Senior Governance, Risk & Compliance (GRC) Analyst

Vale Base Metals - 68 Jobs

Newfoundland and Labrador | Nova Scotia | New Brunswick | Prince Edward Island | Quebec | Ontario | Manitoba | Saskatchewan | Alberta | British Columbia

Posted today

Job Details:

In-person
Full-time
Experienced

Ready to build a rewarding career in an industry that is growing?

Who We Are

We are a global mining company dedicated to safely delivering nickel, copper, cobalt, and platinum group metals essential for the world's energy transition.

Our mission is to improve lives and shape a better future together.

From utensils to cellphones to satellites, our operations simplify daily life and enhance connectivity. Our metals are integral to life-saving medical equipment and the electric vehicles driving the fight against climate change – our work truly matters.

Join our diverse team of 15,000 talented individuals committed to transforming critical minerals into prosperity and sustainable development in countries like Canada, Brazil, Indonesia, the United Kingdom, and Japan. We invite you to use your skills with us and contribute to something meaningful and enduring.

The Opportunity

We are currently seeking a Senior Governance, Risk & Compliance (GRC) Analyst (Global Cybersecurity) to join our Global Cyber Risk, Governance, Risk & Compliance team in Toronto, Ontario.

Reporting to the Senior Manager, Cyber Risk, Audit, Compliance & Data Privacy, you will play a critical role in advancing our global cybersecurity governance, risk management, compliance, audit readiness, privacy governance, and third-party risk programs.

This role partners with stakeholders across Cybersecurity, IT, Operational Technology (OT), Legal, Privacy, Procurement, Internal Audit, Finance, and Business Operations to assess risk, strengthen controls, support compliance efforts, and provide executive-ready reporting that enables informed decision-making across our global organization.

Key Responsibilities

Cyber Governance & Control Framework

  • Support the development, maintenance, and continuous improvement of global cybersecurity policies, standards, controls, and governance processes.
  • Align cybersecurity control frameworks with industry standards including NIST CSF, ISO 27001, COBIT, CIS Controls, and ITGC requirements.
  • Coordinate governance activities and prepare materials for leadership reviews, risk committees, audits, and executive reporting.
  • Promote consistent control ownership, accountability, and evidence management practices globally.

Cyber Risk Assessment & Advisory

  • Lead cybersecurity risk assessments across applications, infrastructure, cloud services, SaaS platforms, identity and access management, OT/ICS environments, and strategic projects.
  • Identify control gaps and recommend remediation, compensating controls, and risk treatment strategies.
  • Advise project teams and technology stakeholders on integrating cybersecurity requirements into design and implementation activities.
  • Prepare risk documentation and executive summaries to support informed business decisions.

Compliance, Assurance & Audit

  • Support internal and external audits, control testing, evidence collection, and remediation tracking activities.
  • Coordinate cybersecurity compliance programs and control self-assessments.
  • Monitor regulatory, privacy, cybersecurity, and governance developments and assess their impact on the organization.
  • Maintain audit-ready documentation, risk registers, and management action plans.

Third-Party Risk Governance

  • Conduct security and risk reviews of suppliers, contractors, SaaS providers, and managed service partners.
  • Evaluate security questionnaires, due diligence assessments, control evidence, and contractual security obligations.
  • Partner with Procurement, Legal, Privacy, and Technology teams to strengthen supplier security governance.
  • Track supplier risks, remediation commitments, exceptions, and risk acceptance decisions.

Reporting & Continuous Improvement

  • Develop dashboards and reporting on cyber risk posture, compliance status, remediation progress, and control health.
  • Translate technical findings into business-focused insights for leadership and stakeholders.
  • Drive improvements in GRC processes, methodologies, reporting, and governance effectiveness.
  • Mentor and support stakeholders on cybersecurity risk management and control expectations.

About You

Experience

  • Minimum 7-10 years of progressive experience in cybersecurity GRC, IT audit, technology risk, compliance, control assurance, privacy, or related advisory roles.
  • Experience supporting global or multinational organizations.
  • Proven experience conducting risk assessments, audit support, compliance reviews, and third-party risk assessments.
  • Experience working across clouds, infrastructure, identity management, applications, and operational technology environments.
  • Strong stakeholder management and influencing skills without direct authority.

