Security Specialist
- CAD
- PowerPoint
- Excel
- Visio
- ServiceNow
- Power BI
- Confluence
- Alteryx
- Tableau
- CISA
- CRISC
- CISSP
- Risk Management
Security Specialist
Location: Toronto, ON
Onsite Flexibility: Hybrid
Contract Details
- Position Type: Contract
- Contract Duration: 12 months (with possibility of extension based on business needs and performance; conversion to permanent also possible based on business needs and performance)
- Pay Rate: C$90.00βC$108.00 / Hour (CAD)
- Shift / Schedule: MondayβFriday, core business hours β 37.5 hours per week, 7.5 hours per day; overtime possible
- Travel Requirements: Not required
Job Summary
This role is a backfill position supporting a team focused onTechnology Controls Governance and Reporting. The team manages technology issues throughout the full issue management lifecycle β including regulatory issues, 1st, 2nd, and 3rd line of defense findings, audit compliance issues, data analytics, and automation. The team performs governance functions focused on technology issues and technology controls, governing the process to ensure it stays on track; they sit above the remediation layer and escalate up or down as needed.
Two positions are being hired, both focused onTechnology Governance, Risk & Control (GRC) / Issue Management. One role is more regulatory-focused, and one focuses on 1st, 2nd, and 3rd line of defense issues; the skill sets are very similar, with the primary difference being the type of findings and issues managed. Location is Canada or U.S., with the best candidates considered regardless of location.
The team sits above the remediation function and does not perform the remediation or control testing themselves. Think of issues as tickets requiring remediation β this team oversees the process rather than doing the technical fix. There can be frequent "fire drills" because the GRC process is still being matured, and executives may request information ad hoc and quickly, so candidates need to be able to retrieve and summarize status rapidly.
A typical day involves 3β4 hours in meetings to collect status and collaborate, followed by 2β3 hours performing governance activities, BAU work, providing updates, and creating reports.
Key Responsibilities
- Govern the technology issue-management lifecycle
- Track issues and findings through remediation
- Monitor deadlines, milestones, and progress
- Identify and escalate blockers
- Provide executive visibility and reporting
- Prepare initial drafts and templates for regulatory communications
- Ensure issues stay on track through governance
- Collect status and collaborate with internal stakeholders in meetings (approximately 3β4 hours per day)
- Perform governance activities, provide updates, and create reports
- Retrieve and summarize status rapidly in response to ad hoc executive requests
Required Skills
- 10 years of regulatory exam findings, internal audits, technology issues management, or technology GRC experience
- Proficiency in Microsoft Suite β PowerPoint, Word, Excel, Visio
- Previous control testing and audit experience
- Ability to write reporting intended for executive level
- Strong communication skills β verbal and written
- Strong critical thinking skills
- Strong attention to detail; proactive and organized
- Ability to work independently and collaborate in a team environment
- Understanding of the lifecycle process of issue remediation and technology controls remediation
- Understanding of what a control is, what an issue is, industry standards, and toll gates
- Ability to analyze data
- Good organizational and project/program management skills to stay on top of issues and milestones
- Ability to draft communications to regulators (will not be communicating directly with regulators)
- Proficiency in ServiceNow AGRC module, PowerBI for reporting, SharePoint, Confluence, Excel (including Macros), and Access
Preferred Skills
- Governance, Risk and Controls (GRC) experience
- Big 4 consulting firm experience
- Alteryx, Power BI, Tableau, or any other automation tools for reporting
- CISA and CRISC certifications or equivalent (strongly preferred for the issues management project)
- CISA/CISSP-type certifications (beneficial, but strong relevant experience can compensate β certification is not the primary selection factor)
Required Experience
- 10 years of overall experience in regulatory exams and findings, internal audits, technology issues management, or technology GRC (10 years preferred but flexible for candidates with strong relevant experience)
- Background from one or more of the following transferable disciplines: Internal Audit, Technology Risk Management, GRC, Control Testing or Control-Testing Oversight/Review, Control Design, Issue Management/Remediation Governance, First/Second/Third Line of Defense, Big 4 Consulting, Technology Governance, or strong Project/Program Management
- Banking experience is NOT mandatory β skills are considered transferable across industries
Education Requirements
- Post-secondary education required; certifications are an asset
- CISA and CRISC certifications or equivalent strongly preferred (for the issues management project)
- CISA/CISSP-type certifications beneficial
About the Client
This client is one of North America's largestfinancial services institutions β the sixth-largest bank on the continent by branches β serving approximately 22 million customers across Canada, the United States, Europe, and the Asia-Pacific region. Headquartered in Toronto, Ontario, it operates a full-service financial platform spanning personal and commercial banking, wealth management, insurance, and payment solutions, delivered through a team of over 85,000 employees worldwide. The Bank's U.S. operations have earned Great Place to Work Certification for ten consecutive years, and teams here span retail banking advisors, commercial lenders, wealth management professionals, risk analysts, and technology specialists β including the GRC and Technology Controls Governance professionals this role supports.
About GTT
GTT is a minority-owned staffing firm and a subsidiary of Chenega Corporation, a Native American-owned company in Alaska. We highly value diverse and inclusive workplaces and support Fortune 500 organizations across banking, financial services, technology, life sciences, biotech, utilities, and retail sectors throughout the U.S. and Canada.
Job Number: 26-14818
#LI-Hybrid #LI-GTT #gttca
Security Specialist Β· GTT, LLC