Wealthsimple

Specialist, Security Risk Management

Wealthsimple$70K — $95K *
US-AnywhereRemote in Canada
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-5 years of experience in IT risk management, information security, or a related GRC function, preferably in financial services or fintech
  • Understanding of IT and security risk frameworks (e.g., NIST CSF, ISO 27001, FAIR)
  • Familiarity with technology risk domains such as cloud, access management, and vulnerability management
  • Experience with third-party/vendor reviews and due diligence review methodology
  • Ability to maintain risk registers and support risk assessment processes
  • Knowledge of compliance frameworks like SOC 2, PCI DSS, and NIST is advantageous
  • Strong analytical and written communication skills, able to convert technical findings to business language

Responsibilities

  • Support the full IT and security risk management lifecycle, from identification to reporting
  • Maintain and enhance the risk register for IT/security, ensuring accurate documentation and ownership
  • Conduct risk assessments across technology domains and third-party environments
  • Evaluate risk mitigation controls alongside business stakeholders to identify gaps
  • Integrate vendor and technology risk findings into the risk management framework
  • Develop and maintain risk policies, standards, and procedures
  • Prepare risk reports and dashboards for leadership and committee audiences
  • Monitor emerging threats and translate them into actionable business insights
  • Support compliance initiatives like PCI DSS and SOC 2 through risk perspectives
  • Engage in risk assessments tied to product launches and strategic initiatives

Benefits

  • Top-tier health benefits and life insurance
  • Employer-matched long-term group savings through Wealthsimple for Business
  • 20 vacation days, 4 wellness days, and unlimited sick and mental health days per year
  • Work remotely from outside Canada for up to 90 days per year
  • Participation in employee resource groups (2SLGBTQ, Women of WS, Black at WS)
  • Work in a hybrid model with over 1,500 employees across North America
  • Collaborate with motivated, talented colleagues who are committed to innovation and excellence
Full Job Description
The Security GRC team plays a critical role in adhering to security frameworks and creating space for risk mitigation and oversight. We want to ensure that Wealthsimple maintains a secure operational environment by implementing and monitoring controls designed to protect information, systems and infrastructure. We are looking to grow the Security GRC team with a Specialist, IT/Security Risk Management to support and mature our enterprise IT and security risk management program. This role will be central to identifying, assessing, and tracking risks across Wealthsimple's technology and security landscape, helping ensure that risk exposure is well-understood and actively managed. You'll partner closely with teams across Security, Engineering, Infrastructure, Product, and Compliance to assess risk, maintain our risk register, and drive risk treatment activities. This is a hands-on role suited for someone who is analytical, detail-oriented, and comfortable operating in a fast-moving fintech environment. In this role, you'll have the opportunity to • Support the end-to-end IT and security risk management lifecycle, including risk identification, assessment, treatment tracking, and reporting • Maintain and continuously improve the enterprise IT/security risk register, ensuring risks are accurately documented, rated, and assigned to appropriate owners • Perform risk assessments across technology domains (cloud infra, access management, application security) and third-party assessments using the appropriate methodology for each • Partner with control owners and business stakeholders to evaluate the effectiveness of risk mitigation controls and identify gaps • Integrate vendor and technology risk findings into the risk register to facilitate tracking and remediation across both IT/Security and Third-Party Risk Management. • Contribute to the development and maintenance of risk policies, standards, and procedures • Assist in preparing risk reporting and dashboards for senior leadership and committee-level audiences • Monitor the threat and vulnerability landscape and help translate emerging risks into actionable insights for the business • Support security and compliance initiatives, including PCI DSS, SOC 2, and NIST, from a risk lens, ensuring risk findings are integrated into broader compliance activities • Participate in risk-related work streams tied to new product launches, infrastructure changes, and strategic initiatives What you'll bring • 3-5 years of experience in IT risk management, information security, or a related GRC function, ideally within financial services or fintech • Solid understanding of IT and security risk frameworks such as NIST CSF, ISO 27001, or FAIR • Familiarity with key technology risk domains including cloud (AWS preferred), identity and access management and vulnerability management • Experience conducting third-party and vendor reviews, with knowledge of due diligence review methodology, is an asset • Experience maintaining risk registers and supporting risk assessment processes • Working knowledge of compliance frameworks such as SOC 2, PCI DSS, and/or NIST is a strong asset • Strong analytical and written communication skills, with the ability to translate technical risk findings into clear business language • Comfortable working cross-functionally with both technical and non-technical stakeholders • Experience with GRC tools and risk management platforms (e.g.Jira, Drata) is an asset • Self-starter who can operate independently, manage competing priorities, and drive work to completion • Relevant certifications are an asset (CRISC, CISA, CISSP, or equivalent) 🌸 Top-tier health benefits and life insurance Long-term group savings with employer match, through Wealthsimple for Business 20 vacation days, 4 wellness days, and unlimited sick and mental health days per year 90 days away: work outside Canada for up to 90 days per year Employee resource groups, including Rainbow (2SLGBTQ), Women of WS, and Black at WS We are a hybrid team with over 1,500 employees across North America. The people are one of the best parts of working here: you'll collaborate with incredibly talented, curious, and driven teammates who are deeply committed to doing great work. ICYMI Technology & Innovation at Wealthsimple: We move quickly and build thoughtfully. That means we're always looking for better ways to work - whether that's new tools, AI, or rethinking how we approach a problem. We don't expect you to have all the answers, but we do expect curiosity and a willingness to evolve alongside the products we're building.

About Wealthsimple

Wealthsimple is a financial services company that provides online investment management and trading services. The company's platform allows users to invest in a variety of financial products, including stocks, bonds, and exchange-traded funds (ETFs), and offers a range of tools and resources to help users manage their investments. Wealthsimple also offers a high-interest savings account and a tax preparation service. The company was founded in 2014 and is headquartered in Toronto, Canada.
Learn more about Wealthsimple
Size
500 employees
Industry
Founded
2014

Similar Jobs

More Jobs at Wealthsimple

More Information Technology Jobs

Find similar Specialist, Security Risk Management jobs: