1

Grc Risk Analyst Jobs in Ontario (NOW HIRING)

This role is responsible to support all aspects of our Governance Risk and Compliance ( GRC ... Strong analytical skills to evaluate and assess the effectiveness of existing control procedures ...

This role is responsible to support all aspects of our Governance Risk and Compliance ( GRC ... Strong analytical skills to evaluate and assess the effectiveness of existing control procedures ...

This role is responsible to support all aspects of our Governance Risk and Compliance ( GRC ... Strong analytical skills to evaluate and assess the effectiveness of existing control procedures ...

This role is responsible to support all aspects of our Governance Risk and Compliance ( GRC ... Strong analytical skills to evaluate and assess the effectiveness of existing control procedures ...

Managing cyber risk using GRC platforms. * Developing KRIs anddetermininghow to measure and report on KRIs. * Collaborating with key client business stakeholders tofacilitatecyber risk analysis and ...

Acting as the primary liaison with Internal Audit (IA), Governance, Risk & Compliance (GRC ... Mentorship & Process Improvement Provide guidance to junior governance analysts, standardize ...

Acting as the primary liaison with Internal Audit (IA), Governance, Risk & Compliance (GRC ... Mentorship & Process Improvement Provide guidance to junior governance analysts, standardize ...

Lead privacy risk assessments for complex systems, cloud platforms, AI solutions, and analytics ... Mentor privacy analysts, GRC professionals, and security architects. * Communicate privacy risks ...

Showing results 41-60

Grc Risk Analyst information

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.
What are popular job titles related to Grc Risk Analyst jobs in Ontario? For Grc Risk Analyst jobs in Ontario, the most frequently searched job titles are:
What job categories do people searching Grc Risk Analyst jobs in Ontario look for? The top searched job categories for Grc Risk Analyst jobs in Ontario are:
What cities in Ontario are hiring for Grc Risk Analyst jobs? Cities in Ontario with the most Grc Risk Analyst job openings:
Infographic showing various Grc Risk Analyst job openings in Ontario as of August 2026, with employment types broken down into 1% As Needed, 79% Full Time, 18% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution.

Senior Cybersecurity GRC Analyst

Rivercity Recruiting and HR

Toronto, ON โ€ข On-site

Full-time

Medical, Dental

Posted 5 days ago


Job description

CareRx is looking for an experienced Senior Cybersecurity Governance & Compliance Analyst for a 3 month contract, reporting to the Director, Cybersecurity, to join our team in a highly regulated healthcare environment where protecting sensitive patient and prescription data is critical to our mission. As a senior member of the Cybersecurity team, you will support CareRx's cybersecurity governance program through PCI DSS readiness, enterprise risk management, policy development, and compliance initiatives that strengthen the organization's overall cybersecurity posture. Working closely with business and technology stakeholders, you will help mature CareRx's governance and compliance capabilities.

You should be able to work in a fast-paced and collaborative environment, with the ability to be nimble, multi-task, and problem solve. You take initiative, excel at strategic planning, and can handle multiple initiatives in parallel. The role is expected to grow in scope and responsibility as the cybersecurity program continues to mature, with measurable impact across risk reduction, detection quality, and incident readiness.

Why you should join CareRxย 

Collaborative Team:ย Work with colleagues who share a passion for shaping the future of senior care.ย 

Make a Real Impact: Feel fulfilled knowing your work directly benefits others within the communities we serve.ย 

Flexible Benefits: For eligible roles, enjoy flexible medical and dental coverage that fits your needs.ย 

Defined Work Schedule: Offers a healthy work-life balance with predictable hours.ย 

Focus on Care: Work in an environment where your clinicalย expertiseย takes priority without the demands of retail pharmacy.ย 

Supportive Culture: Be part of a respectful, inclusive workplace where collaboration,ย connectionย and shared purpose drive everything we do.ย 

Stability and Growth: Join a well-established Canadian company withย a strong foundationย for job security and opportunities to grow your career.ย 

Appreciation in Action: We recognizeย great workย through peer-nominated awards, team shout-outsย and everyday moments of appreciation.ย 

Celebrations and Community: From cultural events to team socials and holiday fun, weย make timeย to connect,ย celebrateย and enjoy the moments that bring us together.ย 

Role Accountabilities:

  • Lead activities supporting CareRx's PCI DSS readiness program by assessing business processes, documenting control gaps, and developing risk-based remediation recommendations.
  • Assess payment workflows, security controls, supporting documentation, and operational processes to identify PCI DSS compliance gaps and opportunities for improvement.
  • Partner with business and technology stakeholders to document current-state processes, validate requirements, and support PCI DSS readiness initiatives.
  • Develop executive and business level reports on remediation recommendations to support PCI DSS readiness initiatives.
  • Develop practical, risk-based remediation recommendations and work with stakeholders to prioritize activities that improve PCI DSS readiness and overall cybersecurity maturity.
  • Monitor remediation initiatives and provide regular reporting on compliance progress, cybersecurity risks, and outstanding actions.
  • Develop, maintain, and continuously improve the enterprise cybersecurity risk register by identifying, documenting, assessing, and tracking cybersecurity risks.
  • Conduct cybersecurity risk assessments and collaborate with stakeholders to evaluate organizational risk and recommend practical mitigation strategies.
  • Develop and maintain cybersecurity policies, standards, procedures, and governance documentation aligned with industry best practices and regulatory requirements.
  • Monitor compliance with cybersecurity policies, standards, and applicable regulatory requirements.
  • Support internal and external compliance activities through evidence collection, documentation, control validation, and remediation tracking.
  • Support third-party risk management activities, including vendor security assessments, security due diligence, and remediation tracking.
  • Develop governance metrics, Key Performance Indicators (KPIs), and Key Risk Indicators (KRIs) to measure program effectiveness and support executive reporting.
  • Participate in cybersecurity assessments, governance reviews, and continuous improvement initiatives.
  • Stay current on emerging cybersecurity threats, governance frameworks, regulatory requirements, and industry best practices.
  • Perform other related duties as assigned.

What you will bring to the team:

  • 5+ years of professional experience in cybersecurity governance, risk management, cybersecurity compliance, PCI Readiness or a related cybersecurity discipline.
  • Demonstrated experience supporting PCI DSS assessments, gap analyses, remediation planning, control assessments, or readiness initiatives.
  • Experience assessing business processes, documenting workflows, identifying control gaps, and developing remediation recommendations.
  • Experience working with cross-functional stakeholders to document, propose solutions to and address control and compliance gaps.
  • Experience conducting cybersecurity risk assessments and developing and maintaining enterprise cybersecurity risk registers.
  • Strong understanding of cybersecurity governance frameworks, including the NIST Cybersecurity Framework (CSF), ISO/IEC 27001, CIS Critical Security Controls (CIS Controls), and COBIT.
  • Experience developing cybersecurity policies, standards, procedures, and governance documentation.
  • Experience using Governance, Risk, and Compliance (GRC) platforms.
  • Strong analytical and problem-solving skills with the ability to assess risk, prioritize remediation activities, and communicate recommendations effectively.
  • Excellent written, presentation, and verbal communication skills with the ability to communicate effectively with technical and non-technical stakeholders.

Nice to Have:

  • Experience within healthcare, pharmacy, or another regulated industry.
  • Knowledge of Canadian privacy legislation, including PIPEDA, and experience supporting regulatory compliance programs.
  • Relevant security certifications such as PCIP, CISSP, CISM, GRISC, CGRC, and ISO/IEC 27001

Compensation Range: 105,000.00 โ€“ 115,000.00

Location:ย ย This is a hybrid role out of our 320 Bay Street location for a 3 month contract

Opportunity:ย This is a current existing positionย 

AI Disclosure: CareRx does not use AI to screen candidatesย 

Application Processย 

CareRx is committed to employment equity and a diverse, inclusive workplace where everyone can thrive. We welcome applicants of all abilities and will provideย accommodationsย upon request throughout the selection process.ย 

All applicants must successfully pass satisfactory background screening which can include depending on role, Criminal Record Check,Credit Check, Driverโ€™s Abstract, Education Verification, Current Professional Registration and Referencing.