We are seeking a highly accomplished Senior Cybersecurity GRC Analyst (Security Specialist) for an enterprise-level contract opportunity based in Toronto. In this role, you will take on a premier strategic capacity within cybersecurity governance, risk management, and regulatory compliance streams, specializing in identifying vulnerabilities, evaluating security architectures, and enforcing enterprise risk controls.
...
As a principal GRC specialist, you will bridge the gap between technical infrastructure, privacy legislation, and enterprise security frameworks. Operating within a hybrid work model, you will lead comprehensive security and privacy impact assessments (PIAs/TRAs), develop and refresh corporate cybersecurity policies, manage third-party vendor risk programs, and ensure strict alignment with industry security standards and Canadian privacy regulations. This position is tailored for a certified security authority (CISSP or CRISC) who can deliver actionable risk analytics, evaluate third-party vendor contracts, and govern compliance across IT, cloud, and operational technology (OT) environments.
Location: Toronto, ON
Assignment Type: Hybrid (2 to 3 days per week onsite)
Contract Duration: 24-month contract (with potential for extension)
Advantages
High-Impact Risk Leadership: Drive enterprise-wide Security Risk Assessments, Privacy Impact Assessments (PIAs), and Threat and Risk Assessments (TRAs).
Broad Framework Exposure: Govern compliance across leading cybersecurity standards, including NIST CSF, ISO/IEC 27001/27002, ISA/IEC 62443, NERC CIP, CIS Controls, and SOC2.
Complex Multi-Environment Scope: Evaluate risk profiles across enterprise IT, cloud platforms, hybrid networks, and industrial/OT infrastructure.
Long-Term Enterprise Engagement: Secure a foundational multi-year contract runway with options for further extension.
Responsibilities
Conduct comprehensive security and privacy risk assessments across new and existing information systems, network infrastructure, cloud environments, and operational technologies.
Analyze existing security controls, perform vulnerability evaluations, and assess technical architectures to identify threats and operational risks.
Formulate, document, and recommend actionable security controls to mitigate identified risks and communicate findings effectively to technical and business stakeholders.
Identify, assess, and monitor cybersecurity and privacy risks, providing predictive analytics to support strategic business decisions.
Develop, refresh, enhance, and communicate enterprise cybersecurity governance frameworks, policies, standards, and operational procedures.
Design technical, administrative, and physical security controls to ensure organizational compliance with Canadian privacy and cyber security legislation (PHIPA, MFIPPA, CASL, CCSPA).
Execute periodic gap assessments across the information security program, validate ongoing control compliance, facilitate remediation plans, and escalate critical issues to leadership.
Manage the security exception review and approval lifecycle, ensuring all risk acceptances are documented and re-evaluated on a defined schedule.
Perform initial and ongoing third-party vendor security due diligence, vendor risk monitoring, and maintain the enterprise supplier risk inventory.
Review information security and privacy clauses within procurement documents (RFIs, RFPs, MPSAs, contracts, and purchase orders) to identify gaps and enforce data protection terms.
Provide expert GRC advisory services across enterprise projects, IT initiatives, and technology modernization programs.
Qualifications
Core Requirements & Mandatory Certifications
Education: University degree in Computer Science, Information Security, Cybersecurity, or a related field (or an equivalent combination of education and professional experience).
Mandatory Professional Certification: Active credential in at least one of the following:
Certified Information Systems Security Professional (CISSP)
Certified in Risk and Information Systems Control (CRISC)
GRC Experience: 7+ years of relevant cybersecurity experience focused on Governance, Risk, and Compliance (GRC).
Privacy Impact Assessments: 5+ years of hands-on experience conducting Privacy Risk Assessments and Privacy Impact Assessments (PIAs).
Enterprise IT Experience: 10+ years of progressive Information Technology experience.
Security Framework Depth: Significant experience applying enterprise security frameworks and standards, such as NIST CSF, ISO/IEC 27001/27002, ISA/IEC 62443, NERC CIP, CIS Controls, and SOC2.
Policy & Governance Development: Demonstrated experience developing, refreshing, and implementing cybersecurity policies, standards, guidelines, and procedures.
Canadian Regulatory Mastery: In-depth understanding and practical application of Canadian privacy and security legislation, including PHIPA, MFIPPA, CASL, Critical Cyber Systems Protection Act (CCSPA), and related digital security acts.
Preferred Technical & Architecture Skills
Architecture & Infrastructure Depth: Strong background in enterprise IT and Security Architecture, spanning cloud, hybrid, and OT/industrial operational environments.
