Reporting to the Cybersecurity Governance, Risk & Compliance Manager, this role supports CN's cybersecurity governance objectives by translating security, risk, and compliance requirements into ...
Reporting to the Cybersecurity Governance, Risk & Compliance Manager, this role supports CN's cybersecurity governance objectives by translating security, risk, and compliance requirements into ...
Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards. * Solid understanding of security principles, including security controls, threat modeling, vulnerability ...
Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards. * Solid understanding of security principles, including security controls, threat modeling, vulnerability ...
Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards. * Solid understanding of security principles, including security controls, threat modeling, vulnerability ...
Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards. * Solid understanding of security principles, including security controls, threat modeling, vulnerability ...
Cyber Security Risk Analyst
Montreal, QC · On-site
Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards. * Solid understanding of security principles, including security controls, threat modeling, vulnerability ...
Cyber Security Risk Analyst
Montreal, QC · On-site
Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards. * Solid understanding of security principles, including security controls, threat modeling, vulnerability ...
Cyber Security Risk Analyst
Becancour, QC · On-site
Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards. * Solid understanding of security principles, including security controls, threat modeling, vulnerability ...
Cyber Security Risk Analyst
Becancour, QC · On-site
Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards. * Solid understanding of security principles, including security controls, threat modeling, vulnerability ...
Act as a key contact for model owners, validators, business lines, technology teams, risk partners, compliance and internal audit on model governance oversight matters. * Support change management ...
New
Act as a key contact for model owners, validators, business lines, technology teams, risk partners, compliance and internal audit on model governance oversight matters. * Support change management ...
New
Act as a key contact for model owners, validators, business lines, technology teams, risk partners, compliance and internal audit on model governance oversight matters. * Support change management ...
New
Act as a key contact for model owners, validators, business lines, technology teams, risk partners, compliance and internal audit on model governance oversight matters. * Support change management ...
New
Act as a key contact for model owners, validators, business lines, technology teams, risk partners, compliance and internal audit on model governance oversight matters. * Support change management ...
New
Act as a key contact for model owners, validators, business lines, technology teams, risk partners, compliance and internal audit on model governance oversight matters. * Support change management ...
New
Act as a key contact for model owners, validators, business lines, technology teams, risk partners, compliance and internal audit on model governance oversight matters. * Support change management ...
Act as a key contact for model owners, validators, business lines, technology teams, risk partners, compliance and internal audit on model governance oversight matters. * Support change management ...
Act as a key contact for model owners, validators, business lines, technology teams, risk partners, compliance and internal audit on model governance oversight matters. Support change management and ...
Act as a key contact for model owners, validators, business lines, technology teams, risk partners, compliance and internal audit on model governance oversight matters. Support change management and ...
... GRC (Governance, Risk & Compliance) & Aviation Partnership, as part of a small team of cybersecurity professionals. What your day would be like * Supporting aviation cybersecurity initiatives ...
... GRC (Governance, Risk & Compliance) & Aviation Partnership, as part of a small team of cybersecurity professionals. What your day would be like * Supporting aviation cybersecurity initiatives ...
... GRC (Governance, Risk & Compliance) & Aviation Partnership, as part of a small team of cybersecurity professionals. What your day would be like * Supporting aviation cybersecurity initiatives ...
... GRC (Governance, Risk & Compliance) & Aviation Partnership, as part of a small team of cybersecurity professionals. What your day would be like * Supporting aviation cybersecurity initiatives ...
Collaborate with model risk governance, model validation, business lines, technology, data, compliance, legal and internal audit teams to promote a consistent interpretation and application of model ...
Collaborate with model risk governance, model validation, business lines, technology, data, compliance, legal and internal audit teams to promote a consistent interpretation and application of model ...
Collaborate with model risk governance, model validation, business lines, technology, data, compliance, legal and internal audit teams to promote a consistent interpretation and application of model ...
New
Collaborate with model risk governance, model validation, business lines, technology, data, compliance, legal and internal audit teams to promote a consistent interpretation and application of model ...
New
Collaborate with model risk governance, model validation, business lines, technology, data, compliance, legal and internal audit teams to promote a consistent interpretation and application of model ...
