CrawlJobs Logo

Manager, IT Governance, Risk & Compliance

fourseasons.com Logo

Four Seasons

Location Icon

Location:
Canada , Toronto

Category Icon

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

85000.00 - 125000.00 CAD / Year

Job Description:

Reporting to the Director, IT Governance, Risk & Compliance, the GRC Manager is responsible for leading governance and compliance initiatives across all properties and the home office, ensuring alignment with privacy regulations, PCI requirements, and internal policies. The ideal candidate will have experience operating in a global enterprise with complex, cross‑functional dependencies, preferably within hospitality or retail PCI environments where multiple locations across various geographic locations and time zones rely on a centralized GRC team for compliance support and guidance. This includes coordinating evidence collection, managing compliance activities across distributed locations, and ensuring consistent adherence to PCI DSS controls. The role requires strong capabilities in PCI, IT, and cybersecurity risk management, including the ability to assess, identify, track, and mitigate risks across diverse business units and operational areas. The GRC Manager should also be skilled in developing risk remediation plans, driving them to completion, and maintaining ongoing compliance in environments. This includes leveraging GRC tooling such as ServiceNow to support workflow management, helpdesk operations, incident and request tracking, evidence collection, and dashboard reporting, as well as demonstrating strong proficiency in the Microsoft Office suite to produce clear documentation, reporting, and stakeholder communications. The primary focus of this role is leading and maintaining PCI Home Office compliance, ensuring continuous alignment with PCI DSS requirements and internal standards. The role also encompasses managing and supporting compliance activities across properties globally, overseeing helpdesk GRC requests, onboarding new properties and teams, delivering targeted training sessions, and maintaining accurate, up‑to‑date compliance statistics and documentation. This position provides broad exposure to current and future GRC initiatives and plays a critical role in sustaining the organization’s overall IT governance, risk, and compliance posture.

Job Responsibility:

  • Lead the Corporate Office PCI compliance Program, including: Define, collect, and conduct internal reviews for the Corporate Quarterly PCI compliance cycles
  • Lead the planning, evidence collection, and internal review processes for the Corporate Annual PCI assessment
  • Scheduling and participating in all audit-related meetings to ensure consistent communication between teams and the QSA
  • Overseeing remediation of audit findings and tracking progress to closure
  • Work closely with the QSA to ensure the successful annual renewal of the company’s AoC (Attestation of Compliance) and RoC (Report of Compliance) as a Level 1 service provider
  • Facilitating the Corporate annual tabletop major incident response exercise with Corporate TID teams
  • Maintain and update the company’s IT policies, standards, and procedures
  • develop new documentation and RACI matrices
  • communicate changes to relevant stakeholders
  • conduct reviews as required
  • and deliver ongoing training to ensure organization‑wide understanding and adherence
  • Lead TID activities to ensure properties globally meet PCI compliance requirements and regulations: Identify opportunities to streamline property global compliance workflows and implement process optimizations or automation to increase efficiency and reduce operational risk
  • Lead the annual Hotel Security Assessment program and guide properties on how to comply with control requirements
  • Manage HSA findings in ServiceNow and follow up with property stakeholders to ensure timely remediation
  • Oversee PCI helpdesk tickets efficiently
  • Onboard new properties into the compliance program and deliver PCI compliance training and follow-up status calls
  • Monitor PCI compliance status across all properties and oversee the timely renewal of PCI self‑attestations
  • Compile and communicate program metrics, providing the GRC Director with clear visibility into compliance trends and remediation progress
  • Maintain and enhance compliance dashboards, SharePoint sites, reports, and documentation to support program oversight and decision‑making
  • Onboard new corporate teams into the Change Management program and ensure alignment with established processes
  • Collaborate with stakeholders to ensure changes are properly endorsed and effectively communicated to all impacted groups
  • Evaluate change requests to determine PCI significance, working closely with corporate PCI teams to ensure adherence to the internal PCI‑significant change process, documentation, and evidence collection alignment with PCI standards
  • Lead and facilitate weekly CAB (Change Advisory Board) meetings, including: Preparing weekly agenda and presentation
  • Reviewing and approving change requests
  • Follow up on pending change requests and ensure post‑implementation reviews and root cause analyses are documented when unplanned service disruptions or service outages occur
  • Support vendor selection activities by evaluating vendor capabilities, assessing risk and compliance alignment, and recommending solutions that best meet program and business needs
  • Manage GRC vendor relationships to ensure solutions and services align with the company’s operational and business needs
  • Conduct internal reviews and manage the renewal process for GRC‑owned contracts in collaboration with vendors and the Four Seasons internal legal team
  • Support GRC Director in overseeing invoice tracking and budget reconciliation for the PCI program
  • Leverage a wide range of technologies to improve operational efficiency and strengthen compliance management, including leading GRC platforms such as RSA Archer, ServiceNow, MetricStream, Refinitiv, and OpenPages
  • Identify, assess, and document cybersecurity and operational risks across systems, applications, vendors, and business processes, using established risk management practices
  • Conduct regular risk analyses aligned with recognized industry frameworks (such as NIST CSF, NIST 800‑30, ISO 27005) to evaluate control effectiveness and determine overall risk exposure
  • Translate technical findings into clear business impacts to support leaders and stakeholders in making informed, risk‑based decisions
  • Monitor emerging threats, vulnerabilities, and regulatory requirements to proactively assess changes that may affect the organization’s security or compliance posture
  • Collaborate with technology and business teams to drive timely remediation of identified risks, track mitigation progress, and confirm closure through appropriate evidence
  • Maintain and enhance risk registers, dashboards, and reporting mechanisms within the organization’s GRC tool to support leadership reporting, governance activities, and audit readiness
  • Advise teams on secure practices, policies, and control requirements to promote a strong risk‑aware culture across the organization
  • Ensure risk management activities support compliance with relevant standards and regulations (e.g., PCI DSS, data protection requirements, cybersecurity frameworks)

