... governance programs, including the CSOX compliance, Internal Audit, and Enterprise Risk Management ... ERM") programs. What You Will Do The Auditor/Senior Auditor works closely with business leaders to ...
... governance programs, including the CSOX compliance, Internal Audit, and Enterprise Risk Management ... ERM") programs. What You Will Do The Auditor/Senior Auditor works closely with business leaders to ...
Senior Legal Counsel
$180K - $250K/yr
Ensure all project contracts are aligned with lender due diligence requirements * Assist with financial close and funding processes 6. Governance, Risk & Compliance * Establish and maintain internal ...
Quick apply
Senior Legal Counsel
$180K - $250K/yr
Ensure all project contracts are aligned with lender due diligence requirements * Assist with financial close and funding processes 6. Governance, Risk & Compliance * Establish and maintain internal ...
Make an impact with our Enterprise Risk - Governance & Risk Management team as an Accountant ... Participate in the delivery of additional Enterprise Risk Services including compliance audits ...
New
Make an impact with our Enterprise Risk - Governance & Risk Management team as an Accountant ... Participate in the delivery of additional Enterprise Risk Services including compliance audits ...
New
Establish and mature governance, risk management, compliance, and data privacy programs. * Lead enterprise AI governance and emerging technology risk management initiatives. * Drive technology ...
Establish and mature governance, risk management, compliance, and data privacy programs. * Lead enterprise AI governance and emerging technology risk management initiatives. * Drive technology ...
Maintain and audit risk registers for accuracy, completeness, and governance compliance * Separate realized risks from unrealized forecast costs; support disciplined projections * Support estimate ...
Maintain and audit risk registers for accuracy, completeness, and governance compliance * Separate realized risks from unrealized forecast costs; support disciplined projections * Support estimate ...
Success will depend on translating enterprise risk objectives into practical governance processes that support informed, compliant, and consistent decision-making across business units. Position ...
New
Success will depend on translating enterprise risk objectives into practical governance processes that support informed, compliant, and consistent decision-making across business units. Position ...
New
Senior Analyst - IT Security
Calgary, AB · On-site
Job Summary We are looking for a Senior Analyst - IT Security with a strong focus on Governance, Risk, and Compliance (GRC) to support our efforts in maintaining ISO 27001 certification and other ...
Senior Analyst - IT Security
Calgary, AB · On-site
Job Summary We are looking for a Senior Analyst - IT Security with a strong focus on Governance, Risk, and Compliance (GRC) to support our efforts in maintaining ISO 27001 certification and other ...
Senior Model Risk & Validation Consultant
Lethbridge, AB · Hybrid
CA$120K - CA$145K/yr
... compliance with OSFI Guideline E 23 and evolving regulatory expectations for AI governance ... Assess model risk severity and the adequacy of controls, overlays, monitoring, and governance ...
Senior Model Risk & Validation Consultant
Lethbridge, AB · Hybrid
CA$120K - CA$145K/yr
... compliance with OSFI Guideline E 23 and evolving regulatory expectations for AI governance ... Assess model risk severity and the adequacy of controls, overlays, monitoring, and governance ...
Senior Model Risk & Validation Consultant
Lloydminster, AB · Hybrid
CA$120K - CA$145K/yr
... compliance with OSFI Guideline E 23 and evolving regulatory expectations for AI governance ... Assess model risk severity and the adequacy of controls, overlays, monitoring, and governance ...
Senior Model Risk & Validation Consultant
Lloydminster, AB · Hybrid
CA$120K - CA$145K/yr
... compliance with OSFI Guideline E 23 and evolving regulatory expectations for AI governance ... Assess model risk severity and the adequacy of controls, overlays, monitoring, and governance ...
Senior Model Risk & Validation Consultant
Calgary, AB · Hybrid
CA$120K - CA$145K/yr
... compliance with OSFI Guideline E 23 and evolving regulatory expectations for AI governance ... Assess model risk severity and the adequacy of controls, overlays, monitoring, and governance ...
Senior Model Risk & Validation Consultant
Calgary, AB · Hybrid
CA$120K - CA$145K/yr
... compliance with OSFI Guideline E 23 and evolving regulatory expectations for AI governance ... Assess model risk severity and the adequacy of controls, overlays, monitoring, and governance ...
