Back to jobs

Senior GRC/S Specialist - Information Security Assurance & Automation

Montréal, Quebec, Canada

Senior GRC/S Specialist - Information Security Assurance & Automation

About us

Broadsign is a growing software company with a mission to make buying, selling, and delivering out-of-home media easier than ever.
Our software is operated by some of the most successful out-of-home businesses and powers impactful, compelling campaigns seen across the world.

Come light up the world as a  Senior GRC/S Specialist in Montreal (Hybrid).

What to expect

We are seeking a highly motivated, experienced, and strategic GRC/S (Governance, Risk, and Compliance/Security) Specialist to join our dynamic team. In this critical senior role, you will play a pivotal part in shaping and executing our security assurance programs, primarily focusing on leading our SOC (Service Organization Control) audit processes and managing complex third-party security questionnaires and assessments. A significant aspect of this role will be driving the identification, implementation, and optimization of automation opportunities to enhance efficiency, accuracy, and scalability across our GRC/S functions. 

Key Responsibilities:

  • Strategic SOC Audit Leadership:
  • Lead all phases of SOC 1 & 2 audits, acting as the primary point of contact for auditors and internal stakeholders.
  • Drive the collection of audit evidence, conduct thorough control walkthroughs, and ensure robust documentation.
  • Oversee the tracking and management of audit findings, collaborating proactively with cross-functional teams to ensure timely and effective remediation.
  • Develop, maintain, and continuously improve control narratives, policies, and procedures to ensure ongoing SOC 1 & 2 compliance and audit readiness.
  • Develop and implement audit plans, ensuring alignment with organizational goals and risk appetite.
  • Advanced Third-Party Security Program Management:
  • Lead the comprehensive management and response to complex incoming third-party security questionnaires (e.g., SIG, CAIQ, custom questionnaires) from key customers and partners, ensuring high-quality and timely submissions.
  • Design and execute thorough security assessments of third-party vendors and service providers, evaluating their security posture, contractual compliance, and alignment with our organizational risk appetite.
  • Establish and maintain, and enhance a robust, centralized repository of security documentation, standardized responses, and detailed vendor assessment findings.
  • Proactively identify and implement strategic initiatives to streamline and scale the third-party assessment process, leveraging industry best practices.
  • GRC/S Automation & Innovation Driver:
  • Champion and lead initiatives to automate repetitive GRC/S tasks, with a strong emphasis on evidence collection for audits, intelligent response generation for questionnaires, and continuous monitoring.
  • Research, evaluate, implement, and optimize advanced GRC/S automation tools, platforms, and technologies.
  • Develop and maintain sophisticated scripts or integrations to enhance data flow, collection, and reporting across various security and business systems.
  • Drive the continuous improvement of GRC/S processes, policies, and tools, fostering a culture of efficiency and innovation.
  • GRC/S Contribution & People Management:
  • Contribute to the development and evolution of the overall GRC/S strategy and roadmap.
  • Provide expert guidance and mentorship to individual contributor team members and internal stakeholders on security best practices, compliance requirements, and risk management principles.
  • Stay ahead of the latest industry trends, regulatory changes, and emerging threats in the cybersecurity and GRC landscape, advising leadership on potential impacts and necessary adjustments.

What you need to perform in this job 

  • Bachelor's degree in Information Security, Computer Science, Information Systems, or a related field, or equivalent practical experience.
  • 8+ years of progressive experience in a GRC, Information Security, or IT Audit role, with a strong emphasis on security compliance and assurance.
  • 2+ years of experience in a people management or team leadership role, with demonstrated ability to mentor and develop individual contributor staff.
  • Relevant industry certifications such as CISA, CRISC, CISM, CISSP, or equivalent.
  • Demonstrated leadership experience in managing and successfully completing SOC 1 & 2 audits, including strategic planning, execution, and remediation oversight.
  • Extensive experience managing and responding to complex third-party security questionnaires and conducting in-depth vendor security assessments.
  • Deep understanding and practical experience leading the implementation and optimization of GRC automation tools and platforms (e.g., LogicManager, MetricStream, Archer, ServiceNow GRC, OneTrust, RiskRecon, Vanta, Drata, or similar).
  • Expert-level familiarity with common security frameworks and standards (e.g., NIST CSF, ISO 27001, SOC 1 and SOC 2 AICPA Trust Services Criteria (TSC), GDPR, HIPAA, PCI DSS).
  • Exceptional written and verbal communication skills, with the ability to articulate complex security and compliance concepts clearly and persuasively to senior leadership, auditors, and technical teams.
  • Strong analytical, critical thinking, and advanced problem-solving abilities, with a proactive and results-oriented approach.
  • Client-oriented approach.
  • Self-motivated, positive attitude, and a team player.

Additional qualifications 

  • Relevant industry certifications such as CISA, CRISC, CISM, CISSP, or equivalent.
  • Proficiency and experience with advanced automation and data analysis.
  • Experience in a leadership, project management, or mentoring capacity.
  • Demonstrated experience working in a fast-paced, high-growth, agile environment.
  • In-depth knowledge of cloud security principles and experience with major cloud platforms (AWS, Azure, GCP) security management.

What we bring to the table

  • Wellness: $500 annual Wellness fund for mental/physical health and office-related expenses. 
  • Comprehensive Benefits: Complete company insurance plan (health, dental, vision, travel) effective from day one (100% employer-paid). $500 annual Health Care Savings Account (HCSA) for additional health-related expenses.Unlimited access to virtual healthcare platform (Telus Health).
  • Paid Time Off: Minimum 3 weeks vacation, plus an additional week off during the holidays, 5 sick/personal days, and 2 volunteer days.
  • Retirement Savings: Group RRSP with a 50% employer matching up to 4% of your salary.
  • Financial Perks: Transportation reimbursement for travel to a Broadsign office.
  • Family Support: Parental leave salary supplement.
  • Growth Opportunities: Training & development opportunities with a yearly budget to support professional growth.

At Broadsign, we value the varied social identities that make up our community. We recognize talent comes in different forms and encourage applications that reflect different backgrounds and experiences. Our promise is to be an inclusive employer and partner, open to learning, with thoughtful strategies and practices that amplify the different voices of our industry.

Knowledge of French is required for positions permanently located in Quebec so incumbents can communicate with their colleagues and partners in Quebec as necessary. French-language training is offered to all incumbents in permanent positions in Quebec who do not have a good knowledge of French. Fluent English is required for this position in order to communicate with colleagues, clients and partners (or suppliers) located outside Quebec and to understand the technical and scientific documentation used in our industry

Create a Job Alert

Interested in building your career at Broadsign Careers? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf