1

Grc Jobs in Quebec (NOW HIRING)

Supporting and administering SAP GRC Access Control modules, including: Access Risk Analysis (ARA) Access Request Management (ARM) Emergency Access Management (EAM / Firefighter) Conducting SoD risk ...

Supporting and administering SAP GRC Access Control modules, including: Access Risk Analysis (ARA) Access Request Management (ARM) Emergency Access Management (EAM / Firefighter) Conducting SoD risk ...

Supporting and administering SAP GRC Access Control modules, including: Access Risk Analysis (ARA) Access Request Management (ARM) Emergency Access Management (EAM / Firefighter) Conducting SoD risk ...

Administrer les solutions SAP GRC Access Control, notamment : ARA (Access Risk Analysis) ARM (Access Request Management) EAM (Emergency Access Management / Firefighter) Effectuer des analyses de ...

Supporting and administering SAP GRC Access Control modules, including: Access Risk Analysis (ARA) Access Request Management (ARM) Emergency Access Management (EAM / Firefighter) Conducting SoD risk ...

Administrer les solutions SAP GRC Access Control, notamment : ARA (Access Risk Analysis) ARM (Access Request Management) EAM (Emergency Access Management / Firefighter) Effectuer des analyses de ...

Administrer les solutions SAP GRC Access Control, notamment : ARA (Access Risk Analysis) ARM (Access Request Management) EAM (Emergency Access Management / Firefighter) Effectuer des analyses de ...

Administrer les solutions SAP GRC Access Control, notamment : ARA (Access Risk Analysis) ARM (Access Request Management) EAM (Emergency Access Management / Firefighter) Effectuer des analyses de ...

Le Responsable GRC est responsable de la gouvernance de la cybersécurité, de la gestion des risques technologiques et de la conformité réglementaire. Il agit comme partenaire afin d'assurer la ...

Le Responsable GRC est responsable de la gouvernance de la cybersécurité, de la gestion des risques technologiques et de la conformité réglementaire. Il agit comme partenaire afin d'assurer la ...

Establish, manage, and mature the information security GRC framework, including risk assessment methodologies, control implementation, and policy lifecycle management. * Manage the information ...

Establish, manage, and mature the information security GRC framework, including risk assessment methodologies, control implementation, and policy lifecycle management. * Manage the information ...

next page

Showing results 1-20

Grc information

Are GRC jobs hard to get?

GRC (Governance, Risk, and Compliance) jobs can be competitive, especially for entry-level positions, but having relevant certifications like CISA or CISSP and experience with compliance frameworks can improve your chances. The difficulty of securing a GRC role depends on your skills, education, and the current job market demand for compliance professionals.

Is GRC a good career?

GRC (Governance, Risk, and Compliance) is a growing field within cybersecurity and corporate management, focusing on ensuring organizations meet regulatory requirements and manage risks effectively. It often requires knowledge of compliance standards, risk assessment, and security frameworks, with certifications like CISA or CISSP enhancing job prospects. The career offers opportunities in various industries, with roles typically involving analysis, policy development, and audits.

What is a GRC?

A GRC (Governance, Risk, and Compliance) job involves managing an organization's policies, regulations, and risk management frameworks to ensure compliance with legal and industry standards. Professionals in this role assess risks, implement controls, and develop strategies to mitigate potential threats while aligning business operations with regulatory requirements. They often work with stakeholders across IT, security, and legal departments to maintain compliance and improve risk management processes.

What are the key skills and qualifications needed for a GRC role?

To thrive in a GRC (Governance, Risk, and Compliance) role, you need a solid understanding of regulatory frameworks, risk assessment methodologies, and compliance standards, often supported by a degree in business, information technology, or a related field. Familiarity with GRC software platforms (such as RSA Archer, LogicGate, or MetricStream), and professional certifications like CRISC, CISA, or CISSP, are highly valued. Strong analytical thinking, attention to detail, and clear communication skills are important for interpreting regulations and working with cross-functional teams. These skills ensure that organizations manage risks effectively, meet regulatory requirements, and maintain enterprise-wide compliance.

What are the daily responsibilities of a GRC professional?

In a GRC position, your day-to-day tasks often include conducting risk assessments, monitoring compliance with internal policies and external regulations, and collaborating with various departments to implement controls or corrective actions. You may also manage and update policies, prepare reports for management, and respond to regulatory audits or inquiries. Additionally, GRC professionals facilitate training sessions to improve organizational awareness of risks and ensure ongoing adherence to compliance standards. The role is dynamic and involves proactive problem-solving to help keep the organization secure and compliant.

Is GRC still in demand?

GRC (Governance, Risk, and Compliance) professionals are in ongoing demand due to increasing regulatory requirements and cybersecurity concerns across industries. Skills in risk management, compliance frameworks, and familiarity with tools like audit software enhance job prospects in this field.

What are GRC jobs?

GRC jobs refer to roles focused on Governance, Risk Management, and Compliance within organizations. These positions involve developing policies, assessing risks, ensuring regulatory adherence, and often require knowledge of frameworks like ISO, COBIT, or NIST, as well as certifications such as CISA or CISSP.
What are the most commonly searched types of Grc jobs in Quebec? The most popular types of Grc jobs in Quebec are:
What job categories do people searching Grc jobs in Quebec look for? The top searched job categories for Grc jobs in Quebec are:
Infographic showing various Grc job openings in Quebec as of August 2026, with employment types broken down into 54% Full Time, and 46% Contract. Highlights an 64% In-person, 12% Hybrid, and 24% Remote job distribution.

