Skip to main content
GRCSEC Services Corp.
Independent GRC & cybersecurity advisory

Govern. Secure. Comply.

Independent GRC and cybersecurity advisory — built on 30 years inside Canada’s most regulated industries.

ISO 27001/27002NIST CSFNIST 800-53COBITSOX / Bill 198 / 52-109PCI DSSSOC 2 / SSAE 18ITIL
30+
Years in IT, security & audit
40+
Enterprise clients served
5
Active certifications
7
Regulated sectors
Sectors Served

Trusted by Canadian enterprises in regulated industries

  • Energy & Pipelines
  • Oil & Gas
  • Utilities
  • Financial Services
  • Telecommunications
  • Public Sector & Education
  • Life Sciences
Practice Areas

Four pillars. One integrated practice.

A senior-led advisory built around how regulated organizations actually buy GRC and cybersecurity — by outcome, not by deliverable.

Pillar 01

GRC Advisory & Governance

Independent advisory to design, mature, and operate enterprise GRC programs — from policy frameworks to board-level reporting.

  • GRC program design, framework selection (ISO 27001, NIST CSF, COBIT)
  • Security policy, standards, and process authoring
  • IT governance structures and steering committee enablement
  • Board and executive reporting, metrics, and risk dashboards
  • Program rationalization for established control environments
Pillar 02

Risk Management & Assessments

Threat, vulnerability, and third-party risk assessments grounded in 15+ years of TRA, TPRA, and PPI engagements across regulated sectors.

  • Threat Risk Assessments (TRA) and Privacy Impact Assessments
  • Third-Party Risk Assessment (TPRA) programs and execution
  • Enterprise risk identification, treatment, and reporting
  • Operational Technology (OT) and IT-OT convergence risk
  • Risk register design and continuous monitoring strategy
Pillar 03

Compliance & Audit Readiness

SOX, C-SOX (Bill 198 / 52-109), PCI DSS, and SOC 2 readiness from a former PCI QSA and CISA-certified auditor.

  • SOX, Bill 198 / 52-109 IT compliance program management
  • IT General Controls (ITGC) design, testing, and remediation
  • PCI DSS readiness, gap assessment, and assessor liaison
  • SOC 2 / SSAE 18 / ISAE 3402 control mapping and prep
  • Internal audit support aligned to IIA professional standards
Pillar 04

Cybersecurity & Virtual CISO

Part-time CISO leadership, security architecture consultation, and AI-enhanced threat and resilience advisory.

  • Virtual / fractional CISO engagements
  • Security architecture and cloud / SaaS migration assurance
  • Disaster Recovery and Business Continuity Planning (DRP/BCP)
  • Incident, problem, and change management process reviews
  • AI-driven threat detection and predictive risk modeling advisory
Selected Engagements

Anonymized outcomes from real engagements.

Representative work across energy, financial services, and public sector — all delivered under independent advisory engagements.

Energy · Pipeline

Standing up risk and vulnerability management for a major Canadian pipeline operator

Embedded as cyber security advisor to assist a national pipeline operator establish its risk and vulnerability management programs across IT, Operational Technology (OT), Industrial Control Systems, and SCADA. Performed risk assessments of new and legacy systems and coordinated remediation with engineering and IT teams to close audit findings.

IT-OT ConvergenceRisk AssessmentsOT/SCADA
Outcome
Risk and vulnerability programs operationalized across IT and OT estates.
Energy · Gas Distribution

Three-year engagement as Information Security Systems Officer at a Canadian gas distributor

Delivered cyber security advisory, Threat Risk Assessments on solutions, projects, and programs, third-party risk assessments, and security architecture consultation across a large regulated gas distribution organization.

Threat Risk AssessmentsThird-Party RiskSecurity Architecture
Outcome
Hundreds of solution-level TRAs and TPRAs delivered against enterprise risk appetite.
Oil & Gas · Public Company

Long-running IT compliance and security partnership with an upstream operator

Provide ongoing SOX compliance program management, ITGC rationalization, awareness and training on logical and physical security, risk and security metrics, and guidance to management on conducting risk management assessments.

