Hiring.Camp

IT Governance, Risk & Compliance (GRC) Analyst 1

Opportunities

·

Yesterday

Salary
$55k – $80k
Location
Canada - Ottawa (Bill Leathem)
Workplace
Onsite
Type
Full-time
Department
Legal
Source
Workday

Description

It's fun to work in a company where people truly BELIEVE in what they're doing!
We're committed to bringing passion and customer focus to the business.


If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!


Lumentum Canada was awarded the 2022 National Capital Region’s Top Employers for the 6th consecutive year and the 2022 Career Directory Canada’s Best Employers for Recent Graduates for the 5th consecutive year.
 

Position Title: IT Governance, Risk & Compliance (GRC) Analyst 1

Employment Type: Full-time, Existing vacancy

Location: Ottawa (On-Site)

About Lumentum

At Lumentum, we’re building the tech behind the world’s fastest networks and most advanced systems. Our optical and photonic solutions power everything from AI and cloud computing to data centers, telecom, and advanced manufacturing.

We’re a global team of innovators working where light meets technology, solving big challenges that keep the world connected and moving forward. If shaping the future of connectivity excites you, you’ll fit right in.

Why You’ll Love This Role

At Lumentum, we are searching for Canada’s brightest young minds engineers and innovators who want to build the next generation of optical technology. If you are driven by curiosity, eager to solve real-world challenges, and excited about developing groundbreaking optical systems, this is your opportunity.

Join us in designing the future of optical cloud & networking technology our advanced photonic modules power the world’s voice and internet traffic, and we need your expertise to take them to the next level. This is not just another job; this is your chance to define & design what’s next in photonics.

What You’ll Be Doing

The IT Governance, Risk & Compliance (GRC) Analyst I supports the organization's information security governance, risk management, compliance, audit, and third-party risk management (TPRM) programs. This role assists in maintaining security policies, conducting risk assessments, supporting internal and external audits, evaluating third-party security risks, and ensuring compliance with applicable regulatory and industry frameworks. This role works closely with IT, Security, Legal, Procurement, Privacy, Internal Audit, and business stakeholders to ensure that information systems, processes, and controls align with organizational policies, industry standards, and regulatory requirements.

The ideal candidate is a proactive, detail-oriented professional with strong analytical and organizational skills and a strong understanding of cybersecurity, governance, risk management, and compliance principles. They communicate effectively with both technical and non-technical stakeholders, demonstrate a collaborative mindset, and are committed to continuous learning and professional growth in cybersecurity governance and risk management.

Responsibilities will include:

Governance & Policy Management

  • Assist with maintaining information security policies, standards, and procedures.
  • Help keep governance documentation and policy records up to date.
  • Support governance initiatives and promote security best practices.
  • Track policy exceptions and follow up on remediation activities.

Risk Management

  • Assist with IT and cybersecurity risk assessments.
  • Help identify, document, and track security risks and remediation efforts.
  • Maintain the IT risk register and support periodic risk reporting.
  • Work with stakeholders to monitor risk mitigation activities.

Compliance & Regulatory Support

  • Support compliance activities for frameworks such as ISO 27001, NIST CSF, SOC 2, GDPR, and CMMC.
  • Assist with compliance assessments, evidence collection, and documentation.
  • Help track remediation activities to address compliance findings.
  • Support internal and external compliance reviews and audits.

Third-Party Risk Management

  • Assist with vendor security assessments during onboarding and periodic reviews.
  • Review vendor security documentation, including questionnaires and audit reports.
  • Track vendor risk findings and remediation activities.
  • Maintain third-party risk records on the GRC platform.

Audit Support

  • Coordinate audit evidence requests and documentation.
  • Track audit findings and remediation activities.
  • Help maintain audit readiness across teams.
  • Support customer security assessments and certification audits.

Program Improvement

  • Support governance, risk, and compliance initiatives across IT and Security.
  • Help monitor compliance metrics, risks, and remediation progress.
  • Assist with identifying process improvements and updating documentation.
  • Perform other duties in support of the Information Security team.

