Talent.com
Canadian Tire Bank
Senior Compliance Security SpecialistCanadian Tire Bank • Oakville, ON
No longer accepting applications
Senior Compliance Security Specialist

Senior Compliance Security Specialist

Canadian Tire Bank • Oakville, ON
20 days ago
Salary
CA$64,000.00 yearly
Job type
  • Full-time
Job description

The Information and Cyber Security Governance (IRGS) function is a dedicated team responsible for effectively managing and controlling information and cyber security within an organization. They develop and maintain policies, standards, and procedures/guidelines/process documents related to information and cyber security. The team identifies, assesses, and manages cyber risks, performs risk assessments, and reports on the organization's cyber risk profile. They promote a strong cyber risk and information security culture throughout the organization.

Additionally, the IRGS team conducts vendor assessments, reviews hardware and software for security gaps, remediates deficiencies, and tests control effectiveness. They build partnerships with stakeholders across the organization, implement self-assessment processes incorporating risk and controls assessment in day-to-day activities, and contribute to adopting state-of-the-art tools and techniques. The team also escalates significant cyber-related issues or observed non-compliance or unethical behavior.

It's important to note that the IRGS team reports directly to the Chief Information Security Officer (CISO)of CTB, who oversees the organization's overall information and cyber security strategy. This reporting relationship ensures alignment with strategic goals and facilitates effective coordination, collaboration, and decision-making between the IRGS function and other areas of the organization.

In summary, the IRGS function plays a vital role in governing and managing information and cyber security to protect the organization's assets, data, and systems from potential threats while maintaining a direct line of communication with senior leadership through its reporting structure to the CISO.

What you’ll do

The Specialist is a key player responsible for spearheading initiatives to identify, investigate, communicate, resolve, and improve information securitygovernance,riskand compliancein our IT investments.

You will partner withacross the organization,including,Technology, Enterprise Risk Management, InternalAudit, PCI Compliance,VendorManagementand other stakeholdersto assess cybersecurity risks for the organization, including 3rd party risk, while helping teams determine mitigation strategies tomaintain and/or reducetheresidualriskofthe organization.

  • Be the champion in risk assessment of technologies and processes in the environment, including our digital crown jewels and other compliance impacting technologies and processes.

  • Connect the dots to improve and enhance risk assessment processes.

  • Understand and collaborate with stakeholders for prioritizing and mitigating vulnerabilities identified within the environment through vulnerability assessment, penetration testing, application security testing and/or any other risk assessment activity.

  • Following up on vulnerabilities, configuration and cloud gaps and track remediation

  • Help further mature existing vulnerability management program

  • Assess third-party risk on the use of vendors for day-to-day operations.

  • Provide oversight, reporting, and metrics on risk functions.

  • Performing security risk assessments for various projects and changes. And assisting with and documenting identified risk for presentation and approval from business and leadership as appropriate.

  • Anticipate risk and assist owners in building action plans for risk mitigation.

  • Review risk assessments of non-senior team members and peers

  • Validating operating effectiveness of IT general controls

  • Maintaining risk and controls repositories and documentation

  • Providing support for policy exception management procedures

  • Assisting with metrics and reporting

  • Manage platforms/applications within the mandate of the team

What you bring

  • University degree or college diploma in technology.

  • Possess one or more professional certifications, such as CISSP, CISM, CISA, CCSP, CRISC etc.

  • Up to 5+ years of experience in understanding risks, audits and processes relating to Information/Cyber Security and IT.

  • Excellent communication skills

  • Good documentation and presentation skills

  • Creative thinker who takes initiative

  • Problem solver with the ability to analyze and prioritize to meet business objectives

  • Collaborative team player with superior influencing skills, who builds relationships easily

  • Organized individual who is always seeking to automate or improve efficiency of procedures

  • Creative thinker who is observant to seek new opportunities and perceptive to abstract ideas

  • Goal driven individual to seek out continuous improvement opportunities

  • The ability to take a collaborate approach to build strong relationships and have positive team experiences

  • Flexible and dynamic individual who is able to adjust and prioritize accordingly to adapt to business demands and requirements

  • Solid foundation of relevant technical skills

  • Demonstrates behaviors of transparency, accountability agility and learning from others that will support your success

  • Good understanding of vulnerability and configuration management procedures and how those impact an organization.

  • Good knowledge and understanding about penetration testing and application security

  • Good scripting skills using Python or similar tools

  • Experience with developing dashboards using Power BI

  • Understands/Experience in risk assessments including third-party risk

  • Good understanding and some experience of managing applications/platforms

  • Have knowledge of security governance frameworks, policies and standards

  • Understands principles of security controls testing

  • Audit and/or IT risk management

  • Knowledge of IT risk and control frameworks, COBIT 5, NIST CSF & ISO27001, CIS

  • Understand System Development Life Cycle (SDLC) process and agile methodologies

  • Familiarity with Data Privacy and Protection standards PCI, PII.

  • Basic knowledge of cryptography and encryption algorithms.

  • Familiarity with identity management controls including Multi Factor Authentication and Single Sign On.

We’re always looking for great talent! In addition to competitive pay, we offer:

  • Comprehensive benefits and retirement programs

  • Performance incentives, Continuing Education Programs

  • Other perks to support your well-being

  • Career growth opportunities and product discounts

Broadband Salary Range: $64,000.00 - $106,000.00

Salary decisions are also dependent on other factors such as your experience, industry benchmarks, internal equity and other role-specific requirements. For critical roles, the compensation offering will be reviewed to ensure alignment with market rate and conditions and the unique value you bring to the role. #LI-AG2

This posting represents an existing vacancy within our organization.


We may use artificial intelligence tools as part of our recruitment process to assist in the initial screening of resumes. All hiring decisions, including candidate evaluation, selection, and disposition, are made by human recruiters.

