安全风险管理专员
Specialist, Security Risk Management
### **打造人们喜爱的产品**
Wealthsimple 是加拿大的领先金融创新者。公司提供一系列简单而先进的金融产品,涵盖托管投资、自助交易、加密货币、税务申报、消费和储蓄。Wealthsimple 目前为超过 400 万加拿大用户提供服务,管理的资产超过 1550 亿美元。公司由一群金融专家和技术企业家于 2014 年创立,总部位于加拿大多伦多。
我们为我们所构建的一切感到自豪——而我们才刚刚开始。阅读我们的 [文化手册](https://www.wealthsimple.com/en-ca/culture),了解更多 [我们的工作方式](https://www.wealthsimple.com/en-ca/careers)。
安全 GRC 团队在遵循安全框架和创造风险缓解与监督空间方面发挥着关键作用。我们希望通过实施和监控旨在保护信息、系统和基础设施的控制措施,确保 Wealthsimple 维持安全的运营环境。
我们正在寻找一位 IT/安全风险管理专家来壮大安全 GRC 团队,以支持并提升我们的企业 IT 和安全风险管理计划。该职位将负责识别、评估和跟踪 Wealthsimple 技术和安全领域的风险,帮助确保风险暴露情况被充分理解和积极管理。
你将与安全、工程、基础设施、产品和合规团队密切合作,评估风险,维护我们的风险登记册,并推动风险处理活动。这是一个需要动手操作的角色,适合一名分析能力强、注重细节且能在快速发展的金融科技环境中工作的人员。
### **在这个职位上,你将有机会**
- 支持端到端的 IT 和安全风险管理生命周期,包括风险识别、评估、处理跟踪和报告
- 维护并持续改进企业 IT/安全风险登记册,确保风险被准确记录、评级并分配给合适的负责人
- 在技术领域(云基础设施、访问管理、应用安全)和第三方进行风险评估,并使用适用于每个领域的适当方法
- 与控制负责人和业务相关方合作,评估风险缓解控制措施的有效性并识别差距
- 将供应商和科技风险发现整合到风险登记册中
查看英文原文
### **Build something people love**
Wealthsimple is Canada’s leading financial innovator. The company offers a full suite of simple, sophisticated financial products across managed investing, do-it-yourself trading, cryptocurrency, tax filing, spending and saving. Wealthsimple currently serves more than 4 million Canadians and holds over $155 billion in assets under administration. The company was founded in 2014 by a team of financial experts and technology entrepreneurs, and is headquartered in Toronto, Canada.
We're proud of what we've built — and we're just getting started. Read our [Culture Manual](https://www.wealthsimple.com/en-ca/culture) and learn more about [how we work](https://www.wealthsimple.com/en-ca/careers).
The Security GRC team plays a critical role in adhering to security frameworks and creating space for risk mitigation and oversight. We want to ensure that Wealthsimple maintains a secure operational environment by implementing and monitoring controls designed to protect information, systems and infrastructure.
We are looking to grow the Security GRC team with a Specialist, IT/Security Risk Management to support and mature our enterprise IT and security risk management program. This role will be central to identifying, assessing, and tracking risks across Wealthsimple's technology and security landscape, helping ensure that risk exposure is well-understood and actively managed.
You'll partner closely with teams across Security, Engineering, Infrastructure, Product, and Compliance to assess risk, maintain our risk register, and drive risk treatment activities. This is a hands-on role suited for someone who is analytical, detail-oriented, and comfortable operating in a fast-moving fintech environment.
### **In this role, you'll have the opportunity to**
- Support the end-to-end IT and security risk management lifecycle, including risk identification, assessment, treatment tracking, and reporting
- Maintain and continuously improve the enterprise IT/security risk register, ensuring risks are accurately documented, rated, and assigned to appropriate owners
- Perform risk assessments across technology domains (cloud infra, access management, application security) and third-party assessments using the appropriate methodology for each
- Partner with control owners and business stakeholders to evaluate the effectiveness of risk mitigation controls and identify gaps
- Integrate vendor and technology risk findings into the risk register to facilitate tracking and remediation across both IT/Security and Third-Party Risk Management.
- Contribute to the development and maintenance of risk policies, standards, and procedures
- Assist in preparing risk reporting and dashboards for senior leadership and committee-level audiences
- Monitor the threat and vulnerability landscape and help translate emerging risks into actionable insights for the business
- Support security and compliance initiatives, including PCI DSS, SOC 2, and NIST, from a risk lens, ensuring risk findings are integrated into broader compliance activities
- Participate in risk-related work streams tied to new product launches, infrastructure changes, and strategic initiatives
### **What you'll bring**
- 3–5 years of experience in IT risk management, information security, or a related GRC function, ideally within financial services or fintech
- Solid understanding of IT and security risk frameworks such as NIST CSF, ISO 27001, or FAIR
- Familiarity with key technology risk domains including cloud (AWS preferred), identity and access management and vulnerability management
- Experience conducting third-party and vendor reviews, with knowledge of due diligence review methodology, is an asset
- Experience maintaining risk registers and supporting risk assessment processes
- Working knowledge of compliance frameworks such as SOC 2, PCI DSS, and/or NIST is a strong asset
- Strong analytical and written communication skills, with the ability to translate technical risk findings into clear business language
- Comfortable working cross-functionally with both technical and non-technical stakeholders
- Experience with GRC tools and risk management platforms (e.g.Jira, Drata) is an asset
- Self-starter who can operate independently, manage competing priorities, and drive work to completion
- Relevant certifications are an asset (CRISC, CISA, CISSP, or equivalent)
### **Why Wealthsimple?**
🌸 Top-tier health benefits and life insurance
📈 Long-term group savings with employer match, through Wealthsimple for Business
🌴 20 vacation days, 4 wellness days, and unlimited sick and mental health days per year
✈️ 90 days away: work outside Canada for up to 90 days per year
👥 Employee resource groups, including Rainbow (2SLGBTQ), Women of WS, and Black at WS
🌎 We are a hybrid team with over 1,500 employees across North America. The people are one of the best parts of working here: you'll collaborate with incredibly talented, curious, and driven teammates who are deeply committed to doing great work.
### **ICYMI**
**Technology & Innovation at Wealthsimple:** We move quickly and build thoughtfully. That means we're always looking for better ways to work — whether that's new tools, AI, or rethinking how we approach a problem. We don't expect you to have all the answers, but we do expect curiosity and a willingness to evolve alongside the products we're building.
**Inclusion Statement:** We're building products for a diverse world, and we need a diverse team to do it well. We strongly encourage applications from everyone, regardless of race, religion, colour, national origin, gender, sexual orientation, age, marital status, or disability status.
**Accessibility Statement:** We're committed to an accessible hiring experience. If you need any accommodations throughout the interview process, please let us know — we'll work with you to make sure you have what you need. We also welcome any feedback on how we can better accommodate candidates with accessibility needs.
**AI in Hiring:** We may use artificial intelligence (AI) tools to support parts of our hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our team but don't replace human judgment – all final hiring decisions are made by people. If you have questions about how your data is used, reach out to us.