Senior Model Risk & Validation Consultant
Edmonton, AB · Hybrid
CA$120K - CA$145K/yr
... compliance with OSFI Guideline E 23 and evolving regulatory expectations for AI governance ... Assess model risk severity and the adequacy of controls, overlays, monitoring, and governance ...
Senior Model Risk & Validation Consultant
Edmonton, AB · Hybrid
CA$120K - CA$145K/yr
... compliance with OSFI Guideline E 23 and evolving regulatory expectations for AI governance ... Assess model risk severity and the adequacy of controls, overlays, monitoring, and governance ...
Lead PCL's enterprise compliance strategy and governance framework, aligning priorities with business objectives and risk management needs. * Drive the ongoing evolution of PCL's compliance program ...
Lead PCL's enterprise compliance strategy and governance framework, aligning priorities with business objectives and risk management needs. * Drive the ongoing evolution of PCL's compliance program ...
Lead PCL's enterprise compliance strategy and governance framework, aligning priorities with business objectives and risk management needs. * Drive the ongoing evolution of PCL's compliance program ...
Lead PCL's enterprise compliance strategy and governance framework, aligning priorities with business objectives and risk management needs. * Drive the ongoing evolution of PCL's compliance program ...
Lead PCL's enterprise compliance strategy and governance framework, aligning priorities with business objectives and risk management needs. * Drive the ongoing evolution of PCL's compliance program ...
Lead PCL's enterprise compliance strategy and governance framework, aligning priorities with business objectives and risk management needs. * Drive the ongoing evolution of PCL's compliance program ...
Line of Service Assurance Industry/Sector Not Applicable Specialism Conduct and Compliance ... Design and implement program governance and program management strategies, including cadence ...
Line of Service Assurance Industry/Sector Not Applicable Specialism Conduct and Compliance ... Design and implement program governance and program management strategies, including cadence ...
Client Success Manager Lead - BizApps Managed Services (Microsoft Dynamics 365 BC/F&O/CE, NetSuit...
Calgary, AB · On-site
... compliance, and continuous improvement. You will act as a trusted advisor to senior client ... Portfolio governance * Risk and issue management * Change control * Quality assurance standards
Client Success Manager Lead - BizApps Managed Services (Microsoft Dynamics 365 BC/F&O/CE, NetSuit...
Calgary, AB · On-site
... compliance, and continuous improvement. You will act as a trusted advisor to senior client ... Portfolio governance * Risk and issue management * Change control * Quality assurance standards
Client Success Manager Lead - BizApps Managed Services (Microsoft Dynamics 365 BC/F&O/CE, NetSuit...
... compliance, and continuous improvement. You will act as a trusted advisor to senior client ... Portfolio governance * Risk and issue management * Change control * Quality assurance standards
Client Success Manager Lead - BizApps Managed Services (Microsoft Dynamics 365 BC/F&O/CE, NetSuit...
... compliance, and continuous improvement. You will act as a trusted advisor to senior client ... Portfolio governance * Risk and issue management * Change control * Quality assurance standards
Experience with Governance, Risk and Compliance (GRC) activities including strategy development, target operating model and roles and responsibility definition, policy and standards development ...
Experience with Governance, Risk and Compliance (GRC) activities including strategy development, target operating model and roles and responsibility definition, policy and standards development ...
... Compliance to drive collaboration and ensure fronttoback success across the commodity transaction lifecycle. * Provide on-going risk policy approval recommendations with clear governance over ...
... Compliance to drive collaboration and ensure fronttoback success across the commodity transaction lifecycle. * Provide on-going risk policy approval recommendations with clear governance over ...
Third-Party Risk Management Analyst (1 Year Contract)
Calgary, AB · Remote
CA$54K - CA$67K/yr
... governance across systems. Leveraging advanced data analytics and reporting, the role analyzes ... Identify compliance issues, manage resolution, and escalate risks or exception requests as required.
Third-Party Risk Management Analyst (1 Year Contract)
Calgary, AB · Remote
CA$54K - CA$67K/yr
... governance across systems. Leveraging advanced data analytics and reporting, the role analyzes ... Identify compliance issues, manage resolution, and escalate risks or exception requests as required.
Governance Risk Compliance information
See Alberta salary details
$35K - $48K
3% of jobs
$48K - $61K
6% of jobs
$61K - $74K
11% of jobs
$79.3K is the 25th percentile. Wages below this are outliers.
