Security Risk Management Specialist

🕒 July 20

🇨🇦 Canada – Remote

💵 CA$89.6k - CA$112k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Wealthsimple

Wealthsimple

1001 - 5000 employees

Founded 2014

💼 Consulting

🛡️ Insurance

💳 Fintech

🔥 Funding within the last year

💰 $393M Series E - Wealthsimple on 2025-10

Consulting • Insurance • Fintech

Wealthsimple is a Canadian financial technology company that provides consumer banking, investing, and wealth management services. It offers chequing accounts, savings, credit cards, self-directed trading (stocks, ETFs, options), cryptocurrency trading, managed portfolios, tax services, and advisory wealth management for high-net-worth clients. Wealthsimple combines digital-first banking and low-fee investing products aimed at retail customers, along with tools and educational content to support personal finance.

📋 Description

• Support the end-to-end IT and security risk management lifecycle, including risk identification, assessment, treatment tracking, and reporting • Maintain and continuously improve the enterprise IT/security risk register, ensuring risks are accurately documented, rated, and assigned to appropriate owners • Perform risk assessments across technology domains (cloud infra, access management, application security) and third-party assessments using the appropriate methodology for each • Partner with control owners and business stakeholders to evaluate the effectiveness of risk mitigation controls and identify gaps • Integrate vendor and technology risk findings into the risk register to facilitate tracking and remediation across both IT/Security and Third-Party Risk Management. • Contribute to the development and maintenance of risk policies, standards, and procedures • Assist in preparing risk reporting and dashboards for senior leadership and committee-level audiences • Monitor the threat and vulnerability landscape and help translate emerging risks into actionable insights for the business • Support security and compliance initiatives, including PCI DSS, SOC 2, and NIST, from a risk lens, ensuring risk findings are integrated into broader compliance activities • Participate in risk-related work streams tied to new product launches, infrastructure changes, and strategic initiatives

🎯 Requirements

• 3–5 years of experience in IT risk management, information security, or a related GRC function, ideally within financial services or fintech • Solid understanding of IT and security risk frameworks such as NIST CSF, ISO 27001, or FAIR • Familiarity with key technology risk domains including cloud (AWS preferred), identity and access management and vulnerability management • Experience conducting third-party and vendor reviews, with knowledge of due diligence review methodology, is an asset • Experience maintaining risk registers and supporting risk assessment processes • Working knowledge of compliance frameworks such as SOC 2, PCI DSS, and/or NIST is a strong asset • Strong analytical and written communication skills, with the ability to translate technical risk findings into clear business language • Comfortable working cross-functionally with both technical and non-technical stakeholders • Experience with GRC tools and risk management platforms (e.g.Jira, Drata) is an asset • Self-starter who can operate independently, manage competing priorities, and drive work to completion • Relevant certifications are an asset (CRISC, CISA, CISSP, or equivalent)

🏖️ Benefits

• Top-tier health benefits and life insurance • Long-term group savings with employer match, through Wealthsimple for Business • 20 vacation days, 4 wellness days, and unlimited sick and mental health days per year • 90 days away: work outside Canada for up to 90 days per year • Employee resource groups, including Rainbow (2SLGBTQ), Women of WS, and Black at WS

Apply Now

Similar Jobs

🕒 July 17

Medavie

5001 - 10000

🏥 Healthcare

⚕️ Healthcare Insurance

Senior Security Architect responsible for enterprise-wide security architectures in national health solutions. Collaborating with leaders to ensure security aligns with business objectives and regulatory requirements.

🇨🇦 Canada – Remote

💵 $99.2k - $132.2k / year

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🕒 July 17

Fortinet

10,000+ employees

🔒 Cybersecurity

☁️ SaaS

🤝 B2B

Presales Security Expert enabling the success of Fortinet's growing cybersecurity business. Collaborating with Account Managers and building technical relationships with customers for secure platform solutions.

🇨🇦 Canada – Remote

💰 $6.5M Series B on 2005-01

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🕒 July 16

Jane.app

201 - 500

🏥 Healthcare

💼 Consulting

⚕️ Healthcare Insurance

Enterprise Security Engineer at Jane focusing on endpoint security and identity management. Collaborating with teams to protect sensitive health information using AI and automation.

🇨🇦 Canada – Remote

💵 $98.4k - $147.6k / year

⏰ Full Time

🟢 Junior

🟡 Mid-level

👮‍♂️ Cybersecurity / Security Engineer

🕒 July 11

Fortinet

10,000+ employees

🔒 Cybersecurity

☁️ SaaS

🤝 B2B

Presales Security Expert at Fortinet designing secure platform solutions. Collaborating with customers and stakeholders on technical security solutions and opportunities.

🇨🇦 Canada – Remote

💰 $6.5M Series B on 2005-01

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🕒 July 7

Thomson Reuters

10,000+ employees

💼 Consulting

⚖️ Legal

🛡️ Insurance

Senior Specialist Legal Editor creating high-quality legal content for Practical Law in data privacy & cybersecurity. Collaborating with teams and leveraging AI technologies for legal solutions while based in Canada.

🇨🇦 Canada – Remote

💵 $126k - $176k / year

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer