Senior GRC Specialist

OCS Ontario Cannabis StoreToronto, ON
CA$82,624 - CA$123,508Onsite

About The Position

The Ontario Cannabis Store (OCS) is seeking a Senior GRC Specialist to enhance its Information Technology (IT) Governance, Risk, and Compliance (GRC) program. This role involves collaborating with business stakeholders and cross-functional teams to provide expertise in IT governance, risk management, compliance, and audit. The specialist will leverage ServiceNow GRC capabilities to improve program effectiveness, identify control enhancements, process improvements, and risk mitigation strategies. The ideal candidate will have a strong grasp of IT risk and compliance, stay updated on emerging technologies and threats, and be passionate about developing an effective and adaptable GRC program.

Requirements

  • Bachelor's degree in Information Security, Information Technology, Computer Science, Engineering, or a related field, or an equivalent combination of education and experience.
  • One or more industry certifications such as CISSP, CISA, CRISC, CISM, GRCP, CGRC, or GIAC.
  • 7+ years of progressive experience in Governance, Risk, and Compliance (GRC), Information Security, or a related discipline.
  • Experience supporting risk management, vulnerability management, remediation activities, and/or security operations.
  • Strong knowledge of governance and security frameworks, including NIST, ISO 27001, CIS Controls, COBIT, and related industry standards.
  • Knowledge of Threat Risk Assessment (TRA) methodologies and practices.
  • Strong analytical, documentation, communication, and stakeholder management skills.
  • Ability to assess risk, communicate complex concepts effectively, and collaborate with technical and business stakeholders.

Nice To Haves

  • CISSP, CGRC, or equivalent advanced security and governance certifications are considered an asset.
  • Experience across multiple security domains, including cloud security, security operations, vulnerability management, security architecture, and GRC program administration is preferred.
  • Experience administering or supporting ServiceNow Integrated Risk Management (IRM/GRC) solutions is an asset.
  • Advanced TRA experience is preferred.

Responsibilities

  • Develop, maintain, and provide guidance on IT policies, standards, procedures, playbooks, plans, and SOPs.
  • Coordinate policy reviews, assess control effectiveness, identify governance gaps, and recommend or implement improvements.
  • Support Data Governance and Records & Information Management initiatives.
  • Execute all aspects of the IT risk management program, including identification, assessment, documentation, monitoring, and reporting.
  • Assess risks against industry frameworks and organizational risk appetite.
  • Review mitigation plans, maintain third-party risk processes, and conduct vendor, service, and Threat Risk Assessments (TRAs).
  • Prepare assessment reports, present findings and recommendations to leadership, and support continuous improvement initiatives.
  • Draft risk acceptance documentation and facilitate risk discussions with relevant teams.
  • Administer compliance activities within the ServiceNow GRC platform.
  • Monitor compliance coverage, strengthen control effectiveness, and implement new compliance controls.
  • Support ongoing monitoring, reporting, and continuous improvement of the IT compliance program.
  • Coordinate internal and external audits, ensuring timely delivery of documentation and evidence.
  • Build strong relationships with auditors and provide guidance to stakeholders during audit and remediation.
  • Participate in cross-training initiatives and provide support across Information Security and GRC functions.

Benefits

  • Accessible, equitable and inclusive candidate and employee experience
  • Reasonable accommodation throughout the recruitment process and in employment
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service