jobs Logo
Kruger Inc. logo

Governance, Risk and compliance Lead

Kruger Inc.about 18 hours ago
Montreal, Quebec, Canada
Senior Level
Full-Time

About the role

Position Overview

Join us to protect the digital future of our organization and the resilience of our operations.

Kruger is seeking a GRC Practice Lead to own and grow our Governance, Risk & Compliance practice. Reporting to the CISO, the GRC Practice Lead serves as the senior operational leader for GRC, defining the practice roadmap, leading the design and continuous improvement of our security governance framework, overseeing cybersecurity risk and compliance programs, and building and mentoring the GRC capability across people, methodologies, and tools. This role also supports the CISO in executive, audit, and regulatory interactions through structured analysis, consolidated risk reporting, and well-supported recommendations.

This role is key to bridging the gap between technical security, business priorities, and regulatory expectations.

Main Responsibilities

Governance

Develop, maintain, and communicate cybersecurity policies, standards, and guidelines aligned with enterprise objectives and industry frameworks (NIST CSF, ISO 27001, CIS Controls, SCF). Run the operational governance cadence (working committees, policy reviews, control maturity assessments) and prepare the executive-level governance forums chaired by the CISO. Define the cybersecurity KPI/KRI measurement strategy and provide transparency on performance and risk exposure.

Risk Management

Oversee the enterprise risk assessment program across IT, OT, and cloud environments; perform assessments on the most complex or strategic scopes. Own the enterprise cyber risk register: ensure risks are properly categorized, prioritized, and assigned to risk owners, and consolidate the risk posture for executive presentation by the CISO. Collaborate with risk owners to define and monitor risk treatment plans; escalate risks that exceed tolerance levels. Own the third-party risk management program (methodology, vendor tiering, oversight of assessments) covering vendors, partners, and MSPs. Lead the cyber resilience workstream within BIA (Business Impact Analysis), Business Continuity (BCP), and Disaster Recovery (DR) exercises, including scenario testing and lessons learned.

Compliance & Audit

Own the compliance management program covering internal policies and standards, as well as applicable regulations (GDPR, Law 25, PCI-DSS, SOX, etc.). Act as operational lead for cybersecurity audits (internal, external, regulatory), including evidence collection, remediation governance, and auditor relationships, with the CISO as executive sponsor. Maintain up-to-date knowledge of evolving regulations and advise on their impact.

Advisory

Act as a trusted advisor by providing structured analysis, metrics, and actionable recommendations. Prepare Board-ready material and executive presentations; present to steering committees and risk review boards as delegated by the CISO. Build strong working relationships with stakeholders to ensure a consistent approach to cyber risk. Promote a culture of accountability and continuous improvement in cybersecurity governance.

Qualifications

Bachelor’s degree in information security, risk management, or a related field. Certifications such as CISM, CRISC, CISSP, ISO 27001 Lead Implementer/Auditor, or equivalent; CISM or CRISC preferred.

Experience

8–10+ years of professional experience in cybersecurity governance, risk management, or compliance, including 3+ years leading a team, program, or practice. Proven track record owning risk registers, compliance programs, and audit engagements. Experience working with multidisciplinary teams (IT, OT, Legal, Audit, Business).

Technical Skills

SKILLS AND ABILITIES

Solid understanding of cybersecurity frameworks (NIST CSF, ISO 27001, CIS Controls, SCF) and risk methodologies (EBIOS, FAIR). Knowledge of regulatory requirements (GDPR, Law 25, SOX, PCI-DSS, NERC). Familiarity with GRC tools and platforms is an asset.

Non-techical skills

Strong analytical and critical thinking skills. Ability to synthesize and present complex information to executives in clear business terms. Excellent organizational and stakeholder management skills. Collaborative, diplomatic, and detail-oriented mindset. Leadership and coaching skills; ability to influence without formal authority across business units. Comfort operating with ambiguity and arbitrating competing priorities.

LANGUAGES

Fluent in both French and English (written and spoken).

Knowledge of English is required for this specific position as Kruger deals with partners across North America and the successful candidate will be required to communicate frequently with them. Kruger has taken all reasonable steps to avoid imposing English language requirements, including assessing the actual language needs associated with the duties to be performed, ensuring that the language skills already required of other employees were insufficient for the performance of those duties, and limiting as much as possible the number of positions with duties requiring English language skills.

About Kruger Inc.

Paper and Forest Product Manufacturing
5001-10,000
Founded in 1904

A forward-looking and progressive company since its very foundation over a century ago, the Kruger organization is constantly evolving and looking for the best talent for its establishments located across Canada and the US.

In addition to its traditional industry sectors where the Company built a solid reputation worldwide, namely pulp and paper, paperboard and packaging, Kruger Inc. is now active in such diverse sectors as green energy, tissue products, recycling and biomaterials.

We put sustainable development and the responsible use of resources at the core of our success and several of our establishments and practices are certified under the strictest industry standards.

Similar Jobs