GRC Contractor (Cybersecurity Risk & Compliance)

Job# FT31016
Location Alberta, AB
Job Type Contract
Salary Negotiable
Contact [email protected]
Status ACTIVE
Date Posted September 11, 2026
Submission Deadline September 18, 2026
Job Stream
Benefits Contract duraion:  Six (6) Months

Details

Job Description :Our client in Alberta is looking for a GRC Contractor (Cybersecurity Risk & Compliance)

Must Have Primary Skills :
  • Provide regular status updates and reporting on key risks, vulnerabilities, third-party assessments, and awareness activities
  • Hands-on experience with vulnerability management tools such as Rapid7.
  • Experience performing vendor/third-party security assessments.
  • Experience planning and executing phishing simulations and security awareness campaigns.


Nice To Have Secondary Skills :
Same as above

Proven Experience In :
  • Conduct security risk assessments for applications, systems, projects, and technology initiatives.
  • Perform third-party/vendor security risk assessments, including reviewing security questionnaires, SOC reports, certifications, and other security documentation
  • Identify, assess, document, and track security risks and recommend appropriate remediation or mitigation actions.
  • Operate vulnerability management (VM) tools to identify, prioritize, track, and report vulnerabilities
  • Review and validate vulnerability findings and work with technology teams to drive remediation
  • Track security issues, risks, and exceptions through to resolution
  • Plan and execute phishing simulation campaigns to assess employee awareness and identify areas for improvement
  • Develop security awareness materials, including phishing awareness, security tips, training content, and employee communications
  • Analyze phishing campaign results and provide recommendations to improve employee security awareness
  • Prepare clear risk assessment, vulnerability, third-party risk, and awareness reports for stakeholders
  • Support continuous improvement of security risk, vulnerability management, third-party risk, and security awareness processes.
  • Provide regular status updates and reporting on key risks, vulnerabilities, third-party assessments, and awareness activities
IND1
[email protected]