1

It Risk And Compliance Jobs in Calgary, AB (NOW HIRING)

You Bring * 3-6 years in IT governance, risk, compliance, service management, or IT security in an operational role * Hands-on experience building or substantially rebuilding a CMDB or asset ...

As Manager, IT Security, you will lead a capable team, strengthen security practices, and help ... Advance risk and compliance by developing standards, support policies, conducting risk assessments ...

Line of Service Assurance Industry/Sector Not Applicable Specialism Conduct and Compliance ... Risk Services, will enable you to assist clients in assessing control activities, policies and ...

... technology risk, IT audit, OT/industrial cybersecurity, compliance, engineering technology environments, or consulting. * Foundational understanding of cybersecurity and risk management ...

IT Solutions Architect From our Calgary HQ to our teams in Edmonton, Red Deer, and the Okanagan ... Lead discovery sessions with client stakeholders to uncover business drivers, risk tolerance ...

Own and drive the technical roadmap for IT Systems integrations and automation-identifying where we can eliminate manual work, reduce operational risk, and accelerate the velocity of Clions across ...

IT Analyst II

Calgary, AB · Hybrid

CA$42.12 - CA$56.86/hr

... compliance in a healthcare setting. In this role, you will troubleshoot and resolve complex ... As an IT Analyst II, you will provide technical support related to information technology ...

Regularly update and maintain IT systems to ensure ongoing security compliance and optimized performance. * Participate in after-hours support, weekend coverage, or on-call rotation as required. What ...

next page

Showing results 1-20

It Risk And Compliance information

What is IT Risk and Compliance?

IT Risk and Compliance refers to the process of identifying, assessing, and managing risks associated with an organization's information technology systems, while ensuring that these systems adhere to relevant laws, regulations, and internal policies. Professionals in this field work to protect sensitive data, prevent security breaches, and ensure that the organization's IT practices are compliant with industry standards such as GDPR, HIPAA, or SOX. They often conduct risk assessments, implement controls, monitor compliance, and respond to audits. The goal is to minimize potential threats to IT infrastructure and maintain the trust of customers and stakeholders.

What are the key skills and qualifications needed to thrive as an IT Risk and Compliance professional?

To thrive as an IT Risk and Compliance professional, you need a solid understanding of IT governance, risk management frameworks, regulatory requirements, and a relevant degree such as in information technology, cybersecurity, or a related field. Familiarity with tools like GRC (Governance, Risk, and Compliance) platforms, as well as certifications such as CISA, CRISC, or CISSP, is typically required. Strong analytical thinking, attention to detail, and effective communication help professionals excel in navigating complex regulations and collaborating with cross-functional teams. These skills and qualifications are crucial for ensuring organizational compliance, mitigating security risks, and maintaining trust with stakeholders.

How does an IT Risk and Compliance professional typically collaborate with other departments to ensure regulatory adherence?

IT Risk and Compliance professionals regularly work with teams across the organization—such as IT, legal, audit, and business operations—to identify risks, interpret regulations, and implement compliance controls. They facilitate training, conduct assessments, and coordinate responses to audits or incidents, ensuring that everyone understands their responsibilities. Effective communication and strong relationship-building skills are essential, as much of the role involves translating technical requirements into actionable steps for non-technical staff. This cross-functional collaboration helps maintain a culture of compliance and minimizes organizational risk.

What is the difference between It Risk And Compliance vs Cybersecurity Analyst?

AspectIt Risk And ComplianceCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, risk assessments, compliance auditsMonitoring security threats, incident response, vulnerability testing
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, financial institutions, government agencies

While both roles focus on protecting information, It Risk And Compliance emphasizes establishing policies, ensuring regulatory adherence, and managing overall risk frameworks. Cybersecurity Analysts primarily focus on identifying and mitigating security threats through technical measures. Understanding these differences helps organizations assign the right responsibilities and professionals for their security needs.

Is IT risk and compliance a good career?

IT risk and compliance is a growing field that involves managing cybersecurity threats, ensuring regulatory adherence, and implementing security controls. Professionals in this area often require certifications like CISSP or CISA and work in environments that demand strong analytical and technical skills. It offers opportunities for career advancement and job stability due to increasing regulatory requirements and cybersecurity concerns.

