Position Overview
The Cybersecurity GRC Lead is responsible for supporting and advancing the cybersecurity governance, risk, and compliance practices within Kruger's Digital and IT Group. The incumbent serves as the senior operational leader for GRC, leading the design and continuous improvement of the cybersecurity governance framework, overseeing cybersecurity risk and compliance programs, and developing and mentoring the GRC capability, including people, methodologies, and tools. The role also supports audit and regulatory interactions through structured analysis, consolidated risk reporting, and well-founded recommendations.
This position reports directly to the Director of Cybersecurity, who is responsible for the role's day-to-day leadership, priorities, and performance. The position also maintains a dotted-line relationship with the Vice President, Legal Affairs, to ensure alignment on regulatory compliance, legal risk, and matters requiring legal guidance or escalation.
Responsibilities
Cybersecurity Governance
- Develop, maintain, and communicate cybersecurity policies, standards, and guidelines aligned with enterprise objectives and industry frameworks (NIST CSF, ISO 27001, CIS Controls, SCF).
- Run the operational governance cadence (working committees, policy reviews, control maturity assessments) and prepare the associated reporting.
- Define the cybersecurity KPI framework and provide visibility into performance and risk exposure.
Cybersecurity Risk Management
- Oversee the cybersecurity risk assessment program across IT, OT, and cloud environments; perform assessments on the most complex or strategic scopes.
- Own the cybersecurity risk register: ensure risks are properly categorized, prioritized, and assigned to risk owners, and consolidate the risk posture.
- Collaborate with risk owners to define and monitor risk treatment plans; escalate risks that exceed tolerance levels.
- Own the third-party risk management program (methodology, vendor tiering, oversight of assessments) covering vendors and suppliers.
- Lead the cybersecurity resilience workstream within Business Impact Analysis (BIA), Business Continuity (BCP), and Disaster Recovery (DR) exercises, including scenario testing and lessons learned.
Cybersecurity Compliance & Audit
- Own the cybersecurity compliance covering internal policies, standards, and regulatory requirements.
- Act as operational lead for cybersecurity audits (internal, external, regulatory), including evidence collection, remediation governance, and auditor relationships.
- Maintain up-to-date knowledge of evolving regulations and advise on their impact.
Cybersecurity Advisory
- Act as a trusted advisor by providing structured analysis, metrics, and actionable recommendations.
- Prepare Board-ready materials and executive presentations for IT Leadership.
- Build strong working relationships with stakeholders to ensure a consistent approach to cyber risk.
- Promote a culture of accountability and continuous improvement in cybersecurity governance.
Qualifications
- Bachelor’s degree in information security or a related field.
- Certifications such as CISM, CRISC, CISSP, ISO 27001 Lead Implementer/Auditor, or equivalent; CISM or CRISC preferred.
Experience
- 8 to 10 years or more of professional experience in cybersecurity governance, risk management, or compliance, including 3+ years leading a practice.
- Proven track record owning risk registers, compliance programs, and audit engagements.
- Experience working with multidisciplinary teams across IT, OT, Legal, Audit, Business functions.
Skills And Abilities
Technical Skills
- Solid understanding of cybersecurity frameworks (NIST CSF, ISO 27001, CIS Controls, SCF) and risk methodologies (EBIOS, FAIR).
- Knowledge of regulatory requirements, including GDPR, Law 25, and NERC.
- Familiarity with GRC tools and platforms is an asset.
Business and Leadership Skills
- Strong analytical and critical thinking skills.
- Ability to synthesize and present complex information to executives in clear business terms.
- Excellent organizational and stakeholder management skills.
- Collaborative, diplomatic, and detail-oriented mindset.
- Leadership and coaching skills; ability to influence without formal authority across business units.
- Comfort operating with ambiguity and arbitrating competing priorities.
LANGUAGES
- Fluent in both English and French (written and spoken).
Knowledge of English is required for this specific position as Kruger deals with partners across North America and the successful candidate will be required to communicate frequently with them. Kruger has taken all reasonable steps to avoid imposing English language requirements, including assessing the actual language needs associated with the duties to be performed, ensuring that the language skills already required of other employees were insufficient for the performance of those duties, and limiting as much as possible the number of positions with duties requiring English language skills.