About the role
CoreFactor is searching for Cybersecurity GRC Consultant on a contract basis for a client in the GTA.
This position is hybrid and will require the successful incumbent to go into the Mississauga office four (4) times per week.
The Opportunity:
As our Governance, Risk Management, and Compliance (GRC) Analyst, you will report to the Director of Security Strategy and Architecture to help us build and grow our cyber practice from the ground up. This is a rare opportunity to join us on our journey on the forefront of cybersecurity, grow with us, and shape the future of the organization.
This role requires a motivated self-starter, someone who has strong analytical and problem-solving skills, a deep understanding of risk and compliance management principles, excellent communication and report-writing abilities, and foundational knowledge of industry-specific regulations, standards, and frameworks. You are passionate about security and compliance and believe in due diligence.
Snapshot of a Day-in-the-Life:
Work with leaders (such as CIO, CISO, GRC Manager, Infrastructure Managers) and assist them in strengthening the organization-wide Cybersecurity program Work with stakeholders and implement Governance Risk and Compliance (GRC) related initiatives aligned with the organizations vision and strategy Conduct risk assessments as per requirements within industry leading standards and frameworks (such as NIST CSF), identify gaps and assist in coordination of activities among other information security functions to resolve the gaps Be the primary point of contact for external assessments, audits and participate in interviews, walkthroughs and requirements gathering process Lead internal assessments (GRC) and audits, and conduct interviews, documentation review and controls assessment Assist in implementation of requirements defined within Cybersecurity related policies and procedures throughout the organization Collaborate with other information security functions (such as IAM, PAM, Resilience etc.) and collect Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs), and periodically report it to GRC Manager Prepare information security reports for senior leaders (such as CIO, CISO and the Cybersecurity Committee) Assist in Implementation of cyber security controls and management of the Cyber Controls Framework (NIST CSF) Assist in development of cyber security related training and awareness initiatives Keep track of risks within the organization. Ensure risks are appropriately addressed by risk owners within the determined timeline. Work with required teams to collect and prepare audit data for C3 audits.
What You’ll Bring:
Understand Information Security Concepts (such as Risk Management, Governance, Data Protection, Incident Management etc.) Knowledge of information security standards and regulations such as NIST CSF, NIST SP Series (800-53, 800-82, 800-207), NIST RMF (Risk Management Framework), C3, and CIS Critical Security Controls framework Quick learner, strategic thinker, strong team player with ability to multi-task Organize, prioritize, and track project activities on a day-to-day basis Identify and communicate project risks to managers and IT leads Analytical and problem-solving mindset Clear verbal/written communication Proficiency in Excel, PowerPoint Risk assessment and risk analysis Risk register management and remediation tracking Control design and operating effectiveness assessment Audit evidence review and audit readiness Third-party risk management and vendor due diligence Policy, standard, and procedure interpretation Security control framework mapping, including NIST CSF, CIS Controls, ISO 27001, SOC 2, and NIST 800-53 KRI/KPI development, tracking, and reporting Executive reporting and dashboard preparation Exception, issue, and risk acceptance management Data classification and data protection risk analysis Cloud, IAM, infrastructure, and resilience risk assessment Strong documentation and report-writing skills Stakeholder management and cross-functional coordination GRC tool proficiency, such as ServiceNow GRC/IRM, Archer, OneTrust, AuditBoard, MetricStream, or similar platforms People Ability to work collaboratively with members across other functions (such as Infrastructure, Cloud, Data etc.) to collaboratively solve problems and build strong processes Track risks assigned to members within other functions (such as Infrastructure, Cloud, Data etc.)
