Post Job Free
Sign in

Senior IT GRC Analyst and Security Compliance

Location:
Toronto, ON, Canada
Posted:
September 30, 2026

Contact this candidate

Resume:

KYUL HAN

Toronto, Ontario, M*C *P*, CANADA

(***) 458 - 9918

**********@*****.***

Skill Set

20+ years with security operations, audit and compliance experience on framework (such as ISO 27001, ISMS, SOX and ITIL) and SOC1 Type II controls.

Strong leadership, organization, coordination and communication skills between auditors and internal departments.

Professional Experience

Senior IT GRC Analyst Nov 2021 - Present

Raymond James Limited, Toronto, Canada

Establish and Implement GRC Framework:

Spearhead the design and implementation of a robust GRC framework (ISO27001, ISMS, COBIT, FFIEC, NIST, CIS, SOX, SOC and CRI), ensuring alignment with industry standards and organizational objectives.

Efficiently Manage Security Exceptions using ServiceNow:

Utilize ServiceNow to streamline the management of Security Exceptions, enhancing visibility and accountability.

Maintain SharePoint for Technology Risk and Assurance:

Administer SharePoint to centralize and manage documentation related to technology risk and assurance processes.

Proactively Implement Security Awareness:

Execute monthly security awareness, fostering a culture of cybersecurity vigilance among staff.

Collaborate Effectively with Diverse Stakeholders:

Establish strong collaborative relationships with Headquarters, branches, external/internal audit teams, IT, and HR.

Prepare for Vendor Risk Assessments with Vulnerability Scans using Kali-Linux:

Establish Vendor Risk Assessments with vulnerability scans using Kali-Linux, providing actionable insights to enhance branch-level security.

Information Security Specialist May 2016 – Nov 2021

Equitable Bank, Toronto, Canada

Implement GRC Strategies using RSA Archer:

Successfully deploy GRC strategies using RSA Archer, ensuring comprehensive coverage of risk management processes.

Generate Insightful Security Metrics/Reports:

Prepare and present detailed security metrics and reports for management, providing a holistic view of risk management aspects.

Proactively gather evidence for IT Audits:

Gather and presented evidence to facilitate IT audits, ensuring compliance with regulatory requirements.

Manage IT Vendor Deliverables:

Oversee and manage deliverables from IT vendors, ensuring adherence to security standards.

Lead and Conduct Cyber Security Self-Assessment for OSFI and PCI-DSS:

Lead the execution of OSFI and PCI-DSS Cyber Security Self-Assessment, identifying and mitigating potential risks.

Lead and Conduct Cloud Security Assessment

Lead the organization for cloud security assessments, ensuring a secure transition to cloud services based on Cloud Controls Matrix (CCM).

Lead and Perform Privileged Access Review:

Lead and Conduct privileged access reviews to enhance access control measures.

Utilize McAfee SIEM for Comprehensive Reporting:

Leverage McAfee SIEM for robust reporting, enhancing the organization's ability to detect and respond to security incidents.

Execute Vulnerability Scans using Qualys:

Conduct thorough vulnerability scans using Qualys, identifying and addressing potential security weaknesses.

Manage Account Lifecycle in M/S Azure and Local AD:

Efficiently handle the lifecycle of accounts through Microsoft Azure and Local Active Directory in Windows Server 2016.

Network Security Analyst (Intern) Feb 2016 - Apr 2016

Secure Links, Toronto, Canada

Analyze Network Security Traffic by using Fortinet

Operate EventTracker SIEM

Information Security Assistant Manager Apr 2006 - Dec 2015

LG Electronics, Seoul, Korea

Administrative Security

-Manage a team of 4 Security Analysts and relationships with Internal and External Auditors

-Design, develop, implement and coordinate IT Security Policies, Standards and Procedures

-Oversee and determine timeframes for IT Security Audits and Projects

-Develop Information Security Management System(ISMS) based on ISO27001 (Information Security Standards) and Private Information Management System(PIMS) through Team Security Score(TSS) Process

-Audit Privacy Information Systems; Gap Analysis, Risk Assessment (www.lgcodechallenger.com) and Identity Access Management (lgpatent.lge.com)

-Improve Security & Privacy Policy, Standard, Procedure and Incident Response Process

-Investigate potential or actual security violations or incidents in an effort to identify issues

-Train over 4,000 employees on information policies and procedures and security awareness

Technical Security

-Operate Network/Endpoint DLP(Data Loss Prevention), LG SIEM

-Monitor security of critical systems (Private Information Web Servers) and changed to highly sensitive computer security controls to ensure appropriate system administrative actions

Sergeant Dec 2002 - Jan 2005

Korea Marine Corps, Korea

Education

Master of Science in Electrical and Electronic Engineering GACHON University, Mar 2011 - Feb 2013

Bachelor of Degree in Electronic Engineering GACHON University, Mar 2009 - Feb 2011

Bachelor of Degree in Computer Science Engineering HANYANG Cyber University, Mar 2007 - Feb 2009

Associate Degree in Digital IT Electronics DONG SEOUL College, Mar 2002 - Feb 2006

Certification

CIA (Certified Internal Auditor), Certification Number: 169367 Mar 2019

CRISC (Certified in Risk and Information Systems Control), Certification Number: 1722596 Aug 2017

PMP (Project Management Professional), Certification Number: 1936692 Jun 2016

CCNA (Cisco Certified Network Associate), Certification Number: CSCO12707579 Sep 2015

CISM (Certified Information Systems Manager), Certification Number: 1528258 Sep 2013

CISA (Certified Information Systems Auditor), Certification Number: 1310772 Dec 2012

CISSP (Certified Information Systems Security Professional), Certification Number: 431992 Sep 2012

CPPG (Certified Privacy Protection General), Certification Number: G12-008-05-00340 May 2012

Information Processing Engineer Jun 2009

Japanese Language Proficiency Test (JLPT) N2 Dec 2006

Volunteer Experience

IT Help Desk in St. Felix Centre Sep 2015 - Present

Preparing workshops in AEIP SUCCESS (46 hours) Oct 2014 - Aug 2015

Supporting children in Social Welfare Volunteer Organization (44 hours) Oct 2013 - Dec 2014

Blood donation (11 times) Dec 2002 - July 2015



Contact this candidate