1

Grc Jobs in Quebec (NOW HIRING)

Establish, manage, and mature the information security GRC framework, including risk assessment methodologies, control implementation, and policy lifecycle management. Manage the information security ...

Establish, manage, and mature the information security GRC framework, including risk assessment methodologies, control implementation, and policy lifecycle management. * Manage the information ...

Support the configuration, monitoring, and operation of SAP GRC Access Control (AC) components: ARA, ARM, EAM, BRM. * Review and remediate SoD conflicts and critical access risks across SAP ...

Our Governance, Risk and Compliance (GRC) practice helps organizations address challenges related to governance, risk management, regulatory compliance, internal controls, and the evolution of risk ...

Ensure the role of "product owner" for selected GRC modules and referential under the PCG team's ownership. * Support transversal topics such as Regulatory Exams, change-the-bank activities, systems ...

Showing results 21-40

Grc information

Are GRC jobs hard to get?

GRC (Governance, Risk, and Compliance) jobs can be competitive, especially for entry-level positions, but having relevant certifications like CISA or CISSP and experience with compliance frameworks can improve your chances. The difficulty of securing a GRC role depends on your skills, education, and the current job market demand for compliance professionals.

Is GRC a good career?

GRC (Governance, Risk, and Compliance) is a growing field within cybersecurity and corporate management, focusing on ensuring organizations meet regulatory requirements and manage risks effectively. It often requires knowledge of compliance standards, risk assessment, and security frameworks, with certifications like CISA or CISSP enhancing job prospects. The career offers opportunities in various industries, with roles typically involving analysis, policy development, and audits.

What is a GRC?

A GRC (Governance, Risk, and Compliance) job involves managing an organization's policies, regulations, and risk management frameworks to ensure compliance with legal and industry standards. Professionals in this role assess risks, implement controls, and develop strategies to mitigate potential threats while aligning business operations with regulatory requirements. They often work with stakeholders across IT, security, and legal departments to maintain compliance and improve risk management processes.

What are the key skills and qualifications needed for a GRC role?

To thrive in a GRC (Governance, Risk, and Compliance) role, you need a solid understanding of regulatory frameworks, risk assessment methodologies, and compliance standards, often supported by a degree in business, information technology, or a related field. Familiarity with GRC software platforms (such as RSA Archer, LogicGate, or MetricStream), and professional certifications like CRISC, CISA, or CISSP, are highly valued. Strong analytical thinking, attention to detail, and clear communication skills are important for interpreting regulations and working with cross-functional teams. These skills ensure that organizations manage risks effectively, meet regulatory requirements, and maintain enterprise-wide compliance.

What are the daily responsibilities of a GRC professional?

In a GRC position, your day-to-day tasks often include conducting risk assessments, monitoring compliance with internal policies and external regulations, and collaborating with various departments to implement controls or corrective actions. You may also manage and update policies, prepare reports for management, and respond to regulatory audits or inquiries. Additionally, GRC professionals facilitate training sessions to improve organizational awareness of risks and ensure ongoing adherence to compliance standards. The role is dynamic and involves proactive problem-solving to help keep the organization secure and compliant.

Is GRC still in demand?

GRC (Governance, Risk, and Compliance) professionals are in ongoing demand due to increasing regulatory requirements and cybersecurity concerns across industries. Skills in risk management, compliance frameworks, and familiarity with tools like audit software enhance job prospects in this field.

What are GRC jobs?

GRC jobs refer to roles focused on Governance, Risk Management, and Compliance within organizations. These positions involve developing policies, assessing risks, ensuring regulatory adherence, and often require knowledge of frameworks like ISO, COBIT, or NIST, as well as certifications such as CISA or CISSP.
What are the most commonly searched types of Grc jobs in Quebec? The most popular types of Grc jobs in Quebec are:
What job categories do people searching Grc jobs in Quebec look for? The top searched job categories for Grc jobs in Quebec are:
Infographic showing various Grc job openings in Quebec as of August 2026, with employment types broken down into 54% Full Time, and 46% Contract. Highlights an 64% In-person, 12% Hybrid, and 24% Remote job distribution.

Information security Manager

Optel

Quebec, QC • On-site

Full-time

This job post has expired today. Applications are no longer accepted.


