Skip to content

Open nowPosted 4 days ago

Principal, IT and GRC

qfg70 open roles

Where
Israel
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowPrincipal, IT and GRCqfg · Israel
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on qfg's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 4 days ago

The posting

What’s in it for you as an employee of QFG?

Health & wellbeing resources and programs Paid vacation and personal days for work-life balance Competitive compensation and benefits packages Work-life balance Career growth and development opportunities Opportunities to contribute to community causes Work with diverse team members in an inclusive and collaborative environment

We’re looking for our next Principal, IT & Cyber GRC. Could It Be You? The Principal, IT & Cyber GRC is the seasoned generalist and trusted advisor across Questrade Financial Group’s (QFG) IT & Cyber GRC function. Operating with breadth across governance, risk, control, audit and regulatory, the Principal is the day-to-day quality bar for the team — identifying and driving requirements, reviewing the work of Analysts, providing technical coaching, and bringing risk and control thinking into cross-functional initiatives early. The role bridges governance, risk, and control intent with operational execution by partnering with IT, Cybersecurity, and business teams to ensure that "built-in" security and compliance is practical, proportionate, and audit-defensible. The Principal brings deep subject matter expertise to this work and partners with the Manager on framework accountability, novel control architecture, and regulatory interpretation. The Principal, IT & Cyber GRC is a champion for putting the customer first and has a deep passion in understanding customer behaviour. They will create lifecycle journeys to improve the customer experience, engagement and retention as we deliver on our promise to help customers keep more of their money as they become more financially successful and secure. Need more details? Keep reading… In this role, responsibilities include but are not limited to: Governance, Policy, and Regulatory Strategy

Governance Documentation Lead: Lead the periodic review and update cycle for Technology and Cyber Governance documents (policies, standards, procedures, frameworks, and handbooks), ensuring they remain accurate, aligned with legislative changes, regulatory requirements, consistent with the relevant frameworks, and reflective of the constantly evolving technology landscape. Audit & Regulatory Management: Support all audit engagements (OSFI, CIRO, SOC 1, SOC 2, etc.) and perform quality-control vetting of materials to ensure a successful "audit-ready" posture. Compliance Initiatives: Drive initiatives including gap assessments for new and existing policies against evolving industry requirements. 

  Control Advisory & Risk Partnership

Collaborative Control Design: Partner with IT & Cyber teams to advise on, review, and validate control designs that manage risk without hindering innovation and velocity; serve as a technical authority for novel control architecture. Horizon Scanning: Maintain a forward-looking understanding of GRC practices and emerging threats to proactively manage risk. Perform analysis and support the issuance of communications to inform of organizational impact. Innovative Monitoring: Identify opportunities to streamline processes through innovative solutions and automation logic.  Tabletop Facilitation: Coordinate and facilitate the execution of cybersecurity tabletop and simulation exercises designed by partner teams — managing scheduling, participant readiness, exercise delivery, and post-exercise documentation and remediation tracking.

  Risk Assessment

Initiative Risk Assessments: Perform and support comprehensive risk assessments for existing processes and new strategic initiatives to identify systemic vulnerabilities.  Entity-Level Risk Assessments: Perform and support entity-level risk assessments across QFG’s regulated entities — identifying systemic risk exposures specific to each entity, assessing control sufficiency against entity-specific regulatory requirements, and partnering with the Manager and entity leadership on remediation roadmaps. Agile Problem Solving: Take ownership of ad-hoc, high-priority activities emerging from a dynamic threat landscape. 

  Mentorship, Metrics & Technical Guidance

Strategic Mentorship & Coaching: Provide technical and craft-level coaching to the Business Analyst and Risk & Control Analyst — reviewing work product, modelling professional skepticism, and raising the quality bar of the team through peer review. This is a technical mentorship relationship, not a people-leadership role; formal performance management remains with the Manager.  Metrics Stewardship: Curate and quality-review IT & Cyber Risk metrics (KRIs/KPIs), ensuring the numbers, narratives, and visualizations that reach executive audiences are accurate, well-contextualized, and actionable.  Automation & AI Vision: Champion and curate the team’s use of AI and automation — setting practical standards for prompt engineering, output validation, and human review — to keep tooling and AI integrations aligned with GRC objectives.

  So are YOU our next Principal, IT & Cyber GRC? You are if you… Professional Experience & Education

Sector Expertise: Minimum of 4+ years of experience in IT and Cyber Risk, Audit, and/or GRC specifically within a regulated financial institution. Academic Foundation: Formally educated in Business, Computer Science, Information Systems, Engineering, or equivalent professional experience.

  Regulatory & Framework Mastery

Framework Proficiency: Deep understanding of a broad set of risk methodologies, frameworks, and practices—including NIST CSF, COBIT, ISO 2700x standards, CIS, COSO, ITIL, and PCI-DSS. Regulatory Knowledge: Comprehensive understanding of the Canadian regulatory environment (OSFI and CIRO) and global assurance frameworks (SOC 1/2). Governance Development: Proven experience in developing, updating, and reviewing high-level Governance documents, including policies, standards, and procedures.

  Control Design & Risk Methodology

Lifecycle Oversight: Extensive experience performing complex risk assessments and designing robust controls. AI and Automation: Proficiency in advanced Prompt Engineering for Generative AI models to accelerate GRC artifacts (e.g., summarizing SOC reports). Technical Literacy: Strong knowledge of technology platforms, including Operating Systems and Databases.

  Metrics, Dashboards & Reporting

Executive Intelligence: Experience in developing and reporting performance and risk metrics (KPIs, KRIs, SLAs, OKRs) and building high-level dashboards for executive leadership teams. Data Integrity: Ability to ensure that metrics provide an accurate reflection of the organization’s risk posture.

  Professional Designations & Tools

Industry Credentials: Holds one or more senior-level industry certifications (e.g., CISA, CRISC, CISM, CGEIT, or CISSP). Technical Enablement: Experience with using compliance automation tools to streamline GRC activities.

  Sounds like you? Click below to apply! #LI-NP1 #LI-Hybrid  

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against qfg's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on qfg's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    qfg's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.