1

Grc Analyst Jobs in Quebec (NOW HIRING)

Supporting and administering SAP GRC Access Control modules, including: Access Risk Analysis (ARA) Access Request Management (ARM) Emergency Access Management (EAM / Firefighter) Conducting SoD risk ...

Supporting and administering SAP GRC Access Control modules, including: Access Risk Analysis (ARA) Access Request Management (ARM) Emergency Access Management (EAM / Firefighter) Conducting SoD risk ...

New

Administrer les solutions SAP GRC Access Control, notamment : ARA (Access Risk Analysis) ARM (Access Request Management) EAM (Emergency Access Management / Firefighter) Effectuer des analyses de ...

Supporting and administering SAP GRC Access Control modules, including: Access Risk Analysis (ARA) Access Request Management (ARM) Emergency Access Management (EAM / Firefighter) Conducting SoD risk ...

New

Supporting and administering SAP GRC Access Control modules, including: Access Risk Analysis (ARA) Access Request Management (ARM) Emergency Access Management (EAM / Firefighter) Conducting SoD risk ...

Administrer les solutions SAP GRC Access Control, notamment : ARA (Access Risk Analysis) ARM (Access Request Management) EAM (Emergency Access Management / Firefighter) Effectuer des analyses de ...

Administrer les solutions SAP GRC Access Control, notamment : ARA (Access Risk Analysis) ARM (Access Request Management) EAM (Emergency Access Management / Firefighter) Effectuer des analyses de ...

New

Administrer les solutions SAP GRC Access Control, notamment : ARA (Access Risk Analysis) ARM (Access Request Management) EAM (Emergency Access Management / Firefighter) Effectuer des analyses de ...

New

The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards.

The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards.

The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards.

The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards.

next page

Showing results 1-20

Grc Analyst information

What are the key skills and qualifications needed to thrive as a GRC analyst?

To thrive as a GRC Analyst, you need a solid understanding of governance, risk management, and compliance frameworks, often complemented by a degree in information security, business, or a related field. Experience with GRC platforms (like RSA Archer, ServiceNow, or LogicManager), and certifications such as CISA, CRISC, or CISSP are highly valued. Strong analytical thinking, attention to detail, effective communication, and collaboration skills set outstanding GRC Analysts apart. These capabilities are vital for ensuring organizations meet regulatory requirements, identify and mitigate risks, and foster a culture of compliance.

Is GRC analyst an entry level job?

A GRC analyst role can be entry-level or require some experience, depending on the organization. Entry-level positions typically focus on basic compliance, risk management, and using tools like GRC software, often requiring relevant certifications or a related degree. More advanced roles may demand several years of experience and specialized knowledge.

Is GRC analyst in high demand?

GRC analysts are in high demand due to increasing focus on cybersecurity, regulatory compliance, and risk management across industries. Organizations seek professionals with skills in risk assessment, policy development, and familiarity with tools like GRC software, making this a growing field for qualified candidates.

What does a GRC analyst do?

GRC Analysts are responsible for monitoring and assessing organizational policies, procedures, and controls to ensure compliance with internal and external regulations. Their daily tasks often include performing risk assessments, maintaining documentation, supporting audits, analyzing data for potential security gaps, and preparing reports for management. They regularly collaborate with IT, legal, and business teams to remediate vulnerabilities and strengthen compliance programs. This dynamic role requires both independent research and cross-departmental communication to help organizations proactively manage risk and regulatory obligations.

What is a GRC analyst?

A GRC (Governance, Risk, and Compliance) Analyst is responsible for ensuring that an organization adheres to regulatory requirements, industry standards, and internal policies. They assess risks, implement compliance programs, and monitor security controls to protect data and systems. Their role often involves working with various departments to identify vulnerabilities, develop risk mitigation strategies, and prepare reports for audits. GRC Analysts play a key role in maintaining regulatory compliance and enhancing an organization's overall security posture.

What job categories do people searching Grc Analyst jobs in Quebec look for? The top searched job categories for Grc Analyst jobs in Quebec are:
Infographic showing various Grc Analyst job openings in Quebec as of August 2026, with employment types broken down into 90% Full Time, 5% Temporary, and 5% Contract. Highlights an 84% In-person, 11% Hybrid, and 5% Remote job distribution.

Full-time

Medical, Retirement, PTO

Posted 18 days ago


Job description

We are banking at another level.

Choosing BDC as your employer means working in a healthy, inclusive, and skilled workplace that puts forward the best conditions to bring together unique teams where employees are empowered to act. It also means being at the centre of ambitious economic and financial projects to see further and to do things differently, to fuel the success of Canadian entrepreneurs.

Choosing BDC as your employer also means:

  • Flexible and competitive benefits, including an Employee Savings and Investment Plan where BDC matches part of your voluntary contributions, a Defined Benefit Pension Plan, a $750 wellness and health care spending account, to name a few

  • In addition to paid vacation each year, five personal days, sick days as necessary, and our offices are closed from December 25 to January 1

  • A hybrid work model that truly balances work and personal life

  • Opportunities for learning, training and development, and much more...