New
Collaborate with model risk governance, model validation, business lines, technology, data, compliance, legal and internal audit teams to promote a consistent interpretation and application of model ...
New
Collaborate with model risk governance, model validation, business lines, technology, data, compliance, legal and internal audit teams to promote a consistent interpretation and application of model ...
Collaborate with model risk governance, model validation, business lines, technology, data, compliance, legal and internal audit teams to promote a consistent interpretation and application of model ...
Collaborate with model risk governance, model validation, business lines, technology, data, compliance, legal and internal audit teams to promote a consistent interpretation and application of model ...
New
Collaborate with model risk governance, model validation, business lines, technology, data, compliance, legal and internal audit teams to promote a consistent interpretation and application of model ...
New
We support highly regulated clients in designing, assessing and enhancing governance, risk management and compliance frameworks. This role offers the opportunity to lead complex engagements, develop ...
We support highly regulated clients in designing, assessing and enhancing governance, risk management and compliance frameworks. This role offers the opportunity to lead complex engagements, develop ...
We support highly regulated clients in designing, assessing and enhancing governance, risk management and compliance frameworks. This role offers the opportunity to lead complex engagements, develop ...
We support highly regulated clients in designing, assessing and enhancing governance, risk management and compliance frameworks. This role offers the opportunity to lead complex engagements, develop ...
Security Governance, Risk & Compliance * Support the maintenance and evolution of PSP's security governance framework, policies, standards, and procedures in alignment with ISO 27001, NIST CSF, and ...
Security Governance, Risk & Compliance * Support the maintenance and evolution of PSP's security governance framework, policies, standards, and procedures in alignment with ISO 27001, NIST CSF, and ...
Governance Risk Compliance information
See Quebec salary details
$35K - $48K
3% of jobs
$48K - $61K
6% of jobs
$61K - $74K
11% of jobs
$79.3K is the 25th percentile. Wages below this are outliers.
$74K - $87K
12% of jobs
$87K - $100K
17% of jobs
The median wage is $101K / yr.
$100K - $113K
14% of jobs
$113K - $126K
11% of jobs
$128K is the 75th percentile. Wages above this are outliers.
$126K - $139K
11% of jobs
$139K - $152K
5% of jobs
$152K - $165K
6% of jobs
$165K - $178K
4% of jobs
$35K
$110.9K
$178K
How much do governance risk compliance jobs pay per year?
What are jobs in governance risk compliance?
Governance risk compliance (GRC) is a method for managing and strategizing an organization's regulations regarding governance, financial or physical risk, and regulatory compliance. It aligns the IT aspects with business objectives and works to improve the efficiency of a company. There are GRC consultants and GRC analysts who provide an assessment of a business’s GRC, identify risks, analyze the data, develop policies to benefit the workplace, and consult on the best choice of action. Your duties may involve optimizing GRC systems, implementing tactics to lower risk, providing internal audits, assisting with cybersecurity, creating routine reports, and ensuring regulatory compliance.
What is the work of governance risk compliance?
What is governance risk compliance?
How does a governance risk compliance professional typically collaborate with other departments within an organization?
What is the difference between Governance Risk Compliance vs Risk Analyst?
| Aspect | Governance Risk Compliance | Risk Analyst |
|---|---|---|
| Certifications | CRISC, CISA, CISSP | CFA, FRM, CRISC |
| Work Environment | Corporate, regulated industries | Financial, consulting firms |
| Employer & Industry Usage | Financial institutions, healthcare, government | Banking, investment firms, insurance |
Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing enterprise-wide risks. Risk Analysts primarily assess specific financial or operational risks through data analysis. While both roles involve risk management, Governance Risk Compliance has a broader scope related to organizational compliance and governance frameworks, whereas Risk Analysts concentrate on analyzing and quantifying particular risks.
What are the key skills and qualifications needed to thrive as a governance risk compliance professional?

