senior cybersecurity grc analyst/ security specialist.
$63.85 - $70.51 per hourRandstad
We are seeking a highly accomplished Senior Cybersecurity GRC Analyst (Security Specialist) for an enterprise-level contract opportunity based in Toronto. In this role, you will take on a premier strategic capacity within cybersecurity governance, risk management, and regulatory compliance streams, specializing in identifying vulnerabilities, evaluating security architectures, and enforcing enterprise risk controls.
As a principal GRC specialist, you will bridge the gap between technical infrastructure, privacy legislation, and enterprise security frameworks. Operating within a hybrid work model, you will lead comprehensive security and privacy impact assessments (PIAs/TRAs), develop and refresh corporate cybersecurity policies, manage third-party vendor risk programs, and ensure strict alignment with industry security standards and Canadian privacy regulations. This position is tailored for a certified security authority (CISSP or CRISC) who can deliver actionable risk analytics, evaluate third-party vendor contracts, and govern compliance across IT, cloud, and operational technology (OT) environments. Location: Toronto, ON Assignment Type: Hybrid (2 to 3 days per week onsite)
Contract Duration: 24-month contract (with potential for extension)
High-Impact Risk Leadership: Drive enterprise-wide Security Risk Assessments, Privacy Impact Assessments (PIAs), and Threat and Risk Assessments (TRAs). Broad Framework Exposure: Govern compliance across leading cybersecurity standards, including NIST CSF, ISO/IEC 27001/27002, ISA/IEC 62443, NERC CIP, CIS Controls, and SOC2. Complex Multi-Environment Scope: Evaluate risk profiles across enterprise IT, cloud platforms, hybrid networks, and industrial/OT infrastructure. Long-Term Enterprise Engagement: Secure a foundational multi-year contract runway with options for further extension. Responsibilities
Conduct comprehensive security and privacy risk assessments across new and existing information systems, network infrastructure, cloud environments, and operational technologies. Analyze existing security controls, perform vulnerability evaluations, and assess technical architectures to identify threats and operational risks. Formulate, document, and recommend actionable security controls to mitigate identified risks and communicate findings effectively to technical and business stakeholders. Identify, assess, and monitor cybersecurity and privacy risks, providing predictive analytics to support strategic business decisions. Develop, refresh, enhance, and communicate enterprise cybersecurity governance frameworks, policies, standards, and operational procedures. Design technical, administrative, and physical security controls to ensure organizational compliance with Canadian privacy and cyber security legislation (PHIPA, MFIPPA, CASL, CCSPA). Execute periodic gap assessments across the information security program, validate ongoing control compliance, facilitate remediation plans, and escalate critical issues to leadership. Manage the security exception review and approval lifecycle, ensuring all risk acceptances are documented and re-evaluated on a defined schedule. Perform initial and ongoing third-party vendor security due diligence, vendor risk monitoring, and maintain the enterprise supplier risk inventory. Review information security and privacy clauses within procurement documents (RFIs, RFPs, MPSAs, contracts, and purchase orders) to identify gaps and enforce data protection terms. Provide expert GRC advisory services across enterprise projects, IT initiatives, and technology modernization programs. Qualifications
Core Requirements & Mandatory Certifications
Education: University degree in Computer Science, Information Security, Cybersecurity, or a related field (or an equivalent combination of education and professional experience). Mandatory Professional Certification: Active credential in at least one of the following: Certified Information Systems Security Professional (CISSP) Certified in Risk and Information Systems Control (CRISC) GRC Experience: 7+ years of relevant cybersecurity experience focused on Governance, Risk, and Compliance (GRC). Privacy Impact Assessments: 5+ years of hands-on experience conducting Privacy Risk Assessments and Privacy Impact Assessments (PIAs). Enterprise IT Experience: 10+ years of progressive Information Technology experience. Security Framework Depth: Significant experience applying enterprise security frameworks and standards, such as NIST CSF, ISO/IEC 27001/27002, ISA/IEC 62443, NERC CIP, CIS Controls, and SOC2. Policy & Governance Development: Demonstrated experience developing, refreshing, and implementing cybersecurity policies, standards, guidelines, and procedures. Canadian Regulatory Mastery: In-depth understanding and practical application of Canadian privacy and security legislation, including PHIPA, MFIPPA, CASL, Critical Cyber Systems Protection Act (CCSPA), and related digital security acts. Preferred Technical & Architecture Skills