What cities near Calgary, AB are hiring for It Risk And Compliance jobs?

Cities near Calgary, AB with the most It Risk And Compliance job openings:

Infographic showing various It Risk And Compliance job openings in Calgary, AB as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 12% Part Time, and 4% Contract. Highlights an 91% Physical, 4% Hybrid, and 5% Remote job distribution.

Senior Manager - IT Audit, Technology Risk Services

Calgary, AB

Full-time

Re-posted 24 days ago


Job description

Overview

At KPMG in Canada, our people bring their unique perspectives to Canada’s most important challenges. Here, you can build momentum that reaches beyond our business, develop skills for the future, and take ownership of your career with support at every stage. Join a firm where your career can make a difference. 

Our Risk Services practice provides clients with a range of Advisory and Assurance services focused on strengthening business resilience, managing business risks, and catalyzing business performance. Our value is in applying and integrating our wide range of technology, business, advisory, assurance, and risk management expertise to specific business and management problems.

KPMG’s Technology Risk services assist our clients to effectively identify, evaluate, and manage the broad range of opportunities, risks, controls, and compliance requirements associated with their use of and reliance on technology-enabled processes, services, and solutions, whether developed and operated in-house or provided by third parties. KPMG Tech Risk services cover a broad range of IT related audit, assurance and advisory services including:

  • Technology Assurance Services
  • SOC 1, SOC 2, and Other Controls Assurance Services
  • IT Internal / External Audit Services
  • Business Systems Controls Services
  • System Implementation Assessment and Assurance Services
  • Technology Project Advisory and Assurance Services
  • Technology Governance, Risk Compliance Services

What you will do
  • Care for the development and implementation of engagement and project plans.
  • Contribute on multiple client engagements of varying size, scope and complexity across multiple industry sectors and technology environments
  • Assessment of governance, risks, and controls in areas, such as: IT planning and organization, IT projects, especially in an “agile” development environment, General IT controls, Business process and IT Application Controls, and System Implementations and Data conversion
  • Planning, managing and completing project tasks including: liaising with client and KPMG teams; collecting, testing and analyzing information; documenting and evaluating business and IT processes, risks, controls, policies, strategies
  • Discussing findings and recommendations with client personnel and developing reports and deliverables
  • Work with clients to take on emerging issues and technologies such as blockchain, crypto-assets, cloud services, intelligent automation, internet of things, virtual/augmented reality, cybersecurity, privacy, and the metaverse
  • Agile involvement in the business community and developing relationships with clients to increase awareness of the firm's services
  • Identifying and assisting in pursuits including developing marketing materials, proposals, presentations, and research
  • Guiding and contributing to practice development such as knowledge sharing, training, coaching, team motivation and practice direction.
  • Assisting with the direction, development, and growth of the practice

What you bring to the role
  • Bachelor’s degree (or higher) in Business, Accounting, Computing Science, Management Information Systems, or other relevant program(s)
  • IT audit designations (e.g., CISA, CISSP, CISM) required
  • Accounting designation(s) (e.g., CPA, CIA) would be an asset
  • A desire to work toward further relevant education/designations (e.g., PMP, CISSP, CRISC) and other technology specific certifications would be an asset
  • 8+ years combined relevant experience in internal/external audit, consulting, and/or industry (e.g., risk management or internal control, IT, project oversight, system implementation, finance, accounting) is preferred
  • Knowledge of PCAOB audit standards with respect to IT controls would be an asset
  • Ability to identify and evaluate business, IT, and audit risks – you understand financial reporting, compliance, audit risks and their IT components
  • Experience auditing, assessing, and/or implementing business systems and/or emerging technologies, and streamlining IT audit processes
  • Knowledge and experience with technology that supports governance, risk controls (GRC) initiatives and processes is desirable
  • Curiosity and thirst for learning new standards, technologies, and skills
  • Excellent verbal and written communication skills with an aptitude for being able to clearly communicate issues and solutions at all levels
  • Demonstrated ability to effectively interact and develop relationships with a diverse group of clients and colleagues
  • Excellent business, engagement, and project ownership skills
  • Highly motivated, committed self-starter who can prioritize work, multitask, and cope with changing priorities

Knowledge of Applications and Tools:

  • Applications: SAP ERP – S4, ECC, GRC; Oracle ERP; D365; other business applications used in Oil and Gas
  • Databases – HANA, Oracle, MS SQL, others
  • Data Analytics – PowerQuery, Power BI, Alteryx, ACL, other tools
  • Experience with documenting in and executing audits in electronic audit files (or applications).

