Leader, Governance, Risk & Compliance

Interac Corp.Toronto, ON
CA$150,000 - CA$180,000Hybrid

About The Position

The Leader, Governance, Risk and Compliance (GRC) will be responsible for establishing the GRC mandate and goals for Interac Corp. and will collaborate closely with key stakeholders and business units on security risk and compliance initiatives and effective risk management practices across the organization. The Leader, will business units embed a security risk management culture into production, delivery, support and operations that enables business objectives. The Leader will be responsible for strengthening controls in IT environments, ensuring that risks are clearly understood, controls are implemented to mitigate those risks and continuous monitoring is established to measure control effectiveness. The Leader, will lead a team in operating and maintaining an Information Security Management System (ISMS) to help Interac Corp. meet and comply with applicable frameworks, data protection laws, regulations, Interac cybersecurity standards and contractual obligations.

Requirements

  • Have a degree/diploma or combined relevant work experience and certifications (8-10 years) in Information Systems, law or policy management.
  • Progressive leadership experience with a focus on information security, Governance, Risk and Compliance.
  • Security certifications such as CISM, CISA, and CRISC.
  • Strong understanding of technology risk regulatory, and industry best practice (ISO 27000 Series, NIST, PCI)
  • Proven ability to identify, analyze and translate risk in the context of what it means to achieving business objectives
  • A “continuous improvement” mindset.
  • Sound and practical business minded approach to implementation of a GRC program.
  • Experienced in the ability to influence and guide others across the organization to solve challenging problems.
  • Build and foster strong relationships through collaboration, influencing change, and building consensus
  • You bring your real self to work and you live our values – trust, teamwork, open communication and accountability.
  • Strong communication skills, including technical and business writing
  • Strong problem-solving skills
  • Ability to acquire secret clearance

Nice To Haves

  • Experience with implementing an Information Security Management System (ISMS) and ISO 27001 certification a benefit
  • Experience with leading GRC platforms, technologies and solutions is an asset

Responsibilities

  • Review corporate policies, identify additional policies and develop policies to enhance existing controls and alignment with ISO 27000 series, NIST and PCI standards and frameworks.
  • Socialize policies and standards and provide guidance to employees on adherence to the policies.
  • Coordinate and guide the Information Security Risk Management process risk owners to ensure that risk treatments are effective.
  • Support the internal IT audit function and external auditors and established organizational security certifications.
  • Assist in the development, training and tracking of the internal control environment associated with the various standards (e.g. SOC 2, ISO27001/2).
  • Conduct compliance activities to ensure adherence with relevant policies, standards, regulations, and applicable laws
  • Manage internal auditors and external auditors and activities.
  • Regularly update and review risk portfolio for changes in the environment. Provide regular reporting of significant risks and the risk portfolio to pertinent Management Committees.
  • Drive improvements in the organization arising from the identification of risk and control gaps that balance risk with business operations.
  • Act as a key point of contact when identifying risk to raise awareness with security management and business unit leads on a risk reduction plan.
  • Maintain a registry of risk remediation supported by a governance lifecycle and the implementation of management tools that are technology enabled.
  • Stay abreast in incident response cases and track occurrence and resolution, with strict documentation and reporting.
  • Provide leadership for disaster recovery and business continuity as they relate to security and framework and organization standards.
  • Leverage industry best practices to implement and mature an adaptive Governance, Risk and Compliance (GRC) program
  • Developing and implement reporting metrics, key performance indicators (KPIs), to measure the effectiveness of Information Security Risk Management practice.
  • Work in tandem with other security leadership for annual strategic and budgetary directives
  • Coaching, mentoring, and managing a team to obtain the best possible results from team members
  • Collaborate with business unit stakeholders including Internal Audit, Legal, Enterprise Risk, Data Governance, Privacy, and Vendor Management to ensure a strong security posture.

Benefits

  • Generous vacation and wellness days to help you recharge
  • Comprehensive employer-paid benefits coverage for peace of mind
  • Market-leading employer-funded RRSP program to invest in your future
  • Flexible hybrid work model for better work-life balance
  • Access to a free and confidential 24/7 employee & family assistance program to offer support for you and your immediate family
  • Pregnancy and parental leave top-up to support growing families
  • Charitable donation matching with United Way to amplify your impact
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service