Security Risk Management Specialist

🔥 12 hours ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Wealthsimple

Wealthsimple

1001 - 5000 employees

Founded 2014

💳 Fintech

🏦 Banking

💸 Finance

🔥 Funding within the last year

💰 $393M Series E - Wealthsimple on 2025-10

Fintech • Banking • Finance

Wealthsimple is a Canadian financial technology company that provides consumer banking, investing, and wealth management services. It offers chequing accounts, savings, credit cards, self-directed trading (stocks, ETFs, options), cryptocurrency trading, managed portfolios, tax services, and advisory wealth management for high-net-worth clients. Wealthsimple combines digital-first banking and low-fee investing products aimed at retail customers, along with tools and educational content to support personal finance.

📋 Description

• Support the end-to-end IT and security risk management lifecycle, including risk identification, assessment, treatment tracking, and reporting • Maintain and continuously improve the enterprise IT/security risk register, ensuring risks are accurately documented, rated, and assigned to appropriate owners • Perform risk assessments across technology domains (cloud infra, access management, application security) and third-party assessments using the appropriate methodology for each • Partner with control owners and business stakeholders to evaluate the effectiveness of risk mitigation controls and identify gaps • Integrate vendor and technology risk findings into the risk register to facilitate tracking and remediation across both IT/Security and Third-Party Risk Management. • Contribute to the development and maintenance of risk policies, standards, and procedures • Assist in preparing risk reporting and dashboards for senior leadership and committee-level audiences • Monitor the threat and vulnerability landscape and help translate emerging risks into actionable insights for the business • Support security and compliance initiatives, including PCI DSS, SOC 2, and NIST, from a risk lens, ensuring risk findings are integrated into broader compliance activities • Participate in risk-related work streams tied to new product launches, infrastructure changes, and strategic initiatives

🎯 Requirements

• 3–5 years of experience in IT risk management, information security, or a related GRC function, ideally within financial services or fintech • Solid understanding of IT and security risk frameworks such as NIST CSF, ISO 27001, or FAIR • Familiarity with key technology risk domains including cloud (AWS preferred), identity and access management and vulnerability management • Experience conducting third-party and vendor reviews, with knowledge of due diligence review methodology, is an asset • Experience maintaining risk registers and supporting risk assessment processes • Working knowledge of compliance frameworks such as SOC 2, PCI DSS, and/or NIST is a strong asset • Strong analytical and written communication skills, with the ability to translate technical risk findings into clear business language • Comfortable working cross-functionally with both technical and non-technical stakeholders • Experience with GRC tools and risk management platforms (e.g.Jira, Drata) is an asset • Self-starter who can operate independently, manage competing priorities, and drive work to completion • Relevant certifications are an asset (CRISC, CISA, CISSP, or equivalent)

🏖️ Benefits

• Top-tier health benefits and life insurance • Long-term group savings with employer match, through Wealthsimple for Business • 20 vacation days, 4 wellness days, and unlimited sick and mental health days per year • 90 days away: work outside Canada for up to 90 days per year • Employee resource groups, including Rainbow (2SLGBTQ), Women of WS, and Black at WS

Apply Now

Similar Jobs

🕒 4 days ago

Medavie

5001 - 10000

⚕️ Healthcare Insurance

🧘 Wellness

Senior Security Architect responsible for enterprise-wide security architectures in national health solutions. Collaborating with leaders to ensure security aligns with business objectives and regulatory requirements.

🕒 4 days ago

Fortinet

10,000+ employees

🔒 Cybersecurity

☁️ SaaS

🤝 B2B

Presales Security Expert enabling the success of Fortinet's growing cybersecurity business. Collaborating with Account Managers and building technical relationships with customers for secure platform solutions.

🕒 4 days ago

Jane

1 - 10

🤝 B2B

🚗 Transport

Enterprise Security Engineer at Jane focusing on endpoint security and identity management. Collaborating with teams to protect sensitive health information using AI and automation.

🕒 6 days ago

Desjardins

10,000+ employees

🏦 Banking

💸 Finance

Senior Offensive Security Advisor helping mitigate threats to Desjardins's systems and networks. Leading strategic initiatives and advising on security posture.

🗣️🇫🇷 French Required

🕒 6 days ago

Desjardins

10,000+ employees

🏦 Banking

💸 Finance

Senior Offensive Security Advisor leading development projects and advising on security measures for Desjardins. Focus on identifying and mitigating threats across systems and applications.

🗣️🇫🇷 French Required