Governance, Risk and Compliance Advisor
TechnologyDescription
Company Description
We are one of the fastest-growing marketing research firms in North America, recognized for our team of visionary experts and our innovative AI-powered approach. We take pride in our panel (LEO) and our unmatched precision results. Stay ahead of the trends and insights shaping your industry.
Why Léger?
- A Quebec-based firm recognized as a leader in marketing research and analytics.
- A dynamic, collaborative, and passionate team.
- Diverse mandates with top-tier organizations.
- Professional development and career growth opportunities.
- A flexible environment fostering autonomy and initiative.
Working within the Information Technology team, the Governance, Risk, and Compliance Advisor contributes to the development, maintenance, and improvement of Léger's information security and personal information protection governance program.
This role plays a central part in managing risks, regulatory compliance, audit preparation, and evaluating client and vendor security requirements.
The individual collaborates with internal teams and stakeholders to enhance security practices, support continuous improvement, and foster an information protection-focused organizational culture.
Responsibilities
- Support the evolution of the information security and personal information protection governance program and compliance initiatives by maintaining and improving company procedures and control mechanisms, and coordinating awareness and training activities.
- Ensure alignment of security and personal information protection practices with applicable laws, regulations, frameworks, and practices, including the Act 25 and LPRPDE (PIPEDA).
- Participate in the analysis of technological needs and documentation of processes to integrate security, confidentiality, compliance, and quality requirements into the company's systems, projects, and processes.
- Assess and manage security, confidentiality, and compliance risks, including those associated with vendors and third parties, maintain the risk register, and ensure the tracking of mitigation measures and treatment plans.
- Coordinate, conduct, and document security, personal information protection, and compliance assessments, including requests from clients, and issue recommendations and action plans.
- Prepare and coordinate audits, certifications, and other assurance and compliance activities, and ensure the tracking of findings and applicable corrective measures.
Qualifications
- Bachelor's degree in a relevant field or equivalent combination of education and experience.
- Minimum of five (5) years of experience in a similar role.
- Experience in Governance, Risk, and Compliance (GRC), cybersecurity, and personal information protection.
- Experience in audit preparation, risk management, or security questionnaire processing is a significant asset.
- Excellent oral and written communication skills in French and English.
- Proficiency in MS Office suite (Word, Excel, PowerPoint, Outlook).
- Bilingualism in French and English.
Skills
- Knowledge of SOC 2 frameworks and Canadian regulations related to personal information protection.
- Knowledge of Microsoft Purview is an asset.
- Excellent project management and complex problem-solving skills.
- Ability to communicate technical concepts and guide users through change.
- Strong organizational skills, diligence, and effective priority and deadline management.
- Analytical and synthesis skills, autonomy, and proactivity.
- Embodies Léger's values: quality, innovation, collaboration, and commitment.
- Additional Information
English proficiency is required for this position, as the incumbent will need to regularly communicate orally and in writing with colleagues, partners, or vendors outside of Quebec, write bilingual internal documents, and participate in English-language meetings. The employer has evaluated the possibility of redistributing tasks or using language support tools but has concluded that English proficiency is essential to the performance of these functions.
For any questions, please refer to our Recruitment Policy.
This posting was aggregated from indeed. Groupe Sentinella is not the employer; applying takes you to the original site. The full text belongs to the original poster.
Want us in your corner?
Join the Sentinella talent bench. We'll reach out when a mandate matches your profile — including roles like this one.
Join the talent bench