IT Governance & Risk Analyst – Software Asset Management

Recrute Action

Not Interested
Bookmark
Report This Job

profile Job Location:

Toronto - Canada

profile Monthly Salary: $ 60 - 70
Posted on: 4 hours ago
Vacancies: 1 Vacancy

Job Summary

IT Governance & Risk Analyst Software Asset Management

Exciting opportunity in the insurance industry for a Governance and Risk Analyst specializing in Software Asset Management. Work on high-impact projects aligning with OSFI regulations manage compliance frameworks and enhance risk reporting. Hybrid role in Toronto using ServiceNow SAM Pro and CMDB tools.

What is in it for you:

Salaried: $60-70 per hour.
Incorporated Business Rate: $70-80 per hour.
4-month contract with the potential for permanent employment.
Full-time position: 37.50 hours per week.
In-office presence required from Tuesday to Thursday.
Remote work available on Mondays and Fridays.

Responsibilities:

Develop a comprehensive Software Risk and Governance Framework aligned to internal Standards 031 and OSFI regulatory expectations.
Define governance structures including accountability risk ownership and escalation paths.
Implement compliance monitoring mechanisms and conduct periodic reviews and self-assessments.
Lead internal and external audit coordination related to software risk cybersecurity and governance.
Collaborate with cybersecurity teams to align vulnerability management and resilience testing with federal guidelines.
Create and maintain governance dashboards tracking control maturity risk indicators and OSFI compliance.
Report governance metrics and risk remediation progress to senior leadership.
Continuously enhance governance practices in line with updates to OSFI guidelines (B-10 B-13 E-21).
Maintain software license recognition and validation within SAM Pro and ServiceNow.
Coordinate with cross-functional teams to ensure asset compliance and accuracy in the CMDB.
Support project coordination efforts within the Software Asset Management team.

What you will need to succeed:

Bachelors degree in Information Technology Cybersecurity Risk Management or a related field.
Certified Software Asset Manager (preferred).
37 years of experience in technology risk IT compliance software governance or cybersecurity.
Strong knowledge of OSFI regulations and associated governance frameworks.
Experience designing governance models policies and maturity controls.
Familiarity with ServiceNow modules and CMDB.
Hands-on experience with SAM Pro software asset management tools.
Knowledge of GRC platforms such as ServiceNow GRC Archer or OneTrust (preferred).
IT Asset Management and audit background (preferred).
Excellent analytical documentation and governance design skills.
Clear communicator with the ability to influence stakeholders across functions.
Detail-oriented and experienced working in regulatory environments.
Self-starter and creative thinker who thrives in a collaborative setting.

Why Recruit Action

Recruit Action (agency permit: AP-2000003) provides recruitment services through quality support and a personalized approach to job seekers and businesses. Only candidates who match hiring criteria will be contacted.

# MFCJP



Required Skills:

Cloud Security Architect Drive AWS cloud security strategy in the insurance industry with a senior-level role focused on secure architecture compliance and automation. Leverage your expertise in AWS services threat detection and identity management in a hybrid multi-account environment. Opportunity to lead security-by-design in a regulated sector. What is in it for you: Salaried: $90-95 per hour. Incorporated Business Rate: $104-109 per hour. 12-month contract with the potential for permanent employment. Full-time position: 37.50 hours per week. Hybrid model 3 days per week on-site. Attendance on Tuesday and Wednesday is mandatory. Responsibilities: Design and implement secure landing zones using AWS Control Tower AWS Organizations and Service Control Policies (SCPs). Define multi-account security guardrails for shared services workloads and sandbox environments. Create reference architectures covering security zones network segmentation and cross-account communication (PrivateLink AWS WAN). Lead threat modelling and risk assessments for new workloads and services including Lambda ECS EC2 S3 RDS and DynamoDB. Develop security-by-design templates integrated into Infrastructure as Code (IaC) pipelines. Partner with compliance teams to maintain continuous alignment with CIS Benchmarks and organizational risk frameworks. Implement federated access and single sign-on with AWS IAM Identity Center (AWS SSO) Okta and Azure AD. Manage cross-account roles STS trust policies and temporary credentials for developers and third parties. Automate secret and credential rotation with AWS Secrets Manager and AWS Systems Manager Parameter Store. Enforce encryption at rest using AWS KMS CloudHSM and envelope encryption patterns. Ensure encryption in transit (TLS 1.2/1.3) across internal and public endpoints. Manage key rotation cross-region replication and HSM-based root of trust. Implement S3 Object Lock Macie for data discovery and classification and Access Points for fine-grained data access. Implement PrivateLink AWS WAN and Route 53 Resolver endpoints for service-to-service isolation. Configure Web Application Firewall (WAF) and AWS Shield Advanced for DDoS mitigation. Enforce egress control through Cloud NAT AWS Gateway Load Balancer (GWLB) or custom proxies. Deploy and integrate AWS Security Hub GuardDuty Macie and Inspector for proactive threat detection. Configure Amazon Detective for forensic investigation and anomaly correlation. Integrate findings into SIEM/SOAR platforms such as FortiSOAR or Azure Sentinel. Automate response playbooks with AWS Step Functions Lambda and SNS alerts. Implement AWS Config rules and Conformance Packs to enforce compliance with benchmarks like CIS AWS Foundations. Use AWS Artifact for vendor assurance and control documentation. Manage compliance dashboards via Security Hub Trusted Advisor and Control Tower drift detection. What you will need to succeed: Bachelors degree in Computer Science Information Security or related field. AWS Certified Security Specialty. AWS Certified Solutions Architect Professional. CISSP CISM CCSP GCSA or GIAC Cloud Security Automation certification. 8 years of experience in cybersecurity. 4 years of experience in AWS cloud security architecture. Deep understanding of the AWS Well-Architected Framework (Security Pillar). Strong hands-on expertise in AWS identity and access management encryption network segmentation and compliance. Familiarity with AWS security services including GuardDuty Inspector Security Hub and Macie. Experience automating security controls using AWS native tools and IaC pipelines. Proficiency in incident response using Step Functions Lambda and Systems Manager. Experience integrating with SIEM/SOAR platforms such as FortiSOAR or Azure Sentinel. Why Recruit Action Recruit Action (agency permit: AP-2504511) provides recruitment services through quality support and a personalized approach to job seekers and businesses. Only candidates who match hiring criteria will be contacted. # AVICJP

IT Governance & Risk Analyst Software Asset ManagementExciting opportunity in the insurance industry for a Governance and Risk Analyst specializing in Software Asset Management. Work on high-impact projects aligning with OSFI regulations manage compliance frameworks and enhance risk reporting. Hybr...
View more view more

Company Industry

IT Services and IT Consulting

Key Skills

  • ISO 27001
  • Microsoft Access
  • Risk Management
  • Financial Services
  • PCI
  • Risk Analysis
  • Analysis Skills
  • COBIT
  • NIST Standards
  • SOX
  • Information Security
  • Data Analysis Skills