Education

  • Undergraduate degree in Cybersecurity, Information Technology, Computer Science, Business, Engineering, Risk Management, Audit, or related discipline.

Skills & Competencies

  • Strong knowledge of NIST CSF, ISO 27001, COBIT, CIS Controls, ITGC/IT SOX, and cybersecurity risk management frameworks.
  • Experience with risk assessments, control testing, audit readiness, compliance programs, and third-party risk management.
  • Strong analytical, problem-solving, and documentation skills.
  • Ability to communicate effectively with technical and non-technical audiences.
  • Advanced proficiency with Microsoft 365, Excel, PowerPoint, SharePoint, GRC tools, and reporting platforms.
  • Strong organizational skills with a high degree of professionalism, confidentiality, and business acumen.

Preferred Qualifications

  • CISA, CRISC, CISM, CISSP, ISO 27001 Lead Implementer/Lead Auditor, COBIT, ITIL, CCSP, CIPM/CIPP, or similar certifications.
  • Experience in mining, industrial, manufacturing, or critical infrastructure environments.
  • Knowledge of OT/ICS cybersecurity and cloud security governance.
  • Experience with OneTrust or similar GRC/privacy platforms.
  • Exposure to board-level cyber risk reporting and audit committee presentations.

What We Offer You

  • Competitive compensation including a variable annual incentive plan
  • Participation in a competitive Defined Contribution Pension package
  • Comprehensive benefits package (company paid core coverage, health and dental coverage, flex accounts, disability plans, and optional insurances)
  • Leave for all of life's reasons (vacation, personal, sick, parental)
  • Work culture dedicated to safety, diversity & inclusion, and career growth
  • Employee Family Assistance Program
  • Virtual Healthcare online
  • Online training and career development opportunities

Why Toronto

Toronto, Canada's largest city and financial hub, is a center of innovation, commerce, and culture. Known for its diverse economy and vibrant urban environment, Toronto offers unparalleled access to talent, technology, and global connectivity.

Our Toronto office serves as a strategic hub for corporate functions, technology development, and business operations. Here, we drive initiatives that support Vale Base Metals' global operations, leveraging advanced analytics, digital transformation, and strategic planning to ensure operational excellence across all regions.

Toronto's dynamic ecosystem enables collaboration with leading technology partners, universities, and research institutions, fostering innovation in mining and metals processing. This location is integral to shaping the future of sustainable mining and advancing our commitment to responsible resource development.

Include to Transform

At Vale Base Metals, we are committed to ensuring an inclusive work environment where people feel comfortable to be themselves. Vale encourages everyone to express their ideas and opinions and values the plurality of individual profiles. We want our people to feel that all.

We want our people to feel that all voices are heard, all cultures respected and that a variety of perspectives are not only welcome – they are critical to our success. We treat each other

fairly and with dignity regardless of race, gender, nationality, ethnic origin, religion, age, sexual orientation, or any other personal consideration that makes us different.

Vale is an equal opportunity employer seeking to increase diversity across our operations and improve equal opportunity at Vale and in the mining industry.

Accommodation is available throughout our recruitment process for applicants with disabilities.

Vale uses artificial intelligence to screen, assess, and/or select applicants for this position.

Pay Grade: F2T

Minimum Starting Salary: CAD $119000

Apply by: Friday, Sep 18, 2026

#ValeBaseMetals

Competition Number: 5591
Company Website: http://valejobs.ca

Share This Job:

About Vale Base Metals

About Vale Base Metals

We are a global mining company dedicated to safely delivering nickel, copper, cobalt, and platinum group metals essential for the world's energy transition.

Our mission is to improve lives and shape a better future together.

From utensils to cellphones to satellites, our operations simplify daily life and enhance connectivity. Our metals are integral to life-saving medical equipment and the electric vehicles driving the fight against climate change - our work truly matters.

Join our diverse team of 15,000 talented individuals committed to transforming critical minerals into prosperity and sustainable development in countries like Canada, Brazil, Indonesia, the United Kingdom, and Japan. We invite you to use your skills with us and contribute to something meaningful and enduring.

Visit Employer Showcase