Our client, is seeking a high-performing, authoritative Security Specialist V (IT Audit & Remediation Assurance Lead) to join their enterprise Global Security & Defense division.
...
In this senior governance role, you will be responsible for leading independent challenge, quality assurance, and assessment of audit and regulatory finding remediations across complex technology infrastructure and applications. Operating within the Three Lines of Defense (3LOD) framework, you will partner closely with technology leaders, second/third-line risk teams, and external regulators to independently validate that issue remediation plans effectively mitigate information security risks. This position is ideal for a seasoned CISA-certified IT Auditor or GRC Lead who pairs 10+ years of audit validation, sample-based testing, and controls framework mastery with exceptional executive communication skills.
Duration: 8-Month Contract (with high potential for extension)
Work Arrangement: Hybrid (Currently 2 days per week on-site at the corporate office, transitioning to 4 days per week on-site in the future)
Advantages
High-Impact Enterprise Governance Scope: Lead independent challenge and quality assurance oversight for critical regulatory, audit, and operational risk remediations across global technology platforms.
Executive Visibility: Provide strategic guidance, trend reporting, and independent challenge directly to senior technology leads, enterprise risk officers, and audit executives.
Modern GRC Ecosystem: Utilize top-tier enterprise governance and tracking platforms, including RSA Archer, ServiceNow, Jira, and Confluence.
Continuous Innovation Focus: Drive lean continuous improvement practices and leverage modern analytics tools (e.g., Power BI/Apps, Python) to optimize audit validation workflows.
Responsibilities
Independent Challenge & Remediation Validation
Remediation Assessment: Lead comprehensive assessments of audit and regulatory finding remediations required to mitigate information security risks within enterprise applications and technology infrastructure.
Sample-Based Test Plans: Design and execute rigorous, sample-based test plans relying on Industry Operational Risk (IOR) methodologies or comparable audit validation frameworks to verify control operating effectiveness.
3LOD Collaboration: Partner across first, second, and third lines of defense to evaluate issue remediation quality, challenge insufficient action plans, and ensure long-term risk sustainability.
Subject Matter Guidance: Provide expert advice to technology segments on IT Risk Governance Control Frameworks (NIST, COBIT, ITIL), Audit & Assurance Standards, and GRC processes.
Risk Reporting, Governance & Continuous Improvement
Executive Reporting & Escalations: Identify emerging risk themes, track remediation trends, and deliver clear governance reports to senior leadership regarding issue escalations, overdue items, or validation failures.
Process Optimization: Leverage Lean and Agile frameworks (Scrum, Kanban) to optimize operational assurance workflows, integrating modern reporting and automation utilities where appropriate.
Documentation & Audit Artifacts: Maintain meticulous, audit-proof documentation, test evidence, and validation artifacts in enterprise GRC tools (RSA Archer, ServiceNow, Jira, Confluence).
Qualifications
IT Audit & Controls Experience: 10+ years of dedicated professional experience in IT Audit, IT Governance, Quality Assurance as it relates to remediation plans, and information security control frameworks.
Remediation & Testing Expertise: 10+ years of hands-on experience assessing, evaluating, and validating audit and regulatory remediations using sample-based test plans and formal audit validation approaches (e.g., IOR methodology).
Control Framework Mastery: In-depth knowledge of enterprise IT governance frameworks and security standards (COBIT, NIST, ITIL).
GRC & Enterprise Tooling: Hands-on experience with GRC and work-tracking platforms, including ServiceNow, RSA Archer, Jira, Confluence, SharePoint, and Advanced MS Excel.
Mandatory Certification: Active Certified Information Systems Auditor (CISA) designation is required.
Communication & Collaboration: Exceptional written and verbal communication skills; strong "auditor mindset" paired with a collaborative, team-oriented approach to problem-solving.
Preferred Assets & Nice-to-Haves
Active Certified Information Systems Security Professional (CISSP) or CRISC certification.
Prior IT audit or risk governance experience within a Tier-1 Bank or Regulated Financial Institution.
Exposure to Lean/Agile methodologies or AI-assisted data analytics tools (Python, Power BI).
Summary
If you are a tech-savvy Security Specialist V who pairs an absolute command of IT audit methodologies, CISA certification, and 10+ years of remediation testing with the independent challenge skills needed to safeguard enterprise technology controls, this 8-month hybrid contract is an outstanding opportunity. Bring your auditor mindset, GRC precision, and collaborative governance leadership to our client's security team today!
Randstad Canada is committed to fostering a workforce reflective of all peoples of Canada. As a result, we are committed to developing and implementing strategies to increase the equity, diversity and inclusion within the workplace by examining our internal policies, practices, and systems throughout the entire lifecycle of our workforce, including its recruitment, retention and advancement for all employees. In addition to our deep commitment to respecting human rights, we are dedicated to positive actions to affect change to ensure everyone has full participation in the workforce free from any barriers, systemic or otherwise, especially equity-seeking groups who are usually underrepresented in Canada's workforce, including those who identify as women or non-binary/gender non-conforming; Indigenous or Aboriginal Peoples; persons with disabilities (visible or invisible) and; members of visible minorities, racialized groups and the LGBTQ2+ community.
Randstad Canada is committed to creating and maintaining an inclusive and accessible workplace for all its candidates and employees by supporting their accessibility and accommodation needs throughout the employment lifecycle. We ask that all job applications please identify any accommodation requirements by sending an email to accessibility@randstad.ca to ensure their ability to fully participate in the interview process.
This posting is for existing and upcoming vacancies.
show more
Our client, is seeking a high-performing, authoritative Security Specialist V (IT Audit & Remediation Assurance Lead) to join their enterprise Global Security & Defense division.
In this senior governance role, you will be responsible for leading independent challenge, quality assurance, and assessment of audit and regulatory finding remediations across complex technology infrastructure and applications. Operating within the Three Lines of Defense (3LOD) framework, you will partner closely with technology leaders, second/third-line risk teams, and external regulators to independently validate that issue remediation plans effectively mitigate information security risks. This position is ideal for a seasoned CISA-certified IT Auditor or GRC Lead who pairs 10+ years of audit validation, sample-based testing, and controls framework mastery with exceptional executive communication skills.
Duration: 8-Month Contract (with high potential for extension)
Work Arrangement: Hybrid (Currently 2 days per week on-site at the corporate office, transitioning to 4 days per week on-site in the future)
Advantages
...
High-Impact Enterprise Governance Scope: Lead independent challenge and quality assurance oversight for critical regulatory, audit, and operational risk remediations across global technology platforms.
Executive Visibility: Provide strategic guidance, trend reporting, and independent challenge directly to senior technology leads, enterprise risk officers, and audit executives.
Modern GRC Ecosystem: Utilize top-tier enterprise governance and tracking platforms, including RSA Archer, ServiceNow, Jira, and Confluence.
Continuous Innovation Focus: Drive lean continuous improvement practices and leverage modern analytics tools (e.g., Power BI/Apps, Python) to optimize audit validation workflows.
Responsibilities
Independent Challenge & Remediation Validation
Remediation Assessment: Lead comprehensive assessments of audit and regulatory finding remediations required to mitigate information security risks within enterprise applications and technology infrastructure.
Sample-Based Test Plans: Design and execute rigorous, sample-based test plans relying on Industry Operational Risk (IOR) methodologies or comparable audit validation frameworks to verify control operating effectiveness.
3LOD Collaboration: Partner across first, second, and third lines of defense to evaluate issue remediation quality, challenge insufficient action plans, and ensure long-term risk sustainability.
Subject Matter Guidance: Provide expert advice to technology segments on IT Risk Governance Control Frameworks (NIST, COBIT, ITIL), Audit & Assurance Standards, and GRC processes.
Risk Reporting, Governance & Continuous Improvement
Executive Reporting & Escalations: Identify emerging risk themes, track remediation trends, and deliver clear governance reports to senior leadership regarding issue escalations, overdue items, or validation failures.
Process Optimization: Leverage Lean and Agile frameworks (Scrum, Kanban) to optimize operational assurance workflows, integrating modern reporting and automation utilities where appropriate.
Documentation & Audit Artifacts: Maintain meticulous, audit-proof documentation, test evidence, and validation artifacts in enterprise GRC tools (RSA Archer, ServiceNow, Jira, Confluence).
Qualifications
IT Audit & Controls Experience: 10+ years of dedicated professional experience in IT Audit, IT Governance, Quality Assurance as it relates to remediation plans, and information security control frameworks.
Remediation & Testing Expertise: 10+ years of hands-on experience assessing, evaluating, and validating audit and regulatory remediations using sample-based test plans and formal audit validation approaches (e.g., IOR methodology).
Control Framework Mastery: In-depth knowledge of enterprise IT governance frameworks and security standards (COBIT, NIST, ITIL).
GRC & Enterprise Tooling: Hands-on experience with GRC and work-tracking platforms, including ServiceNow, RSA Archer, Jira, Confluence, SharePoint, and Advanced MS Excel.
Mandatory Certification: Active Certified Information Systems Auditor (CISA) designation is required.
Communication & Collaboration: Exceptional written and verbal communication skills; strong "auditor mindset" paired with a collaborative, team-oriented approach to problem-solving.
Preferred Assets & Nice-to-Haves
Active Certified Information Systems Security Professional (CISSP) or CRISC certification.
Prior IT audit or risk governance experience within a Tier-1 Bank or Regulated Financial Institution.
Exposure to Lean/Agile methodologies or AI-assisted data analytics tools (Python, Power BI).
Summary
If you are a tech-savvy Security Specialist V who pairs an absolute command of IT audit methodologies, CISA certification, and 10+ years of remediation testing with the independent challenge skills needed to safeguard enterprise technology controls, this 8-month hybrid contract is an outstanding opportunity. Bring your auditor mindset, GRC precision, and collaborative governance leadership to our client's security team today!
Randstad Canada is committed to fostering a workforce reflective of all peoples of Canada. As a result, we are committed to developing and implementing strategies to increase the equity, diversity and inclusion within the workplace by examining our internal policies, practices, and systems throughout the entire lifecycle of our workforce, including its recruitment, retention and advancement for all employees. In addition to our deep commitment to respecting human rights, we are dedicated to positive actions to affect change to ensure everyone has full participation in the workforce free from any barriers, systemic or otherwise, especially equity-seeking groups who are usually underrepresented in Canada's workforce, including those who identify as women or non-binary/gender non-conforming; Indigenous or Aboriginal Peoples; persons with disabilities (visible or invisible) and; members of visible minorities, racialized groups and the LGBTQ2+ community.
Randstad Canada is committed to creating and maintaining an inclusive and accessible workplace for all its candidates and employees by supporting their accessibility and accommodation needs throughout the employment lifecycle. We ask that all job applications please identify any accommodation requirements by sending an email to accessibility@randstad.ca to ensure their ability to fully participate in the interview process.
This posting is for existing and upcoming vacancies.
show more