Job Title: IT Security Specialist V
Duration: 6 months (possibility of extension/conversion)
Location: Toronto OR Mississauga, ON (2 days onsite initially, might change to 4 days onsite/week)
Department Overview
The organization is building a world-class, diverse and inclusive technology team.
The scale and scope of the organization, combined with the rapid pace of technological change, make it essential to be smart and open-minded in the way technology risks are managed. Technology and business teams are becoming increasingly intertwined as new opportunities emerge.
The Global Security & Defense team consists of highly valued professionals who support technology-related regulatory interactions, including examinations led by the 1st, 2nd, and 3rd Lines of Defense.
The team provides oversight and governance and independently challenges high and medium-severity issues associated with:
- Regulatory findings
- Audit findings
- Operational Risk Management
- Issue remediation
- Potential overdue issues
- Validation failures
- Governance reporting
- Regulatory examinations
- Assurance functions
The team also provides issue support, insights, governance reporting, examination support, and demand management support for assurance functions.
Job-Specific Accountabilities
We are looking for someone who is well-versed in providing Governance, Risk & Compliance (GRC), issue remediation oversight, technology risk management, and control best practices that align with the organization's overall technology strategy and objectives.
The individual will partner with Technology teams to provide independent challenge and oversight of issue remediation plans affecting the organization's information security control environment.
Key responsibilities include:
- Lead assessments of audit and regulatory finding remediation required to mitigate risks within technology infrastructure and applications.
- Work with stakeholders across the Three Lines of Defense to ensure effective risk mitigation and remediation.
- Provide advice and guidance to Technology teams and Technology Risk functions in areas requiring subject matter expertise and interpretation, including:
- Audit & Assurance Standards
- IT Risk Governance
- Technology Control Frameworks
- Governance, Risk & Compliance (GRC) frameworks
- Contribute to the development and maturation of Governance, Oversight & Control practices through improvements in:
- Risk Identification
- Control Design
- Control Testing
- Operating Effectiveness
- Review and challenge remediation plans associated with audit, regulatory, technology risk, and information security findings.
- Assess supporting evidence to determine whether remediation activities sufficiently address identified risks and control deficiencies.
- Identify emerging risk themes and trends and provide specialized risk-management advice to senior management and relevant teams.
- Raise awareness of relevant industry, external, internal, enterprise, technology, and security risks.
- Lead continuous improvement initiatives using Agile and Lean methodologies to develop sustainable and innovative solutions.
- Leverage technologies and tools including:
- Artificial Intelligence (AI)
- Machine Learning (ML)
- Power BI
- Power Apps
- Python
MUST-HAVE Hard Skills
- Very strong communication skills, both written and verbal. This is a key requirement.
- 10+ years of experience as an IT Risk Specialist, with relevant experience in Governance, Risk & Compliance (GRC) within regulated industries.
- Professional audit, risk, information security, or technology control certification preferred, such as:
- Must have practical experience performing assurance, validation, or quality assurance reviews of audit and regulatory findings.
- CISA
- CRISC
- CIA
- Equivalent certification
- Formal training or demonstrated competency in:
- Audit testing techniques
- Evidence evaluation
- Issue remediation validation
- Root Cause Analysis (RCA)
- Control Operating Effectiveness assessment
SOFT SKILLS
- Strong attention to detail
- Excellent written and verbal communication
- Ability to work with multiple stakeholders and senior management
- Ability to independently challenge risk and remediation decisions
NICE-TO-HAVE
- Six Sigma
- CISSP certification or equivalent experience
- AI Security / AI Risk experience and related tools
- ServiceNow
- Lean / Agile continuous improvement experience
- Power BI / Power Apps
- Python
- Exposure to AI / Machine Learning initiatives