Full-time

Medical, Retirement, PTO

Posted 18 days ago


Job description

We are banking at another level.

Choosing BDC as your employer means working in a healthy, inclusive, and skilled workplace that puts forward the best conditions to bring together unique teams where employees are empowered to act. It also means being at the centre of ambitious economic and financial projects to see further and to do things differently, to fuel the success of Canadian entrepreneurs.

Choosing BDC as your employer also means:

  • Flexible and competitive benefits, including an Employee Savings and Investment Plan where BDC matches part of your voluntary contributions, a Defined Benefit Pension Plan, a $750 wellness and health care spending account, to name a few

  • In addition to paid vacation each year, five personal days, sick days as necessary, and our offices are closed from December 25 to January 1

  • A hybrid work model that truly balances work and personal life

  • Opportunities for learning, training and development, and much more...

Explore the BDC Way in our Culture Book

POSITION OVERVIEW

BDC is seeking a Tech Lead to join the Risk & Value Office squad in Montreal. This role combines technical leadership, risk expertise, and data-driven delivery to advance InfoSec's ability to monitor and manage its risk landscape. The Tech Lead will guide the design and implementation of GRC engineering capabilities, ensure the quality and consistency of squad deliverables, and drive the adoption of scalable analytics, automation, and reporting solutions. Acting as a key advisor, the role also strengthens technology risk management practices and enables actionable, executive-level insights.

CHALLENGES TO BE MET

Technical Leadership & Squad Enablement
Act as the tech lead for the Risk & Value Office squad, providing guidance on GRC engineering and risk management.
Review and challenge the quality of the squad deliverables to ensure alignment with InfoSec standards and executive expectations.
Coach and mentor squad members on GRC engineering practices and risk management concepts, fostering capability uplift and autonomy.
Drive adoption of best practices in data, automation, and secure development, ensuring consistency across initiatives.
Provide technical guidance in prioritization and backlog refinement, ensuring work is aligned with value, risk reduction, and strategic objectives.

Risk Management & Governance
Lead and contribute to the continuous improvement of the InfoSec technical risk management framework, ensuring strong integration with data-driven insights.
Oversee the identification, assessment, and monitoring of technology and cyber risks, leveraging metrics, analytics, and automation.
Ensure risk outputs, such as KRIs, control effectiveness and audit findings, are consistent, traceable, and defensible.
Provide expert guidance on risk posture, remediation strategies, and prioritization, to support management decision-making.
Lead or support key risk management initiatives, such as the Digital Crown Jewels framework and Cyber Operational Risk Events Management.
Support internal and external audits, ensuring timely completion of remediation actions.
Prepare documentation related to policy, standards, and procedures.

Data-Driven GRC & Engineering
Participate to the design and implementation of data-driven GRC capabilities, including automated data ingestion, transformation, and insight generation.
Define and enforce data architecture and governance practices for security metrics and reporting.
Support the squad in maintaining and developing key security metrics, including risk and control indicators.
Contribute to the development of scalable solutions leveraging tools such as Power BI, Power Platform, SQL, and APIs.
Identify and implement opportunities to automate workflows, controls monitoring, and reporting processes.
Ensure integration across tools and datasets to enable end-to-end visibility of InfoSec risk posture.
Provide technical leadership for the evolution of GRC tools, including asset register modernization.
Identify opportunities, support the design and enhancement of Continuous Control Monitoring (CCM) to provide timely visibility into control performance and identify issues proactively.

Data & Reporting Initiatives
Deliver insights driven by robust data analytics.
Contribute to improving reporting processes and ensuring data reliability.
Support data initiatives from source identification to final reporting.
Present findings and recommendations to managers and stakeholders.

WHAT WE ARE LOOKING FOR


REQUIRED QUALIFICATIONS

Bachelor's degree in computer science, information security, data analytics, or a related field.

At least 8 years of experience in cyber risk, cybersecurity, or GRC, with strong exposure to data-driven approaches and analytics.
Minimum 3 years in a tech lead or senior role, including delivery leadership, output review, and team coaching.
Extensive experience in:

  • Risk analytics, metrics development (KRIs/KPIs), and automated reporting.
  • Driving automation and implementing data solutions in complex environments.

Advanced proficiency in Power BI, Power Platform, SQL, and data integration (APIs).
Strong understanding of data architecture, data governance, and analytics lifecycle.
Experience designing and implementing automated workflows and reporting solutions.
Experience with Continuous Control Monitoring (CCM) and control automation concepts.

Strong knowledge of technology risk management frameworks (e.g., NIST, ISO 27001, COBIT).
Experience applying risk frameworks, audit practices, and control assessments.

Strong ability to review, challenge, and enhance the quality of deliverables.
Demonstrated leadership in coaching, mentoring, and developing team capabilities.
Excellent stakeholder management skills, with the ability to operate in complex, high-visibility environments.
Ability to translate technical and risk concepts into a clear business language.
Strong analytical thinking, problem-solving, and decision-making skills.
Highly organized, detail-oriented, and able to manage multiple priorities effectively.

PREFERRED QUALIFICATIONS

Financial services or regulated environments.
Relevant certifications (e.g., CRISC, CISM, FAIR).
Knowledge on OSFI.


#INDHP

Proudly one of Canada's Top 100 Employers and one of Canada's Best Diversity Employers, we are committed to fostering a diverse, equitable, inclusive and accessible environment where all employees can thrive and feel empowered to bring their whole selves to work. If you require an accommodation to complete your application, please do not hesitate to contact us at accessibility@bdc.ca.

While we appreciate all applications, we advise that only the candidates selected to participate in the recruitment process will be contacted.