Back to all jobs

TECH LEAD - GRC ENGINEERING

Sales & marketing
BDCMontréal, QC, CAPosted 2026-07-22
Temps plein$750accessibility@bdc.ca.

Description

We are banking at another level.

Choosing BDC as your employer means working in a healthy, inclusive, and skilled workplace that puts forward the best conditions to bring together unique teams where employees are empowered to act. It also means being at the centre of ambitious economic and financial projects to see further and to do things differently, to fuel the success of Canadian entrepreneurs.

Choosing BDC as your employer also means

  • Flexible and competitive benefits, including an Employee Savings and Investment Plan where BDC matches part of your voluntary contributions, a Defined Benefit Pension Plan, a $750 wellness and health care spending account, to name a few
  • In addition to paid vacation each year, five personal days, sick days as necessary, and our offices are closed from December 25 to January 1
  • A hybrid work model that truly balances work and personal life
  • Opportunities for learning, training and development, and much more...
  • Explore the BDC Way in our Culture Book

POSITION OVERVIEW

BDC is seeking a Tech Lead to join the Risk \& Value Office squad in Montréal. This role combines technical leadership, risk expertise, and data-driven delivery to advance InfoSec’s ability to monitor and manage its risk landscape. The Tech Lead will guide the design and implementation of GRC engineering capabilities, ensure the quality and consistency of squad deliverables, and drive the adoption of scalable analytics, automation, and reporting solutions. Acting as a key advisor, the role also strengthens technology risk management practices and enables actionable, executive-level insights.

CHALLENGES TO BE MET

Technical Leadership \& Squad Enablement

  • Act as the tech lead for the Risk \& Value Office squad, providing guidance on GRC engineering and risk management.
  • Review and challenge the quality of the squad deliverables to ensure alignment with InfoSec standards and executive expectations.
  • Coach and mentor squad members on GRC engineering practices and risk management concepts, fostering capability uplift and autonomy.
  • Drive adoption of best practices in data, automation, and secure development, ensuring consistency across initiatives.
  • Provide technical guidance in prioritization and backlog refinement, ensuring work is aligned with value, risk reduction, and strategic objectives.

Risk Management \& Governance

  • Lead and contribute to the continuous improvement of the InfoSec technical risk management framework, ensuring strong integration with data-driven insights.
  • Oversee the identification, assessment, and monitoring of technology and cyber risks, leveraging metrics, analytics, and automation.
  • Ensure risk outputs, such as KRIs, control effectiveness and audit findings, are consistent, traceable, and defensible.
  • Provide expert guidance on risk posture, remediation strategies, and prioritization, to support management decision-making.
  • Lead or support key risk management initiatives, such as the Digital Crown Jewels framework and Cyber Operational Risk Events Management.
  • Support internal and external audits, ensuring timely completion of remediation actions.
  • Prepare documentation related to policy, standards, and procedures.

Data-Driven GRC \& Engineering

  • Participate to the design and implementation of data-driven GRC capabilities, including automated data ingestion, transformation, and insight generation.
  • Define and enforce data architecture and governance practices for security metrics and reporting.
  • Support the squad in maintaining and developing key security metrics, including risk and control indicators.
  • Contribute to the development of scalable solutions leveraging tools such as Power BI, Power Platform, SQL, and APIs.
  • Identify and implement opportunities to automate workflows, controls monitoring, and reporting processes.
  • Ensure integration across tools and datasets to enable end-to-end visibility of InfoSec risk posture.
  • Provide technical leadership for the evolution of GRC tools, including asset register modernization.
  • Identify opportunities, support the design and enhancement of Continuous Control Monitoring (CCM) to provide timely visibility into control performance and identify issues proactively.

Data \& Reporting Initiatives

  • Deliver insights driven by robust data analytics.
  • Contribute to improving reporting processes and ensuring data reliability.
  • Support data initiatives from source identification to final reporting.
  • Present findings and recommendations to managers and stakeholders.

REQUIRED QUALIFICATIONS

  • Bachelor’s degree in computer science, information security, data analytics, or a related field.
  • At least 8 years of experience in cyber risk, cybersecurity, or GRC, with strong exposure to data-driven approaches and analytics.
  • Minimum 3 years in a tech lead or senior role, including delivery leadership, output review, and team coaching.
  • Extensive experience in:
  • Risk analytics, metrics development (KRIs/KPIs), and automated reporting.
  • Driving automation and implementing data solutions in complex environments.
  • Advanced proficiency in Power BI, Power Platform, SQL, and data integration (APIs).
  • Strong understanding of data architecture, data governance, and analytics lifecycle.
  • Experience designing and implementing automated workflows and reporting solutions.
  • Experience with Continuous Control Monitoring (CCM) and control automation concepts.
  • Strong knowledge of technology risk management frameworks (e.g., NIST, ISO 27001, COBIT).
  • Experience applying risk frameworks, audit practices, and control assessments.
  • Strong ability to review, challenge, and enhance the quality of deliverables.
  • Demonstrated leadership in coaching, mentoring, and developing team capabilities.
  • Excellent stakeholder management skills, with the ability to operate in complex, high-visibility environments.
  • Ability to translate technical and risk concepts into a clear business language.
  • Strong analytical thinking, problem-solving, and decision-making skills.
  • Highly organized, detail-oriented, and able to manage multiple priorities effectively.

PREFERRED QUALIFICATIONS

  • Financial services or regulated environments.
  • Relevant certifications (e.g., CRISC, CISM, FAIR).
  • Knowledge on OSFI.

Proudly one of Canada’s Top 100 Employers and one of Canada’s Best Diversity Employers, we are committed to fostering a diverse, equitable, inclusive and accessible environment where all employees can thrive and feel empowered to bring their whole selves to work. If you require an accommodation to complete your application, please do not hesitate to contact us at accessibility@bdc.ca.

While we appreciate all applications, we advise that only the candidates selected to participate in the recruitment process will be contacted.

This posting was aggregated from indeed. Groupe Sentinella is not the employer; applying takes you to the original site. The full text belongs to the original poster.

Want us in your corner?

Join the Sentinella talent bench. We'll reach out when a mandate matches your profile — including roles like this one.

Join the talent bench