Senior GRC Analyst
Ottawa, ON, Canada
Full Time Senior-level / Expert CAD 77K - 88K
Barracuda Networks Inc.
Barracuda Networks is the worldwide leader in Email Protection, Application Protection, Network Security, and Data Protection SolutionsYou will be a member of Barracuda’s Security team and will support the development of global compliance initiatives by leading compliance focused programs, collaborating with other departments and business units on key global policies and procedures, defining and communicating strategies, conducting employee training, and defining compliance-related controls. Tech Stack Exposure
- Microsoft Entra ID, Atlassian Cloud, GitHub, Enterprise Risk Assessment tools, Identity & Access Management tools, and Third-Party Risk Management tools.
- Conduct detailed risk assessments, identify vulnerabilities, and develop mitigation strategies.
- Ensure adherence to regulatory requirements (e.g., GDPR, HIPAA) and industry standards (e.g., ISO 27001, NIST).
- Create and maintain security policies, procedures, and guidelines.
- Lead internal and external audits, including SOC 2, ISO 27k, and other compliance frameworks.
- Develop and implement incident response plans and conduct post-incident reviews.
- Design and deliver security awareness training programs for employees.
- Utilize data analytics tools to monitor compliance metrics and generate reports.
- Lead the onboarding of third-party security vendors (i.e. IAM).
- Collaborate with cross-functional teams to integrate compliance requirements
- Monitor and review regulatory updates and issues relative to pertinent security regulatory requirements.
- Drive continuous improvement efforts to enhance IT compliance and governance practices.
- Bachelor's degree in information security, Computer Science, or a related field.
- 5+ years in a GRC role, preferably within the cybersecurity industry.
- Proficiency in GRC tools (e.g., AuditBoard, Jira, ServiceNow), risk assessment methodologies, and compliance frameworks.
- Relevant certifications such as CISSP, CISM, CRISC, or CISA.
- Strong analytical, communication, and project management skills.
Tags: Analytics Audits CISA CISM CISSP Cloud Compliance Computer Science CRISC Data Analytics GDPR GitHub Governance HIPAA IAM Incident response ISO 27000 ISO 27001 Jira NIST Risk assessment Risk management SOC SOC 2 Vulnerabilities XDR
Perks/benefits: Career development Equity / stock options
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.