Job Description
The Interim Director, Technology GRC will lead and mature governance, risk, and compliance programs across IT and cybersecurity during the interim period. This role oversees IT SOX controls, cybersecurity governance, vendor risk, vulnerability management, and privacy-related technology controls.
The successful candidate will partner with Legal, Technology, Compliance, and business stakeholders to strengthen risk management practices and maintain alignment with regulatory, audit, and policy requirements.
Key Responsibilities
IT SOX Compliance
- Oversee the full IT SOX control lifecycle, including annual scoping, testing, remediation, and reporting.
- Oversee access management controls, role-based access, and periodic access reviews for in-scope systems while strengthening access governance practices.
- Partner with internal teams to ensure SOX controls are properly designed and operating effectively.
- Work with internal and external auditors to support efficient audit cycles and timely issue resolution.
Cybersecurity Governance
- Develop and maintain cybersecurity policies, risk frameworks, and governance practices aligned with standards such as NIST CSF and ISO 27001.
- Track and report enterprise control effectiveness and overall risk posture.
- Ensure controls are implemented effectively across on-premises, hybrid, cloud, and SaaS environments.
Vendor Risk Management
- Lead third-party risk assessments for technology vendors and service providers.
- Partner with procurement and business owners to reduce vendor-related security risks.
Vulnerability Management Oversight
- Work with infrastructure and application teams to remediate identified vulnerabilities on time.
- Analyze vulnerability data to identify recurring issues and drive lasting improvements.
Privacy and Legal Collaboration
- Partner with Legal and Compliance to implement and maintain privacy controls aligned with applicable laws, including GDPR and CCPA.
- Coordinate Data Subject Access Requests across technical and business teams to support timely, compliant fulfillment.
- Provide risk and control guidance for new initiatives and third-party engagements involving personal or sensitive data.
Leadership and Stakeholder Engagement
- Lead cross-functional risk discussions and help stakeholders make informed, risk-aware decisions.
- Coach junior team members and help build a strong, accountable GRC culture.
- Maintain a clear GRC operating rhythm, including priority tracking, issue follow-up, stakeholder updates, and escalation of key risks or control gaps.
- Prepare clear risk, compliance, and control updates for technology leadership, audit stakeholders, and business partners.
- Track audit findings, remediation plans, and management action items to ensure issues are resolved on time and supported by appropriate evidence.
Experience
- 10+ years of experience in IT risk management, audit, cybersecurity governance, compliance, or a related field.
- Deep understanding of IT general controls (ITGC), SOX compliance, and technology risk frameworks.
- Experience stepping into interim leadership roles with minimal ramp-up time.
- Experience managing or contributing to privacy compliance efforts.
- Strong background in third-party risk and vulnerability management programs.
- Proven ability to work with technical and non-technical stakeholders, including Legal, Compliance, Technology, and business teams.
Education and Designations
- Degree in Information Technology, Cybersecurity, Information Systems, Risk Management, or a related field.
- Professional certifications such as CISA, CIA, CRISC, or equivalent are strongly preferred.
- Familiarity with frameworks such as NIST CSF, ISO 27001, COBIT, and SOC 2.
Affinity Earn
Know someone who’s great for this, or any of our open roles? Earn up to $4,000/year for each successful referral through Affinity Earn. You can also earn up to $50,000 for helping us find new clients. Learn about our referral program at https://affinity-group.ca/earn/ or browse our jobs & follow us at https://www.linkedin.com/company/affinity-staffing/jobs/
About Affinity
Affinity Group is a technology and business consulting and services company. We believe in creating long term relationships between clients and consultants that foster a mutually beneficial partnership. Affinity is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All employment is decided on the basis of qualifications, merit and business need.
For more information on Affinity, please visit www.affinity-group.ca
Job Number: 14011