Architecture & Infrastructure Depth: Strong background in enterprise IT and Security Architecture, spanning cloud, hybrid, and OT/industrial operational environments. Networking & Protocols: Solid understanding of networking principles (TCP/IP, WAN/LAN) and core security/internet protocols (SMTP, FTP, LDAP, SAMLv2, OAuth, SSL/TLS). Vendor & Contract Risk: Direct experience evaluating vendor risk, reviewing RFP/contractual security terms, and utilizing GRC risk management tooling. Soft Skills & Professional Attributes
Analytical Problem Solving: Superior diagnostic capabilities to evaluate complex risk scenarios, weigh costs versus benefits, and recommend pragmatic mitigations. Consultative Communication: Exceptional written and verbal communication skills with meticulous attention to detail when presenting risk findings to diverse audiences. Time Management & Adaptability: Proven ability to manage competing priorities, deliver under tight deadlines, and navigate fast-paced environments effectively. Summary
If you're interested in the "Senior Cybersecurity GRC Analyst (Security Specialist)" role based in Toronto, we encourage you to apply online at
Only qualified candidates will be contacted for the next steps. We look forward to hearing from you! Randstad Canada is committed to fostering a workforce reflective of all peoples of Canada. As a result, we are committed to developing and implementing strategies to increase the equity, diversity and inclusion within the workplace by examining our internal policies, practices, and systems throughout the entire lifecycle of our workforce, including its recruitment, retention and advancement for all employees. In addition to our deep commitment to respecting human rights, we are dedicated to positive actions to affect change to ensure everyone has full participation in the workforce free from any barriers, systemic or otherwise, especially equity-seeking groups who are usually underrepresented in Canada's workforce, including those who identify as women or non-binary/gender non-conforming; Indigenous or Aboriginal Peoples; persons with disabilities (visible or invisible) and; members of visible minorities, racialized groups and the LGBTQ2+ community. Randstad Canada is committed to creating and maintaining an inclusive and accessible workplace for all its candidates and employees by supporting their accessibility and accommodation needs throughout the employment lifecycle. We ask that all job applications please identify any accommodation requirements by sending an email to View email address on randstad.com to ensure their ability to fully participate in the interview process. This posting is for existing and upcoming vacancies. show more
- ...at . The Opportunity: We’re looking for an experienced Security GRC Specialist to join our growing Security GRC team. Reporting to the... ...assurance programs and reporting appropriate metrics to the senior leadership. Who you are: Service – You put your clients...SeniorFull timeInternship
$50k - $90k per year
...support the delivery of Application Security engagements across leading... ...in Application Security, GRC Access Controls, Business Process... ...let’s talk about you As an Analyst , You are curious, motivated, and passionate about cybersecurity, with a desire to build your...SuggestedLong term contractPermanent employmentFlexible hours- ...this role? The Governance, Risk, and Compliance (GRC) team at Cohere operates as a centralized function within the Security organization, leading efforts across governance,... ...reports, metrics, and presentations for senior leadership, including communicating compliance posture...SeniorFull timeWork at officeRemote workFlexible hours
- ...Angelo , Larry Summers , and Jack Dorsey . Position: Cybersecurity Expert Type: Contract Compensation: $1,750–$... ...related to threat analysis, vulnerability assessment, and security architecture recommendations. Create realistic scenarios based...SeniorHourly payFull timeContract workSummer workRemote work
