Jobedly Post a Job

GRC Lead/Security Analyst

Ivalua · Montreal - Canada
Full-timeInformation SecurityTechnology$111,000–$150,000/yr
Apply on Jobedly ⚡ One-click AI Apply

About the Grc Lead Security Analyst role

Grc Lead Security Analyst positions focus on delivering results in their domain. This page aggregates open Grc Lead Security Analyst roles and what employers typically expect.

GRC Lead/Security Analyst (Montreal - Canada) Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions. COMPANY OVERVIEW At Ivalua we are a global community of exceptional professionals, who believe that digital transformation revolutionizes supply chain sustainability and resiliency to unlock the power of supplier collaboration. We achieve this through our leading cloud-based spend management platform that empowers hundreds of the world's most admired brands to effectively manage all categories of spend and all suppliers to increase profitability, improve ESG (environmental, social, and corporate governance) performance, lower risk, and improve productivity. Driven by our passions and fueled by our shared ambitions, we empower and challenge each other to create meaningful experiences for our colleagues, customers, partners, and communities. Learn more at www.ivalua.com . Follow us on LinkedIn THE OPPORTUNITY CONTEXT: You will be part of the InfoSec team with a mission to build, maintain, and continuously improve our Information Security program, providing peace of mind and assurance of protection and safety to our customers. Our team is hands-on, with a strong problem-solving mindset, capable of thinking holistically about implementation and providing solutions to address our customers' long-term challenges. We work hard and play hard, enjoying various indoor and outdoor activities organized by the company, allowing you to focus, collaborate, and unleash your creativity. ROLE: We are looking for a GRC Lead/Security Analyst to join our InfoSec team. This role will help drive various GRC activities which include supporting prospect and customer security questions, maintaining security policies, supporting security audits and assessments and driving new security certifications/compliance initiatives. WHAT YOU WILL DO WITH US Lead and support compliance initiatives in accordance with global and regional standards, including SOC 1/SOC 2, ISO 27001, IRAP, PCI-DSS, SecNumCloud, Cyber Essentials Plus (CE+), BSI C5, and NIST 800-53. Evaluate technical controls across the entire technology stack, including all layers of the TCP/IP model (e.g., network segmentation, firewall rules, TLS/SSL configuration, IDS/IPS, access controls, application security, encryption in transit and at rest, and cloud security configurations), and translate security requirements into concrete guidelines for engineering and infrastructure teams. Lead and manage client security audits, security questionnaires, and contract reviews, primarily for the EMEA region. Participate in the negotiation and review of French contracts to ensure alignment with security and compliance requirements. Participate in meetings with prospects and clients and effectively present Ivalua’s security architecture and controls to them. Lead or support internal and third-party security risk management processes, including the identification, analysis, scoring, mitigation planning, and ongoing monitoring of risks. Support ongoing compliance monitoring activities using manual processes, automation, and GRC tools to maintain the effectiveness of controls, generate audit evidence, and ensure ongoing audit readiness. Ensure the implementation and coordination of key security and availability controls, such as business impact assessments, disaster recovery plan tests, security incident response drills, access reviews, etc. YOUR PROFILE If you have the below experience and strengths this role could be for you: Skills and Experience: At least 4 years of experience as a GRC Security Analyst. Solid practical knowledge of security, risk, and compliance frameworks (e.g., NIST CSF & 800-53, ISO 27001, SOC, HITRUST, HIPAA, PCI-DSS, GDPR). Direct experience managing audits, self-assessments, or risk assessments against one or more of the InfoSec frameworks listed above. Experience in implementing or supporting security risk management processes (risk assessments, risk…

Salary estimate

$111,000 – $150,000/yr
Provided by the employer.

Skills for this role

RESTNegotiationSecurityAutomation

Resume tips for Grc Lead Security Analyst applicants

Interview preparation

Prepare concrete STAR-format stories that show Grc Lead Security Analyst outcomes you drove.

Research the employer's product and recent news before the interview.

Be ready to explain how you'd approach a typical Grc Lead Security Analyst problem end to end.

Have thoughtful questions ready about the team, tools and success metrics.

About Ivalua

Ivalua is actively hiring on Jobedly. Explore their open roles and what it's like to work there.

Apply on Jobedly ⚡ One-click AI Apply

Similar jobs

Companies hiring for similar roles