$74K - $87K
12% of jobs
$87K - $100K
17% of jobs
The median wage is $101K / yr.
$100K - $113K
14% of jobs
$113K - $126K
11% of jobs
$128K is the 75th percentile. Wages above this are outliers.
$126K - $139K
11% of jobs
$139K - $152K
5% of jobs
$152K - $165K
6% of jobs
$165K - $178K
4% of jobs
$35K
$110.9K
$178K
How much do governance risk compliance jobs pay per year?
What are jobs in governance risk compliance?
Governance risk compliance (GRC) is a method for managing and strategizing an organization's regulations regarding governance, financial or physical risk, and regulatory compliance. It aligns the IT aspects with business objectives and works to improve the efficiency of a company. There are GRC consultants and GRC analysts who provide an assessment of a business’s GRC, identify risks, analyze the data, develop policies to benefit the workplace, and consult on the best choice of action. Your duties may involve optimizing GRC systems, implementing tactics to lower risk, providing internal audits, assisting with cybersecurity, creating routine reports, and ensuring regulatory compliance.
What is the work of governance risk compliance?
What is governance risk compliance?
How does a governance risk compliance professional typically collaborate with other departments within an organization?
What is the difference between Governance Risk Compliance vs Risk Analyst?
| Aspect | Governance Risk Compliance | Risk Analyst |
|---|---|---|
| Certifications | CRISC, CISA, CISSP | CFA, FRM, CRISC |
| Work Environment | Corporate, regulated industries | Financial, consulting firms |
| Employer & Industry Usage | Financial institutions, healthcare, government | Banking, investment firms, insurance |
Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing enterprise-wide risks. Risk Analysts primarily assess specific financial or operational risks through data analysis. While both roles involve risk management, Governance Risk Compliance has a broader scope related to organizational compliance and governance frameworks, whereas Risk Analysts concentrate on analyzing and quantifying particular risks.
What are the key skills and qualifications needed to thrive as a governance risk compliance professional?

Internal Audit, Control and Enterprise Risk Auditor/Senior Auditor
Calgary, AB • On-site
Full-time
Medical, Dental, Vision, Life
Posted 25 days ago
Job description
Internal Audit, Control and Enterprise Risk Auditor/Senior Auditor
Location:Â Calgary Head OfficeÂ
Job status:Â Full Time Permanent
Department:Governance, Enterprise Risk and AssuranceÂ
Is this position safety sensitive:Â NoÂ
Apply today! Application Deadline is July 31, 2026 at 11:59pm
At Gibson, we believe our competitive advantage lies in the strength and talents of our employees. That means connecting our employees to rewarding careers, building a high-performance culture where collaboration and creativity are rewarded, and providing real growth opportunities for employees to take on new challenges. Â
The RoleÂ
The Internal Audit, Controls and Enterprise Risk Auditor/Senior Auditor reports directly to the Senior Manager of Internal Audit, Controls and Enterprise Risk ("Senior Manager"). This role is responsible for planning, executing and supporting the organization's governance, risk management and internal audit activities to support obligations to the C-Suite and the Audit Committee of the Board of Directors. The position advances the company's objectives by assessing the adequacy and operational effectiveness of internal controls across multiple governance programs, including the CSOX compliance, Internal Audit, and Enterprise Risk Management ("ERM") programs. Â
What You Will Do
The Auditor/Senior Auditor works closely with business leaders to assess risks, strengthen internal controls and promote continuous improvement, while ensuring compliance with regulatory requirements (NI 52-109) and corporate governance expectations. Key responsibilities include: Â
- Leading the ICFR (CSOX) program by developing and maintaining process documentation (narratives and flowcharts), preparing initial planning and scoping and risk assessments, performing and reviewing walk-throughs, testing internal controls, and reporting findings to the Senior Manager.
- Leading and executing internal audit engagements, including developing and performing detailed audit procedures, evaluating the adequacy and effectiveness of processes, operating systems, and internal controls, reviewing audit work papers, and preparing documentation in accordance with the standards set by the Institute of Internal Auditors (IIA) Professional Practices Framework.
- Tracking and validating the implementation of management action plans from prior audit engagements.
- Providing advisory support on policy development, process enhancements, and control design to strengthen governance and risk mitigation practices.
- Building and maintaining strong, collaborative relationships with Corporate and Business Unit leadership, including senior management.
- Maintaining a high level of integrity, professionalism and confidentiality.
- Supporting the overall goals of the team and organization by performing other duties as assigned. Â
What You Bring to the RoleÂ
- Minimum of one (1) of either CPA Professional Accounting or CIA Internal Audit designation is required.
- Additional audit-related designations (CISA, CFE, etc.) are considered assets.
- Minimum 4-7 year(s) Â internal audit and controls-related work experience required.
- Public accounting or audit firm experience is considered an asset.
- Previous experience with CSOX (or SOX) compliance programs would be considered an asset.
- Strong interpersonal skills with the ability to work collaboratively across teams and build effective relationships.
- Strong business analytical skills including process mapping, process improvement and root cause analysis.
- Excellent written and verbal communication skills, with the ability to translate complex concepts into clear, concise messages for stakeholders.
- Firm understanding of the standards under the IIA Professional Practises Framework and the COSO internal control framework.
- Demonstrates initiative, strong organisational skills and the ability to work independently in a fast-paced environment, while managing multiple priorities.
- Strong data analytic skills would be considered an asset.
- Understanding of controls relating to IT systems and databases is an asset.Â
Working ConditionsÂ
- Work is primarily performed in an office environment. Â
- This position may be required to travel to other Gibson offices across Canada and the U.S..
- This job is subject to background checks as outlined in Gibson Energy's Background Checks policy. Background checks may include: employment history verification, reference checks, education and/or credentials verification, credit check and a criminal history check.
Why You'll Love Working at GibsonÂ
For over 70 years, Gibson has been defined by our people - those who seize opportunities and make exceptional customer service a part of everything we do. Working at Gibson is an opportunity to be part of a place where employees feel valued, supported and motivated to do their best work. Here's what sets us apart:Â
- A competitive Total Rewards packagethat truly values your contributions.Â
- Employer contributions to your DC Pensionbecause we believe in your future.Â
- Comprehensive health, dental & vision benefits, with industryleadingcoverage for mental health and family planning - ensuring you and your loved ones thrive.Â
- Generous time offto rest, recharge and live life to the fullest.
- An incredible work environment and culturewhere your career development and advancement are prioritized every step of the way.Â
Gibson Energy Inc. ("Gibson" or the "Company") is a diversified North American energy infrastructure company headquartered in Calgary, Alberta. They have significant terminal assets, including 25 million barrels of storage and over 300 miles (500 kilometres) of crude pipelines across North America. The company has been providing market access to the oil and gas industry for over 70 years and is publicly traded on the Toronto Stock Exchange (TSX:GEI) with a market capitalization of approximately $4 billion.Â
Gibson Energy operates through two main segments:Â
- Infrastructure: This includes terminals, marine loading, rail loading and unloading facilities, gathering pipelines, a diluent recovery unit, and a crude oil processing facility. Key facilities within this segment include the Hardisty, Edmonton, and Ingleside Terminals, as well as gathering pipelines in the United States and a crude oil processing facility in Moose Jaw, Saskatchewan.Â
- Marketing: This involves the purchasing, selling, storing, and optimizing of hydrocarbon products.Â
Gibson Energy has a strong presence in the United States, due to the acquisition of the Gateway Terminal in Ingleside, Texas. This terminal is a world-class liquids terminal and export facility with very large crude carrier (VLCC) capabilities and direct pipeline connections to key basins like the Permian and Eagle Ford. The acquisition strengthens Gibson's cash flow with over 95% of the revenue under take-or-pay contracts with high-quality counterparties.Â
Our Values, The Gibson WayÂ
The Gibson Way is how we succeed together. We believe in the power of both 'We' (collectively working together) and "I" (contributing individually) to achieve our shared goals.Â
The 'We & I' play a very important role in our success!Â
- Contribute & Add Value EverydayÂ
- Keep Our Edge & Be ResilientÂ
- Stay Focused & Open-MindedÂ
- Work it Out & Do it TogetherÂ
This is what we are all about and we encourage you to learn more! Click Here:The Gibson Way Â
Still Interested and Don't Meet Every Single Requirement?
We are dedicated to build an authentic and motivating workforce composed of individuals with diverse identities, so if you're excited about this role but your past experience doesn't align perfectly with every skill or education requirement described above, we encourage you to apply anyways. You may be just the right candidate for this or other roles.
For more information, visit www.gibsonenergy.com.