Leader, Governance, Risk & Compliance
Core
Establish GRC mandate and goals, lead ISMS operations, and embed security risk management culture across production, delivery, and operations for a Canadian digital payments ecosystem.
Role type
Senior IC Leader, Governance, Risk & Compliance (GRC)
Builds
Information Security Management System (ISMS), risk treatment plans, compliance frameworks, and reporting metrics for a national financial technology platform.
Domain
Financial Technology / Cybersecurity / Regulatory Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
GRC program leadership, ISMS implementation, risk analysis and translation, policy development, audit management, regulatory compliance, team coaching and mentoring, strategic budgeting, stakeholder influence.
Preferred skills
CISM, CISA, CRISC certifications, ISO 27001 implementation experience, GRC platform expertise, secret clearance eligibility.
Technologies
ISO 27000 Series, NIST, PCI standards, GRC platforms
Responsibilities
Develop and socialize corporate policies aligned with ISO/NIST/PCI; coordinate risk management processes and risk treatments; support internal and external audit functions; manage risk portfolio and reporting to management committees; drive improvements from risk/control gaps; lead disaster recovery and business continuity; mentor and manage the GRC team; collaborate with Legal, Privacy, and Vendor Management.
Seniority
Senior, hands-on IC with leadership responsibilities