What We’re Looking For

Education:

  • Bachelor’s degree in information technology, Cybersecurity, Information Systems, Risk Management, Business Administration, or a related field.
  • Equivalent combination of education and experience may be considered.

Preferred Certifications

One or more of the following certifications (or willingness to obtain) is preferred:

  • CompTIA Security+
  • Certified Information Systems Auditor (CISA) (or pursuing)
  • Certified in Risk and Information Systems Control (CRISC) (or pursuing)
  • Certified Information Security Manager (CISM)
  • ISO 27001 Lead Implementer or Lead Auditor
  • Security+ or equivalent cybersecurity certification

Experience:

  • 2 – 5 years of internship or entry-level experience in IT governance, risk management, compliance, cybersecurity, IT audit, or related fields.
  • Experience supporting audits and compliance assessments.
  • Familiarity with risk assessment methodologies and control frameworks.

Skills:

  • Experience with Automated Test System using VB.NET, C or C# 
  • Proven ability to work in a collaborative team environment with excellent communication skill;
  • Experience in any of the following is an asset:
  • Knowledge of optical components and systems;
  • Experience with SQL and web app development;
  • Hands-on experience with electrical and optical test and measurement equipment.

Technical Knowledge

  • Working knowledge of:
    • Information Security principles
    • Risk assessment methodologies
    • Governance and compliance processes
    • Security frameworks such as NIST CSF, ISO 27001, and SOC 2
    • Microsoft Office Suite (Excel, Word, PowerPoint) or similar
  • Preferred experience with GRC platforms such as:
    • ServiceNow GRC
    • Archer
    • OneTrust
    • AuditBoard

Key Competencies

  • Analytical and problem-solving skills
  • Attention to detail and organizational skills
  • Effective written and verbal communication
  • Ability to work independently and as part of a team
  • Basic understanding of risk, compliance, and governance principles
  • Customer-focused with strong stakeholder relationship skills
  • Ability to manage multiple priorities in a fast-paced environment
  • Willingness to learn and continuously develop GRC knowledge

Success Measures

Success in this role is demonstrated by:

  • Timely completion of assigned risk assessments, compliance activities, and vendor reviews.
  • Accurate, organized, and complete documentation and reporting.
  • Effective support of internal and external audits, including timely evidence collection.
  • Consistent tracking and follow-up of risk, audit, and compliance remediation activities.
  • Positive collaboration with business and technical stakeholders.
  • Demonstrated growth in GRC knowledge, skills, and professional development.

Perks You’ll Love

  • Flexible time off
  • Health and wellness benefits (physical and mental)
  • Tuition reimbursement and career growth support
  • A workplace built for you: free gym, games room, prayer room
  • Subsidized meals, free coffee/tea
  • Employee stock options and incentive plans
  • A collaborative, innovative, and inclusive culture

Working Conditions

  • May require coordination across multiple time zones and business units.

Salary Range: $55,000 - $80,000 CAD (flexible).

Final compensation will be determined based on factors such as experience, skills, and qualifications. In line with our commitment to being a great place to work, Lumentum offers competitive total rewards which may include annual bonus, equity, and comprehensive health and welfare benefits.

Join a Team That’s Shaping the Future

At Lumentum, we’re more than just a workplace—we’re a launchpad for creativity and innovation. We’re committed to celebrating your unique talents and helping you grow. Our guiding principles—Innovate, Engage, Deliver, Excel, and Win—aren’t just words; they’re the heart of what we do.

Let’s Build a Brighter Future Together!

We’re committed to building an inclusive workplace where everyone feels valued and empowered. We welcome applicants from all backgrounds and provide accommodations for individuals with disabilities throughout the hiring process. Your uniqueness makes us stronger, sparks creativity, and drives our success.

Please contact us at [email protected] to request accommodation.

Join us—your future starts here!