Explore the BDC Way in our Culture Book

POSITION OVERVIEW

BDC is seeking a Tech Lead to join the Risk & Value Office squad in Montreal. This role combines technical leadership, risk expertise, and data-driven delivery to advance InfoSec's ability to monitor and manage its risk landscape. The Tech Lead will guide the design and implementation of GRC engineering capabilities, ensure the quality and consistency of squad deliverables, and drive the adoption of scalable analytics, automation, and reporting solutions. Acting as a key advisor, the role also strengthens technology risk management practices and enables actionable, executive-level insights.

CHALLENGES TO BE MET

Technical Leadership & Squad Enablement
Act as the tech lead for the Risk & Value Office squad, providing guidance on GRC engineering and risk management.
Review and challenge the quality of the squad deliverables to ensure alignment with InfoSec standards and executive expectations.
Coach and mentor squad members on GRC engineering practices and risk management concepts, fostering capability uplift and autonomy.
Drive adoption of best practices in data, automation, and secure development, ensuring consistency across initiatives.
Provide technical guidance in prioritization and backlog refinement, ensuring work is aligned with value, risk reduction, and strategic objectives.

Risk Management & Governance
Lead and contribute to the continuous improvement of the InfoSec technical risk management framework, ensuring strong integration with data-driven insights.
Oversee the identification, assessment, and monitoring of technology and cyber risks, leveraging metrics, analytics, and automation.
Ensure risk outputs, such as KRIs, control effectiveness and audit findings, are consistent, traceable, and defensible.
Provide expert guidance on risk posture, remediation strategies, and prioritization, to support management decision-making.
Lead or support key risk management initiatives, such as the Digital Crown Jewels framework and Cyber Operational Risk Events Management.
Support internal and external audits, ensuring timely completion of remediation actions.
Prepare documentation related to policy, standards, and procedures.

Data-Driven GRC & Engineering
Participate to the design and implementation of data-driven GRC capabilities, including automated data ingestion, transformation, and insight generation.
Define and enforce data architecture and governance practices for security metrics and reporting.
Support the squad in maintaining and developing key security metrics, including risk and control indicators.
Contribute to the development of scalable solutions leveraging tools such as Power BI, Power Platform, SQL, and APIs.
Identify and implement opportunities to automate workflows, controls monitoring, and reporting processes.
Ensure integration across tools and datasets to enable end-to-end visibility of InfoSec risk posture.
Provide technical leadership for the evolution of GRC tools, including asset register modernization.
Identify opportunities, support the design and enhancement of Continuous Control Monitoring (CCM) to provide timely visibility into control performance and identify issues proactively.

Data & Reporting Initiatives
Deliver insights driven by robust data analytics.
Contribute to improving reporting processes and ensuring data reliability.
Support data initiatives from source identification to final reporting.
Present findings and recommendations to managers and stakeholders.

WHAT WE ARE LOOKING FOR


REQUIRED QUALIFICATIONS

Bachelor's degree in computer science, information security, data analytics, or a related field.

At least 8 years of experience in cyber risk, cybersecurity, or GRC, with strong exposure to data-driven approaches and analytics.
Minimum 3 years in a tech lead or senior role, including delivery leadership, output review, and team coaching.
Extensive experience in:

  • Risk analytics, metrics development (KRIs/KPIs), and automated reporting.
  • Driving automation and implementing data solutions in complex environments.

Advanced proficiency in Power BI, Power Platform, SQL, and data integration (APIs).
Strong understanding of data architecture, data governance, and analytics lifecycle.
Experience designing and implementing automated workflows and reporting solutions.
Experience with Continuous Control Monitoring (CCM) and control automation concepts.

Strong knowledge of technology risk management frameworks (e.g., NIST, ISO 27001, COBIT).
Experience applying risk frameworks, audit practices, and control assessments.

Strong ability to review, challenge, and enhance the quality of deliverables.
Demonstrated leadership in coaching, mentoring, and developing team capabilities.
Excellent stakeholder management skills, with the ability to operate in complex, high-visibility environments.
Ability to translate technical and risk concepts into a clear business language.
Strong analytical thinking, problem-solving, and decision-making skills.
Highly organized, detail-oriented, and able to manage multiple priorities effectively.

PREFERRED QUALIFICATIONS

Financial services or regulated environments.
Relevant certifications (e.g., CRISC, CISM, FAIR).
Knowledge on OSFI.


#INDHP

Proudly one of Canada's Top 100 Employers and one of Canada's Best Diversity Employers, we are committed to fostering a diverse, equitable, inclusive and accessible environment where all employees can thrive and feel empowered to bring their whole selves to work. If you require an accommodation to complete your application, please do not hesitate to contact us at accessibility@bdc.ca.

While we appreciate all applications, we advise that only the candidates selected to participate in the recruitment process will be contacted.