Full-time
Posted 11 days ago
Canadian National Railway rating
7.5
Based on 49 frontline employees who took The Breakroom Quiz
136th of 360 rated logistics
Job description
Specialist Information Security
At CN, everyday brings new and exciting challenges. You can expect an interesting environment where you're part of making sure our business is running optimally and safely-helping keep the economy on track. We provide the kind of paid training and opportunities that long-term careers are built on and we recognize hard workers who strive to make a difference. You will be able to thrive in our close-knit, safety-focused culture working together as ONE TEAM. The careers we offer are meaningful because the work we do matters. Join us!
Job Summary
CN is looking for a Cybersecurity GRC (Governance, Risk & Compliance) specialist to help sustain and grow our Cybersecurity Governance team.
Reporting to the Cybersecurity Governance, Risk & Compliance Manager, this role supports CN's cybersecurity governance objectives by translating security, risk, and compliance requirements into practical processes, evidence, reporting, and guidance for I&T and business stakeholders, with a primary focus on maintaining, supporting, and operating the CN IS Management System.
Key Responsibilities
Maintain, support, and operate CN's Cybersecurity GRC framework, including information security classification, risk management processes, security-related policies, dissemination activities, and ongoing improvements to reflect business needs.
Communicate and support security recommendations that meet business objectives in a proactive and pragmatic manner, leveraging ServiceNow workflows and maintaining appropriate engagement with clients to support successful outcomes.
Support control testing, documentation, and maintenance activities to help ensure security controls remain adequate, effective, and aligned with regulatory and cybersecurity requirements.
Collaborate with the compliance team to ensure controls and compliance metrics are properly integrated into dashboards and reports that support overall metrics and KPIs.
Track cybersecurity issues, risks, and remediation actions in the ServiceNow Integrated Risk Management (IRM) module, including follow-up on risk assessments, security testing outcomes, and related business impacts.
Provide guidance during the assessment or review of new IT solutions and new or existing technologies to maintain alignment with regulatory requirements, such as Sarbanes-Oxley, PCI, and SWIFT, and security requirements using the ServiceNow Third Party Risk Management workflow.
Interact with other cybersecurity teams and I&T stakeholders to understand, apply, and support the enforcement of security requirements.
Requirements
Experience
Knowledge of CN IT operations and business units is an asset.
3+ years of experience in cybersecurity, compliance, IT audit, or a related role.
Practical experience with KPIs/KRIs
Previous experience in risk management is an asset
Experience with a GRC tool is an asset.
Education/Certification/Designation
Bachelor's degree in an IT discipline or a related field -or- equivalent work experience
Cybersecurity certifications such as Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), or other related certifications are an asset.
Technical Skills/Knowledge
Knowledge of cybersecurity risk management practices
Cybersecurity governance and compliance frameworks
Knowledge of industry standards and frameworks, including the ISO/IEC 27000 series, ISF, NIST Special Publications, risk management methodologies, and security evaluation methodologies.
Understanding of security and privacy regulations and legislative compliance requirements, such as the Sarbanes-Oxley Act, PCI DSS, and PIPEDA.
Knowledge of ServiceNow, including its landscape & workflows
General Skills and Competencies
Integrity with a high ethical standard
Client-focused mindset with the ability to provide practical guidance to business and I&T stakeholders.
Effective communication and interaction with others
Teamwork and collaboration to achieve common goals.
Flexibility to manage multiple assignments effectively and adapt to changing priorities.
About CN
CN is a world-class transportation leader and trade-enabler. Essential to the economy, to the customers, and to the communities it serves, CN safely transports more than 300 million tons of natural resources, manufactured products, and finished goods throughout North America every year. As the only railroad connecting Canada's Eastern and Western coasts with the Southern tip of the U.S. through a 19,500 mile rail network, CN and its affiliates have been contributing to community prosperity and sustainable trade since 1919. CN is committed to programs supporting social responsibility and environmental stewardship. At CN, we work as ONE TEAM, focused on safety, sustainability and our customers, providing operational and supply chain excellence to deliver results.
What Canadian National Railway employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Canadian National Railway
Sourced by ZipRecruiter
Industry
Rail transportation
Company size
10,000+ Employees
Headquarters location
West Montreal, QC, CA