The Tech Lead will guide the design and implementation of GRC engineering capabilities, ensure the quality and consistency of squad deliverables, and drive the adoption of scalable analytics ...
The Tech Lead will guide the design and implementation of GRC engineering capabilities, ensure the quality and consistency of squad deliverables, and drive the adoption of scalable analytics ...
ABOUT YOUR ROLE As a Senior Analyst, Security GRC & Crisis Management , you will report to the Manager, Security GRC and be part of the broader Information Security group. You will contribute to PSP ...
ABOUT YOUR ROLE As a Senior Analyst, Security GRC & Crisis Management , you will report to the Manager, Security GRC and be part of the broader Information Security group. You will contribute to PSP ...
Supporting and administering SAP GRC Access Control modules, including: Access Risk Analysis (ARA) Access Request Management (ARM) Emergency Access Management (EAM / Firefighter) Conducting SoD risk ...
Supporting and administering SAP GRC Access Control modules, including: Access Risk Analysis (ARA) Access Request Management (ARM) Emergency Access Management (EAM / Firefighter) Conducting SoD risk ...
Supporting and administering SAP GRC Access Control modules, including: Access Risk Analysis (ARA) Access Request Management (ARM) Emergency Access Management (EAM / Firefighter) Conducting SoD risk ...
New
Supporting and administering SAP GRC Access Control modules, including: Access Risk Analysis (ARA) Access Request Management (ARM) Emergency Access Management (EAM / Firefighter) Conducting SoD risk ...
New
Administrer les solutions SAP GRC Access Control, notamment : ARA (Access Risk Analysis) ARM (Access Request Management) EAM (Emergency Access Management / Firefighter) Effectuer des analyses de ...
Administrer les solutions SAP GRC Access Control, notamment : ARA (Access Risk Analysis) ARM (Access Request Management) EAM (Emergency Access Management / Firefighter) Effectuer des analyses de ...
SAP Security Specialist
Montreal, QC · Hybrid
Supporting and administering SAP GRC Access Control modules, including: Access Risk Analysis (ARA) Access Request Management (ARM) Emergency Access Management (EAM / Firefighter) Conducting SoD risk ...
New
SAP Security Specialist
Montreal, QC · Hybrid
Supporting and administering SAP GRC Access Control modules, including: Access Risk Analysis (ARA) Access Request Management (ARM) Emergency Access Management (EAM / Firefighter) Conducting SoD risk ...
New
Supporting and administering SAP GRC Access Control modules, including: Access Risk Analysis (ARA) Access Request Management (ARM) Emergency Access Management (EAM / Firefighter) Conducting SoD risk ...
Supporting and administering SAP GRC Access Control modules, including: Access Risk Analysis (ARA) Access Request Management (ARM) Emergency Access Management (EAM / Firefighter) Conducting SoD risk ...
Soutenir la configuration, la surveillance et l'exploitation des composantes SAP GRC Access Control ... Excellentes capacités d'analyse et de résolution de problèmes. * Capacité à communiquer ...
Soutenir la configuration, la surveillance et l'exploitation des composantes SAP GRC Access Control ... Excellentes capacités d'analyse et de résolution de problèmes. * Capacité à communiquer ...
Administrer les solutions SAP GRC Access Control, notamment : ARA (Access Risk Analysis) ARM (Access Request Management) EAM (Emergency Access Management / Firefighter) Effectuer des analyses de ...
Administrer les solutions SAP GRC Access Control, notamment : ARA (Access Risk Analysis) ARM (Access Request Management) EAM (Emergency Access Management / Firefighter) Effectuer des analyses de ...
Soutenir la configuration, la surveillance et l'exploitation des composantes SAP GRC Access Control ... Compétences comportementales Excellentes capacités d'analyse et de résolution de problèmes.
Soutenir la configuration, la surveillance et l'exploitation des composantes SAP GRC Access Control ... Compétences comportementales Excellentes capacités d'analyse et de résolution de problèmes.
Soutenir la configuration, la surveillance et l'exploitation des composantes SAP GRC Access Control ... Excellentes capacités d'analyse et de résolution de problèmes. * Capacité à communiquer ...
Soutenir la configuration, la surveillance et l'exploitation des composantes SAP GRC Access Control ... Excellentes capacités d'analyse et de résolution de problèmes. * Capacité à communiquer ...
Soutenir la configuration, la surveillance et l'exploitation des composantes SAP GRC Access Control ... Excellentes capacités d'analyse et de résolution de problèmes. * Capacité à communiquer ...
New
Soutenir la configuration, la surveillance et l'exploitation des composantes SAP GRC Access Control ... Excellentes capacités d'analyse et de résolution de problèmes. * Capacité à communiquer ...
New
Spécialiste en sécurité SAP
Montreal, QC · On-site
Administrer les solutions SAP GRC Access Control, notamment : ARA (Access Risk Analysis) ARM (Access Request Management) EAM (Emergency Access Management / Firefighter) Effectuer des analyses de ...
New
Spécialiste en sécurité SAP
Montreal, QC · On-site
Administrer les solutions SAP GRC Access Control, notamment : ARA (Access Risk Analysis) ARM (Access Request Management) EAM (Emergency Access Management / Firefighter) Effectuer des analyses de ...
New
Administrer les solutions SAP GRC Access Control, notamment : ARA (Access Risk Analysis) ARM (Access Request Management) EAM (Emergency Access Management / Firefighter) Effectuer des analyses de ...
New
Administrer les solutions SAP GRC Access Control, notamment : ARA (Access Risk Analysis) ARM (Access Request Management) EAM (Emergency Access Management / Firefighter) Effectuer des analyses de ...
New
Soutenir la configuration, la surveillance et l'exploitation des composantes SAP GRC Access Control ... Excellentes capacités d'analyse et de résolution de problèmes. * Capacité à communiquer ...
New
Soutenir la configuration, la surveillance et l'exploitation des composantes SAP GRC Access Control ... Excellentes capacités d'analyse et de résolution de problèmes. * Capacité à communiquer ...
New
Lead GRC system implementation in 6 months to migrate manual processes and embed automated ... Natural analytical mind and strong ability to think in terms of process. * Professional proficiency ...
Lead GRC system implementation in 6 months to migrate manual processes and embed automated ... Natural analytical mind and strong ability to think in terms of process. * Professional proficiency ...
The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards.
The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards.
The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards.
The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards.
Cyber Security Risk Analyst
Montreal, QC · On-site
The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards.
Cyber Security Risk Analyst
Montreal, QC · On-site
The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards.
Cyber Security Risk Analyst
Becancour, QC · On-site
The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards.
Cyber Security Risk Analyst
Becancour, QC · On-site
The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards.
Grc Analyst information
What are the key skills and qualifications needed to thrive as a GRC analyst?
To thrive as a GRC Analyst, you need a solid understanding of governance, risk management, and compliance frameworks, often complemented by a degree in information security, business, or a related field. Experience with GRC platforms (like RSA Archer, ServiceNow, or LogicManager), and certifications such as CISA, CRISC, or CISSP are highly valued. Strong analytical thinking, attention to detail, effective communication, and collaboration skills set outstanding GRC Analysts apart. These capabilities are vital for ensuring organizations meet regulatory requirements, identify and mitigate risks, and foster a culture of compliance.
Is GRC analyst an entry level job?
Is GRC analyst in high demand?
What does a GRC analyst do?
GRC Analysts are responsible for monitoring and assessing organizational policies, procedures, and controls to ensure compliance with internal and external regulations. Their daily tasks often include performing risk assessments, maintaining documentation, supporting audits, analyzing data for potential security gaps, and preparing reports for management. They regularly collaborate with IT, legal, and business teams to remediate vulnerabilities and strengthen compliance programs. This dynamic role requires both independent research and cross-departmental communication to help organizations proactively manage risk and regulatory obligations.
What is a GRC analyst?
A GRC (Governance, Risk, and Compliance) Analyst is responsible for ensuring that an organization adheres to regulatory requirements, industry standards, and internal policies. They assess risks, implement compliance programs, and monitor security controls to protect data and systems. Their role often involves working with various departments to identify vulnerabilities, develop risk mitigation strategies, and prepare reports for audits. GRC Analysts play a key role in maintaining regulatory compliance and enhancing an organization's overall security posture.

Full-time
Medical, Retirement, PTO
Posted 18 days ago
Job description
We are banking at another level.
Choosing BDC as your employer means working in a healthy, inclusive, and skilled workplace that puts forward the best conditions to bring together unique teams where employees are empowered to act. It also means being at the centre of ambitious economic and financial projects to see further and to do things differently, to fuel the success of Canadian entrepreneurs.
Choosing BDC as your employer also means:
Flexible and competitive benefits, including an Employee Savings and Investment Plan where BDC matches part of your voluntary contributions, a Defined Benefit Pension Plan, a $750 wellness and health care spending account, to name a few
In addition to paid vacation each year, five personal days, sick days as necessary, and our offices are closed from December 25 to January 1
A hybrid work model that truly balances work and personal life
Opportunities for learning, training and development, and much more...
