Security GRC Specialist
Aviso Wealth
At Aviso, we are dedicated to improving the financial well-being of Canadians. As a leading wealth management organization, we are committed to leadership, innovation, partnership, responsibility, and community. Working with talented and energetic professionals who exemplify our values every day, you will quickly notice that our people and dynamic ‘oneaviso’ culture sets us apart. If you are looking for interesting and challenging work, at a company committed to its people, find out more about what Aviso has to offer at .
The Opportunity:
We’re looking for an experienced Security GRC Specialist to join our growing Security GRC team.
Reporting to the Director of Security Governance, Risk & Compliance (GRC), the Security GRC Specialist will be responsible to govern the risk management lifecycle, including monitoring findings remediation, assurance programs and reporting appropriate metrics to the senior leadership.
Who you are:
- Service – You put your clients’ needs first. You advocate service excellence, and work to deliver client-centric solutions, and proactively develop strategic partnerships that allow Aviso to become a trusted advisor and partner
- Execution – You are committed to achieving your goals and to succeed. This includes focusing on “getting things done”, as well as recognizing and taking advantage of opportunities as they arise. You are consistently looking for ways to improve your personal best and see value in continuous improvement. You take accountability for your actions and learn from mistakes
- Collaboration – You work collaboratively with others with the common goal of driving positive results. Making meaningful contributions to your team to achieve organizational goals is a priority. You proactively encourage collaboration, build trust and inclusion, and work to establish effective relationships both inside and outside of the organization
What your day looks like:
Risk Management
- Conduct risk assessments of IT infrastructure, applications, third parties, and critical processes to identify, assess and report on technology and cybersecurity risks
- Track and Manage mitigation plans and ensure timely resolution
- Support the development and maintenance of cybersecurity risk register KPI monitoring and reporting
Governance
- Assist in development, review and maintenance of Technology & Cybersecurity Policies, Standards, and procedures
- Ensure alignment of internal policies with industry frameworks (NIST, ISO, COBIT) ·
- Support audits and board level reporting including preparing key metrics
Assurance
- Monitor compliance with external regulatory and internal control requirements
- Support internal and external audits · Conduct periodic control testing including design and operating effectiveness
Third Party Risk
- Support vendor risk assessments, including reviewing response to questionnaire
GRC Tools ·
- Maintain and enhance governance process through GRC tools (e.g., Archer, ServiceNow GRC, Resolver etc.)
- Support reporting, dashboard creation and automation of risk and compliance processes
Your experience and skills:
- Bachelor's Degree in Information Security, Computer Science, Business, Risk Management or a related field
- Relevant certifications such as CRISC, CISA, CISSP are an asset
- 5-8 years of experience in IT risk, cybersecurity risk, audit, compliance or equivalent roles
- Working knowledge of IT governance frameworks and standards (e.g., NIST CSF, ISO 27001, ITIL)
- Familiarity with regulatory and compliance requirements
- Experience with GRC platforms and tools
- Ability to work in a fast-paced environment and stay updated on emerging threats and vulnerabilities
- Proactiveness, natural curiosity, a willingness to learn, adaptability in an evolving environment, and a strong problem-solving mindset
- Ability to work across multiple business units and collaborate across teams
- Fluent communication skills in English are required and bilingual skills in French are an asset
Why Aviso?
At Aviso, you will find a dynamic and inclusive culture that rewards innovation and celebrates success.
Here are a few things that set us apart:
- Competitive compensation package that rewards and recognizes individual contributions
- Excellent health, dental and insurance benefits to meet the diverse needs of our employees
- Generous vacation time, fitness benefit, parental leave top-up options
- Matching contributions to our retirement program
- Commitment to the continuous improvement of our staff through learning & development and an education assistance program
- Regular social events to foster teamwork
Your Information
By submitting your application, you consent to the collection, use, and disclosure of your provided personal information for the purposes of assessing your qualifications and suitability for employment with Aviso. Your information will be handled in accordance with applicable Canadian privacy laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and relevant provincial legislation. Your data may be shared with authorized personnel involved in the recruitment process and retained only as long as necessary to fulfill these purposes or as required by law.
Further information is available on the Privacy link on our Career Page – Privacy Policies
Equal Employment Opportunity
Aviso welcomes and encourages applications from all qualified individuals including persons with disabilities. If you require an accommodation, we will work with you to meet your needs in all stages of the hiring process.
We thank all applicants for their interest, however, only those selected for further consideration will be contacted.
No recruiters or agencies, please.