SOX / 52-109ITGCRisk Management
Outcome
Sustained SOX-ready control environment and a rationalized ITGC portfolio.
Public Sector · Education

Disaster Recovery and Business Continuity build for a Canadian school district

Developed Disaster Recovery and Business Continuity Planning artefacts for a large Canadian Catholic school district, aligning recovery objectives with operational and regulatory priorities.

DRP/BCPResilience
Outcome
DRP/BCP program delivered and handed over to internal owners.
Energy · Utility

IT General Controls rationalization for a major Western Canadian utility

Performed a rationalization exercise across the IT General Controls environment, mapping business process controls to general computing controls and applying COBIT, ISO/IEC 27002, and ITIL frameworks.

ITGC RationalizationCOBITISO 27002
Outcome
Streamlined ITGC portfolio with reduced audit burden and clearer control ownership.
Financial Services · Telecom

PCI DSS, SAS70-to-SSAE16, and continuous compliance at a national telecom

Led the IT Services risk management program, emergency management initiatives in support of DRP, and the transition from the SAS70 standard to SSAE16. Consolidated controls across the organization — including PCI DSS — to achieve continuous compliance with policy, regulatory, and legislative requirements.

PCI DSSSAS70 → SSAE16Continuous Compliance
Outcome
Single, consolidated control set supporting PCI, audit, and regulatory obligations.
Credentials & Frameworks

Senior credentials.
Framework-fluent advisory.

Engagements are led personally by a senior practitioner holding the principal GRC, audit, security, and privacy certifications — backed by a 30-year career in IT, audit, and security operations.

Former Payment Card Industry Qualified Security Assessor (PCI QSA). Bilingual English / French; working Spanish and Italian.

CISSP
Certified Information Systems Security Professional
(ISC)²
CISA
Certified Information Systems Auditor
ISACA
CRISC
Certified in Risk and Information Systems Control
ISACA
CDPSE
Certified Data Privacy Solutions Engineer
ISACA
ITIL
Foundation Certificate in IT Service Management
AXELOS
PCI QSA
Former Payment Card Industry Qualified Security Assessor
PCI SSC
About the Principal

A career built inside regulated environments.

AG
Angelo Gallo
Principal & Founder, GRCSEC Services Corporation
CISSP, CISA, CRISC, CDPSE, ITIL

Angelo Gallo is a senior IT security, risk, and governance practitioner with over 30 years in the field — including 20+ years in audit, security, and risk advisory across pipelines, utilities, oil & gas, telecommunications, financial services, education, and life sciences.

His engagements emphasize independence, board-level clarity, and audit-ready outcomes — from threat and risk assessments and SOX / 52-109 programs to virtual CISO retainers and OT / IT convergence advisory.

Education
B.Eng. Automated Production — ETS, Université du Québec à Montréal
Languages
English & French (fluent); Spanish & Italian (working)

Career milestones

  1. 2017 – Present
    GRCSEC Services Corporation

    Founder and Principal — GRC, audit, and security advisory to enterprises across Canada.

  2. 2023 – Present
    Trans Mountain Canada Inc.

    Cyber Security Consultant — risk and vulnerability programs across IT, OT, ICS, and SCADA.

  3. 2020 – 2023
    Enbridge Gas Distribution

    Information Security Systems Officer IV — TRAs, TPRAs, and security architecture consultation.

  4. 2012 – 2017
    Focal Point Data Risk

    Senior Manager, IT Security Advisory — SOX/C-SOX, ITGC, COBIT/ISO 27002 assessments.

  5. 2000 – 2012
    TELUS Communications / Mobility

    IT audit, risk, security, compliance leadership including the SAS70 → SSAE16 transition and PCI DSS consolidation.

Community

Former Board Director and Chair of the Risk Management Committee at Kids Code Jeunesse — a bilingual Canadian charity for digital and AI literacy education.

Get in touch

Let's discuss your risk & compliance challenges.

Whether you're standing up a GRC program, preparing for audit, or looking for senior virtual CISO support — start with a confidential conversation.

All submissions are confidential. Response within 1 business day.