- ...working world for all. We are actively seeking a Cloud Security Manager to join our Cybersecurity team. You’ll work alongside respected industry... ...identify risks within engagements and raise any issues with senior members of the team. Client Responsibilities Help...SeniorLong term contractShift workWeekend work
$78 per hour
...Position: Senior SAP GRC Security Consultant (SAP S/4HANA, SAP Security, Identity Access Governance) Location: Hybrid (Greater Toronto Area... ...stakeholders, project managers, and technical teams to deliver secure SAP solutions Collaborate with Internal and External Audit...SeniorContract workFlexible hours2 days per week3 days per week- ...The Sr. Security Specialist will support and deliver on multiple initiatives related to Security... ...Security Governance, Risk and Compliance (GRC) ~ Bachelorâs or Masterâs degree in... ...delivering presentations to stakeholders and senior leadership. 20 points Requirements...SeniorFull time
$80 - $120 per hour
...include Benchmark , General Catalyst , Peter Thiel , Adam D'Angelo , Larry Summers , and Jack Dorsey . Position: Cybersecurity / IT GRC Evaluator Type: Contract Compensation: $80–$120/hour Location: Remote Role Responsibilities...Remote jobContract workSummer workWork at office$80 - $120 per hour
...include Benchmark , General Catalyst , Peter Thiel , Adam D'Angelo , Larry Summers , and Jack Dorsey . Position: Cybersecurity / IT GRC Evaluator Type: Contract Compensation: $80–$120/hour Location: Remote Role Responsibilities...Full timeContract workSummer workWork at officeRemote work$90k - $145k per year
Cybersecurity Advisor (GRC ) Position Description Location: Toronto- hybrid- ability to go on client site downtown... ...firms in the world. Conseiller en cybersécurité Job Description En tant que conseiller en sécurité, vous jouerez un rôle crucial dans la protection...- ...potential attack vectors and security gaps. Reviewing system architecture... .... Strong command of cybersecurity governance practices,... ...of attack vectors to inform secure design decisions and guide risk... ...presentations to stakeholders and senior leadership. 10 Points...SeniorFull time
- ...TEHORA est présentement à la recherche d’un(e) analyste en cybersécurité sénior Sans être exhaustifs, voici les services et livrables que devra... ...fournir la personne retenue : Définir les stratégies de sécurité; Réaliser des analyses de risques; Participer aux audits...SeniorHourly payFull timeContract workApprenticeshipRemote workFlexible hours
$88k - $132k per year
...Opportunity EY is looking for dynamic individuals in the SAP Security, Controls, and SAP GRC space. These professionals will know how to help clients... ...providing support, maintaining communication and updating senior team members on progress To qualify for the role you...Senior$90k - $136k per year
...Join EY and help to build a better working world. The opportunity We are actively seeking a Cloud Security Senior Consultant to join our Cybersecurity team. You’ll work alongside respected industry professionals, learning about and applying leading practices to...SeniorShift workWeekend work- ...The Security Specialist for Threat Risk Assessment, Threat Modelling, Vulnerability Assessment, Risk Identification will develop new workflows... ...in a dynamic risk environment. Responsibilities: The Senior Security Specialist will be responsible for conducting Threat...SeniorFull timeWork at office
- We are seeking a highly accomplished Security Analyst - Intermediate for an enterprise-level contract... ...this role, you will take on a premier cybersecurity, governance, and risk management... ...governance, risk management, and compliance (GRC). Robust TPRM Program Engagement: Lead...SeniorContract workRemote workFlexible hours3 days per week
$70 - $90 per hour
...Angelo , Larry Summers , and Jack Dorsey . Position: Cybersecurity Experts Type: Contract Compensation: $70–$90... ...Role Responsibilities Analyze and review content for security vulnerabilities with a focus on pattern recognition and classification...Full timeContract workSummer workRemote workFlexible hours$65 - $75 per hour
...Senior IT Security Contract Specialist Join a recognized leader in the insurance sector and contribute to high-impact initiatives involving technology... ..., cloud, software licensing, professional services, cybersecurity, data protection, and custodial agreements. •...SeniorHourly payPermanent employmentContract workWork at office3 days per week- ...firm that partners with high-growth technology companies across cybersecurity, AI software, robotics, defense. We manage about $6B in... ...operations. About the Role We're looking for an IT & Security Analyst to join our IT and Security Team keeping Georgian's internal...Full timeInternshipWork at officeImmediate start3 days per week
