TECH LEAD - GRC ENGINEERING

BDC

Montreal, CAhybridPosted Jul 22, 2026
Posting intelligenceActively listedReposted 2×, possible evergreen/ghost posting

About the role

We are banking at another level.

Choosing BDC as your employer means working in a healthy, inclusive, and skilled workplace that puts forward the best conditions to bring together unique teams where employees are empowered to act. It also means being at the centre of ambitious economic and financial projects to see further and to do things differently, to fuel the success of Canadian entrepreneurs.

Choosing BDC as your employer also means:

Flexible and competitive benefits, including an Employee Savings and Investment Plan where BDC matches part of your voluntary contributions, a Defined Benefit Pension Plan, a $750 wellness and health care spending account, to name a few

In addition to paid vacation each year, five personal days, sick days as necessary, and our offices are closed from December 25 to January 1

A hybrid work model that truly balances work and personal life

Opportunities for learning, training and development, and much

Explore the BDC Way in our Culture Book

POSITION OVERVIEW

BDC is seeking a Tech Lead to join the Risk & Value Office squad in Montréal. This role combines technical leadership, risk expertise, and data-driven delivery to advance InfoSec’s ability to monitor and manage its risk landscape. The Tech Lead will guide the design and implementation of GRC engineering capabilities, ensure the quality and consistency of squad deliverables, and drive the adoption of scalable analytics, automation, and reporting solutions. Acting as a key advisor, the role also strengthens technology risk management practices and enables actionable, executive-level insights.

CHALLENGES TO BE MET

Technical Leadership & Squad Enablement

Act as the tech lead for the Risk & Value Office squad, providing guidance on GRC engineering and risk management.

Review and challenge the quality of the squad deliverables to ensure alignment with InfoSec standards and executive expectations.

Coach and mentor squad members on GRC engineering practices and risk management concepts, fostering capability uplift and autonomy.

Drive adoption of best practices in data, automation, and secure development, ensuring consistency across initiatives.

Provide technical guidance in prioritization and backlog refinement, ensuring work is aligned with value, risk reduction, and strategic objectives.

Risk Management & Governance

Lead and contribute to the continuous improvement of the InfoSec technical risk management framework, ensuring strong integration with data-driven insights.

Oversee the identification, assessment, and monitoring of technology and cyber risks, leveraging metrics, analytics, and automation.

Ensure risk outputs, such as KRIs, control effectiveness and audit findings, are consistent, traceable, and defensible.

Provide expert guidance on risk posture, remediation strategies, and prioritization, to support management decision-making.

Lead or support key risk management initiatives, such as the Digital Crown Jewels framework and Cyber Operational Risk Events Management.

Support internal and external audits, ensuring timely completion of remediation actions.

Prepare documentation related to policy, standards, and procedures.

Data-Driven GRC & Engineering

Participate to the design and implementation of data-driven GRC capabilities, including automated data ingestion, transformation, and insight generation.

Define and enforce data architecture and governance practices for security metrics and reporting.

Support the squad in maintaining and developing key security metrics, including risk and control indicators.

Contribute to the development of scalable solutions leveraging tools such as Power BI, Power Platform, SQL, and APIs.

Identify and implement opportunities to automate workflows, controls monitoring, and reporting processes.

Ensure integration across tools and datasets to enable end-to-end visibility of InfoSec risk posture.

Provide technical leadership for the evolution of GRC tools, including asset register modernization.

Identify opportunities, support the design and enhancement of Continuous Control Monitoring (CCM) to provide timely visibility into control performance and identify issues proactively.

Data & Reporting Initiatives

Deliver insights driven by robust data analytics.

Contribute to improving reporting processes and ensuring data reliability.

Support data initiatives from source identification to final reporting.

Present findings and recommendations to managers and stakeholders.

WHAT WE ARE LOOKING FOR

REQUIRED QUALIFICATIONS

Bachelor’s degree in computer science, information security, data analytics, or a related field.

At least 8 years of experience in cyber risk, cybersecurity, or GRC, with strong exposure to data-driven approaches and analytics.

Minimum 3 years in a tech lead or senior role, including delivery leadership, output review, and team coaching.

Extensive experience in:

Risk analytics, metrics development (KRIs/KPIs), and automated reporting.

Driving automation and implementing data solutions in complex environments.

Advanced proficiency in Power BI, Power Platform, SQL, and data integration (APIs).

Strong understanding of data architecture, data governance, and analytics lifecycle.

Experience designing and implementing automated workflows and reporting solutions.

Experience with Continuous Control Monitoring (CCM) and control automation concepts.

Strong knowledge of technology risk management frameworks (e.g., NIST, ISO 27001, COBIT).

Experience applying risk frameworks, audit practices, and control assessments.

Strong ability to review, challenge, and enhance the quality of deliverables.

Demonstrated leadership in coaching, mentoring, and developing team capabilities.

Excellent stakeholder management skills, with the ability to operate in complex, high-visibility environments.

Ability to translate technical and risk concepts into a clear business language.

Strong analytical thinking, problem-solving, and decision-making skills.

Highly organized, detail-oriented, and able to manage multiple priorities effectively.

PREFERRED QUALIFICATIONS

Financial services or regulated environments.

Relevant certifications (e.g., CRISC, CISM, FAIR).

Knowledge on OSFI.

Proudly one of Canada’s Top 100 Employers and one of Canada’s Best Diversity Employers, we are committed to fostering a diverse, equitable, inclusive and accessible environment where all employees can thrive and feel empowered to bring their whole selves to work. If you require an accommodation to complete your application, please do not hesitate to contact us at accessibility@bdc.ca.

While we appreciate all applications, we advise that only the candidates selected to participate in the recruitment process will be contacted.

Questions about this role

Click "Apply with AI Applyd" above. We auto-fill the application from your resume and answer screening questions in seconds. No copy and paste, no juggling tabs.

Compensation for Other roles in Canada varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Other hub for Canada medians across recent openings.

Most applications complete in under 90 seconds. You can track the status in your dashboard and watch the screenshot proof land the moment the application submits.

AI Applyd supports Greenhouse, Lever, Ashby, Workday, iCIMS, SmartRecruiters, Personio, Teamtailor and other major ATS platforms. If we can submit through the platform, we do.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.