Specialist, Security Risk Management

Posted Yesterday
Be an Early Applicant
Hiring Remotely in Toronto, ON, CAN
In-Office or Remote
90K-112K Annually
Mid level
Financial Services
The Role
Supports Wealthsimple’s IT and security risk management program by identifying, assessing, documenting, and tracking technology and third-party risks. Maintains the enterprise risk register, evaluates control effectiveness, supports PCI DSS, SOC 2, and NIST initiatives, develops risk reporting, monitors emerging threats, and partners with technical and business stakeholders on remediation and risk treatment.
Summary Generated by Built In
Build something people love

Wealthsimple is Canada’s leading financial innovator. The company offers a full suite of simple, sophisticated financial products across managed investing, do-it-yourself trading, cryptocurrency, tax filing, spending and saving. Wealthsimple currently serves more than 4 million Canadians and holds over $155 billion in assets under administration. The company was founded in 2014 by a team of financial experts and technology entrepreneurs, and is headquartered in Toronto, Canada.

We're proud of what we've built — and we're just getting started. Read our Culture Manual and learn more about how we work.

The Security GRC team plays a critical role in adhering to security frameworks and creating space for risk mitigation and oversight. We want to ensure that Wealthsimple maintains a secure operational environment by implementing and monitoring controls designed to protect information, systems and infrastructure.

We are looking to grow the Security GRC team with a Specialist, IT/Security Risk Management to support and mature our enterprise IT and security risk management program. This role will be central to identifying, assessing, and tracking risks across Wealthsimple's technology and security landscape, helping ensure that risk exposure is well-understood and actively managed.

You'll partner closely with teams across Security, Engineering, Infrastructure, Product, and Compliance to assess risk, maintain our risk register, and drive risk treatment activities. This is a hands-on role suited for someone who is analytical, detail-oriented, and comfortable operating in a fast-moving fintech environment.

In this role, you'll have the opportunity to
  • Support the end-to-end IT and security risk management lifecycle, including risk identification, assessment, treatment tracking, and reporting

  • Maintain and continuously improve the enterprise IT/security risk register, ensuring risks are accurately documented, rated, and assigned to appropriate owners

  • Perform risk assessments across technology domains (cloud infra, access management, application security) and third-party assessments using the appropriate methodology for each

  • Partner with control owners and business stakeholders to evaluate the effectiveness of risk mitigation controls and identify gaps

  • Integrate vendor and technology risk findings into the risk register to facilitate tracking and remediation across both IT/Security and Third-Party Risk Management.

  • Contribute to the development and maintenance of risk policies, standards, and procedures

  • Assist in preparing risk reporting and dashboards for senior leadership and committee-level audiences

  • Monitor the threat and vulnerability landscape and help translate emerging risks into actionable insights for the business

  • Support security and compliance initiatives, including PCI DSS, SOC 2, and NIST, from a risk lens, ensuring risk findings are integrated into broader compliance activities

  • Participate in risk-related work streams tied to new product launches, infrastructure changes, and strategic initiatives

What you'll bring
  • 3–5 years of experience in IT risk management, information security, or a related GRC function, ideally within financial services or fintech

  • Solid understanding of IT and security risk frameworks such as NIST CSF, ISO 27001, or FAIR

  • Familiarity with key technology risk domains including cloud (AWS preferred), identity and access management and vulnerability management

  • Experience conducting third-party and vendor reviews, with knowledge of due diligence review methodology, is an asset

  • Experience maintaining risk registers and supporting risk assessment processes

  • Working knowledge of compliance frameworks such as SOC 2, PCI DSS, and/or NIST is a strong asset

  • Strong analytical and written communication skills, with the ability to translate technical risk findings into clear business language

  • Comfortable working cross-functionally with both technical and non-technical stakeholders

  • Experience with GRC tools and risk management platforms (e.g.Jira, Drata) is an asset

  • Self-starter who can operate independently, manage competing priorities, and drive work to completion

  • Relevant certifications are an asset (CRISC, CISA, CISSP, or equivalent)

Why Wealthsimple?