Skills

.NETSQLExcelServiceNowCybersecuritySOCRisk ManagementComplianceProcurementSOC 2GDPRISO 27001CompTIA

Similar Jobs

30

IT Governance, Risk & Compliance Manager

ALKEGEN Career Opportunities · US - Tonawanda, United States of America +1

4 days ago

IT Governance Risk Compliance Analyst Lead

Franciscanalliance · Work From Home, United States of America · Remote

1 week ago

Senior Specialist IT Governance & Risk

Vontobel · München / Alter Hof 5, Germany

3 weeks ago

SSBI IT Governance, IT Risk and IT Outsourcing Vice President

Statestreet · Gdansk, Poland +1

1 month ago

IT Governance, Risk & Compliance Officer

Tigerbrands · BRY1, South Africa · Onsite

1 month ago

Manager, IT Governance, Risk and Compliance

Petvalu · 0001 – Markham Office, Canada · Hybrid

1 month ago

IT Governance, Risk & Compliance Analyst

Petron Malaysia · Damansara Heights, Kuala Lumpur

1 month ago

Head of IT Governance, Risk, and Compliance (GRC)

"LabConnect, LLC" · Remote - US, 2304 Silverdale Drive, Johnson City, Tennessee, United States of America · Remote

1 month ago

IT Governance Risk & Compliance (GRC) Analyst

Trustmark · Ridgeland, MS, US +1 · Remote

1 month ago

Manager - IT Governance, Risk and Compliance

Plexus · Neenah, WI,US, US

2 months ago

IT Governance, Risk, & Compliance Manager

Qualcomm · San Diego, CA,US, US · Onsite

2 months ago

Senior Consultant - IT Governance, Risk & Compliance (GRC)

Infinitive Inc · Ashburn, VA

4 months ago

Senior Analyst, IT Governance, Risk & Compliance

Altamed · Corporate - (2040 Camfield Ave), United States of America · Hybrid

5 months ago

IT Governance, Risk & Compliance (GRC) Analyst, Luxembourg

Stripe · Onsite

5 months ago

IT Governance, Risk & Audit Lead (IT GRC)

Careerally Pte Ltd · Singapore

5 months ago

Senior IT Governance, Risk, and Compliance Analyst - Research Cybersecurity

Euv Emory · Atlanta, GA, US

1+ year ago

Senior IT Governance, Risk, and Compliance Analyst - Research Cybersecurity

Staff Emory · Atlanta, GA, US

1+ year ago

Manager, IT Governance, Risk & Compliance

LendingPoint · Las Colinas, Texas

1+ year ago

IT Governance, Risk and Compliance Consultant (Contract Contingent)

ProSidian Consulting · Arlington, VA, United States

1+ year ago

Principal IT Governance and Risk Consultant

Pseg · Bethpage, New York, US · Remote, Hybrid, Onsite

Yesterday

IT Governance and Risk Assessment Officer

Global Water Solutions · Woking, United Kingdom

1 month ago

IT Governance and Risk Assessment Officer

Global Water Solutions · Boksburg Gauteng, South Africa, South Africa

1 month ago

Senior Analyst, IT & Cyber Governance, Risk & Control

Questrade Financial Group · 5700 Yonge St, North York, ON M2M 4K2, Canada

1 month ago

Head IT Governance and Risk Asia

Juliusbaer · Singapore

4 months ago

Manager, IT Security, Governance, Risk and Compliance

Burlington · 00505 - Edgewater Park Corporate Office, United States of America · Hybrid

5 months ago

Associate & Senior Associate - Internal Audit, Governance, Risk & Controls, IT Audit [OTS] - Bologna, Parma, Firenze

Pwc · Bologna - Via Carlo Farini, Italy +2

10 months ago

Intern - Internal Audit, Governance, Risk & Controls, IT Audit - Milano

Pwc · Milano - Piazza Tre Torri 2, Italy

1+ year ago

IT Risk Management Project Manager - IT Governance Section, IT Strategy Department (ITSD) (Tokyo OR Osaka)

Rakuten · Rakuten Crimson House, Japan +1

4 months ago

Governance, Risk, and Compliance Manager (IT)

Weaver · DALLAS, TX +2

6 months ago

IT Working Student - Technology Governance & Third Party Risk Management 60 - 100% (f/m/d)

Juliusbaer · Zurich, Switzerland

1 month ago