Intermediate Cyber Security GRC Analyst to focus on technical administrative governance and control assurance for our Oil and Gas client (Req 10632)
S.i. Systems
Calgary, AB-
Number of positions available : 1
- Salary To be discussed
-
Contract job
- Published on February 24th, 2026
-
Starting date : 1 position to fill as soon as possible
Description
Our Oil and Gas client is seeking a Intermediate Cyber Security GRC Analyst to focus on technical administrative governance and control assurance
Candidates will be in-office 5 days/week in downtown Calgary
Must haves:
- 5+ years of experience as a Cyber Security Analyst or IT Controls with a focus on focus on technical administrative governance and control assurance.
- Experience with identity and access management, account monitoring, and domain hygiene within large enterprise environments.
- Familiarity with control frameworks and compliance standards (e.g., NIST, ISO 27001, COBIT, SOX), with emphasis on control execution rather than framework design.
- Previous Oil and Gas experience
Nice to haves:
- Clear and professional written and verbal communication skills
- Prior experience in oil and gas or other highly regulated industries, with exposure to formal governance, audit, or compliance expectations.
- Practical familiarity with Active Directory governance, including its role in access control, segregation of duties, and enterprise IT control environments.
- Exposure to IT audit, control testing, or risk management activities, such as evidence preparation, issue tracking, and remediation support.
Responsibilities:
- Execute recurring access reviews (including SOX, privileged, and standard user access) in accordance with documented procedures, ensuring continued alignment with approved access models, security policies, and regulatory requirements.
- Perform ongoing monitoring and maintenance of directory and domain hygiene, including user account lifecycle activities, group membership validation, and identification of stale, orphaned, or non-compliant accounts.
- Administer established cybersecurity governance and compliance processes, ensuring controls are performed consistently, evidence is complete, and deviations from policy are identified and escalated.
- Conduct routine control-based risk assessments focused on identifying control gaps, misconfigurations, or process breakdowns rather than theoretical threat modeling.
- Monitor, validate, and evidence the operation of technical and administrative security controls, ensuring controls are functioning as designed and producing auditable results.
- Work with IT service owners and business stakeholders to resolve access discrepancies, hygiene issues, and control deficiencies, particularly those arising from operational processes or third-party dependencies.
- Maintain detailed documentation, logs, and reports for governance, risk, and compliance activities to support audits, management review, and regulatory scrutiny.
- Participate in internal and external audits by preparing evidence, responding to auditor inquiries, and supporting remediation of identified findings.
AI may be used in evaluating candidates.
This posting is for an existing vacancy.
Requirements
undetermined
undetermined
undetermined
undetermined
Other S.i. Systems's offers that may interest you