Security Analyst – GRC supporting clients on their security journey in a remote role at Kobalt.io. Collaborate with vCISOs and manage compliance programs for cybersecurity.
Responsibilities
Partner directly with clients to draft and implement policies and customized security roadmaps, set up and manage user security awareness training campaigns and manage recurring phishing simulations.
Manage small-scale security compliance programs, guiding clients from initial readiness through successful audit completion.
Lead and assist with regular client meetings to track progress, resolve blockers, and maintain project momentum.
Collaborate with vCISOs to design and execute Incident Response tabletop exercises, test the resilience of client IR plans, conduct various security assessments to identify gaps and mature client security postures.
Leverage GRC platforms to accelerate compliance and streamline security program management.
Act as a responsive subject matter expert across all communication channels, ensuring a "customer-first" resolution to security challenges.
Build automation tools to compress manual tasks.
Capture key performance metrics and contribute to the evolution of Kobalt’s service offerings through documentation and knowledge-base creation.
Requirements
3-5 years of experience in GRC, Internal Audit, Information Security, Technology Risk, or related fields.
Direct experience with governance frameworks (e.g., SOC 2, ISO 27001, HIPAA, etc.)
Strong understanding of cybersecurity domains, including Security Operations, Security Engineering, and Information Risk Management.
Customer-first focus, with the ability to support both internal teams and external client inquiries.
Excellent ability to communicate effectively, both verbally and in writing, with clients and internal audiences.
Can work independently and with teams to identify and resolve challenges and overcome roadblocks.
Ability to adapt security best practices to diverse client tech stacks.
Professional certification is desired but not required.
Intermediate scripting/coding skills for process automation.
A strong team player with the ability to provide on-the-job training and knowledge sharing to other team members.
Self-initiative with strong time management and the ability to perform in high-paced environments.
Solid sense of integrity and identification with the mission.
Understanding and basic level competence with AI systems such as Google Gemini, Google NotebookLM, Anthropic Claude, or OpenAI ChatGPT.
Benefits
Competitive salary
health benefits
RRSP matching
equity
Comprehensive health, dental, and vision insurance
Analyste en sécurité des produits chez Alithya, intégrant la sécurité de l’information aux projets technologiques. Évaluation des risques, recommandations et suivi des mesures de sécurité.
Intermediate SOC Analyst monitoring and responding to security incidents for Long View, a North American IT provider. Managing SIEM tools, cloud environments, escalations, and 24x7 operations.
Azure AD Security Analyst leading identity and access management for Intact, a Canadian insurer. Integrating Azure AD, supporting IAM architecture, automation, privileged access, and major incidents.
Analyste sécurité informatique chez Beneva, compagnie d’assurance et de services financiers. Intégration des contrôles IAM, analyse des exigences de sécurité et accompagnement des équipes applicatives.
Security Analyst leading Cyber Threat Exposure Management transformation for iA Financial Group, a Canadian insurance and wealth - management provider. Coordinating risk reduction, governance, and cross - functional CTEM initiatives.
Senior Security Risk Analyst at Twilio enhancing security risk management and collaborating with cross - functional teams. Focused on identifying and mitigating cyber risks effectively and ensuring compliance.