This recruiter is online.

This is your chance to shine!

Apply Now

Senior Risk Compliance Specialist to lead security and vendor risk assessments, identifying risks and gaps, and developing mitigation strategies for third-

Toronto, ON
  • Number of positions available : 1

  • To be discussed
  • Contract job

  • Starting date : 1 position to fill as soon as possible

Our public sector client is seeking a Senior Risk Compliance Specialist to lead security and vendor risk assessments, identifying risks and gaps, and developing mitigation strategies for third-party vendors. - RQ00153


Duration - July 7, 2025 to Jan 7, 2026 with a possibility of extension

Work mode - Hybrid, 2 days a week on site downtown Toronto

Hours per day - 7.25


Responsibilities: Coordinate and perform risk assessments against a wide variety of inputs. Analyzes data from various sources to identify remediation of risks. Interprets policies, legislation and standards to adequately provide advice for management and executives. General Skills: Experience interpreting requirements from those standards and translating them into actionable implementations Strong understanding of internal control frameworks, control mappings, and scoping Familiar with a broad range of technical concepts: logical access control, agile development process, secure coding principles, security architecture, information security, network security, and privacy Expertise in gap analysis, remediation, control design and risk assessments Exceptional verbal and written communication skills Desirable Skills: Experience with GRC (Governance, Risk, Compliance) tools is a plus


Deliverables

  • Lead security and vendor risk assessments, identifying risks and gaps, and developing mitigation strategies for third-party vendors.
  • Conduct detailed assessments of third-party vendors’ security domains, communicate findings, prepare regular reports and updates to management and stakeholders.
  • Develop and implement cybersecurity governance frameworks, policies, and procedures in collaboration with cross-functional teams.
  • Provide support for audit, compliance, and regulatory requests. Precise and thorough documentation and analysis are essential for effective security auditing and compliance efforts.
  • Collaborate with internal teams and vendors to develop cybersecurity requirements for new solutions, ensuring alignment with security policies and standards.
  • Work with other team members to develop and align with cybersecurity requirements for solutions as required
  • Work with project teams to recommend and implement security controls to address identified risks.
  • Work with Enterprise Architecture, Solution Delivery, Security and Operations teams as part of a large program/project team to ensure security solutions and meet security compliance and security policies and standards
  • Identify requirements for policies and standards, and work with relevant teams in creation, development, review and approval
  • Act as a cybersecurity resource for new and upcoming project-based detail work
  • Work with project teams to identify and recommend security controls to remediate security risks and issues
  • Ongoing compliance work related to regulatory requirements and/or compliance to client standards
  • Develop the security process, procedure, governance artifacts and security controls within the Cybersecurity Risk Management and Governance/Compliance Programs.
  • Assist with security audits and threat/risk assessments to ensure compliance with security policies, standards and procedures, and work with business/technical/operational areas in taking corrective actions on any identified security exposures
  • Provide advice, risk assessment, recommendations and technical assistance in implementing security controls for projects
  • Communicate regularly with cybersecurity teams, internal stakeholders, project teams and representatives from various functional teams, including escalating any matters to senior team members that require additional analysis
  • Support the implementation of security principles, policies, and standards to align with industry best practices, ensuring security controls are integrated into system development, deployment, and operation



Must Haves

  • 7+ Leading security and vendor risk assessments, identifying risks and gaps, and developing mitigation strategies for third-party vendors.
  • 7+ Collaborate with internal teams and vendors to develop cybersecurity requirements for new solutions
  • 7+ Develop the security process, procedure, governance artifacts and security controls within the Cybersecurity Risk Management and Governance/Compliance Programs.
  • 7+ years experience in contract negotiation with procurement and legal teams through RFP processes and vendor evaluations throughout procurement life cycle
  • 7+ years experience knowledge of industry standards and regulations such as PCI-DSS, NIST, ISO 27001
  • 7+ years experience with cybersecurity risk management and third-party risk management tools - ServiceNow and OneTrust
  • 7+ years experience facilitating cybersecurity awareness training
  • A current security designation (CISSP, CISM, CCSP or CISA)



Apply

Requirements

Level of education

undetermined

Work experience (years)

undetermined

Written languages

undetermined

Spoken languages

undetermined