GRC Lead/Security Analyst
Ivalua · Montreal - Canada · 2026-08-10
About this role
GRC Lead/Security Analyst
(Montreal - Canada)
Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions.
COMPANY OVERVIEW
At Ivalua we are a global community of exceptional professionals, who believe that digital transformation revolutionizes supply chain sustainability and resiliency to unlock the power of supplier collaboration. We achieve this through our leading cloud-based spend management platform that empowers hundreds of the world's most admired brands to effectively manage all categories of spend and all suppliers to increase profitability, improve ESG (environmental, social, and corporate governance) performance, lower risk, and improve productivity. Driven by our passions and fueled by our shared ambitions, we empower and challenge each other to create meaningful experiences for our colleagues, customers, partners, and communities.
Learn more at www.ivalua.com. Follow us on LinkedIn
THE OPPORTUNITY
CONTEXT:
You will be part of the InfoSec team with a mission to build, maintain, and continuously improve our Information Security program, providing peace of mind and assurance of protection and safety to our customers. Our team is hands-on, with a strong problem-solving mindset, capable of thinking holistically about implementation and providing solutions to address our customers' long-term challenges. We work hard and play hard, enjoying various indoor and outdoor activities organized by the company, allowing you to focus, collaborate, and unleash your creativity.
ROLE:
We are looking for a GRC Lead/Security Analyst to join our InfoSec team. This role will help drive various GRC activities which include supporting prospect and customer security questions, maintaining security policies, supporting security audits and assessments and driving new security certifications/compliance initiatives.
WHAT YOU WILL DO WITH US
• Lead and support compliance initiatives in accordance with global and regional standards, including SOC 1/SOC 2, ISO 27001, IRAP, PCI-DSS, SecNumCloud, Cyber Essentials Plus (CE+), BSI C5, and NIST 800-53.
• Evaluate technical controls across the entire technology stack, including all layers of the TCP/IP model (e.g., network segmentation, firewall rules, TLS/SSL configuration, IDS/IPS, access controls, application security, encryption in transit and at rest, and cloud security configurations), and translate security requirements into concrete guidelines for engineering and infrastructure teams.
• Lead and manage client security audits, security questionnaires, and contract reviews, primarily for the EMEA region. Participate in the negotiation and review of French contracts to ensure alignment with security and compliance requirements.
• Participate in meetings with prospects and clients and effectively present Ivalua’s security architecture and controls to them.
• Lead or support internal and third-party security risk management processes, including the identification, analysis, scoring, mitigation planning, and ongoing monitoring of risks.
• Support ongoing compliance monitoring activities using manual processes, automation, and GRC tools to maintain the effectiveness of controls, generate audit evidence, and ensure ongoing audit readiness.
• Ensure the implementation and coordination of key security and availability controls, such as business impact assessments, disaster recovery plan tests, security incident response drills, access reviews, etc.
YOUR PROFILE
If you have the below experience and strengths this role could be for you:
Skills and Experience:
• At least 4 years of experience as a GRC Security Analyst.
• Solid practical knowledge of security, risk, and compliance frameworks (e.g., NIST CSF & 800-53, ISO 27001, SOC, HITRUST, HIPAA, PCI-DSS, GDPR).
• Direct experience managing audits, self-assessments, or risk assessments against one or more of the InfoSec frameworks listed above.
• Experience in implementing or supporting security risk management processes (risk assessments, risk registers, business impact analyses).
• Proficiency with continuous compliance and monitoring platforms.
• A solid understanding of cloud platforms (Azure, AWS, GCP) and the ability to discuss security architecture and the implementation of controls with technical teams.
• Knowledge and experience working with the IT and security team, as well as a thorough understanding of security concepts across all technology layers (network, infrastructure, web applications, cloud environments).
• Knowledge of security and risk industry literature, as well as leading reference knowledge bases (e.g., OWASP, MITRE ATT&CK, NIST 800-39).
• Relevant certifications in auditing and/or information security (e.g., CISSP, CISA, CISM, Azure Cloud Security) are preferred.
• Previous experience at a Big 4 firm or in a security/compliance role in a cloud/SaaS environment is a plus.
• Bachelor’s degree in Computer Science, or relevant field preferred with a minimum of 4 years of relevant professional experience OR Equivalent combination of education and experience
Soft Skills:
• Excellent interpersonal, organizational, and communication skills. Ability to communicate effectively and professionally in French and English, including in contractual, regulatory, and technical contexts.
• Ability to conduct business in English is required given our customer base; wherever possible, we will support the employee's right to work in French
• Proven ability to work with geographically dispersed teams as well as with external service providers, auditors, or regulators.
Strong organizational skills and attention to detail; ability to manage multiple priorities simultaneously in a fast-paced environment.
• Strong sense of initiative, high level of motivation, and the ability to work independently with minimal supervision.
WHAT HAPPENS NEXT
If your application fits this specific position’s needs, our skilled Talent team will reach out to schedule…
Skills asked for
- rest
- azure
- aws
- gcp
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.