Requirements
A minimum of 3 years of security related experience within GRC function A minimum of 7 years of security related experience in total within various information security functions (GRC, MITRE ATT&CK, Resilience etc.) Experience in conducting risk assessments as per requirements in industry leading standards and frameworks (such as NIST CSF) is a must. Experience in conducting ITGC (IT General Controls) controls testing (Preferred) Experience in Data Protection, Third-party Risk Management and Resilience (Preferred) Prior experience in working in Consumer or Food & Beverage Industry (Preferred) Risk register ownership and lifecycle management — documenting risks, assigning owners, tracking remediation, validating closure, and preparing risk status updates. Control testing and evidence review — assessing control design and operating effectiveness, reviewing audit evidence, and identifying gaps. Third-party/vendor risk assessments — reviewing security questionnaires, SOC 2 reports, ISO 27001 certificates, penetration test summaries, and remediation plans. Risk reporting for leadership — preparing executive-level dashboards, KRIs/KPIs, risk summaries, and remediation progress updates. Framework mapping — mapping risks and controls to NIST CSF, CIS Controls, ISO 27001, SOC 2, or internal control frameworks. Exception and risk acceptance management — documenting exceptions, residual risk, compensating controls, expiry dates, and approval workflows. Experience with GRC tools — such as Archer, ServiceNow GRC/IRM, OneTrust, AuditBoard, MetricStream, or similar platforms. Data classification and privacy/security risk — evaluating how sensitive data is collected, stored, transmitted, retained, and protected. Cloud and infrastructure risk assessments — assessing risks related to cloud platforms, IAM, network security, endpoint controls, backup/recovery, and resilience. Audit readiness and compliance support — preparing teams for audits, collecting evidence, coordinating responses, and tracking findings to closure.
Education
Bachelor's degree in Information Technology, Engineering or Computer Science (Preferred) Professional certifications in Information Security such as CISSP, CISM, CRISC, CC or equivalent (Preferred)
About CoreFactor
CoreFactor's ecosystem of services and solutions include Consulting Services, Managed Services and Staffing Services.
CoreFactor's Consulting & Managed Services division specializes in helping our clients by taking on engagements through our network of strategic partners that possess functional or technical expertise.
CoreFactor's Staffing divisions provide top talent in the areas of Executive Search, Permanent Search and Contract Staffing.
Our mandate is....Minding your business: CoreFactor prides itself in building long-term sustainable relationships based on open communication and collaboration. By working with like minded organizations that are focused on being best in class, we provide high quality services to our clients enabling them to meet their goals and objectives.
Similar Jobs
About the role
CoreFactor is searching for Cybersecurity GRC Consultant on a contract basis for a client in the GTA.
This position is hybrid and will require the successful incumbent to go into the Mississauga office four (4) times per week.
The Opportunity:
As our Governance, Risk Management, and Compliance (GRC) Analyst, you will report to the Director of Security Strategy and Architecture to help us build and grow our cyber practice from the ground up. This is a rare opportunity to join us on our journey on the forefront of cybersecurity, grow with us, and shape the future of the organization.
This role requires a motivated self-starter, someone who has strong analytical and problem-solving skills, a deep understanding of risk and compliance management principles, excellent communication and report-writing abilities, and foundational knowledge of industry-specific regulations, standards, and frameworks. You are passionate about security and compliance and believe in due diligence.
Snapshot of a Day-in-the-Life:
Work with leaders (such as CIO, CISO, GRC Manager, Infrastructure Managers) and assist them in strengthening the organization-wide Cybersecurity program Work with stakeholders and implement Governance Risk and Compliance (GRC) related initiatives aligned with the organizations vision and strategy Conduct risk assessments as per requirements within industry leading standards and frameworks (such as NIST CSF), identify gaps and assist in coordination of activities among other information security functions to resolve the gaps Be the primary point of contact for external assessments, audits and participate in interviews, walkthroughs and requirements gathering process Lead internal assessments (GRC) and audits, and conduct interviews, documentation review and controls assessment Assist in implementation of requirements defined within Cybersecurity related policies and procedures throughout the organization Collaborate with other information security functions (such as IAM, PAM, Resilience etc.) and collect Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs), and periodically report it to GRC Manager Prepare information security reports for senior leaders (such as CIO, CISO and the Cybersecurity Committee) Assist in Implementation of cyber security controls and management of the Cyber Controls Framework (NIST CSF) Assist in development of cyber security related training and awareness initiatives Keep track of risks within the organization. Ensure risks are appropriately addressed by risk owners within the determined timeline. Work with required teams to collect and prepare audit data for C3 audits.
