LocationBrookfield Place - 181 Bay Street
Technology ServicesTechnology Services (TS) is responsible for delivering all enterprise infrastructure, applications and related end user technology services across all Brookfield business groups.
Job DescriptionDepartment: Technology Services (IT Risk & Compliance)
Reports To: ITRC Manager
Role SummaryThe Senior Analyst is responsible for supporting internal and external audit, execute attestation, and governance activities within the IT Risk and Compliance program. This role supports audit readiness, performs control assessments, and collaborates with stakeholders to ensure compliance with internal policies and external requirements. The position focuses on delivering high-quality audit support and governance outcomes.
Key Responsibilities- Support internal and external audits by coordinating requests, gathering evidence, and facilitating discussions
- Execute control assessments and compliance reviews to evaluate design and operating effectiveness
- Perform vendor risk assessments and review third-party control reports from an IT risk standpoint.
- Validate control deficiencies and track remediation activities to completion
- Collaborate with stakeholders to assess risk and provide recommendations for mitigation
- Support the development and enhancement of reporting tools and dashboards
- Contribute to governance processes related to cloud and security environments
- Identify opportunities to improve processes and enhance efficiency
Required Experience- 2-5 years of experience in IT risk, compliance, or audit functions
- Experience supporting SOX and IT audits, ITGC testing within SOX compliance programs, and compliance assessments such as NIST and SWIFT Customer Security Programme (CSP)
- Experience with cloud and security governance practices, including basic knowledge of cloud environments and experience supporting cloud audits and cloud risk assessments
- Experience in IT vendor risk management or third-party assessments is a good to have
- Experience working with governance and reporting tools such as AuditBoard, OneTrust is a plus.
- Experience with SOC 1/SOC 2 report reviews and audit coordination
- Basic knowledge of security vulnerability management practices and processes
Skills & Qualifications- Strong analytical and problem-solving skills
- Understanding of IT control frameworks and compliance practices
- Effective communication and collaboration skills
- Ability to manage multiple priorities and deadlines
- Knowledge of GRC platforms such as OneTrust and AuditBoard
- Understanding of cloud environment risks and security vulnerability management concepts
Preferred Qualifications- Bachelor's degree in information technology or accounting fields.
- Professional certifications such as CISA and/or CISSP.
- Experience with ServiceNow is an added advantage
Salary Range: $80,000 - $100,000 CAD
Position Opening Reason:New Position