Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

senior cybersecurity grc analyst/ security specialist.

$63.85 - $70.51 per hour

Randstad

We are seeking a highly accomplished Senior Cybersecurity GRC Analyst (Security Specialist) for an enterprise-level contract opportunity based in Toronto. In this role, you will take on a premier strategic capacity within cybersecurity governance, risk management, and regulatory compliance streams, specializing in identifying vulnerabilities, evaluating security architectures, and enforcing enterprise risk controls.

As a principal GRC specialist, you will bridge the gap between technical infrastructure, privacy legislation, and enterprise security frameworks. Operating within a hybrid work model, you will lead comprehensive security and privacy impact assessments (PIAs/TRAs), develop and refresh corporate cybersecurity policies, manage third-party vendor risk programs, and ensure strict alignment with industry security standards and Canadian privacy regulations. This position is tailored for a certified security authority (CISSP or CRISC) who can deliver actionable risk analytics, evaluate third-party vendor contracts, and govern compliance across IT, cloud, and operational technology (OT) environments.

Location: Toronto, ON

Assignment Type: Hybrid (2 to 3 days per week onsite)


Contract Duration: 24-month contract (with potential for extension)

Advantages
High-Impact Risk Leadership: Drive enterprise-wide Security Risk Assessments, Privacy Impact Assessments (PIAs), and Threat and Risk Assessments (TRAs).

Broad Framework Exposure: Govern compliance across leading cybersecurity standards, including NIST CSF, ISO/IEC 27001/27002, ISA/IEC 62443, NERC CIP, CIS Controls, and SOC2.

Complex Multi-Environment Scope: Evaluate risk profiles across enterprise IT, cloud platforms, hybrid networks, and industrial/OT infrastructure.

Long-Term Enterprise Engagement: Secure a foundational multi-year contract runway with options for further extension.

Responsibilities
Conduct comprehensive security and privacy risk assessments across new and existing information systems, network infrastructure, cloud environments, and operational technologies.

Analyze existing security controls, perform vulnerability evaluations, and assess technical architectures to identify threats and operational risks.

Formulate, document, and recommend actionable security controls to mitigate identified risks and communicate findings effectively to technical and business stakeholders.

Identify, assess, and monitor cybersecurity and privacy risks, providing predictive analytics to support strategic business decisions.

Develop, refresh, enhance, and communicate enterprise cybersecurity governance frameworks, policies, standards, and operational procedures.

Design technical, administrative, and physical security controls to ensure organizational compliance with Canadian privacy and cyber security legislation (PHIPA, MFIPPA, CASL, CCSPA).

Execute periodic gap assessments across the information security program, validate ongoing control compliance, facilitate remediation plans, and escalate critical issues to leadership.

Manage the security exception review and approval lifecycle, ensuring all risk acceptances are documented and re-evaluated on a defined schedule.

Perform initial and ongoing third-party vendor security due diligence, vendor risk monitoring, and maintain the enterprise supplier risk inventory.

Review information security and privacy clauses within procurement documents (RFIs, RFPs, MPSAs, contracts, and purchase orders) to identify gaps and enforce data protection terms.

Provide expert GRC advisory services across enterprise projects, IT initiatives, and technology modernization programs.

Qualifications
Core Requirements & Mandatory Certifications
Education: University degree in Computer Science, Information Security, Cybersecurity, or a related field (or an equivalent combination of education and professional experience).

Mandatory Professional Certification: Active credential in at least one of the following:

Certified Information Systems Security Professional (CISSP)

Certified in Risk and Information Systems Control (CRISC)

GRC Experience: 7+ years of relevant cybersecurity experience focused on Governance, Risk, and Compliance (GRC).

Privacy Impact Assessments: 5+ years of hands-on experience conducting Privacy Risk Assessments and Privacy Impact Assessments (PIAs).

Enterprise IT Experience: 10+ years of progressive Information Technology experience.

Security Framework Depth: Significant experience applying enterprise security frameworks and standards, such as NIST CSF, ISO/IEC 27001/27002, ISA/IEC 62443, NERC CIP, CIS Controls, and SOC2.

Policy & Governance Development: Demonstrated experience developing, refreshing, and implementing cybersecurity policies, standards, guidelines, and procedures.

Canadian Regulatory Mastery: In-depth understanding and practical application of Canadian privacy and security legislation, including PHIPA, MFIPPA, CASL, Critical Cyber Systems Protection Act (CCSPA), and related digital security acts.

Preferred Technical & Architecture Skills
Architecture & Infrastructure Depth: Strong background in enterprise IT and Security Architecture, spanning cloud, hybrid, and OT/industrial operational environments.

Networking & Protocols: Solid understanding of networking principles (TCP/IP, WAN/LAN) and core security/internet protocols (SMTP, FTP, LDAP, SAMLv2, OAuth, SSL/TLS).

Vendor & Contract Risk: Direct experience evaluating vendor risk, reviewing RFP/contractual security terms, and utilizing GRC risk management tooling.

Soft Skills & Professional Attributes
Analytical Problem Solving: Superior diagnostic capabilities to evaluate complex risk scenarios, weigh costs versus benefits, and recommend pragmatic mitigations.

Consultative Communication: Exceptional written and verbal communication skills with meticulous attention to detail when presenting risk findings to diverse audiences.

Time Management & Adaptability: Proven ability to manage competing priorities, deliver under tight deadlines, and navigate fast-paced environments effectively.

Summary
If you're interested in the "Senior Cybersecurity GRC Analyst (Security Specialist)" role based in Toronto, we encourage you to apply online at
Only qualified candidates will be contacted for the next steps. We look forward to hearing from you!

Randstad Canada is committed to fostering a workforce reflective of all peoples of Canada. As a result, we are committed to developing and implementing strategies to increase the equity, diversity and inclusion within the workplace by examining our internal policies, practices, and systems throughout the entire lifecycle of our workforce, including its recruitment, retention and advancement for all employees. In addition to our deep commitment to respecting human rights, we are dedicated to positive actions to affect change to ensure everyone has full participation in the workforce free from any barriers, systemic or otherwise, especially equity-seeking groups who are usually underrepresented in Canada's workforce, including those who identify as women or non-binary/gender non-conforming; Indigenous or Aboriginal Peoples; persons with disabilities (visible or invisible) and; members of visible minorities, racialized groups and the LGBTQ2+ community.

Randstad Canada is committed to creating and maintaining an inclusive and accessible workplace for all its candidates and employees by supporting their accessibility and accommodation needs throughout the employment lifecycle. We ask that all job applications please identify any accommodation requirements by sending an email to View email address on randstad.com to ensure their ability to fully participate in the interview process.

This posting is for existing and upcoming vacancies. show more
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the senior cybersecurity grc analyst/ security specialist. in Toronto, ON vacancy
  •  ...Opportunity: We’re looking to fill an opening with an experienced Security GRC Specialist to join our growing Security GRC team. Reporting to the...  ...assurance programs and reporting appropriate metrics to the senior leadership. As  one aviso:   ~ We Care – You do the... 
    Senior
    Full time
    Internship

    Aviso Wealth

    Toronto, ON
    21 days ago
  • $75k - $85k per year

     ...Position: Security Analyst (Cybersecurity & GRC) Location: Toronto, ON - Hybrid (4 days on-site, Downtown Toronto) Salary: $75,000 to $85,000/year Job Type: Permanent Position Type: Open Vacancy We are seeking an experienced Security Analyst to join a leading... 
    Suggested
    Permanent employment
    Full time

    Quantum Technology Recruiting Inc. (QTR)

    Toronto, ON
    14 days ago
  • $101.15k - $130.9k per year

     ...communities where we live, work and play. It’s an exciting time to join the team at Hydro One!   Job Function: The Senior Cybersecurity Specialist, GRC Risk Management is a senior advisor responsible for cyber risk management across IT, OT, cloud, AI, and emerging... 
    Senior

    Hydro One Networks Inc

    Toronto, ON
    1 day ago
  •  ...TEHORA est présentement à la recherche d’un(e) analyste en cybersécurité sénior Sans être exhaustifs, voici les services et livrables que devra...  ...fournir la personne retenue : Définir les stratégies de sécurité; Réaliser des analyses de risques; Participer aux audits... 
    Senior
    Hourly pay
    Full time
    Contract work
    Apprenticeship
    Remote work
    Flexible hours

    TEHORA

    Toronto, ON
    21 days ago
  • $90k - $145k per year

    Cybersecurity Advisor (GRC ) Position Description Location: Toronto- hybrid- ability to go on client site downtown...  ...firms in the world. Conseiller en cybersécurité Job Description En tant que conseiller en sécurité, vous jouerez un rôle crucial dans la protection... 
    Suggested
    Toronto, ON
    13 days ago
  • $78 per hour

     ...Position: Senior SAP GRC Security Consultant (SAP S/4HANA, SAP Security, Identity Access Governance) Location: Hybrid (Greater Toronto Area...  ...stakeholders, project managers, and technical teams to deliver secure SAP solutions Collaborate with Internal and External Audit... 
    Senior
    Contract work
    Flexible hours
    2 days per week
    3 days per week

    CorGTA

    Toronto, ON
    19 hours ago
  • $80 - $120 per hour

     ...include Benchmark , General Catalyst , Peter Thiel , Adam D'Angelo , Larry Summers , and Jack Dorsey . Position: Cybersecurity / IT GRC Evaluator Type: Contract Compensation: $80–$120/hour Location: Remote Role Responsibilities... 
    Remote job
    Contract work
    Summer work
    Work at office

    Mercor

    Toronto, ON
    1 day ago
  •  ...to create new products and improve existing platforms to optimize the seamless delivery of our services. The GRC Specialist works with the Information Security Team in a global environment. The incumbent coordinates and performs Security Governance, Risk, and Compliance assessments... 
    Full time
    Work at office
    Worldwide

    Guidepoint

    Toronto, ON
    1 day ago
  • We are seeking a highly accomplished Senior Security Specialist to lead multiple initiatives across Security Governance, Risk, and Compliance (GRC) and Cyber Defense Operations. In this role, you will hold complete technical ownership over security strategy, audit alignment... 
    Senior
    Contract work
    Work at office
    Remote work

    Randstad

    Toronto, ON
    26 days ago
  • $88k - $132k per year

     ...is looking for dynamic individuals in the Oracle Applications Security and GRC space for on premise and cloud applications. These professionals...  ..., providing support, maintaining communication and updating senior team members on progress. You will develop materials for engagement... 
    Senior
    Weekend work

    Ernst & Young

    Toronto, ON
    3 days ago
  • We are seeking an experienced Senior Security Specialist to drive end-to-end Threat Risk Assessment (TRA) initiatives to evaluate and elevate organizational security posture across information systems, applications, infrastructure, and business processes. In this role, you will... 
    Senior
    Contract work
    Flexible hours

    Randstad

    Toronto, ON
    6 days ago
  •  ...TEHORA est présentement à la recherche d’un(e) Analyste en sécurité opérationnelle sénior Sans être exhaustifs, voici les services et livrables que devra fournir la personne retenue : Surveiller les incidents de sécurité; Analyser les vulnérabilités; Mettre en... 
    Senior
    Hourly pay
    Full time
    Contract work
    Apprenticeship
    Remote work
    Flexible hours

    TEHORA

    Toronto, ON
    21 days ago
  • $115 per hour

     ...are looking for contract S enior Cyber Security Specialist Duration : 12 month Experience...  ...eliminate identified risks. ~ Knowledge of cybersecurity concepts, including threats,...  ...stakeholders ranging from technical teams to senior executives within the organization. Adeptness... 
    Senior
    Hourly pay
    Full time
    Contract work
    For contractors
    Fixed term contract
    Relocation
    Shift work

    EBF

    Toronto, ON
    1 day ago
  • $80k - $130k per year

    Intermediate/Senior Business Analyst (GRC) Position Description This role is hybrid and requires you to be at our downtown Toronto and/or Client office (downtown) at a minimum 4 days per week subject to change at any time.  We are seeking an experienced Business Analyst... 
    Senior
    Manual labor
    Work at office
    Toronto, ON
    a month ago
  • $90 per hour

     ...Job Responsibility: This role will require contractors to come onsite for occasional meetings.This is a new security modernization project from OPS. They will be reviewing vendor security.They will need to have experience reviewing SOC 2 Type 2 documentation and writing recommendations... 
    Senior
    Hourly pay
    Full time
    For contractors
    Fixed term contract
    Relocation
    Monday to friday

    Isheva Inc

    Toronto, ON
    1 day ago
  •  ...on #TeamBell. Summary We are seeking a Senior Security Operations Specialist II with hands-on experience in network security operations...  ...-on experience supporting enterprise network security, cybersecurity operations, and critical infrastructure in a complex... 
    Senior
    Full time
    Work at office
    3 days per week

    Bell

    Toronto, ON
    12 days ago
  • $85.77 - $94.88 per hour

     ...seeking a high-performing, authoritative Security Specialist V (IT Audit & Remediation Assurance Lead...  ...Security & Defense division. In this senior governance role, you will be responsible...  ...a seasoned CISA-certified IT Auditor or GRC Lead who pairs 10+ years of audit... 
    Senior
    Long term contract
    Contract work
    Work at office
    2 days per week

    Randstad

    Toronto, ON
    5 days ago
  • $110k - $160k per year

     ...The Opportunity The Tech Risk-SAP GRC team within EY’s Business Consulting domain...  ...is looking for a dynamic person in the SAP Security, Controls, and SAP GRC space. This candidate...  ..., maintaining communication and updating senior team members on progress To qualify for... 
    Senior
    Flexible hours
    Weekend work

