Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Security Governance, Risk and Compliance Specialist image - Rise Careers
Job details

Security Governance, Risk and Compliance Specialist

Having recognized the advantages of remote work, such as improved employee morale, increased productivity, and positive impacts on both employee wellbeing and the environment, we are proud to be a digital-first company. Our digital-first work environment, combined with our conveniently located offices and collaborative workspaces, provides our team with the freedom and flexibility to work in the most productive way for them.

About us

Tecsys is a fast-growing innovator offering supply chain solutions to industry leading healthcare systems, hospitals, and pharmacy businesses to distributors, retailers, and 3PLs. We work with industry leaders to transform their supply chains through technology. If you thrive on tackling interesting challenges with continuous learning opportunities, then Tecsys could be a good fit for you!

About the Role

We are seeking a Security Governance, Risk and Compliance specialist who will be involved in defining how security can enable business initiatives, and how we should meet security best practices, as well as applicable various contractual and regulatory requirements. The successful candidate will be supporting the implementation of a security risk management framework. The GRC specialist’s role will also encompass the management of vendor risk and business continuity programs. As a security subject matter expert, you will recommend improvements to reduce, contain and mitigate identified risks, as well as partake in various business and security initiatives to improve Tecsys’s security maturity.

What you’ll do

  • Support continuous security risk management framework.
  • Collaborate with technical teams for the development, implementation and monitoring of required corrective action plans relating to security compliance issues or audit deficiencies.
  • Collaborate with stakeholders to define processes, automate and continuously monitor information security controls, exceptions, risks, testing and evidence gathering.
  • Develop reporting metrics and dashboards.
  • Help identify cyber risks and solve various governance gaps and process inefficiencies.
  • Develop, execute and actively partake in internal and external security and compliance assessment initiatives such as SOC 2, PCI-DSS, NIST, FedRAMP
  • Review and optimize vendor risk management program.
  • Monitor existing controls and conduct periodic audits and reviews to ensure their efficiency and operating effectiveness, and to identify and report on potential issues.
  • Collaborate with internal IT and business teams to identify cyber risks and prioritize security compliance-related improvements
  • As security subject matter expert, support IT and cyber teams on the implementation of controls to meet security and privacy compliance requirements and best practices
  • Support the development, review, update and optimization of security documentation.

Formal Education & Certification

  • Bachelor’s degree in information systems or equivalent experience
  • Minimum 3 years of cumulated hands-on experience 

Knowledge & Experience

  • Experience in the development and implementation of governance, risk and compliance strategy and security control framework.
  • Experience in risk assessments and cyber risk management methodology/processes.
  • Broad knowledge of defense in depth security concepts and best practices through practical experience.
  • Good knowledge of cybersecurity frameworks such as NIST, CIS, PCI DSS.
  • Familiarity with business continuity process and planning.
  • Familiarity with IP networking fundamentals and internet protocols.
  • Familiarity with Linux, Mac, and Windows operating systems, mobile devices, and the IT application landscape.
  • Familiarity with public cloud Infrastructure-as-a-Service (IaaS) environments and Software-as-a-Service (SaaS) solutions. 

Personal Attributes

  • Ability to work with minimal supervision.
  • Strong ability to define problems, collect and analyze data, establish facts and draw valid conclusions. 
  • Positive attitude and agile mindset.
  • Motivated, team, and customer oriented.
  • Not afraid to fail.
  • Excellent interpersonal skills.
  • Ability to plan and deliver on commitment.
  • Strong proficiency in both written and verbal English communication essential for effective correspondence with clients, suppliers, business partners, and colleagues beyond the province of Quebec.

We understand that experience comes in many forms and that careers are not always linear. If you don't meet every requirement in this posting, we still encourage you to apply.

At Tecsys, we are committed to fostering a diverse and inclusive workplace where all employees feel valued, respected, and empowered. We believe that diversity drives innovation and strengthens our ability to deliver exceptional solutions. We welcome and encourage applicants from all backgrounds, experiences, and perspectives to join our team.

Tecsys is an equal opportunity employer. Accommodation is available for applicants selected for an interview.

NB: if you are applying to this position, you must be a Canadian Citizen or a Permanent Resident of Canada, OR, have a valid Canadian work permit.

Average salary estimate

$80000 / YEARLY (est.)
min
max
$70000K
$90000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security Governance, Risk and Compliance Specialist, Tecsys Inc.

At Tecsys, we are excited to invite applications for the role of Security Governance, Risk and Compliance Specialist. We pride ourselves on being a digital-first company, which allows our team to experience the benefits of remote work while also enjoying collaborative office spaces when needed. As a leading provider of supply chain solutions for healthcare systems and organizations, we tackle interesting challenges and foster continuous learning. In this role, you'll play a key part in ensuring that our security initiatives align with business goals while adhering to regulatory requirements. You will be instrumental in supporting the implementation of a security risk management framework, engaging with various stakeholders, and enhancing our vendor risk management strategies. Your expertise will help detect potential cyber risks, keep us compliant with standards like SOC 2, PCI-DSS, and NIST, and assist in developing reporting metrics that drive action. If you're passionate about improving security maturity and possess a proactive mindset, you'll fit right in with our team. Join us at Tecsys where we prioritize employee growth and innovation in tackling the evolving challenges of supply chain security!

