Talent.com
Hays
IT Risk and Compliance AnalystHays • Mississauga
No longer accepting applications
IT Risk and Compliance Analyst

IT Risk and Compliance Analyst

Hays • Mississauga
30+ days ago
Job type
  • Full-time
Job description
Our client has an immediate opening for a Senior IT Risk andpliance Analyst to join their team in Mississauga.
In your new role as a Senior IT Risk andpliance Analyst, you will support and strengthen an enterprise-wide IT Risk andpliance program. You will work closely with the Director to design, implement, and monitor risk and control initiatives that align with regulatory requirements, internal policies, and client expectations. This role offers the opportunity to contribute meaningfully to overall risk posture while collaborating with cross-functional teams across the organization.
This is a hybrid role with requirements to be on site 3 days a week, providing a balance between remote flexibility and in-person collaboration.
About The Role:
Lead the ongoing execution and effectiveness of the IT Risk andpliance program, ensuring technology risks are identified, assessed, monitored, and reported across infrastructure, applications, cloud platforms, and related processes.
  • Maintain the IT risk register, capturing assessment results, emerging risks, and control trends, and ensuring risk information is current, consistent, and decision‑useful.
  • Prepare and maintain IT risk reporting, including KRIs, KPIs, dashboards, and analysis used to support audits, client discussions, and management oversight.
  • Perform control testing activities, identify control gaps, deficiencies, and thematic issues, and validate remediation actions to confirm issues are addressed in line with internal requirements, regulatory expectations, and clientmitments.
  • Act as the primary point of contact for IT risk andpliance matters during internal audits, external audits, client assessments, and third‑party reviews including PCI DSS, CCM, ISO 27001 certifications, engaging directly with auditors, assessors, and stakeholders.
  • Review, validate, and maintain audit and assessment evidence, ensuring submissions are accurate,plete, traceable, and aligned with stated control objectives and risk assertions.
  • Execute ongoing IT risk andpliance activities, including access and privilege reviews, firewall rule reviews, SOC report reviews, social engineering simulation, and exception tracking, ensuring issues are appropriately risk‑rated and documented.
  • Review and assess the results of penetration testing, vulnerability assessments, and similar technical testing, validate remediation actions, and track findings through to closure.
  • Support the issue management lifecycle, including documenting findings, validating corrective actions, and supporting risk acceptance where residual risk remains.
  • Collaborate with Legal, Privacy, Vendor Management, Enterprise Risk, Corporate Security, and Sales to support contract reviews, vendor assessments, and client due‑diligence activities.
  • Review IT policies, architecture artefacts, and solution designs to assess alignment with existing controls and security requirements, providing practical, risk‑based input.
  • Provide technical guidance and support to ensure consistent assessment practices, evidence quality, and sound professional judgment across the team.
What You Need to Succeed:Education:
  • Post‑secondary diploma or university degree in a related discipline, or an equivalentbination of education, training, and relevant experience.
  • Relevant professional certification(s) in IT audit, security, cloud security, or risk management (e.g., CISA, CISSP, CISM, CRISC, CGEIT, CCSK, CCSP, or equivalent), preferred.
Experience:
  • Minimum of five (5) years of practical, hands‑on experience executing IT risk assessments, technical control testing, and audit support activities within IT Risk Management, Information Security, IT Audit, or IT Risk andpliance functions.
Experience operating in banking, financial services, or other highly regulated enterprise environments, with direct responsibility for reviewing technical evidence, assessing control effectiveness, and supporting internal and external audits.Skills and Knowledge:
  • Solid understanding of the technology threat landscape and applicable regulatory, security expectations,
  • Strong working knowledge of industry‑recognized IT control frameworks and standards, including PCI DSS, NIST SP 800‑53, ISO/IEC 27002, COBIT, AICPA Trust Services Criteria (SOC 2), CSA Cloud Controls Matrix (CCM), andernment of Canada Protected B security requirements.
  • Experience using GRC tools to support IT risk assessments, control testing, issue management, and risk reporting.
  • Awareness of industry trends and emerging practices related to IT risk management,pliance, cloud security, and third‑party risk.
Create a job alert for this search

IT Risk and Compliance Analyst • Mississauga

Similar jobs

IT Security Risk Analyst

Onico SolutionsMississauga, Peel Region, CA
Permanent

The IT Security Risk Analyst supports the Information Security Risk Management and Governance programs.They work with technology and business stakeholders to identify Information Security risks, co... Show more

 • Promoted

Compliance and Risk Analyst at LTIMindtree

LTMMississauga, Peel region, Canada
Full-time

Advance your skills in compliance as a Governance Risk and Compliance Analyst at LTIMindtree, located in Mississauga, Ontario.Work alongside teams to strengthen security controls and ensure regulat... Show more

 • Promoted

Remote Information Risk & Security Analyst

DexianMississauga, Peel Region, CA
Remote
Full-time

A leading IT services firm is seeking an Information Control Testing Specialist to manage information risk and ensure compliance with security policies.You will work on global initiatives, conduct ... Show more

 • Promoted

Analyst Compliance and Dispute Resolution

Independent Electricity System Operator (IESO)Oakville, ON, CA
Full-time

Market Assessment & Compliance.For standard 35-hour work week.The successful candidate will be placed at the appropriate step within the salary grade/band, based on relevant years of experience and... Show more

 • Promoted

Senior Grc Security Analyst: Risk & Compliance Leader - C$105,000 - C$125,000 A Year

Metro Supply ChainMississauga, Canada
Full-time

Senior Cybersecurity Analyst to lead governance, risk, and compliance for a logistics company.Responsibilities include policy development, assessments, and reporting. Show more

 • Promoted

Mid-Senior Risk & IT Analytics Consultant

TechDoQuestMississauga, Peel region, Canada
Full-time

A leading technology firm is seeking a mid-senior level IT Analyst based in Mississauga to lead risk management initiatives.The role involves comprehensive risk assessments and communication with c... Show more

 • Promoted

Lead Application Security Analyst at Purolator

Purolator Inc.Mississauga
Full-time

Join Purolator as a Lead Application Security Analyst, focusing on integrating security in application development.Help teams secure their software and APIs against evolving threats.In this key rol... Show more

 • Promoted

Technology Risk Manager - It Risk & Compliance Lead - C$73,000 - C$109,500 A Year

KPMG CanadaOakville, Canada
Full-time

Oversee technology risk in operations, facilitate risk assessments, and collaborate with stakeholders. Show more

 • Promoted

Compliance and Safety Analyst at Clearlight Energy

Clearlight EnergyOakville
Full-time

Drive compliance standards at Clearlight Energy as a Compliance and Safety Analyst.Collaborate with teams to enhance safety protocols in a hybrid work environment.As a Safety and Compliance Analyst... Show more

 • Promoted

GFL IT Audit Analyst Career Opportunity

GFL Environmental Inc.Vaughan
Full-time

Shape your future with GFL as an IT Audit Analyst in Vaughan.We’re seeking individuals ready to engage in IT audit and compliance in a leading environmental services firm.This position supports the... Show more

 • Promoted

Governance, Risk & Compliance Consultant

MalleumMississauga, Peel region, Canada
Full-time

Governance, Risk & Compliance Consultant.Governance, Risk & Compliance Consultant.We are a premier cybersecurity consultancy, blending advanced offensive and defensive strategies to safeguard our c... Show more

 • Promoted

Remote Director of IT Security Role

DirectiveMississauga, Peel Region, CA
Remote
Full-time

Shape Directive Consulting's cybersecurity landscape as the Director of IT Security.This fully remote position emphasizes strategic oversight of information security across multiple regions.As the ... Show more

 • Promoted

Sr. IT Security Analyst

407 ETR Concession Company LimitedVaughan
Full-time

Department: Information Technology.Location: 6300 Steeles Ave West, Woodbridge.Total Potential Compensation: $115,000-$140,000.The Senior Security Analyst – Security Operations is responsible for o... Show more

 • Promoted

Senior Analyst, Enterprise Risk Management, Risk Advisory Services

Loblaw Companies LimitedBrampton
Full-time

As a key business partner, the Risk Advisory Services (RAS) team collaborates with business functions to protect, improve, and grow technology and infrastructure, governance, people and programs th... Show more

 • Promoted

Sr. IT Security Analyst

407 ETRvaughan, york region, Canada
Full-time

The Senior Security Analyst – Security Operations is responsible for operating, maturing, and continuously improving core cyber defense and detection capabilities across the enterprise.This role ha... Show more

 • Promoted

Compliance Analyst Needed at Wellington-Altus

Wellington-Altus Financial Inc.Burlington, Halton Region, Canada
Full-time

Advance your career as a Compliance Analyst with Wellington-Altus in Winnipeg, Toronto, Burlington, or Vancouver.This role focuses on ensuring compliance with regulatory standards and supporting th... Show more

 • Promoted

IT Service Delivery Analyst

goeasy Ltd.Mississauga, Peel region, Canada
Full-time

Responsible for second‑ and third‑level support for business‑critical applications, triage across teams, and core IT service management functions including Major Incident Management, Change Managem... Show more

 • Promoted

Director, Enterprise Risk Management – It Security & Cyber Risk

Sagen MI Canada Inc.Oakville, Canada
Full-time

Director, Enterprise Risk Management – IT Security & Cyber RiskJob DescriptionSagen is Canada’s leading private mortgage insurance company making home ownership more accessible to first time ho... Show more

 • Promoted

Senior IT Audit Leader - Risk, Controls & Advisory

Clarity RecruitmentVaughan
Full-time

A recruitment firm specializing in Finance & Accounting seeks an experienced IT Audit Manager in Vaughan, Canada.You will lead the planning and execution of complex IT audits, develop risk-based re... Show more

 • Promoted

It Security Leader: Strategy, Policy & Risk | Hybrid - C$84,000 - C$105,000 A Year

Health Solutions ProviderBrampton, Canada
Full-time

Manager of IT Security to lead information security strategy, policy, and risk management.Focus on compliance and stakeholder collaboration in a hybrid work model. Show more