IT Security Analyst GRC

Toronto, Ontario • Contract • August 21, 2026 • 89903

Job Title: IT Security Analyst GRC
Job ID: 89903
Location: Toronto, Ontario 


Overview:
On behalf of our client we are looking for a IT Security Analyst -GRC Contract - Remote Toronto based. The IT Security Analyst supports the organization's Information Security Governance, Risk, and Compliance program by helping identify, assess, document, and monitor information security risks and control obligations. The role partners with IT, business stakeholders, Legal, Privacy, Internal Audit, and third-party vendors to support audit readiness, risk assessments, policy governance, compliance evidence collection, vendor reviews, and management reporting. The successful candidate will bring strong analytical, documentation, and stakeholder management skills, with the ability to translate technical control requirements and risk findings into practical business language suitable for a regulated, global enterprise environment. Role alignment: supports ISO 27001/ISMS activities, security risk assessments, corrective action tracking, control evidence management, policy governance, vendor reviews, and security reporting.


What you will be doing:
Governance & Compliance

  • Support development, maintenance, and periodic review of information security policies, standards, procedures, and guidelines.

  • Coordinate compliance evidence collection for internal audits, external audits, ISO 27001 activities, and other assurance requirements.

  • Maintain accurate governance documentation, control records, exception records, and supporting artifacts in approved repositories or GRC platforms.

  • Assist in preparing security metrics, dashboards, management summaries, and committee materials.

  • Track policy review cycles, control attestations, audit requests, and management action items to closure.

Risk Management

  • Conduct or support information security risk assessments for systems, applications, cloud services, vendors, projects, and business initiatives.

  • Document risks, likelihood, impact, existing controls, treatment plans, residual risk, and ownership in the risk register.

  • Facilitate risk reviews with risk owners, process owners, technology teams, and business stakeholders.

  • Track risk treatment plans, remediation actions, security exceptions, and risk acceptance decisions.

  • Support reporting of risk posture, key risk indicators, and remediation status to management.

Third-Party & Vendor Risk Management

  • Perform vendor security due diligence and third-party risk assessments using questionnaires, interviews, and document reviews.

  • Review SOC 1/SOC 2 reports, ISO certifications, penetration test summaries, policies, and other vendor assurance documentation.

  • Identify vendor control gaps, document risks, and recommend practical mitigation actions.

  • Monitor vendor remediation commitments, reassessment timelines, and security review outcomes.

  • Maintain vendor security assessment records and provide concise reporting to stakeholders.

Audit & Control Assurance

  • Support audit planning, evidence gathering, control walkthroughs, and responses to auditor requests.

  • Perform control testing and compliance reviews against internal security requirements and recognized frameworks.

  • Track audit observations, corrective actions, root cause analysis outcomes, and remediation evidence.

  • Validate closure and effectiveness of corrective actions where assigned.

  • Support continuous monitoring of key information security controls.

Security Awareness & Governance Support

  • Support security awareness, compliance training, and reporting activities.

  • Assist with Information Security Steering Committee or governance meeting materials, minutes, and action tracking.

  • Prepare clear executive summaries, status updates, and decision materials for security leadership.

  • Promote a risk-aware culture by helping business teams understand security obligations in practical terms.


What you must have:
Education

  • Bachelor's degree in Information Security, Cybersecurity, Information Technology, Risk Management, Business Administration, or a related discipline.

  • Equivalent combination of education, training, and professional experience will be considered.

Experience

  • 3–5 years of experience in Information Security, IT Risk, Compliance, Internal Audit, Technology Assurance, or a related governance role.

  • Experience supporting enterprise control frameworks, audit readiness, risk assessments, and compliance programs.

  • Experience conducting vendor security reviews or third-party risk assessments is strongly preferred.

  • Experience working in regulated or global enterprise environments is an asset.

Preferred Certification

  • CISA, CRISC, CISM, CISSP, ISO 27001 Lead Implementer or Lead Auditor, Security+, or equivalent certification.

  • Candidates actively pursuing relevant certifications may also be considered.

Technical Knowledge

  • Information Security Governance ISO/IEC 27001:2022, Security risk assessment  methodologies NIST Cybersecurity Framework, SOC 2 reporting

Third-party risk management

  • GRC Tools Any GRC tools and workflow tracking platforms

  • Cloud security concepts, including Microsoft 365 and Azure

Skills & Competencies

  • Strong analytical and critical thinking skills.

  • Excellent written and verbal communication skills, with the ability to prepare concise, business-ready documentation.

  • Ability to translate technical findings, control gaps, and risk scenarios into clear business impact statements.

  • Strong attention to detail and commitment to evidence quality.

  • Effective stakeholder management and ability to coordinate across IT, business, audit, legal, privacy, and vendor teams.

  • Ability to manage competing priorities and meet deadlines in a dynamic enterprise environment.

  • Practical mindset focused on balancing security, risk reduction, and business enablement.


Salary/Rate Range: $50.00 -$65.00/hr Incorporated


Thank you for your interest in this opportunity. If you are selected to move forward in the process, we will contact you directly. If you do not hear from us, we encourage you to continue visiting our website for other roles that may be a good fit.


For more information about TEEMA and to consider other career opportunities, please visit our website at www.teemagroup.com 

Share This Job

Related Jobs