Specialist - Cyber Security
Toronto-Ontario-CAOn-siteFull-timeCybersecurity
Description
Job Role: GRC Consultant Location: Missisauga, ON We are looking for someone who genuinely operates across both someone who can go deep on cybersecurity requirements in the morning and present a databacked product recommendation to senior stakeholders in the afternoon You will own the translation layer between compliance and product taking technical security concepts and turning them into crisp requirements user stories and insights that drive real roadmap decisions You will be embedded across our B2B SaaS and B2C consumer product lines and you need to be comfortable with the distinct dynamics each brings Key Responsibilities Act as the connective tissue between technical cybersecurity requirements and product delivery owning documentation requirements and stakeholder alignment end-to-end Analyze data across both SaaS and consumer product lines to surface insights identify gaps and make prioritization recommendations with confidence Translate compliance frameworks NIST SOC 2 ISO 27001 directly into product requirements and acceptance criteria without needing it filtered through a security team first Run stakeholder interviews workshops and review sessions independently communicate findings fluently to both technical and executive audiences Maintain and continuously improve the product backlog write user stories and functional specs that engineering can act on without back and forth Build and own KPI dashboards and product performance reporting used by senior leadership Create wireframes and process flows to communicate product requirements visually using diagramming tools such as Lucid chart or equivalent Support internationalization initiatives including coordination of translation workflows localization compliance and regional regulatory requirements Support sprint planning and serve as a reliable bridge between business needs and engineering execution
Required Qualifications
13 years of experience in a hybrid PM and BA capacity candidates from purely one track or the other will not be considered
Experience across both B2B SaaS and B2C consumer products you understand how user needs data models and stakeholder dynamics differ between the two.
Deep hands-on cybersecurity knowledge is required you should be able to interpret a compliance requirement and write a product spec from it without support
Strong data and analytics skills experience building dashboards or reports that inform product decisions not just track output
Proven ability to communicate complex technical topics clearly to non-technical stakeholders
�this is a core function of the role not a nice to have
Internationalization experience is required including hands-on involvement with translation workflows and localization compliance experience with translation management platforms such as Smartling is strongly preferred Experience with consent management platforms CMPs and the ability to translate privacy and consent requirements into product specifications Experience with subscription billing platforms such as Stripe or Chargebee including familiarity with billing logic and how billing requirements surface in product design Proficiency with diagramming and wireframing tools such as Lucidchart or equivalent Familiarity with NIST SOC 2 or ISO 27001 and the ability to apply them in a product context Fluency in Agile Scrum experience with Azure DevOps or equivalent tools Strong written and spoken English proficiency is required this role involves daily communication with US based stakeholders via Slack Azure DevOps and video calls
Requirements
Mandatory Skills : GRC - Prevalent, GRC Risk - Third Party Risk Management (TPRM), GRC Risk Assessment, Project Planning