Requirements:

  • Bachelor’s degree or equivalent business qualifications
  • Minimum 5 years of experience with PCI standard and GRC methodologies
  • Information Security Certification or Accreditation is an asset
  • Professional security management certifications are highly preferred (ie. CISSP, CRISC)
  • PCI Compliance: Strong understanding of PCI DSS requirements and the use of compliance tools to support adherence to the standards
  • Reporting & Analytics: Proficient in reporting tools for creating dashboards, analyzing program data, and generating compliance and risk reports that support leadership decision‑making
  • IT Governance: Strong knowledge of governance frameworks such as COBIT and ISO 27001, applying these structures to strengthen compliance and manage risks effectively
  • Ticketing & ITIL: Proficient in ITIL‑based ticketing systems such as ServiceNow to manage incidents, problems, and changes, ensuring smooth service delivery and timely issue resolution
  • Risk Management: Comprehensive understanding of IT and cybersecurity risk practices, including identifying and evaluating risks and supporting remediation efforts
  • Change Management: Experienced in managing and reviewing IT change requests to assess compliance and risk impact, ensuring proper approvals, documentation, and alignment with internal change governance processes
  • Business Productivity Tools: Strong proficiency in the Microsoft Office suite, using these tools to develop reports, presentations, and documentation that support compliance and risk management activities, and to effectively communicate information and updates to stakeholders
  • Strong attention to detail and stakeholder awareness, ensuring all work aligns with compliance standards
  • Results‑focused, with disciplined execution around deadlines, documentation, and reporting
  • Confident presence and professional authority, effectively guiding teams and stakeholders through compliance and risk decisions
  • Analytical thinker capable of evaluating complex issues and making sound, strategic decisions
  • Self‑directed, able to work independently while consistently delivering high‑quality outcomes
  • Improvement‑oriented, with a mindset that seeks root causes and drives continuous enhancement
  • Highly organized multitasker, effective in fast‑paced and evolving environments
  • Clear communicator, able to translate technical and compliance concepts for diverse audiences
  • Experienced in managing compliance activities with centralized oversight across multiple business units and sites, including reviewing evidence, identifying control gaps, and maintaining accurate documentation to support PCI, IT risk, change management, and governance requirements
  • Effective at monitoring compliance performance, analyzing data, and generating clear, meaningful reports that inform decision‑making and ensure alignment with regulatory and internal standards
  • Skilled in preparing clear, well‑structured technical documentation and tailoring content for both technical and non‑technical audiences
  • Capable translating complex risk, compliance, and TID control concepts into practical guidance that supports effective collaboration with stakeholders, vendors, and external partners

Additional Information:

Job Posted:
March 02, 2026

Employment Type:
Fulltime
Work Type:
Hybrid work
Job Link Share:

Looking for more opportunities? Search for other job offers that match your skills and interests.

