Wealthsimple

Specialist, Security Risk Management

Wealthsimple$70K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-5 years of experience in IT risk management, information security, or related GRC function, preferably in fintech or financial services.
  • Solid understanding of IT and security risk frameworks (NIST CSF, ISO 27001, FAIR).
  • Familiarity with technology risk domains such as cloud (AWS preferred), access management, and vulnerability management.
  • Experience with third-party vendor assessments and due diligence review is an asset.
  • Experience maintaining risk registers and conducting risk assessments.
  • Knowledge of compliance frameworks (SOC 2, PCI DSS, NIST) is a strong plus.
  • Strong analytical skills with the ability to communicate technical risks in business language.

Responsibilities

  • Support the IT and security risk management lifecycle from identification to reporting.
  • Maintain and improve the enterprise IT/security risk register.
  • Conduct risk assessments across technology domains and third parties.
  • Evaluate risk mitigation controls with stakeholders to identify gaps.
  • Integrate vendor and technology risk findings into the risk register.
  • Contribute to the creation and upkeep of risk policies, standards, and procedures.
  • Monitor emerging threats and translate risks into actionable business insights.

Benefits

  • Top-tier health benefits and life insurance.
  • Long-term group savings with employer matching through Wealthsimple for Business.
  • 20 vacation days, 4 wellness days, and unlimited sick/mental health days annually.
  • Ability to work outside Canada for up to 90 days per year.
  • Employee resource groups for underrepresented communities.
  • Hybrid work environment with a talented, committed team.
Full Job Description
The Security GRC team plays a critical role in adhering to security frameworks and creating space for risk mitigation and oversight. We want to ensure that Wealthsimple maintains a secure operational environment by implementing and monitoring controls designed to protect information, systems and infrastructure. We are looking to grow the Security GRC team with a Specialist, IT/Security Risk Management to support and mature our enterprise IT and security risk management program. This role will be central to identifying, assessing, and tracking risks across Wealthsimple's technology and security landscape, helping ensure that risk exposure is well-understood and actively managed. You'll partner closely with teams across Security, Engineering, Infrastructure, Product, and Compliance to assess risk, maintain our risk register, and drive risk treatment activities. This is a hands-on role suited for someone who is analytical, detail-oriented, and comfortable operating in a fast-moving fintech environment. In this role, you'll have the opportunity to 3 Support the end-to-end IT and security risk management lifecycle, including risk identification, assessment, treatment tracking, and reporting 3 Maintain and continuously improve the enterprise IT/security risk register, ensuring risks are accurately documented, rated, and assigned to appropriate owners 3 Perform risk assessments across technology domains (cloud infra, access management, application security) and third-party assessments using the appropriate methodology for each 3 Partner with control owners and business stakeholders to evaluate the effectiveness of risk mitigation controls and identify gaps 3 Integrate vendor and technology risk findings into the risk register to facilitate tracking and remediation across both IT/Security and Third-Party Risk Management. 3 Contribute to the development and maintenance of risk policies, standards, and procedures 3 Assist in preparing risk reporting and dashboards for senior leadership and committee-level audiences 3 Monitor the threat and vulnerability landscape and help translate emerging risks into actionable insights for the business 3 Support security and compliance initiatives, including PCI DSS, SOC 2, and NIST, from a risk lens, ensuring risk findings are integrated into broader compliance activities 3 Participate in risk-related work streams tied to new product launches, infrastructure changes, and strategic initiatives What you'll bring 3 3-5 years of experience in IT risk management, information security, or a related GRC function, ideally within financial services or fintech 3 Solid understanding of IT and security risk frameworks such as NIST CSF, ISO 27001, or FAIR 3 Familiarity with key technology risk domains including cloud (AWS preferred), identity and access management and vulnerability management 3 Experience conducting third-party and vendor reviews, with knowledge of due diligence review methodology, is an asset 3 Experience maintaining risk registers and supporting risk assessment processes 3 Working knowledge of compliance frameworks such as SOC 2, PCI DSS, and/or NIST is a strong asset 3 Strong analytical and written communication skills, with the ability to translate technical risk findings into clear business language 3 Comfortable working cross-functionally with both technical and non-technical stakeholders 3 Experience with GRC tools and risk management platforms (e.g.Jira, Drata) is an asset 3 Self-starter who can operate independently, manage competing priorities, and drive work to completion 3 Relevant certifications are an asset (CRISC, CISA, CISSP, or equivalent) 384 Top-tier health benefits and life insurance Long-term group savings with employer match, through Wealthsimple for Business 20 vacation days, 4 wellness days, and unlimited sick and mental health days per year 90 days away: work outside Canada for up to 90 days per year Employee resource groups, including Rainbow (2SLGBTQ), Women of WS, and Black at WS We are a hybrid team with over 1,500 employees across North America. The people are one of the best parts of working here: you'll collaborate with incredibly talented, curious, and driven teammates who are deeply committed to doing great work. ICYMI Technology & Innovation at Wealthsimple: We move quickly and build thoughtfully. That means we're always looking for better ways to work - whether that's new tools, AI, or rethinking how we approach a problem. We don't expect you to have all the answers, but we do expect curiosity and a willingness to evolve alongside the products we're building.

About Wealthsimple

Wealthsimple is a financial services company that provides online investment management and trading services. The company's platform allows users to invest in a variety of financial products, including stocks, bonds, and exchange-traded funds (ETFs), and offers a range of tools and resources to help users manage their investments. Wealthsimple also offers a high-interest savings account and a tax preparation service. The company was founded in 2014 and is headquartered in Toronto, Canada.
Learn more about Wealthsimple
Size
500 employees
Industry
Founded
2014

Similar Jobs

More Jobs at Wealthsimple

More Information Technology Jobs

Find similar Specialist, Security Risk Management jobs: