- To support our continued growth and success, we are actively recruiting for an Information Security Compliance Professional to assist in and support all aspects of our program
- If you are looking for a challenge that will allow you to collaborate within dynamic teams and work in a fast-paced environment, this position is for you
- Provide leadership in identifying control gaps, compliance risks, and process improvement opportunities across operational, regulatory, legal, and technology domains
- Establish and maintain effective governance over the organization’s control framework, ensuring controls remain current, relevant, and aligned with business objectives
- Drive accountability for remediation activities by overseeing management action plans and ensuring timely and sustainable resolution of identified control weaknesses
- Act as a trusted advisor to leadership and business stakeholders, championing a strong risk management culture and promoting adherence to governance standards across the organization
- Partner with control functions and business leaders to strengthen the effectiveness of the Three Lines of Defense model and enhance overall risk and control practices
- Provide independent challenge and oversight of complex technology and business processes, leveraging risk-based analysis to assess control effectiveness and identify emerging risks
- Lead the successful execution of internal, external, client, and regulatory audits, ensuring organizational readiness and effective stakeholder engagement throughout the audit lifecycle
- Own and govern information security compliance programs, including PCI DSS, SOX and SOC 2, delivering strategic oversight, program direction, and continuous improvement
- Influence and coordinate cross-functional stakeholders to ensure alignment on audit objectives, evidence collection, remediation activities, and regulatory expectations
- Communicate audit outcomes, key risks, and remediation progress to senior leadership, enabling informed decision-making and effective risk management
- Challenge and evaluate management responses to audit findings, ensuring remediation plans appropriately address root causes and reduce organizational risk
- Serve as a subject matter expert and trusted advisor, providing guidance on compliance obligations, regulatory requirements, and audit readiness initiatives
- Lead the governance and execution of client security and due diligence assessment programs, ensuring accurate, consistent, and timely responses that reflect organizational capabilities and controls
- Oversee the assessment of client requirements, contractual obligations, and associated risks, ensuring appropriate stakeholder engagement and risk mitigation strategies
- Strengthen client trust and support business growth by providing strategic direction on security assurance responses and compliance-related inquiries
- Drive continuous improvement of the due diligence response process through knowledge management, content governance, and operational efficiencies
- Maintain and enhance the organization’s assurance knowledge repository, ensuring responses remain current, consistent, and aligned with evolving regulatory and client expectations
- Partner with business, technology, legal, and compliance stakeholders to address complex client concerns while balancing risk, compliance, and commercial objectives- The ideal candidate will have solid experience in developing and/or maintaining information security policies and procedures, as well as familiarity with security frameworks and standards including CSA CCM, PCI-DSS, SOC2, ISO27001, etc. Excellent communication skills, both verbal and written, are essential
- Must have a positive attitude, excellent critical thinking and problem-solving skills to support the business working with cross-functional teams on projects and initiatives
- Liaise with internal and external stakeholders on an ongoing basis during the audit, relative to plans, objectives, evidence collection and results documenting, presenting and tracking findings and remediation actions
- Managing the PCI, SOC-2 and other compliance programs end-to-end
- Ability to influence change through effective communication and interpersonal skills
- Certified Professional designation (CSA CCM, CISSP, CISA, CRISC) or willingness to work towards one or more of these certifications
- Experience with GDPR and/or PIPEDA and/or similar Data Privacy frameworks
- Experience with information management/ RFP platforms (e.g., Loopio, RFPIO, RFP360, etc.)
- Ability to work and partner with others in different levels of the organization
- Evaluating internal stakeholders’ response to audits and reporting to management on appropriateness
- Understanding of risk management and Information Security frameworks
- Intellectually curious, self-motivated, passionate works well both independently and as part of a team
- Ability to multi-task, be organized and take initiative audit management
- Preferably 5 - 7 years’ experience with/in:
• IT security controls • IT Audit, and/or • Compliance management, and/or • Project management/ coordination (document collections, coordination, tracking, customer partnership), and/or • Information management
- Experience working with auditors and other stakeholders, managing audits, collecting evidence and tracking findings to a resolution
- Acting in a consultative capacity, providing advice and clarity to teams on compliance requirements and audits