GRC Manager / Security Analyst
(Montreal - Canada)
Founded in 2000, Ivalua is a global leader in cloud-based spend management solutions.
OUR COMPANY
At Ivalua, we are a global community of experts convinced that digital transformation makes supply chains more sustainable and resilient, while improving collaboration with suppliers. We achieve this through our cloud-based spend management platform, which enables hundreds of major brands to manage their spending and suppliers while optimizing their profitability, ESG (Environmental, Social, and Governance) performance, reducing risks, and improving productivity. Driven by our passions and fueled by our shared ambitions, we empower ourselves to meet challenges and create impactful experiences for our customers and our partner ecosystem, while giving meaning to our teams.
Find out more at www.ivalua.com. Follow us on LinkedIn
THE OPPORTUNITY
CONTEXT:
You will be part of the InfoSec team with the mission to design, maintain, and continuously improve our information security program, providing peace of mind and guarantees of protection and security to our customers. Our team is field-oriented, with a strong problem-solving spirit, capable of thinking about implementation globally and proposing solutions to meet our customers' long-term challenges. We work hard and know how to unwind, enjoying various indoor and outdoor activities organized by the company, allowing you to focus, collaborate, and unleash your creativity.
ROLE:
We are looking for a GRC Manager / Security Analyst to join our InfoSec team. This role will contribute to driving various GRC activities, including handling security questionnaires from prospects and customers, maintaining security policies, supporting security audits and assessments, and leading new security certification and compliance initiatives.
WHAT YOU WILL DO WITH US
- Lead and support compliance initiatives within global and regional frameworks, including SOC 1/SOC 2, ISO 27001, IRAP, PCI-DSS, SecNumCloud, Cyber Essentials Plus (CE+), BSI C5, NIST 800-53.
- Evaluate technical controls across the entire technology stack, including all layers of the TCP/IP model (e.g., network segmentation, firewall rules, TLS/SSL configuration, IDS/IPS, access controls, application security, encryption in transit/at rest, cloud security configurations), and translate security requirements into concrete guidelines for engineering and infrastructure teams.
- Lead and manage customer security audits, security questionnaires, and contract reviews, primarily for the EMEA region. Participate in the negotiation and review of French contracts to ensure alignment with security and compliance obligations.
- Participate in meetings with prospects and customers and effectively present Ivalua's security architecture and control mechanisms to them.
- Lead or support internal and third-party security risk management processes, including identification, analysis, scoring, treatment planning, and continuous risk monitoring.
- Support continuous compliance monitoring activities using manual processes, automation, and GRC tools to maintain control effectiveness, generate audit evidence, and ensure constant audit readiness.
- Ensure the execution and coordination of key security and availability controls, such as business impact analysis, disaster recovery plan testing, security incident response exercises, access reviews, etc.
YOUR PROFILE
If you possess the experience and assets below, this position might be for you:
Skills and experience:
- At least 4 years of experience as a GRC Security Analyst.
- Strong practical knowledge of security, risk, and compliance frameworks (e.g., NIST CSF & 800-53, ISO 27001, SOC, HITRUST, HIPAA, PCI-DSS, GDPR).
- Direct experience in managing audits, self-assessments, or risk assessments against one or more of the InfoSec frameworks listed above.
- Experience in conducting or supporting security risk management processes (risk assessments, risk registers, business impact analyses).
- Proficiency in continuous compliance and monitoring platforms.
- Good understanding of cloud platforms (Azure, AWS, GCP) and the ability to discuss security architecture and control implementation with technical teams.
- Knowledge and experience working with IT and security teams, as well as mastery of security concepts across all technology layers (network, infrastructure, web applications, cloud environments).
- Knowledge of security and risk industry literature, as well as reference knowledge bases (e.g., OWASP, MITRE ATT&CK, NIST 800-39).
- Relevant certifications in audit and/or information security (e.g., CISSP, CISA, CISM, Azure Cloud Security) are desired.
- Prior experience within a Big 4 firm or in a security/compliance role in a cloud/SaaS environment is a plus.
- Bachelor's degree in computer science or a relevant field (preferred), with at least 4 years of relevant professional experience OR an equivalent combination of education and experience.
Soft Skills
- Excellent interpersonal, organizational, and communication skills. Ability to communicate effectively and professionally in French and English, including in contractual, regulatory, and technical contexts.
- Given our clientele, proficiency in English is essential; as far as possible, we will respect the right of employees to work in French.
- Demonstrated ability to work with geographically distributed teams as well as external providers, auditors, or regulators.
- Strong organizational skills and rigor/attention to detail; ability to manage multiple priorities simultaneously in a fast-paced environment.
- Strong sense of initiative, highly motivated, and ability to work independently with limited supervision.
WHAT HAPPENS NEXT
If your application matches the skills desired for this role, our recruitment team will contact you to schedule an initial phone call. Take a step closer to achieving your goals - apply today!
A dedicated recruiter will guide you through every step of the recruitment process. We are here to support you!
Our recruitment process is designed to evaluate your skills through a series of personalized interviews with our teams. Interviews will take place virtually and in person at our offices.
WHAT YOU WILL FIND AT IVALUA
- A “Hybrid” model (3 days on-site, 2 days remote),
- We are a team driven by the desire to push the boundaries of product and technological innovation,
- Privately held company in constant growth,
- A stable and profitable company,
- Every week, the opportunity to get together around a meal provided by the company,
- Thrive while pursuing your goals through a powerful team mindset, conducive to creativity and productivity,
- Reveal your professional potential through our training and career development program,
- Join a dynamic and international team composed of experts in their fields, and collaborate with people passionate about their work and guided by the same vision,
- Experience an inclusive work environment open to diversity, where your contribution will be appreciated and valued,
- Take part in the many events organized by the company (sports competitions, musical events, and team building),
- Highly rated by its employees, Ivalua has been named by the company Comparably (https://www.comparably.com/companies/ivalua):
Driven by our differences - Your energy is our strength!
United by our values, we celebrate diversity and equity in all their breadth to build an inclusive work environment. To help our customers make their supply chains more efficient, sustainable, and resilient, we rely on our international teams with diverse and varied backgrounds, skills, and perspectives. We believe in equal opportunity and diversity as drivers of innovation, fostering a spirit of inclusivity, a productive and pleasant work environment, and offering fulfilling career prospects for all Ivaluans.
Experience Ivalua - watch our captivating video! Discover our unique company culture and a glimpse of what it's like to work with us.
#LI-MV1
#LI-HYBRID
