Sentrix

GRC · Montréal

Senior Cybersecurity Analyst, GRC

Senior GRC analyst in Montréal: lead customers' ISO 27001, SOC 2, TGV and CPCSC programs, assess risks, write policies and prepare audits with the team.

Team
Compliance services
Location
Montréal, Québec · Hybrid
Type
Full-time
Posted
2026-09-20
Languages
French · English

You lead our customers' governance, risk and compliance programs, from gap analysis to certification. You work with leadership teams that must decide, IT teams that must execute, and auditors who must be convinced by evidence.

What you will do

  • Lead certification and attestation engagements: ISO 27001, SOC 2, TGV, CPCSC, CAN/DGSI 104, and sector requirements (OSFI, Law 25, GDPR).
  • Carry out gap analyses and risk assessments, and turn them into prioritized treatment plans the customer's leadership can decide on.
  • Write and get adopted the policies, procedures and statement of applicability; organize evidence in the Sentrix platform.
  • Prepare customers for audit, run internal audits, manage nonconformities and corrective actions through closure.
  • Structure third-party risk programs: questionnaires, vendor assessment, action plan follow-up.
  • Answer our customers' customers' security questionnaires and auditors' requests.
  • Contribute to the evolution of framework content and crosswalks in the platform, with the product team.

What we expect

  • At least eight years in information security, five of them in governance, risk and compliance, with programs led through to certification.
  • CISA, CISM, CRISC, ISO 27001 Lead Implementer or Lead Auditor certification; CISSP an asset.
  • Practice of ISO 27001:2022, SOC 2 and NIST CSF; knowledge of Law 25 and GDPR; TGV and CPCSC a strong asset.
  • Impeccable writing in French and English: policies, audit reports, answers to auditors.
  • Ability to run workshops with leadership and to carry several engagements in parallel.

What makes the difference

The judgement to tell a real risk from a formal gap, the firmness to tell a customer what they do not want to hear, and the wish to leave behind a program the customer can run without us.

Apply : Senior Cybersecurity Analyst, GRC

Name the role in your message and include a link to your profile or résumé.

Frequently asked questions

How is this different from the Senior Cybersecurity Analyst role?
The senior cybersecurity analyst starts from the technical side and works up to governance; you start from governance, risk and compliance and work down to the controls. You lead customers' certification programs, run their risk assessments, write their policies and prepare them for audit, in Sentrix and outside it.
Which certifications do you expect?
At least one of CISA, CISM, CRISC or ISO 27001 Lead Implementer or Lead Auditor, with real practice of at least two certification audit cycles. CISSP is an asset, not a requirement. We look above all at the programs you led to certification and how you handled nonconformities.
How do I apply?
Through the site's contact form, naming the role and including a link to your profile or résumé. We answer every application; shortlisted profiles have a first thirty-minute call, then a case interview around a risk assessment and a statement of applicability.

Last updated: 2026-09-20