Networking & Protocols: Solid understanding of networking principles (TCP/IP, WAN/LAN) and core security/internet protocols (SMTP, HTTP, FTP, LDAP, SAMLv2, OAuth, SSL/TLS).
Vendor & Contract Risk: Direct experience evaluating vendor risk, reviewing RFP/contractual security terms, and utilizing GRC risk management tooling.
Soft Skills & Professional Attributes
Analytical Problem Solving: Superior diagnostic capabilities to evaluate complex risk scenarios, weigh costs versus benefits, and recommend pragmatic mitigations.
Consultative Communication: Exceptional written and verbal communication skills with meticulous attention to detail when presenting risk findings to diverse audiences.
Time Management & Adaptability: Proven ability to manage competing priorities, deliver under tight deadlines, and navigate fast-paced environments effectively.
Summary
If you're interested in the "Senior Cybersecurity GRC Analyst (Security Specialist)" role based in Toronto, we encourage you to apply online at www.randstad.ca.
Only qualified candidates will be contacted for the next steps. We look forward to hearing from you!
Randstad Canada is committed to fostering a workforce reflective of all peoples of Canada. As a result, we are committed to developing and implementing strategies to increase the equity, diversity and inclusion within the workplace by examining our internal policies, practices, and systems throughout the entire lifecycle of our workforce, including its recruitment, retention and advancement for all employees. In addition to our deep commitment to respecting human rights, we are dedicated to positive actions to affect change to ensure everyone has full participation in the workforce free from any barriers, systemic or otherwise, especially equity-seeking groups who are usually underrepresented in Canada's workforce, including those who identify as women or non-binary/gender non-conforming; Indigenous or Aboriginal Peoples; persons with disabilities (visible or invisible) and; members of visible minorities, racialized groups and the LGBTQ2+ community.
Randstad Canada is committed to creating and maintaining an inclusive and accessible workplace for all its candidates and employees by supporting their accessibility and accommodation needs throughout the employment lifecycle. We ask that all job applications please identify any accommodation requirements by sending an email to accessibility@randstad.ca to ensure their ability to fully participate in the interview process.
This posting is for existing and upcoming vacancies.
show more
We are seeking a highly accomplished Senior Cybersecurity GRC Analyst (Security Specialist) for an enterprise-level contract opportunity based in Toronto. In this role, you will take on a premier strategic capacity within cybersecurity governance, risk management, and regulatory compliance streams, specializing in identifying vulnerabilities, evaluating security architectures, and enforcing enterprise risk controls.
As a principal GRC specialist, you will bridge the gap between technical infrastructure, privacy legislation, and enterprise security frameworks. Operating within a hybrid work model, you will lead comprehensive security and privacy impact assessments (PIAs/TRAs), develop and refresh corporate cybersecurity policies, manage third-party vendor risk programs, and ensure strict alignment with industry security standards and Canadian privacy regulations. This position is tailored for a certified security authority (CISSP or CRISC) who can deliver actionable risk analytics, evaluate third-party vendor contracts, and govern compliance across IT, cloud, and operational technology (OT) environments.
Location: Toronto, ON
Assignment Type: Hybrid (2 to 3 days per week onsite)
...
Contract Duration: 24-month contract (with potential for extension)
Advantages
High-Impact Risk Leadership: Drive enterprise-wide Security Risk Assessments, Privacy Impact Assessments (PIAs), and Threat and Risk Assessments (TRAs).
Broad Framework Exposure: Govern compliance across leading cybersecurity standards, including NIST CSF, ISO/IEC 27001/27002, ISA/IEC 62443, NERC CIP, CIS Controls, and SOC2.
Complex Multi-Environment Scope: Evaluate risk profiles across enterprise IT, cloud platforms, hybrid networks, and industrial/OT infrastructure.
Long-Term Enterprise Engagement: Secure a foundational multi-year contract runway with options for further extension.
Responsibilities
Conduct comprehensive security and privacy risk assessments across new and existing information systems, network infrastructure, cloud environments, and operational technologies.
Analyze existing security controls, perform vulnerability evaluations, and assess technical architectures to identify threats and operational risks.
Formulate, document, and recommend actionable security controls to mitigate identified risks and communicate findings effectively to technical and business stakeholders.
Identify, assess, and monitor cybersecurity and privacy risks, providing predictive analytics to support strategic business decisions.