Briefcase Icon

Similar Jobs for Manager, IT Governance, Risk & Compliance

Enterprise Risk Manager

We're looking for an experienced professional to manage risks across our entire ...
Location
Location
United States , Greenbelt
Salary
Salary:
Not provided
https://www.roberthalf.com Logo
Robert Half
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor’s Degree in Business, Management, Law, or related fields
  • Minimum of 5 years in a risk management role, preferably in a higher education or governmental setting
  • Proficiency in auditing is essential
  • Experience in enterprise risk is crucial
  • Experience in a university environment or government entity is strongly preferred
  • Experience in Governance Risk Compliance (eGRC)
  • Familiarity with risk framework is important
  • Excellent decision-making and leadership capabilities
  • Excellent oral and written communication skills
Job Responsibility
Job Responsibility
  • Identify, assess and monitor risks across all departments and functions
  • Develop and enforce comprehensive risk management policies and procedures that align with our strategic goals
  • Lead the creation and implementation of a risk management plan
  • Monitor and report on the effectiveness of risk management processes to drive continuous improvement
  • Ensure compliance with industry regulations and standards, serving as the primary advisor on risk-related matters
  • Develop risk reports for stakeholders and regulatory bodies
  • Liaising with functional/departmental managers to ensure the organization's risks are managed effectively
  • Provide training and technical support to the organization on risk management concepts and issues
  • Provide strategic guidance to leadership and advise departments on accident prevention, risk reduction, and loss control strategies
  • Ensure workplace compliance with safety regulations by overseeing safety programs
What we offer
What we offer
  • Competitive salary
  • Healthcare benefits
  • Retirement plans
  • Commitment to work-life balance
  • Fulltime
Read More
Arrow Right

AML Compliance Risk Management Senior Analyst

This role is integral part of the country Compliance team. The team is a group o...
Location
Location
Israel , Tel Aviv
Salary
Salary:
Not provided
https://www.citi.com/ Logo
Citi
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Knowledge of AML local laws, rules, regulations and risks
  • At least 5 years of experience at a local financial institution in AML role
  • Has the ability to operate with a limited level of direct supervision
  • Can exercise independence of judgement and autonomy
  • Must be a self-starter, flexible, innovative and adaptive
  • Strong interpersonal skills with the ability to work collaboratively and with people at all levels of the organization
  • Good analytical, process management and implementation tasks
  • Ability to interface and partner with Compliance/AML/Control/Technology/Operations and Business across countries
  • High responsibility, with the ability to go down to details, determined to complete tasks and accurate
  • Proactively execute goals and priorities and prioritize the tasks effectively.
Job Responsibility
Job Responsibility
  • To assist and facilitate research and investigation of potentially AML investigations/escalations, including ensuring timely resolution of cases and filing of suspicious activity report to the regulator
  • To provide an effective ongoing credible challenge on the AML processes managed by the business
  • Working as a Subject Matter Expert in supporting Citi teams on AML matters
  • To support the implementation of the Citi AML Policy, and the various Global AML directives and projects
  • Responsible for implementation of local and global relevant AML regulations
  • Working closely with wide range of business lines and supporting units to ensure effective AML regime and discipline
  • Collaborate with global and regional stakeholders to accomplish unit objectives
  • Manage effective training plan on AML for impacted staff as well as increase and maintain awareness for the importance of AML requirements
  • Prepare, review and/or provide oversight for any other regulatory mandated reporting as applicable
  • Serving as Sanctions officer, manage disposition of transactional alerts
What we offer
What we offer
  • Generous holiday allowance starting at 22 days
  • Private medical insurance packages
  • Employee Assistance Program
  • Hybrid working model with up to 2 days working at home per week
  • Competitive base salary (annually reviewed).
  • Fulltime
Read More
Arrow Right