Company Overview:
Aviso is a leading wealth management and investment services provider for the Canadian financial industry, with approximately $145 billion in total assets under administration and management, and over 1,000 employees. We’re building a comprehensive, technology-enabled, client-centric wealth services ecosystem. Our clients include our partners, advisors, and investors. We’re a trusted partner for nearly all credit unions across Canada, in addition to a wide range of portfolio managers, investment dealers, insurance and trust companies, and introducing brokers. Our partners depend on Aviso for specific solutions that give them a competitive edge in a rapidly evolving, highly competitive industry. Our investment dealer and mutual fund dealer and our insurance services support thousands of investment advisors. Our asset manager, NEI Investments, specializes in investing responsibly. Our online brokerage, Qtrade Direct Investing®, empowers self-directed investors, and our fully automated investing service, Qtrade Guided Portfolios®, serves investors who prefer a hands-off approach. Aviso Correspondent Partners provides custodial and carrying broker services to a wide range of firms. We have offices in Toronto, Vancouver, Montreal, and Winnipeg. Aviso is backed by the collective strength of our owners: the credit union Centrals, Co-operators/CUMIS, and Desjardins. We’re proud to power businesses that empower investors .
A career with Aviso means being part of a group of talented, energetic professionals who live their values every day, and belonging to an organization dedicated to your success and career development. If you’re looking for interesting and challenging work, at a company committed to its people, apply to join our team.
Salary
This position is posted with an expected salary range of $105000 - $125,000 CAD annually. Individual compensation packages are based on various factors unique to each candidate and the requirements of the position.
$80 - $120 per hour
...Benchmark , General Catalyst , Peter Thiel , Adam D'Angelo , Larry Summers , and Jack Dorsey . Position: Cybersecurity / IT GRC Evaluator Type: Contract Compensation: $80–$120/hour Location: Remote Role Responsibilities...SuggestedFull timeContract workSummer workWork at officeRemote work- ...The Sr. Security Specialist will support and deliver on multiple initiatives related to Security Governance, Risk and Compliance and Cyber... ...management, IT audits and/or Security Governance, Risk and Compliance (GRC) ~ Bachelorâs or Masterâs degree in Computer Science,...SuggestedFull time
$70 - $90 per hour
...Contract Compensation: $70–$90/hour Location: Remote Role Responsibilities Analyze and review content for security vulnerabilities with a focus on pattern recognition and classification in an AI context. Apply expertise in systems...SuggestedFull timeContract workSummer workRemote workFlexible hours$114k - $164k per year
...Work ®, seven years in a row! As a Senior Infrastructure Security Specialist , you will play a key role in protecting Kepler's corporate,... ...security controls, and ensure Kepler's infrastructure remains secure and resilient as the organization continues to scale. The role...SuggestedFull timeContract workInternshipWork at officeRemote workRelocation package- ...team today! Position Summary: Reporting to the Project Manager, you will have the opportunity to execute and lead various security system projects. Your role will encompass estimation, engineering design, programming, commissioning, and client training. We value...SuggestedFull timeFor contractorsWork at office
- ...The Security Specialist for Threat Risk Assessment, Threat Modelling, Vulnerability Assessment, Risk Identification will develop new workflows and contribute to the growth and maturity of the Security Risk Management and Information Security Office growth and maturity...Full timeWork at office
- ...e.g., STRIDE, MITRE ATT&CK) to map potential attack vectors and security gaps. Reviewing system architecture, data flows, and existing... ...data flow diagrams and identification of attack vectors to inform secure design decisions and guide risk mitigation strategies across...Full time
$140k - $165k per year
...the future of care. The Opportunity We're looking for an experienced Governance, Risk & Compliance (GRC) Manager to lead and mature Fullscript's security compliance program. This is a hands-on leadership role responsible for driving our governance, risk, and compliance...Full timeWork at officeWork from homeFlexible hours$100 - $150 per hour
...data exfiltration , ransomware , worms , and exploits . Evaluate POC exploit development to determine boundaries between security research and malicious intent. Provide ground-truth labels to improve classifiers that enhance AI safety . Work...Hourly payWeekly payFull timeContract workFor contractorsSummer workRemote work$63.85 - $70.51 per hour
We are seeking a highly accomplished Senior Cybersecurity GRC Analyst (Security Specialist) for an enterprise-level contract opportunity based in Toronto... .../OT infrastructure. Long-Term Enterprise Engagement: Secure a foundational multi-year contract runway with options for...Long term contractContract work2 days per week3 days per week$68.82 - $75.7 per hour
We are seeking a highly skilled SAP Security Consultant for an enterprise-level contract opportunity... ..., manage Governance, Risk & Compliance (GRC) frameworks, configure Identity & Access Management (IAM) cloud services, and secure Business Technology Platform (BTP) applications...Contract workRemote work3 days per week$78 per hour
...Position: Senior SAP GRC Security Consultant (SAP S/4HANA, SAP Security, Identity Access Governance) Location: Hybrid (Greater Toronto... ...stakeholders, project managers, and technical teams to deliver secure SAP solutions Collaborate with Internal and External Audit teams...Contract workFlexible hours2 days per week3 days per week$100k - $110k per year
