GRC / TPRM Specialist in Information Security

Job title:

GRC / TPRM Specialist in Information Security

Company

emergiTEL

Job description

  • 5+ years proven experience in GRC
  • Proven experience in Technology TPRM and third-party risk assessments, including knowledge of cybersecurity and regulatory frameworks. (ex;. OnetTrust, Sentinel, Security Scrorecard, etc)
  • Good understanding of SOX IT General Controls (ITGCs) and compliance expectations related to external service providers.
  • Demonstrated experience in technology risk analysis, action plan mapping, and residual risk management.
  • Practical experience with technology-related due diligence processes.

Langue : Bilingue ou AngloJob description:We are seeking to engage a consultant to support our Technology Third Party Risk Management (TPRM) program. The selected professional will work closely with the Information Security Governance, Risk & Compliance (GRC) team and other stakeholders to assess and monitor technology-related risks associated with external vendors.
Scope of Work:

  • Support the Technology TPRM process by performing risk assessments of third-party vendors providing technology products or services.
  • Review and analyze vendor responses to cybersecurity and risk questionnaires, including relevant supporting documentation.
  • Identify and report control gaps, with a particular focus on risks that could impact SOx (Sarbanes-Oxley) compliance.
  • Conduct technology risk analysis, map mitigation action plans, and track the closure of identified risks.
  • Assess and report on residual risk levels, ensuring clear documentation and escalation of high-risk findings.
  • Assist in conducting technology due diligence for new and existing vendors.
  • Collaborate with internal teams (Procurement, Legal, Privacy, Architecture) to ensure vendor engagements align with internal policies, standards, and regulatory requirements.

Required Qualifications:

  • Proven experience in Technology TPRM and third-party risk assessments, including knowledge of cybersecurity and regulatory frameworks.
  • Solid understanding of SOx IT General Controls (ITGCs) and compliance expectations related to external service providers.
  • Demonstrated experience in technology risk analysis, action plan mapping, and residual risk management.
  • Practical experience with technology-related due diligence processes.
  • Strong analytical, communication, and documentation skills.
  • Ability to work independently and manage multiple priorities in a dynamic environment.

Expected salary

Location

Brossard, QC

Job date

Sun, 06 Jul 2025 01:04:38 GMT

To help us track our recruitment effort, please indicate in your email/cover letter where (jobsnearcanada.com) you saw this job posting.

Share

CUPE – Fall 2025 – TA – ADM3395

Job title: CUPE - Fall 2025 - TA - ADM3395 Company University of Ottawa Job…

3 minutes ago

Human Resources Administrator – 6 Month Contract

Job title: Human Resources Administrator - 6 Month Contract Company Sodexo Job description identity, status…

14 minutes ago

Bilingual Tax Analyst III

Job title: Bilingual Tax Analyst III Company WilsonHCG Job description supervision Prior programming/coding experience is…

45 minutes ago

Bilingual Long-Term Resource Planner (Contract)

xpathjobsnearcanada.com/html/body/div[2]/div[1]/div/div[1]/h1/ajobsnearcanada.com_company_name xpathjobsnearcanada.com/html/body/div[2]/div[1]/div/div[1]/div/ajobsnearcanada.com_job_location

56 minutes ago

Assistant Professor – Indigenous Education

jobsnearcanada.com Job Family: Academic Leadership and Faculty Union affiliation: APUO Faculty/Department: Formation à l'enseignement_FT Campus:…

56 minutes ago

Senior Global Product Manager/Owner

xpathjobsnearcanada.com/html/body/div[2]/div[1]/div/div[1]/h1/ajobsnearcanada.com_company_name xpathjobsnearcanada.com/html/body/div[2]/div[1]/div/div[1]/div/ajobsnearcanada.com_job_location

56 minutes ago
For Apply Button. Please use Non-Amp Version

This website uses cookies.