🌸 Top-tier health benefits and life insurance

📈 Long-term group savings with employer match, through Wealthsimple for Business

🌴 20 vacation days, 4 wellness days, and unlimited sick and mental health days per year

✈️ 90 days away: work outside Canada for up to 90 days per year

👥 Employee resource groups, including Rainbow (2SLGBTQ), Women of WS, and Black at WS

🌎 We are a hybrid team with over 1,500 employees across North America. The people are one of the best parts of working here: you'll collaborate with incredibly talented, curious, and driven teammates who are deeply committed to doing great work.

ICYMI

Technology & Innovation at Wealthsimple: We move quickly and build thoughtfully. That means we're always looking for better ways to work — whether that's new tools, AI, or rethinking how we approach a problem. We don't expect you to have all the answers, but we do expect curiosity and a willingness to evolve alongside the products we're building.

Inclusion Statement: We're building products for a diverse world, and we need a diverse team to do it well. We strongly encourage applications from everyone, regardless of race, religion, colour, national origin, gender, sexual orientation, age, marital status, or disability status.

Accessibility Statement: We're committed to an accessible hiring experience. If you need any accommodations throughout the interview process, please let us know — we'll work with you to make sure you have what you need. We also welcome any feedback on how we can better accommodate candidates with accessibility needs.

AI in Hiring: We may use artificial intelligence (AI) tools to support parts of our hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our team but don't replace human judgment – all final hiring decisions are made by people. If you have questions about how your data is used, reach out to us.

Skills Required

  • 3-5 years of experience in IT risk management, information security, or a related GRC function
  • Experience ideally within financial services or fintech
  • Understanding of IT and security risk frameworks such as NIST CSF, ISO 27001, or FAIR
  • Familiarity with cloud technology, preferably AWS
  • Familiarity with identity and access management
  • Familiarity with vulnerability management
  • Experience conducting third-party and vendor reviews
  • Knowledge of due diligence review methodology
  • Experience maintaining risk registers and supporting risk assessment processes
  • Working knowledge of SOC 2, PCI DSS, and/or NIST compliance frameworks
  • Strong analytical and written communication skills
  • Ability to translate technical risk findings into clear business language
  • Ability to work cross-functionally with technical and non-technical stakeholders
  • Experience with GRC tools and risk management platforms such as Jira or Drata
  • Ability to operate independently, manage competing priorities, and drive work to completion
  • Relevant certification such as CRISC, CISA, CISSP, or equivalent

Wealthsimple Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Wealthsimple and has not been reviewed or approved by Wealthsimple.

  • Leave & Time Off Breadth Time off programs include generous vacation, unlimited sick and mental health days, and a “90 Days Away” option to work internationally. These policies signal broad flexibility and ample opportunities for rest and renewal.
  • Parental & Family Support Paid parental leave is topped up to full salary for extended periods for both primary and secondary caregivers. Structured reboarding and gradual return options reinforce support for growing families.
  • Wellbeing & Lifestyle Benefits Offerings include a substantial mental health budget, Headspace access, wellness and home office stipends, and a remote‑friendly setup. These benefits emphasize whole‑person wellbeing beyond core pay and insurance.

Wealthsimple Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Toronto
1,046 Employees
Year Founded: 2014

What We Do

All of your investing, made simple. wsim.co/legal

Similar Jobs

Affirm Logo Affirm

Security Risk Management Specialist II

Big Data • Fintech • Mobile • Payments • Financial Services
Easy Apply
Remote
Canada
2200 Employees
101K-151K Annually

Learneo Logo Learneo

Senior Performance Marketing Specialist, Paid Media

Artificial Intelligence • Edtech • Machine Learning • Software
Easy Apply
Remote
CAN
397 Employees

Square Logo Square

Marketing Manager

eCommerce • Fintech • Hardware • Payments • Software • Financial Services
Remote or Hybrid
8 Locations
12000 Employees
136K-245K Annually

Samsara Logo Samsara

Senior Security Engineer

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
CA
4000 Employees
203K-239K Annually

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account