Explore the BDC Way in our Culture Book
POSITION OVERVIEW
BDC is seeking a Tech Lead to join the Risk & Value Office squad in Montreal. This role combines technical leadership, risk expertise, and data-driven delivery to advance InfoSec's ability to monitor and manage its risk landscape. The Tech Lead will guide the design and implementation of GRC engineering capabilities, ensure the quality and consistency of squad deliverables, and drive the adoption of scalable analytics, automation, and reporting solutions. Acting as a key advisor, the role also strengthens technology risk management practices and enables actionable, executive-level insights.
CHALLENGES TO BE MET
Technical Leadership & Squad Enablement
Act as the tech lead for the Risk & Value Office squad, providing guidance on GRC engineering and risk management.
Review and challenge the quality of the squad deliverables to ensure alignment with InfoSec standards and executive expectations.
Coach and mentor squad members on GRC engineering practices and risk management concepts, fostering capability uplift and autonomy.
Drive adoption of best practices in data, automation, and secure development, ensuring consistency across initiatives.
Provide technical guidance in prioritization and backlog refinement, ensuring work is aligned with value, risk reduction, and strategic objectives.
Risk Management & Governance
Lead and contribute to the continuous improvement of the InfoSec technical risk management framework, ensuring strong integration with data-driven insights.
Oversee the identification, assessment, and monitoring of technology and cyber risks, leveraging metrics, analytics, and automation.
Ensure risk outputs, such as KRIs, control effectiveness and audit findings, are consistent, traceable, and defensible.
Provide expert guidance on risk posture, remediation strategies, and prioritization, to support management decision-making.
Lead or support key risk management initiatives, such as the Digital Crown Jewels framework and Cyber Operational Risk Events Management.
Support internal and external audits, ensuring timely completion of remediation actions.
Prepare documentation related to policy, standards, and procedures.
Data-Driven GRC & Engineering
Participate to the design and implementation of data-driven GRC capabilities, including automated data ingestion, transformation, and insight generation.
Define and enforce data architecture and governance practices for security metrics and reporting.
Support the squad in maintaining and developing key security metrics, including risk and control indicators.
Contribute to the development of scalable solutions leveraging tools such as Power BI, Power Platform, SQL, and APIs.
Identify and implement opportunities to automate workflows, controls monitoring, and reporting processes.
Ensure integration across tools and datasets to enable end-to-end visibility of InfoSec risk posture.
Provide technical leadership for the evolution of GRC tools, including asset register modernization.
Identify opportunities, support the design and enhancement of Continuous Control Monitoring (CCM) to provide timely visibility into control performance and identify issues proactively.
Data & Reporting Initiatives
Deliver insights driven by robust data analytics.
Contribute to improving reporting processes and ensuring data reliability.
Support data initiatives from source identification to final reporting.
Present findings and recommendations to managers and stakeholders.
WHAT WE ARE LOOKING FOR
REQUIRED QUALIFICATIONS
Bachelor's degree in computer science, information security, data analytics, or a related field.
At least 8 years of experience in cyber risk, cybersecurity, or GRC, with strong exposure to data-driven approaches and analytics.
Minimum 3 years in a tech lead or senior role, including delivery leadership, output review, and team coaching.
Extensive experience in:
- Risk analytics, metrics development (KRIs/KPIs), and automated reporting.
- Driving automation and implementing data solutions in complex environments.
Advanced proficiency in Power BI, Power Platform, SQL, and data integration (APIs).
Strong understanding of data architecture, data governance, and analytics lifecycle.
Experience designing and implementing automated workflows and reporting solutions.
Experience with Continuous Control Monitoring (CCM) and control automation concepts.
Strong knowledge of technology risk management frameworks (e.g., NIST, ISO 27001, COBIT).
Experience applying risk frameworks, audit practices, and control assessments.
Strong ability to review, challenge, and enhance the quality of deliverables.
Demonstrated leadership in coaching, mentoring, and developing team capabilities.
Excellent stakeholder management skills, with the ability to operate in complex, high-visibility environments.
Ability to translate technical and risk concepts into a clear business language.
Strong analytical thinking, problem-solving, and decision-making skills.
Highly organized, detail-oriented, and able to manage multiple priorities effectively.
PREFERRED QUALIFICATIONS
Financial services or regulated environments.
Relevant certifications (e.g., CRISC, CISM, FAIR).
Knowledge on OSFI.
#INDHP
Proudly one of Canada's Top 100 Employers and one of Canada's Best Diversity Employers, we are committed to fostering a diverse, equitable, inclusive and accessible environment where all employees can thrive and feel empowered to bring their whole selves to work. If you require an accommodation to complete your application, please do not hesitate to contact us at accessibility@bdc.ca.
While we appreciate all applications, we advise that only the candidates selected to participate in the recruitment process will be contacted.