Director, Governance, Risk, and Compliance (GRC) at Procom
Calgary, AB, Canada -
Full Time


Start Date

Immediate

Expiry Date

08 Dec, 25

Salary

0.0

Posted On

09 Sep, 25

Experience

10 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Security, Leadership, Cobit, Itil, Cisa, Risk, Regulatory Requirements

Industry

Financial Services

Description

DIRECTOR, GOVERNANCE, RISK, AND COMPLIANCE

On behalf of our Financial Services client, Procom is searching for a Director, Governance, Risk, and Compliance for a permanent role. This position is a hybrid position with 2 days onsite at our client’s Calgary or Edmonton office.

DIRECTOR, GOVERNANCE, RISK, AND COMPLIANCE - JOB DESCRIPTION:

Our client is expanding its Information Security Department and is seeking a Director of Governance, Risk, and Compliance. This role involves overseeing security governance frameworks and managing information security risk processes to ensure compliance with audit and regulatory requirements.

DIRECTOR, GOVERNANCE, RISK, AND COMPLIANCE - MANDATORY SKILLS:

  • 10+ years’ experience in Information Security and Risk leadership roles.
  • Experience with frameworks and standards such as NIST Cybersecurity Framework, COBIT, and ITIL.
  • Strong knowledge of regulatory requirements and their application to information security and risk.
  • Leadership and strategic planning skills for building and guiding security governance teams.
  • Certified Information Systems Security Professional (CISSP).

DIRECTOR, GOVERNANCE, RISK, AND COMPLIANCE – NICE-TO-HAVE SKILLS:

  • Certified Information Security Manager (CISM).
  • Certified Information Systems Auditor (CISA).
  • Certified in Risk and Information Systems Control (CRISC).
  • A strong preference for candidates residing within Alberta.
Responsibilities
  • Develop and implement enterprise-level security governance frameworks.
  • Track and report on internal IS risks and third-party IT risks to ensure business continuity and security.
  • Develop metrics and KRIs for board and internal teams to demonstrate the effectiveness of security controls.
  • Ensure compliance with regulatory cybersecurity requirements and oversee security audits.
  • Lead confidential investigations and evidence collection while ensuring legal and ethical handling of sensitive information.
  • Develop and implement security awareness programs to educate employees and promote a security-conscious culture.
Loading...