Ivalua

Senior Security Analyst - GRC

Ivalua$95K — $115K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • At least 4 years of experience as a Security Analyst focused on Governance, Risk, and Compliance (GRC).
  • Strong knowledge of security, risk, and compliance frameworks like NIST CSF & 800-53, ISO 27001, and PCI-DSS.
  • Experience managing audits or risk assessments against relevant InfoSec frameworks.
  • Familiarity with continuous compliance and monitoring platforms.
  • A good understanding of cloud security across platforms like Azure, AWS, and GCP.

Responsibilities

  • Lead compliance initiatives across global frameworks including SOC 1/SOC 2 and ISO 27001.
  • Evaluate and translate security requirements into actionable guidance for technical teams.
  • Drive customer security audits and manage contract reviews, especially in the EMEA region.
  • Present security architecture information to prospects and customers effectively.
  • Manage security risk processes including risk identification and treatment planning.
  • Support ongoing compliance monitoring using GRC tools and maintain control effectiveness.
  • Coordinate key security controls like Business Impact Analysis and Disaster Recovery testing.

Benefits

  • Hybrid working model (3 days in the office per week).
  • Opportunities for personal and professional development through training programs.
  • Regular social events and team activities to foster collaboration.
  • An inclusive work environment that values individual contributions.
  • Free snacks and weekly lunches provided in the office.
Full Job Description
Senior Security Analyst - GRC

(Montreal - Canada)

THE OPPORTUNITY

CONTEXT:

You will be part of the InfoSec team with a mission to build, maintain, and continuously improve our Information Security program, providing peace of mind and assurance of protection and safety to our customers. Our team is hands-on, with a strong problem-solving mindset, capable of thinking holistically about implementation and providing solutions to address our customers' long-term challenges. We work hard and play hard, enjoying various indoor and outdoor activities organized by the company, allowing you to focus, collaborate, and unleash your creativity.

ROLE:

We are looking for a Senior Security Analyst to join our InfoSec team. This role will help drive various GRC activities which include supporting prospect and customer security questions, maintaining security policies, supporting security audits and assessments and driving new security certifications/compliance initiatives.

WHAT YOU WILL DO WITH US
  • Lead and support compliance initiatives across global and regional frameworks including SOC 1/SOC 2, ISO 27001, IRAP, PCI-DSS, SecNumCloud, Cyber Essentials Plus (CE+), BSI C5, NIST 800-53
  • Evaluate technical controls across the technology stack, including all layers of the TCP/IP model (e.g. network segmentation, firewall rulesets, TLS/SSL configuration, IDS/IPS, access controls, application security, encryption in transit/at rest, cloud security configurations), and translate security requirements into actionable guidance for engineering and infrastructure teams.
  • Drive and manage customer security audits, security questionnaires, and contract reviews with a primary focus on the EMEA region. Participate in the negotiation and review of French contracts to ensure alignment with security and compliance obligations.
  • Attend prospect and customer meetings and effectively present Ivalua's security architecture and control information to them.
  • Lead or support internal and third party security risk management processes, including risk identification, analysis, scoring, treatment planning, and ongoing monitoring.
  • Support continuous compliance monitoring activities using manual and automation and GRC tooling to maintain control effectiveness, generate evidence, and ensure audit readiness.
  • Own execution and coordination of key security and availability controls such as Business Impact Analysis (BIA), Disaster Recovery testing, security incident response exercises, access reviews, etc.

YOUR PROFILE

If you have the below experience and strengths this role could be for you:

Skills and Experience:
  • At least 4 years of experience as Security Analyst GRC
  • Strong working knowledge of security, risk, and compliance frameworks (e.g. NIST CSF & 800-53, ISO 27001, SOC, HITRUST, HIPAA, PCI-DSS, GDPR)
  • Direct experience managing audits, self-assessments, or risk assessments against one or more InfoSec frameworks listed above
  • Experience performing or supporting security risk management processes (risk assessments, risk registers, business impact analysis)
  • Familiarity with continuous compliance and monitoring platforms
  • Good understanding of cloud platforms (Azure, AWS, GCP) and ability to discuss security architecture and control implementation with technical teams
  • Knowledge and experience working with IT and security personnel as well as security concepts across all layers of technology (network, infrastructure, web applications, cloud environments)
  • Knowledge of risk and security industry literature and knowledge bases (e.g. OWASP, MITRE ATT&CK, NIST 800-39)
  • Relevant audit and/or Information Security certifications (e.g. CISSP, CISA, CISM, Azure Cloud Security) are desired
  • Prior experience at a Big 4 firm or in a security/compliance function in a cloud/SaaS environment is a plus

Soft Skills:
  • Excellent interpersonal, communication, and organizational skills. Ability to communicate efficiently and professionally in both French and English, including in contractual, regulatory, and technical contexts
  • Demonstrated ability to work across geographically distributed teams and with external vendors, auditors, or regulators.
  • Strong organizational skills and attention to detail; able to manage multiple competing priorities in a fast-paced environment
  • High degree of initiative, self-motivation, and ability to work independently with limited supervision

WHAT HAPPENS NEXT

If your application fits this specific position's needs, our skilled Talent team will reach out to schedule an initial screening call. Get one step closer to achieving your goals - apply today!

Our Talent team will guide you through every step of the interview process - from preparation to completion. They're here to support you!

Our recruitment process is designed to assess your competencies through a series of personalized interviews with internal stakeholders relevant to the role.

Interviews will be conducted virtually via video or on-site with face-to-face meetings.

LIFE AT IVALUA
  • Hybrid working model (3 days in the office per week)
  • We're a team dedicated to pushing the boundaries of product innovation and technology
  • Sustainable Growth, Privately Held
  • A stable and cash-flow positive Company since 10 years
  • Snacks and weekly lunches in the office
  • Feel empowered to pursue your goals with improved team collaboration and increased creativity/productivity
  • Unlock and unleash your full professional potential with our exceptional training and career development program
  • Join a dynamic and international team of top-notch professionals who are experts in their respective fields
  • Collaborate with like-minded individuals who are deeply passionate and highly motivated about their work
  • Experience a truly diverse and inclusive work environment where your unique contributions are highly valued
  • Regular social events, competitive outings, team running events, and musical activities
  • Comparably recognized Ivalua for the following (https://www.comparably.com/companies/ivalua):


Powered by People - Powered by You!

#LI-MV1

#LI-HYBRID

About Ivalua

Ivalua is a provider of cloud-based spend management software. The company's platform automates procurement and supply chain processes, including sourcing, contract management, and supplier management. Ivalua was founded in 2000 and is headquartered in Needham, Massachusetts.
Learn more about Ivalua
Size
800 employees
Industry
Founded
2000

Similar Jobs

More Jobs at Ivalua

More Information Technology Jobs

Find similar Senior Security Analyst - GRC jobs: