1

Cyber Audit Jobs in Quebec (NOW HIRING)

Maintenir le registre corporatif des risques cyber. * Réaliser les analyses de risques ... Participer aux audits internes et externes. * Maintenir le registre des exigences réglementaires ...

Collaborer avec les equipes d'audit, de gestion des risques cyber, d'affaires juridiques, de conformite, de technologies de l'information, de gestion des risques et les unites d'affaires afin ...

Collaborer avec les equipes d'audit, de gestion des risques cyber, d'affaires juridiques, de conformite, de technologies de l'information, de gestion des risques et les unites d'affaires afin ...

Support audit, regulatory, and compliance activities (e.g., ISO 27001, NIST, SOC) related to ... Continuously monitor evolving cyber threats, emerging technologies, and industry practices to ...

Support audit, regulatory, and compliance activities (e.g., ISO 27001, NIST, SOC) related to ... Continuously monitor evolving cyber threats, emerging technologies, and industry practices to ...

Support audit, regulatory, and compliance activities (e.g., ISO 27001, NIST, SOC) related to ... Continuously monitor evolving cyber threats, emerging technologies, and industry practices to ...

Support audit, regulatory, and compliance activities (e.g., ISO 27001, NIST, SOC) related to ... Continuously monitor evolving cyber threats, emerging technologies, and industry practices to ...

next page

Showing results 1-20

Cyber Audit information

What is the difference between Cyber Audit vs Cyber Security Analyst?

AspectCyber AuditCyber Security Analyst
CertificationsISO 27001 Lead Auditor, CISACompTIA Security+, CISSP
Work EnvironmentAudit firms, consulting companies, internal audit departmentsSecurity operations centers, IT departments, corporate security teams
Employer & Industry UsageFinancial, healthcare, government sectorsAll industries with IT infrastructure
Primary FocusAssessing compliance, evaluating controls, auditing security policiesMonitoring security threats, implementing security measures, incident response

While both roles focus on cybersecurity, Cyber Audit primarily involves evaluating an organization's security controls and compliance through audits. Cyber Security Analysts actively monitor and respond to security threats. Understanding these differences helps organizations assign the right responsibilities and professionals for their cybersecurity needs.

What job categories do people searching Cyber Audit jobs in Quebec look for? The top searched job categories for Cyber Audit jobs in Quebec are:
Infographic showing various Cyber Audit job openings in Quebec as of July 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution.

Security Governance, Risk and Compliance Specialist

Tecsys Inc.

Montreal, QC • On-site

Full-time

Posted 16 days ago


Job description

Having recognized the advantages of remote work, such as improved employee morale, increased productivity, and positive impacts on both employee wellbeing and the environment, we are proud to be a digital-first company. Our digital-first work environment, combined with our conveniently located offices and collaborative workspaces, provides our team with the freedom and flexibility to work in the most productive way for them.

About us

Tecsys is a fast-growing innovator offering supply chain solutions to industry leading healthcare systems, hospitals, and pharmacy businesses to distributors, retailers, and 3PLs. We work with industry leaders to transform their supply chains through technology. If you thrive on tackling interesting challenges with continuous learning opportunities, then Tecsys could be a good fit for you!

About the Role

We are seeking a Security Governance, Risk and Compliance specialist who will be involved in defining how security can enable business initiatives, and how we should meet security best practices, as well as applicable various contractual and regulatory requirements. The successful candidate will be supporting the implementation of a security risk management framework. The GRC specialist’s role will also encompass the management of vendor risk and business continuity programs. As a security subject matter expert, you will recommend improvements to reduce, contain and mitigate identified risks, as well as partake in various business and security initiatives to improve Tecsys’s security maturity.

What you’ll do
  • Support continuous security risk management framework.
  • Collaborate with technical teams for the development, implementation and monitoring of required corrective action plans relating to security compliance issues or audit deficiencies.
  • Collaborate with stakeholders to define processes, automate and continuously monitor information security controls, exceptions, risks, testing and evidence gathering.
  • Develop reporting metrics and dashboards.
  • Help identify cyber risks and solve various governance gaps and process inefficiencies.
  • Develop, execute and actively partake in internal and external security and compliance assessment initiatives such as SOC 2, PCI-DSS, NIST, FedRAMP
  • Review and optimize vendor risk management program.
  • Monitor existing controls and conduct periodic audits and reviews to ensure their efficiency and operating effectiveness, and to identify and report on potential issues.
  • Collaborate with internal IT and business teams to identify cyber risks and prioritize security compliance-related improvements
  • As security subject matter expert, support IT and cyber teams on the implementation of controls to meet security and privacy compliance requirements and best practices
  • Support the development, review, update and optimization of security documentation.

Requirements

Formal Education & Certification

  • Bachelor’s degree in information systems or equivalent experience
  • Minimum 3 years of cumulated hands-on experience

Knowledge & Experience

  • Experience in the development and implementation of governance, risk and compliance strategy and security control framework.
  • Experience in risk assessments and cyber risk management methodology/processes.
  • Broad knowledge of defense in depth security concepts and best practices through practical experience.
  • Proven experience conducting security audits such as SOC2 or PCI DSS.
  • Experience with cybersecurity frameworks such as NIST, CIS.
  • Good knowledge of business continuity process and planning.
  • Familiarity with IP networking fundamentals and internet protocols.
  • Familiarity with Linux, Mac, and Windows operating systems, mobile devices, and the IT application landscape.
  • Proven experience with governing the security of public cloud platforms such as AWS and Azure.

Personal Attributes

  • Ability to work with minimal supervision.
  • Strong ability to define problems, collect and analyze data, establish facts and draw valid conclusions.
  • Positive attitude and agile mindset.
  • Motivated, team, and customer oriented.
  • Not afraid to fail.
  • Excellent interpersonal skills.
  • Ability to plan and deliver on commitment.
  • Strong proficiency in both written and verbal English communication essential for effective correspondence with clients, suppliers, business partners, and colleagues beyond the province of Quebec.

We understand that experience comes in many forms and that careers are not always linear. If you don't meet every requirement in this posting, we still encourage you to apply.

At Tecsys, we are committed to fostering a diverse and inclusive workplace where all employees feel valued, respected, and empowered. We believe that diversity drives innovation and strengthens our ability to deliver exceptional solutions. We welcome and encourage applicants from all backgrounds, experiences, and perspectives to join our team.

Tecsys is an equal opportunity employer. Accommodation is available for applicants selected for an interview.

NB: if you are applying to this position, you must be a Canadian Citizen or a Permanent Resident of Canada, OR, have a valid Canadian work permit.