Security Analyst – GRC supporting clients on their security journey in a remote role at Kobalt.io. Collaborate with vCISOs and manage compliance programs for cybersecurity.
Responsibilities
Partner directly with clients to draft and implement policies and customized security roadmaps, set up and manage user security awareness training campaigns and manage recurring phishing simulations.
Manage small-scale security compliance programs, guiding clients from initial readiness through successful audit completion.
Lead and assist with regular client meetings to track progress, resolve blockers, and maintain project momentum.
Collaborate with vCISOs to design and execute Incident Response tabletop exercises, test the resilience of client IR plans, conduct various security assessments to identify gaps and mature client security postures.
Leverage GRC platforms to accelerate compliance and streamline security program management.
Act as a responsive subject matter expert across all communication channels, ensuring a "customer-first" resolution to security challenges.
Build automation tools to compress manual tasks.
Capture key performance metrics and contribute to the evolution of Kobalt’s service offerings through documentation and knowledge-base creation.
Requirements
3-5 years of experience in GRC, Internal Audit, Information Security, Technology Risk, or related fields.
Direct experience with governance frameworks (e.g., SOC 2, ISO 27001, HIPAA, etc.)
Strong understanding of cybersecurity domains, including Security Operations, Security Engineering, and Information Risk Management.
Customer-first focus, with the ability to support both internal teams and external client inquiries.
Excellent ability to communicate effectively, both verbally and in writing, with clients and internal audiences.
Can work independently and with teams to identify and resolve challenges and overcome roadblocks.
Ability to adapt security best practices to diverse client tech stacks.
Professional certification is desired but not required.
Intermediate scripting/coding skills for process automation.
A strong team player with the ability to provide on-the-job training and knowledge sharing to other team members.
Self-initiative with strong time management and the ability to perform in high-paced environments.
Solid sense of integrity and identification with the mission.
Understanding and basic level competence with AI systems such as Google Gemini, Google NotebookLM, Anthropic Claude, or OpenAI ChatGPT.
Benefits
Competitive salary
health benefits
RRSP matching
equity
Comprehensive health, dental, and vision insurance
Threat Intelligence Analyst investigating telecom security threats and customer deployment data for Enea, a global telecom and cybersecurity software company. Supporting client security reviews and threat intelligence operations.
Information Security Analyst governing End - User Computing risks, controls, and remediation for TD, a major North American bank. Advising stakeholders and supporting governance reporting, audits, and regulatory requirements.
IT Security Analyst II coordinating cybersecurity monitoring, MSP oversight, audits, and incident follow - up. Supporting Veristat’s global life - sciences services and regulated technology environments.
Security Analyst protecting GitLab’s DevSecOps platform through vulnerability triage and CVE operations. Coordinating researchers, customers, and internal teams on secure software response.
SIEM/SOAR cybersecurity analyst monitoring threats, building alerts, and measuring controls. Supporting Wepoint’s digital transformation work for businesses and public sector organizations.
SIEM/SOAR information security analyst supporting Wepoint’s digital transformation services. Developing cybersecurity monitoring cases, alerts, dashboards, and security - control documentation.
Security Analyst II protecting Intact’s insurance operations through incident response and SIEM monitoring. Supporting security platforms, incident resolution, dashboards, and IT security initiatives.