...care. The Opportunity Fullscript is looking for a Cloud Security Engineer to help secure the cloud platforms that power care delivery for millions... .... You’ll work closely with Security Engineering, GRC, SOC, Platform Engineering, and product teams to prevent, detect...Full timeRemote workFlexible hours$80.9k - $115.5k per year
...Job Function: The Senior Cybersecurity Specialist, GRC Risk Management is a senior advisor... ...with business, technology, compliance, and security architecture stakeholders to identify, assess... ...in both their success and ours. To secure the best talent, we seek to create a workforce...$125k - $145k per year
...partner with the AVP of Corporate Information Security on strategy, mentor and grow the team, and... ...technical strategy across CI/CD, IaC, secure cloud architecture, detection, and compliance... ...and risk treatment plans; partner with GRC and Operational Risk Management. Make the...Full timeWork at officeRemote workRelocationMonday to fridayFlexible hours$110k - $160k per year
...EY and help to build a better working world. The Opportunity The Tech Risk-SAP GRC team within EY’s Business Consulting domain is looking for a dynamic person in the SAP Security, Controls, and SAP GRC space. This candidate will know how to help clients identify, design...Flexible hoursWeekend work$68k - $102k per year
...advise on a range of projects, from conducting current state assessments to designing and implementing Governance, Risk and Compliance (GRC) technology solutions. The role demands curiosity, proactivity and quick learning, with the expectation that you dive into the...Permanent employmentFlexible hours$88k - $132k per year
...and help to build a better working world. The Opportunity EY is looking for dynamic individuals in the Oracle Applications Security and GRC space for on premise and cloud applications. These professionals will know how to help clients identify, design, implement and...Weekend work- ...Role Responsibilities Review and evaluate AI-generated outputs related to threat analysis, vulnerability assessment, and security architecture recommendations. Create realistic scenarios based on cybersecurity workflows such as incident response runbooks, threat...Hourly payFull timeContract workSummer workRemote work
$71.4k - $105.66k per year
...each day to pursue your passions. THE CHALLENGE Take-Two Security's goal is to empower our label divisions to securely develop... ...firewall change requests internally and across subsidiaries to ensure secure connectivity. You will also regularly work with Security...Full timeCasual work- ...investment lifecycle, and drives the adoption of AI for our internal operations. About the Role We're looking for an IT & Security Analyst to join our IT and Security Team keeping Georgian's internal IT and security operations running smoothly. You'll be the...Full timeInternshipWork at officeImmediate start3 days per week
- ...about creating something big! The Opportunity As a Senior Security Engineer, you will be a hands-on technical leader strengthening... ...practical controls, automate security processes, and help teams ship secure and reliable software. What you'll do Cloud and...Full timeImmediate start
- ...detail. Excellent customer communication skills, and is a team player with a can-do attitude. Have a good knowledge of CANASA and security industry Standards. Electronic Installation Qualification(s) - Or equivalent. (Preferred). You should be able to manage your...Full time
- ...technology that makes public transport simpler, fairer and more accessible for millions of people. That only works if our platform is secure, trusted and reliable. As our Head of Security & Compliance, you’ll step into a role that is central to how we build trust with our...Full timeInternshipWork at officeHome office
- ...learning, note-taking, and live captioning, and Podium Solution, an on-device classroom accessibility platform designed with privacy and security at its core. Our technology is used by educational institutions including Harvard, UC Berkeley, Yale, the University of Toronto, and...Full timePart timeInternshipWork at officeImmediate startRemote work
$162k - $420k per year
...team is building its AI-native future. About The Role The Security Team is responsible for securing all things Sentry: our... ...security domains. You'll contribute to the practices that keep Sentry secure as we grow: security reviews, threat modeling, vulnerability management...Hourly payFull time- .... Join us on our mission and shape the future! As a Senior Security Engineer you will: Serve as trusted advisor to team’s leadership... ...and able to review what tools are available ~ You understand secure engineering best practices, can articulate problem statements...Full timeWork at officeRemote workFlexible hours
$90 - $110 per hour
...clients and interested in working for a company that values fun? We are looking for an energetic and client-orientated Network Security Consultant for our Toronto branch. You will lead the migration of legacy firewall estates to cloud-based Palo Alto firewalls and...Full timeContract workFlexible hours- ...future of care. The Opportunity We're looking for a Staff Security Engineer to join Fullscript's Security Engineering team as a senior... ...security design and implementation; Understands how to build secure, scalable solutions in production environments. The ideal candidate...Long term contractFull timeRemote workFlexible hours
- ...Selling autonomous systems into manufacturing, infrastructure, and logistics means our customers audit us before they trust us — security and compliance are a precondition for deploying our platform, not a function beside it. We hold SOC 2 Type 2 and ISO 27001, and we...Full time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security GRC Specialist. Be the first to apply!
- physical security specialist Toronto, ON
- security consultant Toronto, ON
- security analyst remote Toronto, ON
- security operations specialist Toronto, ON
- application security consultant Toronto, ON
- security analyst Toronto, ON
- physical security analyst Toronto, ON
- spécialiste en sécurité Toronto, ON
- conseiller en sécurité financière Toronto, ON
- spécialiste en sécurité informatique Toronto, ON

