GRC Lead/Security Analyst

IvaluaMontreal, QC
Hybrid

About The Position

You will be part of the InfoSec team with a mission to build, maintain, and continuously improve our Information Security program, providing peace of mind and assurance of protection and safety to our customers. Our team is hands-on, with a strong problem-solving mindset, capable of thinking holistically about implementation and providing solutions to address our customers' long-term challenges. We work hard and play hard, enjoying various indoor and outdoor activities organized by the company, allowing you to focus, collaborate, and unleash your creativity. We are looking for a GRC Lead/Security Analyst to join our InfoSec team. This role will help drive various GRC activities which include supporting prospect and customer security questions, maintaining security policies, supporting security audits and assessments and driving new security certifications/compliance initiatives.

Requirements

  • At least 4 years of experience as a GRC Security Analyst.
  • Solid practical knowledge of security, risk, and compliance frameworks (e.g., NIST CSF & 800-53, ISO 27001, SOC, HITRUST, HIPAA, PCI-DSS, GDPR).
  • Direct experience managing audits, self-assessments, or risk assessments against one or more of the InfoSec frameworks listed above.
  • Experience in implementing or supporting security risk management processes (risk assessments, risk registers, business impact analyses).
  • Proficiency with continuous compliance and monitoring platforms.
  • A solid understanding of cloud platforms (Azure, AWS, GCP) and the ability to discuss security architecture and the implementation of controls with technical teams.
  • Knowledge and experience working with the IT and security team, as well as a thorough understanding of security concepts across all technology layers (network, infrastructure, web applications, cloud environments).
  • Knowledge of security and risk industry literature, as well as leading reference knowledge bases (e.g., OWASP, MITRE ATT&CK, NIST 800-39).
  • Bachelor’s degree in Computer Science, or relevant field preferred with a minimum of 4 years of relevant professional experience OR Equivalent combination of education and experience.
  • Excellent interpersonal, organizational, and communication skills.
  • Ability to communicate effectively and professionally in French and English, including in contractual, regulatory, and technical contexts.
  • Ability to conduct business in English is required given our customer base; wherever possible, we will support the employee's right to work in French.
  • Proven ability to work with geographically dispersed teams as well as with external service providers, auditors, or regulators.
  • Strong organizational skills and attention to detail; ability to manage multiple priorities simultaneously in a fast-paced environment.
  • Strong sense of initiative, high level of motivation, and the ability to work independently with minimal supervision.

Nice To Haves

  • Relevant certifications in auditing and/or information security (e.g., CISSP, CISA, CISM, Azure Cloud Security) are preferred.
  • Previous experience at a Big 4 firm or in a security/compliance role in a cloud/SaaS environment is a plus.

Responsibilities

  • Lead and support compliance initiatives in accordance with global and regional standards, including SOC 1/SOC 2, ISO 27001, IRAP, PCI-DSS, SecNumCloud, Cyber Essentials Plus (CE+), BSI C5, and NIST 800-53.
  • Evaluate technical controls across the entire technology stack, including all layers of the TCP/IP model (e.g., network segmentation, firewall rules, TLS/SSL configuration, IDS/IPS, access controls, application security, encryption in transit and at rest, and cloud security configurations), and translate security requirements into concrete guidelines for engineering and infrastructure teams.
  • Lead and manage client security audits, security questionnaires, and contract reviews, primarily for the EMEA region. Participate in the negotiation and review of French contracts to ensure alignment with security and compliance requirements.
  • Participate in meetings with prospects and clients and effectively present Ivalua’s security architecture and controls to them.
  • Lead or support internal and third-party security risk management processes, including the identification, analysis, scoring, mitigation planning, and ongoing monitoring of risks.
  • Support ongoing compliance monitoring activities using manual processes, automation, and GRC tools to maintain the effectiveness of controls, generate audit evidence, and ensure ongoing audit readiness.
  • Ensure the implementation and coordination of key security and availability controls, such as business impact assessments, disaster recovery plan tests, security incident response drills, access reviews, etc.

Benefits

  • Hybrid working model (3 days in the office per week)
  • Snacks and weekly lunches in the office
  • Exceptional training and career development program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service