Providing you with the support you need to be at your best


Our Values, The KPMG Way

Integrity, we do what is right | Excellence, we never stop learning and improving | Courage, we think and act boldly | Together, we respect each other and draw strength from our differences | For Better, we do what matters

KPMG in Canada is a proud equal opportunities employer and we are committed to creating a respectful, inclusive and barrier-free workplace that allows all of our people to reach their full potential. A diverse workforce is key to our success and we believe in bringing your whole self to work. We welcome all qualified candidates to apply and hope you will choose KPMG in Canada as your employer of choice.

Adjustments and accommodations throughout the recruitment process

At KPMG, we are committed to fostering an inclusive recruitment process where all candidates can be themselves and excel. We aim to provide a positive experience and are prepared to offer adjustments or accommodations to help you perform at your best. Adjustments (informal requests), such as extra preparation time or the option for micro breaks during interviews, and accommodations (formal requests), such as accessible communication supports or technology aids, are tailored to individual needs and role requirements. You will have an opportunity to request an adjustment or accommodation at any point throughout the recruitment process. If you require support, please contact KPMG’s Employee Relations Service team by calling 1-888-466-4778.

AI Usage

Weembrace the use of artificial intelligence (AI) to enhance the candidate experience and streamline our recruitment processes. AI tools may help with organizing applications or surfacing relevant qualifications. However, no hiring decisions are made using AI. Every hiring decision is made by our hiring managers and recruitment professionals, who are equipped with training that empowers them to use these tools responsibly. AI technologies used in our recruitment process undergo detailed risk assessments, including security and privacy requirements, that align with KPMG’s Trusted AI framework.

We believe technology should empower human judgment, not replace it. It’s one of the many ways we’re delivering on our vision of being a technology-first, people-driven firm.

Qualifications:
  • Bachelor’s degree (or higher) in Business, Accounting, Computing Science, Management Information Systems, or other relevant program(s)
  • IT audit designations (e.g., CISA, CISSP, CISM) required
  • Accounting designation(s) (e.g., CPA, CIA) would be an asset
  • A desire to work toward further relevant education/designations (e.g., PMP, CISSP, CRISC) and other technology specific certifications would be an asset
  • 8+ years combined relevant experience in internal/external audit, consulting, and/or industry (e.g., risk management or internal control, IT, project oversight, system implementation, finance, accounting) is preferred
  • Knowledge of PCAOB audit standards with respect to IT controls would be an asset
  • Ability to identify and evaluate business, IT, and audit risks – you understand financial reporting, compliance, audit risks and their IT components
  • Experience auditing, assessing, and/or implementing business systems and/or emerging technologies, and streamlining IT audit processes
  • Knowledge and experience with technology that supports governance, risk controls (GRC) initiatives and processes is desirable
  • Curiosity and thirst for learning new standards, technologies, and skills
  • Excellent verbal and written communication skills with an aptitude for being able to clearly communicate issues and solutions at all levels
  • Demonstrated ability to effectively interact and develop relationships with a diverse group of clients and colleagues
  • Excellent business, engagement, and project ownership skills
  • Highly motivated, committed self-starter who can prioritize work, multitask, and cope with changing priorities

Knowledge of Applications and Tools:

  • Applications: SAP ERP – S4, ECC, GRC; Oracle ERP; D365; other business applications used in Oil and Gas
  • Databases – HANA, Oracle, MS SQL, others
  • Data Analytics – PowerQuery, Power BI, Alteryx, ACL, other tools
  • Experience with documenting in and executing audits in electronic audit files (or applications).

Providing you with the support you need to be at your best

Education:UNAVAILABLEEmployment Type: FULL_TIME