal controls, and risk mitigation strategies.
  • Monitor emerging risks, industry trends, and regulatory changes.
  • Prepare risk reports, dashboards, and presentations for executive leadership.
  • Develop and deliver training to promote risk awareness across the organization.
  • Collaborate with senior leaders to integrate risk management into strategic planning.
  • Communicate with stakeholders regarding business and technical decisions impacting solutions.

Skills

Communication skills
Strategic thinking
Risk management
Cybersecurity knowledge
Stakeholder management
Content creation

Education

Bachelor's degree in Business/Technology

Job description

To support the Manager of Risk Management Centre of Excellence and senior cybersecurity leadership in maintaining a Client wide cybersecurity program that enhances protection across the organization.

To provide strategic cyber risk management expertise by identifying, assessing, and mitigating enterprise wide risks across the Client’s divisions, agencies, and corporations.

To lead the development and execution of Governance, Risk & Compliance (GRC) frameworks, ensuring alignment with regulatory requirements, industry best practices, and corporate policies.

To oversee risk remediation planning, monitor compliance initiatives, and provide guidance to senior leadership on risk related decisions to enhance the Client’s overall risk posture.

MAJOR RESPONSIBILITIES:
  • Oversees risk remediation plans, ensuring timely implementation of mitigation strategies in collaboration with stakeholders.
  • Drives the Governance, Risk & Compliance (GRC) program by developing policies, frameworks, and controls to manage enterprise risks effectively.
  • Provides expert guidance on regulatory compliance, internal controls, and risk mitigation strategies to support business objectives.
  • Monitors emerging risks, industry trends, and regulatory changes to proactively adjust risk management strategies.
  • Prepares risk reports, dashboards, and presentations for executive leadership, identifying key risk exposures and recommended actions.
  • Develops and delivers training programs to enhance risk awareness and promote a risk conscious culture across the organization.
  • Collaborates with senior leaders and cross functional teams to integrate risk management into strategic planning and decision making.
  • Communicates effectively with stakeholders, clients, project managers, and team members regarding business and technical decisions and actions that may impact solutions.
QUALIFICATIONS / CERTIFICATIONS:
  • Post secondary degree in Business, Technology, or a related discipline.
  • 10+ years of experience in Risk Management, primarily focused on Cyber Risk Management.
  • Extensive knowledge of risk concepts, including vulnerability, threat, likelihood, impact, mitigation, and remediation.
  • Extensive expertise in Information Security or Governance, Risk & Compliance (GRC).
  • Extensive experience conducting third party assessments, particularly involving small and medium sized service providers.
  • Extensive experience reviewing and assessing SOC 2 Type II reports and ISO 27001 certifications.
  • Experience conducting PCI assessments or preparing an organization for PCI audits.
  • Experience developing and implementing cybersecurity policies and standards across an enterprise.
  • Experience conducting risk assessments based on the NIST Cybersecurity Framework and related standards.
  • Minimum of two certifications required: CISSP, CISA, CISM, CRISC.
SKILLS:
  • Excellent written and verbal communication skills, with the confidence to communicate effectively with business partners, leadership, vendors, and technical stakeholders.
  • Creative, critical, and strategic thinker.
  • Ability to assess communication gaps and opportunities and develop strategies that support business objectives.
  • Ability to create content, toolkits, and awareness materials supporting transformative programs.
  • Ability to lead effective communication across project stakeholders, internal teams, corporate partners, clients, and external partners.

This posting is for an existing vacancy.

Tundra Technical Solutions is a global workforce and technology delivery firm, ranked by Staffing Industry Analysts as one of the largest in North America. At Tundra, we aren't just hiring top talent at the world's most recognizable brands; we are pioneers of social recruitment. We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other legally protected characteristics. We welcome and encourage diversity in the workplace.

We use artificial intelligence tools to help our recruiters screen and assess talent. These tools do not replace human decision making in the process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Specialist Risk Management
Senior Specialist Risk Management

TEEMA • Toronto

On-site
CAD 126,000 - 176,000
Senior Cyber Risk & GRC Leader
Senior Cyber Risk & GRC Leader

Tundra Technical Solutions • Toronto

On-site
CAD 120,000 - 180,000
Senior Consultant, Cyber Risk Management & Transformation
Senior Consultant, Cyber Risk Management & Transformation

BDO Canada • Toronto

On-site
CAD 100,000 - 140,000
Senior Consultant, Cyber Risk Management & Transformation
Senior Consultant, Cyber Risk Management & Transformation

BDO Canada • Ottawa

On-site
CAD 90,000 - 125,000
Senior Manager, Cybersecurity & GRC
Senior Manager, Cybersecurity & GRC

Axiom Global Technologies • Mississauga

On-site
CAD 150,000 - 210,000
Senior Manager, Technology Risk Governance & Compliance
Senior Manager, Technology Risk Governance & Compliance

Corus Entertainment • Toronto

Hybrid
CAD 85,000 - 110,000
Senior Cyber Security Analyst - GRC
Senior Cyber Security Analyst - GRC

Metro Supply Chain • Mississauga

On-site
CAD 105,000 - 125,000
Client Risk Analyst
Client Risk Analyst

Eliassen Group • Dover

On-site
USD 69,000 - 83,000
Medical benefits
401k with match
Life insurance
+1
(Canada) Senior Cyber Compliance & Audit Analyst (contract)
(Canada) Senior Cyber Compliance & Audit Analyst (contract)

Thomson Reuters  • Toronto

Hybrid
CAD 55,104 - 66,124
Medical benefits
Dental benefits
Vision benefits
+1
Security Governance, Risk and Compliance Specialist
Security Governance, Risk and Compliance Specialist

RXinsider LTD. • Montreal (administrative region)

Hybrid
CAD 90,000 - 120,000