Retour à la recherche
BJ
Bennett JonesSource d’offres vérifiée

Information Security, GRC Analyst

Offre en anglais

The analyst will implement and maintain the organization's GRC program, focusing on third-party security compliance and internal controls. Key duties include managing security questionnaires, conducting vendor due diligence, and maintaining ISO 27001 and ISO 22301 certifications.

  • Sur place
  • Calgary, AB
  • Publié 28 juill. 2026
  • Postuler avant le 27 août 2026
  • 1 poste

Résumé du poste

Ranked a Best Employer in Canada for 25 years, Bennett Jones is one of Canada’s premier business law firms and home to 450 lawyers and business advisors. With deep experience in complex transactions and litigation matters, and offices in Calgary, Edmonton, Montréal, Toronto, Vancouver and New York, the firm is well equipped to advise businesses and investors with Canadian ventures and connect Canadian businesses and investors with opportunities around the world. Serving clients since 1922, we are proud to be the firm that businesses trust with their most complex legal matters. We are currently recruiting for the following role in our Calgary office: Information Security, GRC Analyst The Role The Information Security GRC analyst, reporting to the Director Information Security GRC, will support the implementation and maintenance of the organization’s Governance, Risk, and Compliance (GRC) program, with a strong focus on third party security compliance, security governance, and internal controls. This role will contribute to maintaining a formally structured, risk-based security framework aligned with industry standards such as ISO 27001 and ISO 22301. The position requires a minimum of three years of information security experience in a similar position and excellent communication skills. Essential Functions Oversee the cybersecurity compliance program for third parties, including: Managing requests from clients, prospects, auditors, cyber-insurers, or others, related to our security program, to ensure the timely and accurate response to security questionnaires and associated requests. Managing the compliance of the Firm's key IT vendors with information security, including a comprehensive initial security due diligence, an annual security re-certification, and a continuous monitoring of the vendors' security profile. Assist with the performance of important internal security processes and controls, including: Tracking the status of key internal security tasks and following up with the responsible person to ensure these tasks are conducted in time and as per the annual schedule. Maintaining security dashboards, metrics, and reports as required for the team, the IT Department and senior management. Making suggestions, and improving existing security standards and procedures. Conduct security tasks as required to maintain the Firm's ISO 27001 and ISO 22301 certifications: Perform limited internal security audits; Collaborate with IT and business functions to remediate compliance gaps; Maintain documentation related to compliance activities, controls, and audit findings; Assist with ad-hoc security investigations; Stay up to date with emerging threats, current regulations, existing standards, and industry trends. Qualifications Bachelor's degree in information technology, computer Science, cybersecurity, or related field Minimum three years of experience in IT compliance, risk management, or information security Knowledge of commonly used security frameworks (e.g., ISO 27001, ISO 22301, NIST) Experience with security risk management processes and compliance tools Outstanding oral and written communication skills Excellent interpersonal relationship skills High-level of attention to detail and accuracy High degree of personal initiative and maturity with an ability to work with minimal supervision Ability to prioritize tasks effectively, respect deadlines, and report any issues, conflict or roadblock in the performance of operational activities, and the planning and scheduling of tasks and projects Professional certifications as follows are an asset CISSP, CISA, CISM, CRISC SANS/GIAC, CompTIA Security+, CEH Apply To Human Resources Bennett Jones Services Limited Partnership 4500 Bankers Hall East 855 - 2 Street SW Calgary, AB T2P 4K7 E-mail: [email protected]

Ce que vous ferez

The analyst will implement and maintain the organization's GRC program, focusing on third-party security compliance and internal controls. Key duties include managing security questionnaires, conducting vendor due diligence, and maintaining ISO 27001 and ISO 22301 certifications.

Exigences

Candidates must have a bachelor's degree in a technical field and at least three years of experience in IT compliance or information security. Proficiency in security frameworks like ISO and NIST, along with strong communication skills, is required.

Autres compétences pertinentes

Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.

  • Third Party Security Compliance
  • Security Governance
  • Internal Controls
  • Risk Management
  • ISO 27001
  • ISO 22301
  • Security Auditing
  • Compliance Monitoring
  • Security Questionnaires
  • Due Diligence
  • Security Metrics
  • Technical Documentation

Domaines d’emploi

  • Security & Safety
  • Technology
  • Legal
  • Consulting

Renseignements supplémentaires

Formation minimale
Diplôme professionnel
Expérience minimale
2+ ans
Postuler avant le
27 août 2026
Langue de l’offre
anglais
Heures de travail
40 heures par semaine
Niveau d’expérience
Mid-Senior level