Senior GRC Specialist at OCS Ontario Cannabis Store | CA | Rezi

Senior GRC Specialist at OCS Ontario Cannabis Store

Senior GRC Specialist

OCS Ontario Cannabis Store · CA

2 weeks ago

Senior GRC Specialist

OCS Ontario Cannabis Store · CA

18 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

Support the execution and continuous improvement of OCS's IT Governance, Risk, and Compliance (GRC) program. Provide expertise across IT governance, risk management, compliance, and audit activities, leveraging ServiceNow GRC capabilities. Identify opportunities to enhance controls, improve processes, and mitigate risk. Support internal and external audits to ensure compliance with regulatory and organizational requirements.

Responsibilities

  • Develop, maintain, and provide guidance on IT policies, standards, procedures, playbooks, plans, and SOPs.
  • Coordinate policy reviews, assess control effectiveness, and identify governance gaps.
  • Support Data Governance and Records & Information Management initiatives.
  • Execute the IT risk management program, including risk identification, assessment, documentation, monitoring, and reporting.
  • Assess risks against industry frameworks and organizational risk appetite.
  • Review mitigation plans, maintain third-party risk processes, and conduct vendor, service, and Threat Risk Assessments (TRAs).
  • Prepare assessment reports and present findings and recommendations to leadership.
  • Draft risk acceptance documentation and facilitate risk discussions.
  • Administer compliance activities within the ServiceNow GRC platform.
  • Monitor compliance coverage and strengthen control effectiveness.
  • Support ongoing monitoring, reporting, and continuous improvement of the IT compliance program.
  • Coordinate internal and external audits, ensuring accurate and timely delivery of required documentation and evidence.
  • Build strong relationships with auditors and provide guidance to stakeholders.
  • Participate in cross-training initiatives and provide support across Information Security and GRC functions.

Requirements

  • Bachelor's degree in Information Security, Information Technology, Computer Science, Engineering, or a related field, or an equivalent combination of education and experience.
  • One or more industry certifications such as CISSP, CISA, CRISC, CISM, GRCP, CGRC, or GIAC.
  • 7+ years of progressive experience in Governance, Risk, and Compliance (GRC), Information Security, or a related discipline.
  • Experience supporting risk management, vulnerability management, remediation activities, and/or security operations.
  • Experience across multiple security domains, including cloud security, security operations, vulnerability management, security architecture, and GRC program administration is preferred.
  • Experience administering or supporting ServiceNow Integrated Risk Management (IRM/GRC) solutions is an asset.
  • Strong knowledge of governance and security frameworks, including NIST, ISO 27001, CIS Controls, COBIT, and related industry standards.
  • Knowledge of Threat Risk Assessment (TRA) methodologies and practices; advanced TRA experience is preferred.
  • Strong analytical, documentation, communication, and stakeholder management skills.
  • Ability to assess risk, communicate complex concepts effectively, and collaborate with technical and business stakeholders.

Skills

  • Information Security
  • Information Technology
  • Computer Science
  • Engineering
  • Governance
  • Risk Management
  • Compliance
  • IT Governance
  • Risk Identification
  • Risk Assessment
  • Risk Documentation
  • Risk Monitoring
  • Risk Reporting
  • Control Effectiveness
  • Policy Development
  • Policy Review
  • ServiceNow GRC
  • Third-Party Risk Management
  • Vendor Risk Assessment
  • Service Risk Assessment
  • Threat Risk Assessment (TRA)
  • Audit Support
  • NIST
  • ISO 27001
  • CIS Controls
  • COBIT
  • Cloud Security
  • Security Operations
  • Vulnerability Management
  • Security Architecture
  • GRC Program Administration
  • Analytical Skills
  • Documentation Skills
  • Communication Skills
  • Stakeholder Management Skills

Location

  • Toronto, ON

Work Type

  • Permanent
  • Full-Time
  • Rare travel within the GTA

Experience Level

  • Senior
  • 7+ years of progressive experience

Education Level

  • Bachelor's degree or equivalent combination of education and experience
  • CISSP, CISA, CRISC, CISM, GRCP, CGRC, or GIAC certifications preferred

Salary/Compensations

  • Target hiring range: $100,000 - $120,000
  • Pay grade 7 salary range: $82,623.96 - $123,507.59

About the Company

  • The Ontario Cannabis Store (OCS) provides safe, responsible access to recreational cannabis for adults 19 and older.
  • Operates the sole legal online store for recreational cannabis in Ontario.
  • Provincial wholesaler of cannabis for private retail stores.
  • An agile start-up in a ground-breaking new industry.
  • A diverse team passionate about delivering a great customer experience.
  • An inclusive organization where every voice is heard.

Equal Opportunity

  • Committed to providing an accessible, equitable and inclusive candidate and employee experience.
  • Provides reasonable accommodation throughout the recruitment process and in employment.