What You’ll Bring:
Understand Information Security Concepts (such as Risk Management, Governance, Data Protection, Incident Management etc.) Knowledge of information security standards and regulations such as NIST CSF, NIST SP Series (800-53, 800-82, 800-207), NIST RMF (Risk Management Framework), C3, and CIS Critical Security Controls framework Quick learner, strategic thinker, strong team player with ability to multi-task Organize, prioritize, and track project activities on a day-to-day basis Identify and communicate project risks to managers and IT leads Analytical and problem-solving mindset Clear verbal/written communication Proficiency in Excel, PowerPoint Risk assessment and risk analysis Risk register management and remediation tracking Control design and operating effectiveness assessment Audit evidence review and audit readiness Third-party risk management and vendor due diligence Policy, standard, and procedure interpretation Security control framework mapping, including NIST CSF, CIS Controls, ISO 27001, SOC 2, and NIST 800-53 KRI/KPI development, tracking, and reporting Executive reporting and dashboard preparation Exception, issue, and risk acceptance management Data classification and data protection risk analysis Cloud, IAM, infrastructure, and resilience risk assessment Strong documentation and report-writing skills Stakeholder management and cross-functional coordination GRC tool proficiency, such as ServiceNow GRC/IRM, Archer, OneTrust, AuditBoard, MetricStream, or similar platforms People Ability to work collaboratively with members across other functions (such as Infrastructure, Cloud, Data etc.) to collaboratively solve problems and build strong processes Track risks assigned to members within other functions (such as Infrastructure, Cloud, Data etc.)
Requirements
A minimum of 3 years of security related experience within GRC function A minimum of 7 years of security related experience in total within various information security functions (GRC, MITRE ATT&CK, Resilience etc.) Experience in conducting risk assessments as per requirements in industry leading standards and frameworks (such as NIST CSF) is a must. Experience in conducting ITGC (IT General Controls) controls testing (Preferred) Experience in Data Protection, Third-party Risk Management and Resilience (Preferred) Prior experience in working in Consumer or Food & Beverage Industry (Preferred) Risk register ownership and lifecycle management — documenting risks, assigning owners, tracking remediation, validating closure, and preparing risk status updates. Control testing and evidence review — assessing control design and operating effectiveness, reviewing audit evidence, and identifying gaps. Third-party/vendor risk assessments — reviewing security questionnaires, SOC 2 reports, ISO 27001 certificates, penetration test summaries, and remediation plans. Risk reporting for leadership — preparing executive-level dashboards, KRIs/KPIs, risk summaries, and remediation progress updates. Framework mapping — mapping risks and controls to NIST CSF, CIS Controls, ISO 27001, SOC 2, or internal control frameworks. Exception and risk acceptance management — documenting exceptions, residual risk, compensating controls, expiry dates, and approval workflows. Experience with GRC tools — such as Archer, ServiceNow GRC/IRM, OneTrust, AuditBoard, MetricStream, or similar platforms. Data classification and privacy/security risk — evaluating how sensitive data is collected, stored, transmitted, retained, and protected. Cloud and infrastructure risk assessments — assessing risks related to cloud platforms, IAM, network security, endpoint controls, backup/recovery, and resilience. Audit readiness and compliance support — preparing teams for audits, collecting evidence, coordinating responses, and tracking findings to closure.
Education
Bachelor's degree in Information Technology, Engineering or Computer Science (Preferred) Professional certifications in Information Security such as CISSP, CISM, CRISC, CC or equivalent (Preferred)
About CoreFactor
CoreFactor's ecosystem of services and solutions include Consulting Services, Managed Services and Staffing Services.
CoreFactor's Consulting & Managed Services division specializes in helping our clients by taking on engagements through our network of strategic partners that possess functional or technical expertise.
CoreFactor's Staffing divisions provide top talent in the areas of Executive Search, Permanent Search and Contract Staffing.
Our mandate is....Minding your business: CoreFactor prides itself in building long-term sustainable relationships based on open communication and collaboration. By working with like minded organizations that are focused on being best in class, we provide high quality services to our clients enabling them to meet their goals and objectives.