    Ernst & Young

    Toronto, ON
    4 days ago
  • $110k - $155k per year

    Cybersecurity AI Engineering Specialist Position Description The Cybersecurity AI Engineering Specialist is part of CGI's Global Security Operations Center (GSOC), which provides 24/7 security monitoring...  ...investigations, reduce analyst workload, and strengthen cyber... 
    Toronto, ON
    13 days ago
  • $63.85 - $70.51 per hour

    We are seeking a highly accomplished and technical Senior Security Architect (Security Specialist) for an enterprise-level contract opportunity based in...  ...will take on a premier leadership capacity within the cybersecurity engineering and information technology governance streams... 
    Senior
    Contract work
    Remote work
    Flexible hours
    2 days per week
    3 days per week

    Randstad

    Toronto, ON
    a month ago
  • $69k - $114k per year

     ...organization.   What will your typical day look like?   Lead the research and development of Deloitte Global cybersecurity standards, detailed security baselines and their supporting documents, to meet Deloitte’s business objectives and cybersecurity risk appetite... 
    Permanent employment
    Remote work
    Flexible hours

    Deloitte

    Toronto, ON
    8 hours ago
  •  ...Security Architect – Enterprise Security & Cybersecurity Required Skills Experience • 10+ years of relevant experience as a Security Architect....  ...architecture processes, standards, and principles to deliver secure, high-performing, scalable, and reusable solutions.... 

    Astra North Infoteck Inc.

    Toronto, ON
    a month ago
  •  ...Archer Business Analyst – GRC, QA & Archer SaaS Role Description • Support the delivery of enterprise Governance, Risk, and Compliance (GRC) solutions on the Archer SaaS platform. • Act as the liaison between business stakeholders and technical teams to ensure... 
    Contract work

    Astra North Infoteck Inc.

    Toronto, ON
    a month ago
  •  ...We are hiring a Senior Manager, Information Security, Risk and Compliance on behalf of a well-established organization...  ...experts.  Bring in external specialists for audit peaks, point-in-time assessments...  ..., with a strong focus on compliance, GRC, or security program management.... 
    Senior
    Permanent employment
    Manual labor

    Hays

    Toronto, ON
    28 days ago
  •  ...TEHORA est présentement à la recherche d’ un(e) architecte sécurité senior ayant une solide expérience en architecture de sécurité, en gestion...  ...Détenir un diplôme universitaire pertinent en cybersécurité, informatique, génie ou dans un domaine connexe, ou une expérience... 
    Senior
    Hourly pay
    Full time
    Contract work
    Apprenticeship
    Remote work
    Flexible hours

    TEHORA

    Toronto, ON
    21 days ago
  •  ...TEHORA est présentement à la recherche d’un(e) Analyste en sécurité opérationnelle intermédiaire Sans être exhaustifs, voici les services et livrables que devra fournir la personne retenue : Surveiller les incidents de sécurité; Analyser les vulnérabilités; Mettre... 
    Hourly pay
    Full time
    Contract work
    Apprenticeship
    Remote work
    Flexible hours

    TEHORA

    Toronto, ON
    21 days ago
  • $60k - $110k per year

    Security Monitoring and Response Specialist Position Description...  ...Canada The Security Monitoring Analyst is part of CGI's Global...  ...surveillance et intervention de sécurité Job Description Lieu :...  ...améliorant la posture globale de cybersécurité de l'organisation.  Au sein... 
    Apprenticeship
    Work at office
    Toronto, ON
    a month ago
  • $52.89 - $60.65 per hour

     ...seeking a detail-oriented, analytical Info Security Analyst IV to join their core Technology...  ...Information Security division. In this senior consulting role, you will play a critical...  ...Analyst, or Technology Risk & Controls Specialist within a large-scale enterprise environment... 
    Senior
    Long term contract
    Contract work
    Work at office
    2 days per week

    Randstad

    Toronto, ON
    20 days ago
  • $78.31k per year

     ...Responsibility: Date Posted: 11/20/2023 Req ID: 34984 Faculty/Division: Ofc of the Chief Information Officer Department: Information Security Campus: St. George (Downtown Toronto) Position Number: 00055800 Description: About us: The Information Security team, part... 
    Full time

    University of Toronto

    Toronto, ON
    1 day ago
  •  ...This is a remote position. Senior Cyber Security Specialist-Offensive Security Location: Remote (Canada) Experience: 10+ Years...  ...required Work with engineering teams on remediation and secure SDLC Provide clear technical risk analysis and... 
    Senior
    Full time
    Contract work
    Remote work

    Trident Staff

    Toronto, ON
    a month ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to senior cybersecurity grc analyst/ security specialist.. Be the first to apply!