Information Security Grc Analyst

 

Description:

The Information Security GRC analyst, reporting to the Director Information Security GRC, will support the implementation and maintenance of the organization’s Governance, Risk, and Compliance (GRC) program, with a strong focus on third party security compliance, security governance, and internal controls. This role will contribute to maintaining a formally structured, risk-based security framework aligned with industry standards such as ISO 27001 and ISO 22301. The position requires a minimum of three years of information security experience in a similar position and excellent communication skills.

Essential Functions
 

  • Oversee the cybersecurity compliance program for third parties, including:
    • Managing requests from clients, prospects, auditors, cyber-insurers, or others, related to our security program, to ensure the timely and accurate response to security questionnaires and associated requests.
    • Managing the compliance of the Firm's key IT vendors with information security, including a comprehensive initial security due diligence, an annual security re-certification, and a continuous monitoring of the vendors' security profile.
  • Assist with the performance of important internal security processes and controls, including:
    • Tracking the status of key internal security tasks and following up with the responsible person to ensure these tasks are conducted in time and as per the annual schedule.
    • Maintaining security dashboards, metrics, and reports as required for the team, the IT Department and senior management.
    • Making suggestions, and improving existing security standards and procedures.
  • Conduct security tasks as required to maintain the Firm's ISO 27001 and ISO 22301 certifications: Perform limited internal security audits; Collaborate with IT and business functions to remediate compliance gaps; Maintain documentation related to compliance activities, controls, and audit findings; Assist with ad-hoc security investigations; Stay up to date with emerging threats, current regulations, existing standards, and industry trends.

Qualifications
 

  • Bachelor's degree in information technology, computer Science, cybersecurity, or related field
  • Minimum three years of experience in IT compliance, risk management, or information security
  • Knowledge of commonly used security frameworks (e.g., ISO 27001, ISO 22301, NIST)
  • Experience with security risk management processes and compliance tools
  • Outstanding oral and written communication skills
  • Excellent interpersonal relationship skills
  • High-level of attention to detail and accuracy
  • High degree of personal initiative and maturity with an ability to work with minimal supervision
  • Ability to prioritize tasks effectively, respect deadlines, and report any issues, conflict or roadblock in the performance of operational activities, and the planning and scheduling of tasks and projects
  • Professional certifications as follows are an asset
  • CISSP, CISA, CISM, CRISC
  • SANS/GIAC, CompTIA Security+, CEH

Organization Bennett Jones
Industry IT / Telecom / Software Jobs
Occupational Category Information Security GRC Analyst
Job Location Calgary,Canada
Shift Type Morning
Job Type Full Time
Gender No Preference
Career Level Experienced Professional
Experience 3 Years
Posted at 2026-07-29 4:24 pm
Expires on 2026-09-12