GRC Lead/Security Analyst
Ivalua Jobs | Ivalua Careers | Ivalua
Apply to this jobGRC Lead/Security Analyst
(Montreal - Canada)
Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions.
COMPANY OVERVIEW
At Ivalua we are a global community of exceptional professionals, who believe that digital transformation revolutionizes supply chain sustainability and resiliency to unlock the power of supplier collaboration. We achieve this through our leading cloud-based spend management platform that empowers hundreds of the world's most admired brands to effectively manage all categories of spend and all suppliers to increase profitability, improve ESG (environmental, social, and corporate governance) performance, lower risk, and improve productivity. Driven by our passions and fueled by our shared ambitions, we empower and challenge each other to create meaningful experiences for our colleagues, customers, partners, and communities.
Learn more at www.ivalua.com. Follow us on LinkedIn
THE OPPORTUNITY
CONTEXT:
You will be part of the InfoSec team with a mission to build, maintain, and continuously improve our Information Security program, providing peace of mind and assurance of protection and safety to our customers. Our team is hands-on, with a strong problem-solving mindset, capable of thinking holistically about implementation and providing solutions to address our customers' long-term challenges. We work hard and play hard, enjoying various indoor and outdoor activities organized by the company, allowing you to focus, collaborate, and unleash your creativity.
ROLE:
We are looking for a GRC Lead/Security Analyst to join our InfoSec team. This role will help drive various GRC activities which include supporting prospect and customer security questions, maintaining security policies, supporting security audits and assessments and driving new security certifications/compliance initiatives.
WHAT YOU WILL DO WITH US
- Lead and support compliance initiatives in accordance with global and regional standards, including SOC 1/SOC 2, ISO 27001, IRAP, PCI-DSS, SecNumCloud, Cyber Essentials Plus (CE+), BSI C5, and NIST 800-53.
- Evaluate technical controls across the entire technology stack, including all layers of the TCP/IP model (e.g., network segmentation, firewall rules, TLS/SSL configuration, IDS/IPS, access controls, application security, encryption in transit and at rest, and cloud security configurations), and translate security requirements into concrete guidelines for engineering and infrastructure teams.
- Lead and manage client security audits, security questionnaires, and contract reviews, primarily for the EMEA region. Participate in the negotiation and review of French contracts to ensure alignment with security and compliance requirements.
- Participate in meetings with prospects and clients and effectively present Ivalua’s security architecture and controls to them.
- Lead or support internal and third-party security risk management processes, including the identification, analysis, scoring, mitigation planning, and ongoing monitoring of risks.
- Support ongoing compliance monitoring activities using manual processes, automation, and GRC tools to maintain the effectiveness of controls, generate audit evidence, and ensure ongoing audit readiness.
- Ensure the implementation and coordination of key security and availability controls, such as business impact assessments, disaster recovery plan tests, security incident response drills, access reviews, etc.
YOUR PROFILE
If you have the below experience and strengths this role could be for you:
Skills and Experience:
- At least 4 years of experience as a GRC Security Analyst.
- Solid practical knowledge of security, risk, and compliance frameworks (e.g., NIST CSF & 800-53, ISO 27001, SOC, HITRUST, HIPAA, PCI-DSS, GDPR).
- Direct experience managing audits, self-assessments, or risk assessments against one or more of the InfoSec frameworks listed above.
- Experience in implementing or supporting security risk management processes (risk assessments, risk registers, business impact analyses).
- Proficiency with continuous compliance and monitoring platforms.
- A solid understanding of cloud platforms (Azure, AWS, GCP) and the ability to discuss security architecture and the implementation of controls with technical teams.
- Knowledge and experience working with the IT and security team, as well as a thorough understanding of security concepts across all technology layers (network, infrastructure, web applications, cloud environments).
- Knowledge of security and risk industry literature, as well as leading reference knowledge bases (e.g., OWASP, MITRE ATT&CK, NIST 800-39).
- Relevant certifications in auditing and/or information security (e.g., CISSP, CISA, CISM, Azure Cloud Security) are preferred.
- Previous experience at a Big 4 firm or in a security/compliance role in a cloud/SaaS environment is a plus.
- Bachelor’s degree in Computer Science, or relevant field preferred with a minimum of 4 years of relevant professional experience OR Equivalent combination of education and experience
Soft Skills:
- Excellent interpersonal, organizational, and communication skills. Ability to communicate effectively and professionally in French and English, including in contractual, regulatory, and technical contexts.
- Ability to conduct business in English is required given our customer base; wherever possible, we will support the employee's right to work in French
- Proven ability to work with geographically dispersed teams as well as with external service providers, auditors, or regulators.
Strong organizational skills and attention to detail; ability to manage multiple priorities simultaneously in a fast-paced environment. - Strong sense of initiative, high level of motivation, and the ability to work independently with minimal supervision.
WHAT HAPPENS NEXT
If your application fits this specific position’s needs, our skilled Talent team will reach out to schedule an initial screening call. Get one step closer to achieving your goals – apply today!
Our Talent team will guide you through every step of the interview process - from preparation to completion. They're here to support you!
Our recruitment process is designed to assess your competencies through a series of personalized interviews with internal stakeholders relevant to the role.
Interviews will be conducted virtually via video or on-site with face-to-face meetings.
LIFE AT IVALUA
- Hybrid working model (3 days in the office per week)
- We're a team dedicated to pushing the boundaries of product innovation and technology
- Sustainable Growth, Privately Held
- A stable and cash-flow positive Company since 10 years
- Snacks and weekly lunches in the office
- Feel empowered to pursue your goals with improved team collaboration and increased creativity/productivity
- Unlock and unleash your full professional potential with our exceptional training and career development program
- Join a dynamic and international team of top-notch professionals who are experts in their respective fields
- Collaborate with like-minded individuals who are deeply passionate and highly motivated about their work
- Experience a truly diverse and inclusive work environment where your unique contributions are highly valued
- Regular social events, competitive outings, team running events, and musical activities
- Comparably recognized Ivalua for the following (https://www.comparably.com/companies/ivalua):
Powered by People - Powered by You!
United by our values we embrace diversity and equity in the broadest possible sense to create an inclusive workplace. To help our customers make supply chains more efficient, sustainable and resilient, we rely on a global team with a variety of backgrounds, skills and views. We believe in equal opportunity and in diversity as a driver of innovation that cultivates a spirit of inclusiveness, creates a productive and fun place to work, and provides fulfilling career opportunities for all Ivaluans. https://www.linkedin.com/company/ivalua/about/
Experience life at Ivalua - check out our captivating video! Gain insight into our unique company culture and get a glimpse of what it's like to work with us.
#LI-MV1
#LI-HYBRID
Summary
Support security compliance, audits, policies, and risk management for cloud-based solutions.
Job title
GRC Lead/Security Analyst
Experience level
4+ years
Minimum experience
4+ years exp
Industry
software
Location requirements
Montreal, Canada; hybrid work allowed
Salary
Not specified
Visa sponsorship
H-1B sponsor history
Management role
No
Required skills
Preferred skills
Specializations
Structured locations inferred from the posting.
Montreal, QC, Canada