Develop, refresh, enhance, and communicate enterprise cybersecurity governance frameworks, policies, standards, and operational procedures.
Design technical, administrative, and physical security controls to ensure organizational compliance with Canadian privacy and cyber security legislation (PHIPA, MFIPPA, CASL, CCSPA).
Execute periodic gap assessments across the information security program, validate ongoing control compliance, facilitate remediation plans, and escalate critical issues to leadership.
Manage the security exception review and approval lifecycle, ensuring all risk acceptances are documented and re-evaluated on a defined schedule.
Perform initial and ongoing third-party vendor security due diligence, vendor risk monitoring, and maintain the enterprise supplier risk inventory.
Review information security and privacy clauses within procurement documents (RFIs, RFPs, MPSAs, contracts, and purchase orders) to identify gaps and enforce data protection terms.
Provide expert GRC advisory services across enterprise projects, IT initiatives, and technology modernization programs.
Qualifications
Core Requirements & Mandatory Certifications
Education: University degree in Computer Science, Information Security, Cybersecurity, or a related field (or an equivalent combination of education and professional experience).
Mandatory Professional Certification: Active credential in at least one of the following:
Certified Information Systems Security Professional (CISSP)
Certified in Risk and Information Systems Control (CRISC)
GRC Experience: 7+ years of relevant cybersecurity experience focused on Governance, Risk, and Compliance (GRC).
Privacy Impact Assessments: 5+ years of hands-on experience conducting Privacy Risk Assessments and Privacy Impact Assessments (PIAs).
Enterprise IT Experience: 10+ years of progressive Information Technology experience.
Security Framework Depth: Significant experience applying enterprise security frameworks and standards, such as NIST CSF, ISO/IEC 27001/27002, ISA/IEC 62443, NERC CIP, CIS Controls, and SOC2.
Policy & Governance Development: Demonstrated experience developing, refreshing, and implementing cybersecurity policies, standards, guidelines, and procedures.
Canadian Regulatory Mastery: In-depth understanding and practical application of Canadian privacy and security legislation, including PHIPA, MFIPPA, CASL, Critical Cyber Systems Protection Act (CCSPA), and related digital security acts.
Preferred Technical & Architecture Skills
Architecture & Infrastructure Depth: Strong background in enterprise IT and Security Architecture, spanning cloud, hybrid, and OT/industrial operational environments.
Networking & Protocols: Solid understanding of networking principles (TCP/IP, WAN/LAN) and core security/internet protocols (SMTP, HTTP, FTP, LDAP, SAMLv2, OAuth, SSL/TLS).
Vendor & Contract Risk: Direct experience evaluating vendor risk, reviewing RFP/contractual security terms, and utilizing GRC risk management tooling.
Soft Skills & Professional Attributes
Analytical Problem Solving: Superior diagnostic capabilities to evaluate complex risk scenarios, weigh costs versus benefits, and recommend pragmatic mitigations.
Consultative Communication: Exceptional written and verbal communication skills with meticulous attention to detail when presenting risk findings to diverse audiences.
Time Management & Adaptability: Proven ability to manage competing priorities, deliver under tight deadlines, and navigate fast-paced environments effectively.
Summary
If you're interested in the "Senior Cybersecurity GRC Analyst (Security Specialist)" role based in Toronto, we encourage you to apply online at www.randstad.ca.
Only qualified candidates will be contacted for the next steps. We look forward to hearing from you!
Randstad Canada is committed to fostering a workforce reflective of all peoples of Canada. As a result, we are committed to developing and implementing strategies to increase the equity, diversity and inclusion within the workplace by examining our internal policies, practices, and systems throughout the entire lifecycle of our workforce, including its recruitment, retention and advancement for all employees. In addition to our deep commitment to respecting human rights, we are dedicated to positive actions to affect change to ensure everyone has full participation in the workforce free from any barriers, systemic or otherwise, especially equity-seeking groups who are usually underrepresented in Canada's workforce, including those who identify as women or non-binary/gender non-conforming; Indigenous or Aboriginal Peoples; persons with disabilities (visible or invisible) and; members of visible minorities, racialized groups and the LGBTQ2+ community.
Randstad Canada is committed to creating and maintaining an inclusive and accessible workplace for all its candidates and employees by supporting their accessibility and accommodation needs throughout the employment lifecycle. We ask that all job applications please identify any accommodation requirements by sending an email to accessibility@randstad.ca to ensure their ability to fully participate in the interview process.
This posting is for existing and upcoming vacancies.
show more