$126k - $234k per year
...modernize their risk and compliance systems, collaborating with solution architects, process experts, and industry-leading vendors. Manage GRC technology programs and services - Oversee solution assessment and implementation projects, and production support and maintenance...SeniorPermanent employmentFlexible hours$48.66 - $52.14 per hour
...RQ00226 - Security Analyst - Intermediate Duration: 6 Months (131 Business Days) Location... ...function, with a focus on IT Security/Cybersecurity. Strong track record of competency in risk... ...and external stakeholders, including Senior Management Team (SMT), Audit, Finance,...SeniorFull timeContract workFor contractorsWork at officeRemote work$110k - $120k per year
...Position: IT Security Analyst Position reports to: Director of IT Position Overview: Greenstone Meats is seeking an IT Security Analyst... ...maintaining our security posture, and fostering a culture of cybersecurity awareness across our corporate and operational environments....Long term contractFull time- ...TEHORA est présentement à la recherche d’un(e) Analyste en sécurité opérationnelle sénior Sans être exhaustifs, voici les services et livrables que devra fournir la personne retenue : Surveiller les incidents de sécurité; Analyser les vulnérabilités; Mettre en...SeniorHourly payFull timeContract workApprenticeshipRemote workFlexible hours
$100 - $150 per hour
..., and Jack Dorsey . Position: Cybersecurity Labeling Expert Type: Contract... ...development to determine boundaries between security research and malicious intent.... .... Masters or early-career through Senior/Principal experience. Compensation...SeniorHourly payWeekly payFull timeContract workFor contractorsSummer workRemote work$110k - $160k per year
...The Opportunity The Tech Risk-SAP GRC team within EY’s Business Consulting domain... ...is looking for a dynamic person in the SAP Security, Controls, and SAP GRC space. This candidate... ..., maintaining communication and updating senior team members on progress To qualify for...SeniorFlexible hoursWeekend work- ...Manage and maintain Information Security Management System (ISMS) design and implementation of new information security... ...":1,"value":"M4C"}],"headerName":"RQ10341 \- Security Specialist \- Threat Risk Assessment \- Senior","widgetId":"383123000000072311","isJobBoard":"false",...SeniorContract workFlexible hours
$125k - $145k per year
...About the role: We’re hiring a Senior DevSecOps Engineer with 8–10+... ...AVP of Corporate Information Security on strategy, mentor and grow the... ...artifacts. Contribute to the cybersecurity risk register and risk treatment plans; partner with GRC and Operational Risk Management...SeniorFull timeWork at officeRemote workRelocationMonday to fridayFlexible hours$85.77 - $94.88 per hour
...seeking a high-performing, authoritative Security Specialist V (IT Audit & Remediation Assurance Lead... ...Security & Defense division. In this senior governance role, you will be responsible... ...a seasoned CISA-certified IT Auditor or GRC Lead who pairs 10+ years of audit...SeniorLong term contractContract workWork at office2 days per week$19.5 per hour
...EVENT SECURITY SPECIALIST Are you passionate about Safety & Security and seeking opportunity to join a team of Security Specialist? A.S.P. Incorporated has provided security and customer service solutions for over 20 years to Canadian clients. We employ more than...Hourly payFull timeFlexible hoursShift workNight shiftWeekend workAfternoon shift- ...build a better working world. The opportunity EY Canada’s Cybersecurity practice is seeking an experienced and technically proficient... ...and recommend mitigation strategies to enhance data security. DLP Implementation: Lead the implementation of DLP solutions...Weekend work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to senior cybersecurity grc analyst/ security specialist.. Be the first to apply!
- cyber security analyst no experience Toronto, ON
- cyber security analyst Toronto, ON
- senior cyber security analyst Toronto, ON
- security analyst remote Toronto, ON
- conseiller santé sécurité Toronto, ON
- physical security analyst Toronto, ON
- security consultant Toronto, ON
- security systems specialist Toronto, ON
- spécialiste en sécurité Toronto, ON
- junior security analyst Toronto, ON
