1

Grc Risk Analyst Jobs in Ontario (NOW HIRING)

The GRC analyst will be responsible for leading the day-to-day cyber compliance, data governance, and cyber risk management functions. * The role will include responsibility for defining, creating ...

Define enterprise GRC target architecture and solution blueprints (data models, taxonomy, control ... Knowledge of FAIR risk quantification, BI/analytics (Power BI/Tableau), continuous control ...

... Risk Analytics. * Perform hands-on configuration/customization across enterprise GRC technologies ... including custom objects, forms, workflows, reporting. Technical Implementation and Integration

Senior SAP GRC Security Consultant (SAP S/4HANA, SAP Security, Identity Access Governance) Location ... Access Risk Analysis (ARA) * Emergency Access Management (EAM) * Business Role Management (BRM ...

Those in governance, risk, controls and compliance at PwC will be responsible for confirming ... Use a broad range of analytics tools, technology, digital solutions, and techniques to extract ...

Specialize in ServiceNow Governance, Risk, and Compliance (GRC) or ServiceNow SecOps product suite ... Excellent verbal/written communication, problem solving, analytical, and independent judgment ...

Information Security Analyst

Mississauga, ON · On-site

CA$66K - CA$80K/yr

Contribute to key GRC initiatives, including risk maturity, audit readiness, vendor compliance, and ... Strong analytical and critical thinking skills with the ability to evaluate controls, identify gaps ...

Information Security Analyst

London, ON · On-site

CA$66K - CA$80K/yr

Contribute to key GRC initiatives, including risk maturity, audit readiness, vendor compliance, and ... Strong analytical and critical thinking skills with the ability to evaluate controls, identify gaps ...

... product, analysts, and Kroll to source insight and ensure technical accuracy. * Turn complex GRC and S&I topics into clear, compelling narratives that resonate with the people who own risk ...

next page

Showing results 1-20

Grc Risk Analyst information

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What job categories do people searching Grc Risk Analyst jobs in Ontario look for?

The top searched job categories for Grc Risk Analyst jobs in Ontario are:

What cities in Ontario are hiring for Grc Risk Analyst jobs?

Cities in Ontario with the most Grc Risk Analyst job openings:

Infographic showing various Grc Risk Analyst job openings in Ontario as of August 2026, with employment types broken down into 1% As Needed, 79% Full Time, 18% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution.

Senior Analyst - Cybersecurity (Risk Management & Compliance)

Hybrid


Sysco
Food and Beverage Wholesalers • 10K+ employees

7.6

Company rating: 7.6 out of 10

Based on 324 frontline employees who took The Breakroom Quiz

120th of 366 rated logistics

People enjoy working here

Good employer

Respectful managers


Full-time

Re-posted 23 days ago


Job description

JOB DESCRIPTION

Senior Analyst - Cybersecurity (Risk Management & Compliance)

Location: Krakow, Poland (Hybrid)

Type: Full-time employment

Shift: [2:00 PM-10:00 PM CET, 7:00 AM-3:00 PM CDT] with flexibility

Job Summary

This position is with the Cyber Governance Compliance & Risk Management Team at Sysco to manage and support the Cyber Risk Management and Compliance areas. You'll work closely with the compliance team to hone and deliver our GRC program while also working alongside Technology and Business teams to help integrate security best practices into their processes to ensure consistent adherence to controls. Additionally, you will assist in developing cyber security requirements, conducting cyber risk assessments, evaluating security services and technologies, and reviewing and documenting information security policies and procedures.

Responsibilities

  • This position is an experienced level, hands-on Senior Analyst Cyber Risk Management & Compliance, performing IT security functions and maintaining systems, while providing technical guidance to the team
  • The GRC analyst will be responsible for leading the day-to-day cyber compliance, data governance, and cyber risk management functions.
  • The role will include responsibility for defining, creating, and managing cyber and organizational policies and standards in support of legal and regulatory compliance including PCI, NACHA as well as general cyber and organizational information security practices.
  • The Senior analyst will participate in process improvements to the RSA Archer Platform
  • Collaborate with stakeholders, business analysts, process leaders, and architects in interpreting requirements and configuring them into software platforms.
  • Execute cybersecurity risk assessment and control attestation processes in GRC.
  • Participate in the development and implementation of the system-wide risk management function of the information security program to ensure cyber security risks are identified and monitored.
  • Participate in the system-wide information security compliance program, ensuring cyber activities, processes, and procedures meet defined requirements, policies and regulations.
  • Monitor, track and manage Cyber Findings, Exceptions and Issue tracking along with reporting them to respective teams.
  • Candidate should be able to provide GRC guidance and interpretation of rules, regulations, risks, and best practices.
  • Ability to trouble shoot, identify, analyze and mitigate GRC related risks in existing processes, policies and procedures.
  • Review control effectiveness evidence to assess the quality and effectiveness of the implemented controls.
  • Document residual risk.
  • Prepare and communicate operational metrics and trend analysis for the Cybersecurity Leadership Team

Qualifications

  • Bachelor's and Seven (7) years or more of related experience
  • 5+ years of experience in GRC, risk management and/or policy management
  • 5 years of experience in risk assessment, IT policy, compliance requirements
  • 5 years of experience with RSA Archer or other GRC Tools/Platform.
  • Strong understanding of cybersecurity frameworks, regulatory compliance standards, and enterprise risk management practices.
  • Excellent communication skills in English (B2+ or higher) and ability to collaborate across functions and geographies.

Why Join Us

  • Be part of a global cybersecurity team protecting a dynamic enterprise environment.
  • Opportunity to work with modern security technologies and drive tool innovation.
  • Collaborative culture with professional development opportunities.
  • Hybrid work model with our Krakow office as the primary location.


What Sysco employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom