The Opportunity:
Symcor is seeking an experienced IT Risk and Compliance professional to support and strengthen our enterprise-wide IT Risk and Compliance program. In this senior role, you will work closely with the Director to design, implement, and monitor risk and control initiatives that align with regulatory requirements, internal policies, and client expectations. This role offers the opportunity to contribute meaningfully to Symcor’s risk posture while collaborating with cross-functional teams across the organization.
This is a hybrid role with requirements to be on site 3 days a week, providing a balance between remote flexibility and in-person collaboration.
About The Role:
Lead the design, implementation, and ongoing management of Symcor’s IT Risk and Compliance program.
Develop and execute IT control testing to identify gaps and ensure alignment with internal policies and industry regulations.
Partner with HR to design and deliver company-wide information security awareness and training programs.
Create and maintain IT risk reports and dashboards, including risk profiles, key risk indicators (KRIs), key performance indicators (KPIs), and more.
Support annual IT security planning and maintain the IT risk register with insights on trends and KRIs.
Serve as the primary IT contact for internal/external audits, client assessments, and vendor risk evaluations.
Collect and organize evidence for audits and compliance reviews.
Collaborate with Legal, Privacy, Procurement, and Vendor Management to streamline contract and MSA (Master Service Agreement) requirements.
Oversee compliance reporting and support ongoing monitoring of controls.
Manage operational compliance processes such as firewall rule approvals, privileged ID reviews, and data leakage prevention follow-ups.
Coordinate penetration testing and SSL certificate management for internal and external stakeholders.
Review policies, architecture, and design documents from a risk and compliance perspective.
Mentor and coach junior members of the IT Risk and Compliance team.
What You Need to Succeed:
Education:
Completion of a post-secondary college diploma or university degree in a related discipline or a combination of education, training and experience deemed to be equivalent.
CISA, CISSP, CISM, CRISC, CIA, CGEIT or similar active certification
Experience:
Minimum of 5+ years in IT Risk, IT Security, IT Audit, or IT Governance.
Strong experience in banking, financial services, or large enterprise environments.
Skills and Knowledge:
Solid understanding of the threat landscape and regulatory expectations.
Strong knowledge of IT frameworks and standards: PCI DSS, ISO/IEC 27002, COBIT, Trust Services Criteria, etc.
Experience using GRC (Governance, Risk, and Compliance) tools.
Awareness of industry trends and best practices related to IT Risk, Compliance, and third-party risk management.