Job description

OPTEL is one of the world’s leading providers of traceability systems. Its mission is to leverage innovative technologies to create a better world through responsible capitalism. The company’s renowned solutions ensure the quality of healthcare products and help fight the counterfeiting of medicines and medical devices worldwide. OPTEL also adapts its technologies to a variety of sectors, from healthcare to smart manufacturing and beyond, enabling all industries to benefit from global traceability. OPTEL’s expertise empowers industries to measure, inspect, control, and track a wide range of elements in order to improve product quality and promote a more responsible use of resources. Job Summary: Reporting directly to the Chief Information Officer (CIO), the Information Security Manager leads the operational execution of the organization's information security program. This role involves managing security functions, implementing strategy, overseeing technologies, and leading Governance, Risk Management, and Compliance (GRC) activities, with a strong focus on cloud/SaaS environments. The role demands close collaboration with IT, Development, Sales, Legal, Compliance, and other core business functions. It requires the ability to represent the company's security posture effectively to external/internal clients and auditors . This individual serves as the primary operational leader for security, advising the CIO, driving initiatives, and acting as a key security liaison both internally and externally. Key Responsibilities: 1. Security Operations & Program Management: Lead and manage core security functions (SecOps, Vulnerability Management, Incident Response). Drive key security programs (Security Awareness, DLP, IAM). Oversee administration and optimization of security tools (SIEM, EDR, DLP, etc.). 2. Governance, Risk Management & Compliance (GRC): Establish, manage, and mature the information security GRC framework, including risk assessment methodologies, control implementation, and policy lifecycle management. Manage the information security risk register, conduct regular risk assessments (incl. SaaS/cloud), propose mitigations, and track remediation. Ensure compliance with relevant laws, regulations (e.g., CERT-In directives, DPDP Act), standards (ISO 27001,SOC 2, etc.), and contractual obligations. Lead security audit preparation (internal/external) and manage responses/remediation efforts. Develop, implement, socialize, and enforce information security policies and standards. 3. SaaS & Cloud Security: Develop, implement, and manage security controls, configurations, and processes for SaaS applications. Conduct security and risk assessments for new and existing SaaS solutions. Provide security guidance for the adoption and secure configuration of SaaS applications. 4. Collaboration & Engagement: Cross-Functional Partnership: Foster strong working relationships across departments, including IT (infrastructure, applications, firewall team), Development, Sales, Legal, Compliance, and other core business functions to integrate security practices effectively. Development Collaboration: Work closely with development teams on Secure SDLC practices (secure coding, threat modeling, AppSec testing). Sales Partnership: Provide security expertise to Sales during the sales cycle. Client-Facing Security: Represent the company's security posture externally, responding to client questionnaires (RFIs/RFPs) and participating in security discussions. 5. Strategy Execution & Advisory: S upport the CIO in developing and refining the security strategy. Translate strategy into actionable plans and lead execution, particularly around GRC and operations. Act as the primary security advisor to the CIO on operational security, GRC status, risk posture, and cloud/SaaS security. Prepare security reports, metrics (including GRC metrics), and briefings for the CIO. 6. Incident Response & Leadership: Lead security incident response coordination. Provide technical leadership on security architecture and secure configurations. Manage security vendor relationships and provide input/manage the security budget. Lead and mentor any direct or indirect security team members. OPTEL is an equal opportunity employer. We believe that diversity is essential to fostering innovation and creativity. We welcome and encourage applications from individuals of all backgrounds, cultures, gender identities, sexual orientations, abilities, ages, and beliefs. We are committed to providing a fair and inclusive recruitment process in which every candidate is evaluated solely on their qualifications, skills, and potential. At OPTEL, each employee’s unique perspective contributes to our collective success, and we celebrate the richness that diversity brings to our tea Required Qualifications: Experience: 8-10 years of progressive experience in Information Security across multiple domains. GRC Expertise: Strong understanding and practical experience with Governance, Risk Management, and Compliance (GRC) principles and frameworks (e.g., implementing controls based on NIST/ISO, managing risk registers, policy lifecycle management, supporting audits such as SOC 2 or ISO 27001). SaaS Security Expertise: Demonstrated experience in securing SaaS applications (controls, configuration, risk assessment). Understanding of identity federation. Collaboration Skills: Proven ability to collaborate effectively with technical (Development, IT) and business/support functions (Sales, Legal, Compliance). Experience with DevSecOps principles desirable. Client-Facing Communication: Excellent client-facing communication, presentation, and interpersonal skills. Ability to represent security posture confidently externally. Business Acumen: Ability to understand business processes and translate technical security concepts into business/risk terms. Leadership: Proven experience leading security operations, projects, or teams. Technical Expertise: Deep understanding of core security principles, technologies, frameworks. Broad knowledge of cloud security, endpoint security, IAM, SIEM, vulnerability management, network security concepts. Risk Management: Solid experience with security risk assessment methodologies. Execution Focus: Demonstrated ability to manage security operations and GRC processes effectively. Education: Bachelor’s degree in Computer Science, Information Security, or related field, or equivalent experience. Preferred Qualifications: Master's degree in Cybersecurity or related field. Certifications: CISSP, CISM, CRISC, CISA, Experience completing industry-standard security questionnaires (e.g., SIG, CAIQ VSAQ). Experience reporting directly to senior leadership. Experience managing security vendors. Knowledge of specific Indian, European and American data protection laws and cybersecurity regulations.

Optel logo

About Optel

Sourced by ZipRecruiter

Industry

Medical equipment and supplies manufacturing

Company size

11 - 50 Employees

Headquarters location

Rochester, NY, US

Year founded

2014