Cybersecurity GRC Consultant (Contract)

CoreFactor is searching for Cybersecurity GRC Consultant on a contract basis for a client in the GTA.<br><br>This position is hybrid and will require the successful incumbent to go into the Mississauga office four (4) times per week.<br><br>The Opportunity:<br><br>As our Governance, Risk Management, and Compliance (GRC) Analyst, you will report to the Director of Security Strategy and Architecture to help us build and grow our cyber practice from the ground up. This is a rare opportunity to join us on our journey on the forefront of cybersecurity, grow with us, and shape the future of the organization.<br><br>This role requires a motivated self-starter, someone who has strong analytical and problem-solving skills, a deep understanding of risk and compliance management principles, excellent communication and report-writing abilities, and foundational knowledge of industry-specific regulations, standards, and frameworks. You are passionate about security and compliance and believe in due diligence.<br><br>Snapshot of a Day-in-the-Life:<br><br><ul><li>Work with leaders (such as CIO, CISO, GRC Manager, Infrastructure Managers) and assist them in strengthening the organization-wide Cybersecurity program </li><li>Work with stakeholders and implement Governance Risk and Compliance (GRC) related initiatives aligned with the organizations vision and strategy </li><li>Conduct risk assessments as per requirements within industry leading standards and frameworks (such as NIST CSF), identify gaps and assist in coordination of activities among other information security functions to resolve the gaps </li><li>Be the primary point of contact for external assessments, audits and participate in interviews, walkthroughs and requirements gathering process </li><li>Lead internal assessments (GRC) and audits, and conduct interviews, documentation review and controls assessment </li><li>Assist in implementation of requirements defined within Cybersecurity related policies and procedures throughout the organization </li><li>Collaborate with other information security functions (such as IAM, PAM, Resilience etc.) and collect Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs), and periodically report it to GRC Manager </li><li>Prepare information security reports for senior leaders (such as CIO, CISO and the Cybersecurity Committee) </li><li>Assist in Implementation of cyber security controls and management of the Cyber Controls Framework (NIST CSF) </li><li>Assist in development of cyber security related training and awareness initiatives </li><li>Keep track of risks within the organization. Ensure risks are appropriately addressed by risk owners within the determined timeline. </li><li>Work with required teams to collect and prepare audit data for C3 audits. <br><br></li></ul>What You’ll Bring:<br><br><ul><li>Understand Information Security Concepts (such as Risk Management, Governance, Data Protection, Incident Management etc.) </li><li>Knowledge of information security standards and regulations such as NIST CSF, NIST SP Series (800-53, 800-82, 800-207), NIST RMF (Risk Management Framework), C3, and CIS Critical Security Controls framework </li><li>Quick learner, strategic thinker, strong team player with ability to multi-task </li><li>Organize, prioritize, and track project activities on a day-to-day basis </li><li>Identify and communicate project risks to managers and IT leads </li><li>Analytical and problem-solving mindset </li><li>Clear verbal/written communication </li><li>Proficiency in Excel, PowerPoint </li><li>Risk assessment and risk analysis </li><li>Risk register management and remediation tracking </li><li>Control design and operating effectiveness assessment </li><li>Audit evidence review and audit readiness </li><li>Third-party risk management and vendor due diligence </li><li>Policy, standard, and procedure interpretation </li><li>Security control framework mapping, including NIST CSF, CIS Controls, ISO 27001, SOC 2, and NIST 800-53 </li><li>KRI/KPI development, tracking, and reporting </li><li>Executive reporting and dashboard preparation </li><li>Exception, issue, and risk acceptance management </li><li>Data classification and data protection risk analysis </li><li>Cloud, IAM, infrastructure, and resilience risk assessment </li><li>Strong documentation and report-writing skills </li><li>Stakeholder management and cross-functional coordination </li><li>GRC tool proficiency, such as ServiceNow GRC/IRM, Archer, OneTrust, AuditBoard, MetricStream, or similar platforms </li><li>People </li><li>Ability to work collaboratively with members across other functions (such as Infrastructure, Cloud, Data etc.) to collaboratively solve problems and build strong processes </li><li>Track risks assigned to members within other functions (such as Infrastructure, Cloud, Data etc.) <br><br></li></ul><strong>Requirements<br><br></strong><ul><li>A minimum of 3 years of security related experience within GRC function </li><li>A minimum of 7 years of security related experience in total within various information security functions (GRC, MITRE ATT&CK, Resilience etc.) </li><li>Experience in conducting risk assessments as per requirements in industry leading standards and frameworks (such as NIST CSF) is a must. </li><li>Experience in conducting ITGC (IT General Controls) controls testing (Preferred) </li><li>Experience in Data Protection, Third-party Risk Management and Resilience (Preferred) </li><li>Prior experience in working in Consumer or Food & Beverage Industry (Preferred) </li><li>Risk register ownership and lifecycle management — documenting risks, assigning owners, tracking remediation, validating closure, and preparing risk status updates. </li><li>Control testing and evidence review — assessing control design and operating effectiveness, reviewing audit evidence, and identifying gaps. </li><li>Third-party/vendor risk assessments — reviewing security questionnaires, SOC 2 reports, ISO 27001 certificates, penetration test summaries, and remediation plans. </li><li>Risk reporting for leadership — preparing executive-level dashboards, KRIs/KPIs, risk summaries, and remediation progress updates. </li><li>Framework mapping — mapping risks and controls to NIST CSF, CIS Controls, ISO 27001, SOC 2, or internal control frameworks. </li><li>Exception and risk acceptance management — documenting exceptions, residual risk, compensating controls, expiry dates, and approval workflows. </li><li>Experience with GRC tools — such as Archer, ServiceNow GRC/IRM, OneTrust, AuditBoard, MetricStream, or similar platforms. </li><li>Data classification and privacy/security risk — evaluating how sensitive data is collected, stored, transmitted, retained, and protected. </li><li>Cloud and infrastructure risk assessments — assessing risks related to cloud platforms, IAM, network security, endpoint controls, backup/recovery, and resilience. </li><li>Audit readiness and compliance support — preparing teams for audits, collecting evidence, coordinating responses, and tracking findings to closure. <br><br></li></ul><strong>Education<br><br></strong><ul><li>Bachelor's degree in Information Technology, Engineering or Computer Science (Preferred) </li><li>Professional certifications in Information Security such as CISSP, CISM, CRISC, CC or equivalent (Preferred)</li></ul>

Back to blog

Other Jobs To Apply

No other job posts for this day.

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...