Third Party Compliance Risk Management Senior Analyst

Serves as a Third Party Compliance Risk Management Senior Analyst for Independen...
Location
Location
United Kingdom , Belfast
Salary
Salary:
Not provided
https://www.citi.com/ Logo
Citi
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Knowledge of Compliance laws, rules, regulations, risks and typologies
  • Excellent written and verbal communication skills
  • Must be a self-starter, flexible, innovative and adaptive
  • Strong interpersonal skills with the ability to work collaboratively and with people at all levels of the organization
  • Work collaboratively with regional and global partners in other functional units
  • ability to navigate a complex organization
  • Excellent project management and organizational skills and capability to handle multiple projects at one time
  • Proficient in MS Office applications (Excel, Word, PowerPoint)
  • Knowledge in area of focus
  • Bachelor's degree
Job Responsibility
Job Responsibility
  • Assessment of Third Party Compliance (ATPC) tool & process owner & subject matter experts (for new relationships & annual assessments)
  • Ongoing buildout of Third Party Compliance Risk Program including strategy, design and ongoing governance for current and post-target state. Includes appropriate tagging and control coverage in MCA
  • Provide guidance and documentation for expectations of PFICRM including tools to support credible challenge requirements
  • Reporting/metrics build out, including identification of areas of high compliance risk and/or weaknesses of quality execution of the ATPC
  • Engage with Compliance Programs for consistency with ATPC future state design under Consent Order
  • Participating in the design, development, delivery and maintenance of best-in-class Compliance, programs, policies and practices for ICRM
  • Analyzing comparative data and preparing regional and global reports related to compliance risk assessments, and monitoring of compliance related issues
  • Reviewing materials to ensure compliance with various regulatory and legal requirements. Identifying and addressing potential risks
  • Investigating and assisting in responses to compliance risk issues. Investigating regulatory inquiries, preparing required documentation, making recommendations to senior management on how to proceed, and preparing responses for the regulatory inquiries
  • Monitoring adherence to Citi’s Compliance Risk Policies and relevant procedures
What we offer
What we offer
  • Generous holiday allowance starting at 27 days plus bank holidays
  • increasing with tenure
  • A discretional annual performance related bonus
  • Private medical insurance packages to suit your personal circumstances
  • Employee Assistance Program
  • Pension Plan
  • Paid Parental Leave
  • Special discounts for employees, family, and friends
  • Access to an array of learning and development resources
  • Fulltime
Read More
Arrow Right

Sr. Director, Cybersecurity Governance, Risk & Compliance

The Sr. Director of Cybersecurity Governance, Risk Management, and Compliance (G...
Location
Location
United States
Salary
Salary:
173500.00 - 419500.00 USD / Year
https://www.hpe.com/ Logo
Hewlett Packard Enterprise
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor's degree or higher in Information Technology, Cybersecurity, Computer Science, or a related field
  • Minimum of 10 years of experience in cybersecurity and/or IT Risk, with at least 5 years focus on GRC
  • Proven track record in a senior leadership role within a large organization
  • Experience in developing and implementing cybersecurity strategies
  • Strong knowledge of relevant regulations and standards, such as GDPR, NIST CSF, and ISO 27001
  • Exceptional leadership and management skills
  • Strong analytical and problem-solving abilities
  • Excellent communication and interpersonal skills
  • Ability to work collaboratively across departments and build consensus
  • Proficient in cybersecurity technologies and tools.
Job Responsibility
Job Responsibility
  • Define and execute a comprehensive cybersecurity GRC strategy that aligns with business objectives and legal/regulatory requirements
  • Partner with cross-functional teams, including Legal, IT, Audit, and Business Units, to integrate security and compliance requirements into business processes
  • Recruit, mentor, and develop a high-performing team of GRC professionals
  • Develop and maintain the cybersecurity governance framework, ensuring it aligns with the organization's overall business objectives
  • Create policies, procedures, and guidelines that support the cybersecurity strategy
  • Ensure compliance with industry standards, regulations, and best practices
  • Identify, assess, and prioritize cybersecurity risks facing the organization
  • Develop risk mitigation strategies and allocate resources to address key risk areas
  • Collaborate with other departments to integrate risk management practices across the organization
  • Monitor and report on the effectiveness of risk management strategies
What we offer
What we offer
  • Comprehensive suite of benefits supporting physical, financial, and emotional wellbeing
  • Career development programs to help achieve career goals
  • Inclusive work environment valuing diverse backgrounds.
  • Fulltime
Read More
Arrow Right

