WHO WE ARE

When it comes to health, we’re always looking for ways to push for better. It’s why we were founded in the first place. In 1957, our founder, pharmacist William Wilkinson, witnessed a mother sacrifice her health by forgoing her own medicine to pay for her sick daughter’s prescription. He knew there had to be a better way. So, he introduced North America’s first prepaid drug plan, and GreenShield was born as a not-for-profit with a mission to support better health for all Canadians.

We aren’t just a health and benefits company. We’re the only not-for-profit social enterprise that brings worlds of coverage and care together, all in one place.

We’re noble challengers, purposefully building a better way and we need the best people to help us create a more holistic approach that takes care of the mind and body.

Our mission is to create better health for all Canadians, and we know that starts with our employees.

THE ROLE IN A NUTSHELL

The Internal Audit Services function is an independent team of professionals with a common purpose of collaborating with the organization to evaluate and improve the organization’s risk mitigation strategies through the provision of independent oversight and assurance, leveraging advanced technologies and insights.

Reporting to the Director, Internal Audit Services (CIA), we are looking to fill the vacant position of IT Audit Specialist. We are seeking an experienced individual who can bring new knowledge and skills to the Internal Audit Services Team and take the lead role in assessing, planning and executing audits in the areas of Information Technology and Cybersecurity, with the objective of ensuring key risks to achieving objectives have been identified; internal controls have been designed appropriately and evaluating their effectiveness; and providing value added advisory services to GreenShield.

Primary accountabilities include:

  • Collaborate with key stakeholders, including IT leadership, Risk Management, Compliance, and business units to assist the Chief Internal Auditor in developing and maintaining an enterprise-wide IT Audit Universe, supporting the creation of a dynamic, risk-based IT audit plan that aligns with the organization's strategic objectives and emerging technology risks.
  • Conduct assurance and advisory reviews to evaluate the design and operating effectiveness of technology assets and systems across the enterprise, ensuring that technology-related risks are properly identified, mitigated with adequate controls, and aligned with regulatory requirements and internationally recognized frameworks and standards.
  • Lead and facilitate CSAE 3416 and SOC 2 audit engagements across the enterprise by coordinating with internal stakeholders and external auditors, ensuring readiness, timely execution, and resolution of identified control gaps to meet compliance objectives and service organization reporting requirements.
  • Collaborate with stakeholders on enterprise initiatives and technology projects to provide proactive insights into risk, ensuring that IT risk considerations are embedded early in project planning and execution, and that appropriate controls are designed to support secure and compliant implementation.
  • Work closely with the Chief Internal Auditor to build and strengthen the Internal Audit program, ensuring alignment with the IIA’s Global Standards and promoting audit practices that are risk-based, forward-looking, and value-driven in addressing strategic, operational, and technology risks across the enterprise.
  • Provide leadership and mentoring to assist in the development of other IT audit team members by sharing technical expertise, offering guidance on audit methodologies and best practices, and fostering a culture of continuous learning, collaboration, and professional growth within the audit function.
  • Monitoring the external environment to identify emerging IT security risks and incorporating them into the audit plan.

WHO WE'RE LOOKING FOR

We’re not looking for just anyone to fill this role. We are looking for an individual who can make an immediate impact. We’re seeking an individual who is confident and who knows what they’re talking about. We don’t want to be seen as “the police”; we want someone who is collaborative and can work with their audit clients to arrive at appropriate conclusions and recommendations to support the achievement of the organization’s objectives and to help create better health for all Canadians.

Education & Experience

  • Minimum post-secondary degree or diploma in computer science, information systems, business, or a related field
  • Professional certification(s) such as CIA, CISA, CISSP, CRISC, or CPA (with IT audit focus) preferred.
  • 5+ years of experience in IT auditing, IT risk management, or IT compliance.

Skills & Knowledge

  • Strong understanding of risk-based IT audit methodologies, including planning, execution, and reporting.
  • Strong understanding of IT frameworks such as COBIT, NIST, ISO 27001, ITIL, and CIS Controls.
  • Familiarity with cybersecurity, cloud technologies (GCP, AWS, Azure), ERP systems, and data analytics tools.
  • Familiarity with CSAE 3416, SOC 1/SOC 2, and other assurance reporting frameworks, as well as applicable regulatory requirements (e.g., privacy laws, cybersecurity regulations).
  • Ability to identify, assess, and articulate technology-related risks in the context of business and regulatory expectations.

Core Competencies

  • Excellent interpersonal skills with the ability to collaborate and build relationships across IT, risk, compliance, and business functions.
  • Excellent verbal and written communication, including the ability to convey complex IT risks and audit findings clearly to both technical and non-technical audiences.
  • Ability to manage multiple assignments, meet deadlines, and work independently or as part of a team.
  • Strong business acumen and experience in discerning priorities and critical accountabilities.
  • Strong personal integrity and work ethic; takes responsibility; likes to be held accountable for results.
  • Excellent planning, organizing, and time management skills with strong attention to detail.
  • Sound knowledge of the Institute of Internal Auditors Global Internal Audit Standards.

Preference will be given to candidates with the following abilities:

  • Bilingualism (English & French).
  • Experience working in a regulated environment.
  • Experience working in a multi-entity environment with multiple IT infrastructures.
  • Previous experience in conducting SOC reviews.

THE CULTURE

We believe a career should be meaningful. Not just a means to earn a living. Our culture is one where everyone's voice is heard and valued. Because that’s what it takes to create better health for all. We dare to challenge the status quo. And we’re driven by people who have challenged theirs. We believe that your workplace should empower you to be the best version of yourself. That’s why we provide a place where you can be inspired, challenged, and rewarded.

Where your growth means our growth.

Where your voice is heard and valued.

Where your work has purpose. And purpose matters.

We believe our people are critical to our overall success. Inclusivity makes us a stronger, smarter and more informed organization. Being intentionally inclusive of diverse backgrounds, perspectives and experiences will enhance our company culture to positively impact how we support our communities. A career at GreenShield isn’t just about personal achievements, it's about making a difference together.

Here’s to Better Health for All!

A FEW MORE DETAILS

Proficiency in English is required for this position. As part of this role, you will be required to communicate with colleagues or customers who use English as their primary language. By requiring English proficiency for this position, we aim to ensure that our employees can excel in their roles, collaborate, and communicate effectively, and contribute to the success of our organization.

GS supports diversity, equity and inclusion in our teams and communities, and we value the unique contributions made by all. Even if your experience doesn’t align perfectly to every requirement, we invite you to apply. We encourage applications from all candidates and will accommodate needs under human rights legislation throughout all stages of the recruitment and selection process. Please let us know of any accommodation through requestforaccommodation@greenshield.ca. Information received relating to accommodation will be addressed confidentially.

Providing this information gives GS consent to use your personal information to assess your suitability for specific positions, future opportunities or for your personnel file. Your résumé will be held in strict confidence and will be viewed only by the Organization. Information may be stored outside of Canada and could be used for aggregate statistical purposes (which uses no personal identification).

Read Full Description
Confirmed 13 hours ago. Posted 30+ days ago.

Discover Similar Jobs

Suggested Articles