- Company Name
- Export Development Canada | Exportation et développement Canada
- Job Title
- Analyste en cybersécurité, Gouvernance, Risques et Conformité (GRC)
- Job Description
-
**Job Title:**
Cybersecurity Analyst – Governance, Risk & Compliance (GRC)
**Role Summary:**
Support the development, maintenance, and enforcement of EDC’s cybersecurity governance framework. Provide operational assistance for risk assessments, maturity evaluations, and compliance monitoring to ensure alignment with internal policies and industry standards.
**Expectations:**
- Maintain up‑to‑date governance documents, policies, standards, and evidence repositories.
- Deliver timely support for risk assessment services and access to EDC‑managed tools.
- Coordinate capability‑maturity assessments, identify gaps, and track remediation progress.
- Monitor adherence to internal cybersecurity policies and external regulatory requirements.
**Key Responsibilities:**
- Draft and version‑control cybersecurity governance frameworks, policies, and guidelines under senior team direction.
- Assist in the execution of risk assessments, including tool provisioning and reference‑material management.
- Lead and coordinate cybersecurity capability‑maturity assessments, collecting data, analyzing gaps, and reporting findings.
- Contribute to continuous compliance monitoring, documenting evidence and supporting audit activities.
- Collaborate with the Digital & Technology Solutions Group to integrate security considerations into digital, data, infrastructure, and project initiatives.
- Stay informed on emerging cybersecurity trends, standards, and technologies to advise on best practices.
**Required Skills:**
- Strong understanding of cybersecurity frameworks (e.g., NIST CSF, ISO 27001/27002, CIS Controls).
- Experience with GRC tools and risk‑assessment methodologies.
- Ability to conduct maturity assessments and gap analysis.
- Excellent written and verbal communication for policy documentation and stakeholder interaction.
- Analytical mindset with attention to detail and strong organizational skills.
- Ability to work collaboratively in a hybrid team environment.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, Information Technology, or a related field (or equivalent experience).
- Preferred certifications: CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or comparable GRC credentials.