1

Grc Risk Analyst Jobs in Toronto, ON (NOW HIRING)

Operational Risk Analyst

Toronto, ON · Hybrid

CA$60K - CA$80K/yr

Reporting to the Head of Risk, TSX Trust, the Operational Risk Analyst is a critical second-line ... Proficiency in GRC tools (preferably Resolver ) and data visualization tools (e.g., Tableau or ...

Define enterprise GRC target architecture and solution blueprints (data models, taxonomy, control ... Knowledge of FAIR risk quantification, BI/analytics (Power BI/Tableau), continuous control ...

... Risk Analytics. * Perform hands-on configuration/customization across enterprise GRC technologies ... including custom objects, forms, workflows, reporting. Technical Implementation and Integration

Analyst II, Security GRC

Toronto, ON · Hybrid

CA$66K - CA$93K/yr

Your Moneris Career - The Opportunity As an Analyst II, Governance, Risk & Compliance (GRC), you will support the Information Security team in maintaining compliance, managing risk, and strengthening ...

Those in governance, risk, controls and compliance at PwC will be responsible for confirming ... Use a broad range of analytics tools, technology, digital solutions, and techniques to extract ...

As a Consultant in our Risk Tech and Data Team, you will support and advise on a range of projects ... If you love tech, data analytics, strategy, and solving real-world business problems, this is the ...

Senior Governance & Control Analyst

Toronto, ON · On-site

CA$81K - CA$115K/yr

TD Finance, Governance, Risk and Control (Finance GRC or 1B)'s mandate is to enable and support ... As a Senior Analyst, Finance GRC, you will be responsible for providing strategic guidance and ...

... Analytics Cloud (SAC), SAP Landscape Transformation Replication Server (SLT), SAP Master Data ... Develop training content for GRC, role assignments, and periodic reviews. * Engagement risk ...

next page

Showing results 1-20

Grc Risk Analyst information

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What are GRC Risk Analysts?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst, and why are they important?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.
What job categories do people searching Grc Risk Analyst jobs in Toronto, ON look for? The top searched job categories for Grc Risk Analyst jobs in Toronto, ON are:
Infographic showing various Grc Risk Analyst job openings in Toronto, ON as of July 2026, with employment types broken down into 73% Full Time, 3% Part Time, and 24% Contract. Highlights an 61% Physical, 5% Hybrid, and 34% Remote job distribution.

Senior Cyber Security Risk Analyst

Alquemy

Toronto, ON

Other

Re-posted 26 days ago


Job description

Job Description We are seeking a Senior Cyber Security Risk Analyst to join our Toronto client's team. In this pivotal role, you will lead the creation of comprehensive cyber system risk reports, translating complex technical findings from penetration tests and Threat and Risk Assessments (TRAs) into actionable business insights for senior stakeholders. As a senior member of the team, you will champion industry-standard frameworks and leverage ServiceNow GRC to maintain, mature, and safeguard the organization's overall cyber risk posture.

Key Responsibilities Lead Risk Reporting: Oversee and manage the cyber risk reporting queue, ensuring the delivery of high-quality, executive-ready risk assessments. Apply Standard Methodologies: Utilize NIST and HTRA methodologies to rigorously assess, quantify, and communicate technical risks. Drive GRC Excellence: Document, track, and manage the lifecycle of risks, treatment plans, and remediation efforts within ServiceNow GRC.

Translate Tech to Business: Bridge the gap between engineering and the boardroom by converting complex technical vulnerabilities into clear, high-impact business risk statements for non-technical leadership. Support Governance & Audits: Act as a trusted advisor during governance forums and internal audits, providing articulate verbal and written risk communications. Innovate Securely: Leverage AI-assisted tools to streamline content generation and report optimization, while strictly maintaining data confidentiality and privacy boundaries.

Education & Experience Education: University Degree or College Diploma in Computer Science, Information Security, Risk Management, or a related field. Experience: 5+ years of progressive experience in cyber security, IT audit, or technology risk management. Executive Reporting: 3+ years of dedicated experience crafting executive-grade risk reports and presentations for C-suite or steering committees.

Technical & Core Competencies Framework Expertise: Deep practical experience applying NIST frameworks (e.g., CSF, 800-53) and HTRA methodologies. Tooling: Hands-on, administrative, or advanced user experience with ServiceNow GRC (Integrated Risk Management). Vulnerability Acumen: A strong understanding of common technical vulnerabilities (OWASP Top 10, CVEs) and the unique ability to map them to operational and financial business impacts

Communication: Exceptional communication and storytelling skills, with the ability to influence stakeholders and defend risk ratings with data-driven logic. Relevant professional certifications (e.g., CRISC, CISM, CISSP, or CISA). Experience integrating AI workflows into daily risk analysis safely.