Governance and Conduct Risk Manager

The Governance and Conduct Risk Manager will be responsible for developing, impl...
Location
Location
United Arab Emirates , Dubai
Salary
Salary:
Not provided
https://www.citi.com/ Logo
Citi
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor's degree in Finance, Business Administration, Law, Economics, or a related field
  • Master's degree or relevant professional certifications (e.g., FRM, PRM, CAMS, ICA qualifications) are a plus
  • Understanding of banking regulations, corporate governance principles, and conduct risk expectations
  • Excellent analytical and problem-solving abilities
  • Exceptional verbal and written communication skills
  • Strong ability to build relationships and collaborate effectively across all levels of the organization
  • Ability to think strategically and translate regulatory requirements into practical business solutions
  • Proven ability to manage multiple projects simultaneously
  • Unquestionable integrity and ethical standards
  • Proficient in Microsoft Office Suite
Job Responsibility
Job Responsibility
  • Design, develop, and implement the bank's governance and conduct risk framework
  • Ensure framework integrates with enterprise risk management framework
  • Develop and maintain robust control environment for governance and conduct risks
  • Conduct regular risk assessments
  • Analyze emerging regulatory requirements and industry trends
  • Facilitate workshops with business units
  • Establish and monitor key risk indicators and key performance indicators
  • Develop comprehensive reports for senior management and Board of Directors
  • Oversee tracking and resolution of governance and conduct risk issues
  • Provide expert advice to business units on governance and conduct risk matters
  • Fulltime
Read More
Arrow Right

Director - Governance, Risk and Compliance

We are a fast-growing fintech company seeking a proactive and highly organized G...
Location
Location
United States , New York
Salary
Salary:
175000.00 - 200000.00 USD / Year
clearstreet.io Logo
Clear Street
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 7+ years of experience in GRC, security compliance, risk management, or related functions
  • Strong understanding of common security frameworks (SOC 2, ISO 27001, NIST CSF, PCI-DSS)
  • Experience managing audits end-to-end
  • Demonstrated ability to build and maintain governance processes and cross-functional compliance programs
  • Excellent documentation, communication, and stakeholder-management skills
  • Experience in technology, fintech, financial services, or other highly regulated industries
Job Responsibility
Job Responsibility
  • Develop, maintain, and manage the company’s security and compliance policy framework
  • Ensure policies are current, properly communicated, approved, and effectively implemented across the organization
  • Oversee periodic reviews of all internal policies
  • Educate teams on policy requirements and drive adherence
  • Build, implement, and continuously refine the company’s cyber security risk management framework
  • Lead risk identification, assessment, scoring, and periodic re-evaluations
  • Maintain the corporate risk register
  • Manage all internal and external audits including SOC 2, ISO 27001, regulatory exams, and customer due-diligence requests
  • Coordinate and prepare audit evidence
  • Serve as the primary liaison with external auditors, security assessors, and regulatory bodies
What we offer
What we offer
  • Competitive compensation packages
  • Company equity
  • 401k matching
  • Gender-neutral parental leave
  • Full medical, dental and vision insurance
  • Lunch stipends
  • Fully stocked kitchens
  • Happy hours
  • Fulltime
Read More
Arrow Right

Security Governance Risk & Compliance (GRC) Analyst

Here at Virtru you’ll help build a cutting edge security compliance program alig...
Location
Location
United States , Washington, DC
Salary
Salary:
130000.00 - 180000.00 USD / Year
virtru.com Logo
Virtru
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Minimum of 5+ years of information security, IT audit and/or IT Risk Management, or GRC Analyst/Engineer experience
  • Deep understanding of at least few of the following: CMMC, NIST 800-53 & 800-171, FedRAMP, SOC 2, PCI, and/or other global privacy compliance frameworks
  • Technical acumen. Strong understanding of modern cloud technologies (AWS, GCP, Azure, etc.) and familiarity with GRC tools (Hyperproof, Vanta, Drata, etc) and SIEM tools (Datadog, Splunk)
  • You’re a relationship builder and have worked with both business and technical risk and understand how to translate risk to various levels of the organization
  • Have experience training and coaching teams to become better security and privacy practitioners
  • Like working on an autonomous agile team
  • Ability to resolve conflicts and drive issues to completion
  • Work independently with little or no supervision while maintaining a high level of efficiency
  • Hands on experience deploying and managing vulnerability scanning/cloud security posture management tools (Wiz, Prismacloud, etc.) to meet security compliance requirements
  • Real-world IR experience participating on security On-Call teams
Job Responsibility
Job Responsibility
  • Manage and implement complex controls frameworks for large systems, consisting of Cloud infrastructure and Software as a Service (SaaS) services (GCP, AWS, GitHub, Okta, etc)
  • Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services
  • Conduct risk assessments across business units and processes. Identify risk findings and recommend remediation and risk mitigation strategies
  • Assist or implement automated controls to support risk mitigation efforts across various business units with stakeholders
  • Incorporate CMMC certification into Virtru’s slate of compliance assessments and ongoing monitoring activities (FedRAMP, SOC 2, PCI)
  • Facilitate the third-party vendor on-boarding and annual review process by evaluating the security of current and prospective partners
  • Participate in incident response (IR) activities, providing risk analysis and remediation support as needed
  • Enhance the team with your individualism, spirit, and love of learning
What we offer
What we offer
  • A Flexible PTO policy
  • A $1,500 annual Learning & Development Stipend
  • Frequent company-sponsored team celebrations
  • Access to an Employee Assistance Program
  • Access to Headspace, a mental health app
  • A flat 3% contribution to your retirement account
  • A high degree of flexibility
  • Competitive compensation
  • Generous parental, medical, and bereavement policies
  • 401K contribution and stock options
  • Fulltime
Read More
Arrow Right

Senior Governance, Risk and Compliance Analyst - Governance

Come join the company that is reinventing cloud security and empowering business...
Location
Location
Netherlands
Salary
Salary:
Not provided
wiz.io Logo
Wiz
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 5+ years of experience in one or more of the Governance, Risk, and Compliance domains
  • Passion for security and keeping Wiz safe
  • Ability to collaborate with technical and non-technical teams alike to further oversight responsibilities of Security
  • Deep knowledge of one or more industry frameworks such as ISO 27001, ISO 27017, SOC 2, PCI DSS, NIST CSF, etc. and baseline knowledge of others
  • Ability to assist with security compliance assessments to ensure compliance with internal and external requirements (ISO, NIST, CIS, etc.)
  • Experience working in a fast-paced tech environment both independently, and collaboratively within a team environment
  • Ability to build strong relationships across teams and functions in a global workplace
  • Applicants must have the legal right to work in the country where the position is based, without the need for visa sponsorship
Job Responsibility
Job Responsibility
  • Design and update policies, procedures, and controls to drive confidentiality, integrity, and availability across the Wiz environment
  • Continuously improve processes, tools, and procedures for audit and compliance management
  • Collaborate and work cross-functionally across the company to address governance and compliance needs and to support the Wiz Control Framework, partnering with Engineering, Product, Sales, Legal, HR, and other teams
  • Proactively improvement control design and performance to address a changing risk landscape
  • Deliver timely audits through working with internal and external auditors
  • Help customer-facing teams respond to information security requirements and questionnaires
  • Assist with third party risk management reviews, assessing vendor’s security, compliance, and privacy posture
  • Participate in team project management, including documentation, project planning, task management, and prioritization
  • Participate in recurring annual core audits (e.g., SOC 2, ISO, PCI)
  • Maintain awareness of security and regulatory trends, perform research and analysis on new certifications, and help Wiz pursue new international compliance initiatives
Read More
Arrow Right