Frequently Asked Questions (FAQs) for Security Governance, Risk and Compliance Specialist Role at Tecsys Inc.
What are the specific responsibilities of a Security Governance, Risk and Compliance Specialist at Tecsys?

As a Security Governance, Risk and Compliance Specialist at Tecsys, you will be responsible for supporting the continuous security risk management framework and developing corrective action plans for security compliance. You'll collaborate closely with technical teams, monitor information security controls, manage vendor risks, and partake in security assessments such as SOC 2 and PCI-DSS, creating a safer environment for our operations.

Join Rise to see the full answer
What qualifications do I need to become a Security Governance, Risk and Compliance Specialist at Tecsys?

To be considered for the position of Security Governance, Risk and Compliance Specialist at Tecsys, you should hold a Bachelor’s degree in Information Systems or a related field along with a minimum of three years of hands-on experience in risk management or cybersecurity. Familiarity with industry standards and frameworks like NIST, CIS, and PCI-DSS is essential.

Join Rise to see the full answer
How does Tecsys support the professional development of its Security Governance, Risk and Compliance Specialists?

Tecsys is committed to the growth of its employees, including those in the role of Security Governance, Risk and Compliance Specialist. We provide continuous learning opportunities through various training programs and hands-on experiences, encouraging you to tackle challenging security issues while fostering a culture of innovation and collaboration within the organization.

Join Rise to see the full answer
What does the work environment look like for a Security Governance, Risk and Compliance Specialist at Tecsys?

At Tecsys, the work environment for a Security Governance, Risk and Compliance Specialist is dynamic and supportive. We embrace a digital-first approach that allows for remote work, while also offering well-equipped office spaces for team collaboration. This flexibility promotes a productive atmosphere where security initiatives can thrive.

Join Rise to see the full answer
What personal attributes do successful Security Governance, Risk and Compliance Specialists at Tecsys possess?

Successful Security Governance, Risk and Compliance Specialists at Tecsys typically exhibit a positive attitude, strong analytical skills, and the ability to work independently. They'll also need to demonstrate excellent communication skills, creativity in problem-solving, and a customer-oriented mindset, which are vital for effectively collaborating with clients and colleagues in this role.

Join Rise to see the full answer
Common Interview Questions for Security Governance, Risk and Compliance Specialist
Can you explain your experience with developing a security risk management framework?

In answering this question, provide specific examples of frameworks you’ve worked on, including any methodologies you used. Highlight your understanding of risk assessments and how they integrate with business processes to promote security compliance.

Join Rise to see the full answer
How do you stay updated on the latest cybersecurity threats and compliance regulations?

Demonstrate your commitment to staying informed by discussing your resources, such as following industry news, participating in forums, attending conferences, or engaging in professional networks relevant to cybersecurity and compliance.

Join Rise to see the full answer
Describe a time you identified a security risk and how you managed it.

Share a specific example of a security risk you encountered, how you assessed it, the steps you took to mitigate it, and the outcome. This shows your proactive approach and problem-solving skills in real situations.

Join Rise to see the full answer
What is your experience with regulatory compliance frameworks like NIST or PCI DSS?

Be prepared to discuss your hands-on experience with implementing specific compliance measures related to these frameworks, any audits you’ve participated in, and how you facilitated adherence to their standards within your previous roles.

Join Rise to see the full answer
How do you prioritize tasks when managing multiple security compliance initiatives?

Illustrate your organizational skills and describe your approach to prioritization—whether using project management tools, having consistent communication with stakeholders, or employing a risk-based methodology to handle compliance initiatives effectively.

Join Rise to see the full answer
What strategies do you employ to encourage a security-conscious culture within an organization?

Share your methods for fostering collaboration, such as conducting training sessions, developing clear reporting channels, and promoting awareness programs to engage employees at all levels in security practices.

Join Rise to see the full answer
Can you outline your approach to vendor risk management?

Discuss your systematic approach to evaluating vendor security measures, conducting audits, and how you establish agreements to ensure that vendor practices align with the organization’s security policies.

Join Rise to see the full answer
What types of reporting metrics do you consider important for assessing security compliance?

Mention specific metrics you’ve used, their importance in tracking compliance, and how these metrics help drive decision-making and policy adjustments within the organization.

Join Rise to see the full answer
How would you handle a situation where a team member is resistant to following security protocols?

Explain your strategies for addressing resistance, such as open communication to understand their concerns, providing alternative solutions, and reinforcing the importance of compliance to protect both the individual and the organization.

Join Rise to see the full answer
What are the most significant challenges faced by Security Governance, Risk and Compliance Specialists today?

Discuss current challenges within the industry, such as evolving threats and compliance requirements, and showcase your insight into how best practices can be adapted to overcome these challenges.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Gcore Remote Poland, Serbia, Luxembourg, Germany
Posted 11 days ago
Photo of the Rise User
Posted 6 days ago
JD Sports Remote Bury, England, United Kingdom
Posted 2 days ago
Photo of the Rise User
DataCamp Remote Buenos Aires, Argentina
Posted 8 days ago
Photo of the Rise User
Impinj Hybrid Seattle, Washington, United States
Posted 6 days ago
Photo of the Rise User
Posted 9 days ago
Photo of the Rise User
Posted 5 days ago

Founded in 1983, Tecsys provides transformative supply chain solutions that equip our customers to succeed in a rapidly-changing omnichannel world. Tecsys is headquartered in Montreal, Quebec.

2 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
December 8, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!