Create a job alert for this search

Senior Compliance Security Specialist • Oakville, ON

Similar jobs

Senior Compliance Security Specialist - $64,000 - $106,000 A Year

Canadian Tire ServicesOakville, Canada
Full-time

The Information and Cyber Security Governance (IRGS) function is a dedicated team responsible for effectively managing and controlling information and cyber security within an organization.They dev... Show more

 • Promoted

Senior IT Security Advisor (Application Security)

goeasy Ltd.Mississauga, ON, Canada
Full-time +1

AI data lab for training frontier models and evaluating AI agents.Experts contribute their diverse subject matter knowledge across domains such as finance, healthcare, STEM engineering, and more.Lo... Show more

 • Promoted

Senior Analyst, Security Compliance

P2PMississauga, Peel Region, CA
Full-time

Our Krakenites are a world-class team with crypto conviction, united by our desire to discover and unlock the potential of crypto and blockchain technology.Kraken is a mission-focused company roote... Show more

 • Promoted

Senior GRC Security Analyst: Risk & Compliance Leader

Metro Supply ChainMississauga, Peel Region, CA
Full-time

A logistics company in Mississauga seeks a Senior Cybersecurity Analyst overseeing governance, risk management, and compliance aspects of the security program.The role involves developing policies,... Show more

 • Promoted

Senior Compliance Security Specialist

Canadian Tire ServicesOakville, Canada
Full-time

The Information and Cyber Security Governance (IRGS) function is a dedicated team responsible for effectively managing and controlling information and cyber security within an organization.They dev... Show more

 • Promoted

Sr. IT Security Analyst

407 ETR Concession Company LimitedVaughan, York Region, CA
Full-time

Department: Information Technology.Location: 6300 Steeles Ave West, Woodbridge.Total Potential Compensation: $115,000-$140,000.The Senior Security Analyst – Security Operations is responsible for o... Show more

 • Promoted

Senior Cyber Security Architect - Enterprise Risk & TRA

ResonaiteMississauga
Full-time

A cybersecurity consulting firm is seeking a Senior Cyber Security Architect in Mississauga to provide enterprise-level security architecture leadership.The ideal candidate will possess 8-12 years ... Show more

 • Promoted

Senior Compliance Security Specialist

Canadian TireOakville, Canada
Full-time

The Information and Cyber Security Governance (IRGS) function is a dedicated team responsible for effectively managing and controlling information and cyber security within an organization.They dev... Show more

 • Promoted

Security Advisor PAM Specialist

Intact Financial CorporationMississauga, Peel Region, CA
Full-time

We are seeking a Senior PAM Specialist with deep hands‑on expertise in IDIRA (formerly CyberArk) to lead the design and architecture of our PAM program and to build advanced integrations, including... Show more

 • Promoted

Specialist

LTMMississauga, Peel region, Canada
Full-time

Governance Risk and Compliance Analyst - Job Description.We are looking for a Governance Risk and Compliance Analyst to be part of our growing security team.Evaluate and report on adequacy/effectiv... Show more

 • Promoted

Regional Compliance Specialist

Monroe Group Ltd.Burlington, Halton Region, CA
Full-time

The Regional Compliance Specialist is responsible for all aspects of Project Based Section 8, Low Income Housing Tax Credit, HOME, and Bond compliance for Monroe Group’s growing portfolio.The posit... Show more

 • Promoted

AtkinsRéalis Senior Cyber Security Role

AtkinsRéalisMississauga
Full-time

Step into a pivotal role at AtkinsRéalis as a Senior Cyber Security and Software Qualification Specialist for the DNNP smart modular reactor initiative.Your focus will be on ensuring cyber security... Show more

 • Promoted

Senior Information Security Analyst

IKO North AmericaMississauga, Peel Region, CA
Full-time

Senior Information Security Analyst.Team Lead, Information Security.We are seeking a Senior Information Security Analyst with deep, hands‑on experience across security operations, incident response... Show more

 • Promoted

Senior Security Analyst: Lead Threat Defense & Security Ops

OpTalent | RecruitmentMississauga, Peel Region, CA
Full-time

A leading recruitment agency in Canada seeks a Senior Security Analyst to enhance cybersecurity within a technology-driven organization.This pivotal role involves managing security operations, resp... Show more

 • Promoted

Senior Compliance Security Specialist

Ct-BankOakville, ON, CA
Full-time

The Information and Cyber Security Governance (IRGS) function is a dedicated team responsible for effectively managing and controlling information and cyber security within an organization.They dev... Show more

 • Promoted

Security Governance, Risk and Compliance Specialist

Tecsys Inc.Mississauga, Peel Region, CA
Full-time +1

Security Governance, Risk and Compliance Specialist.Having recognized the advantages of remote work, such as improved employee morale, increased productivity, and positive impacts on both employee ... Show more

 • Promoted

Compliance Specialist

BrunelMississauga, Peel Region, CA
Full-time

We are currently hiring a Compliance Specialist (Biobank / Human Biological Sample) for our client, a global pharmaceutical company known for its innovative technology and products.This position is... Show more

 • Promoted

Security Systems Technical Specialist Level 1

New Age GroupVaughan, York Region, CA
Full-time

Security Systems Technical Specialist Level 1 – Security Systems & Technology Integration.Location: Concord/Vaughan, Ontario.For over 25 years, The New Age Group has delivered trusted security and ... Show more

 • Promoted

Sr. IT Security Analyst

407 ETRVaughan, York Region, CA
Full-time

The Senior Security Analyst – Security Operations is responsible for operating, maturing, and continuously improving core cyber defense and detection capabilities across the enterprise.This role ha... Show more

 • Promoted

Senior Research Compliance Specialist - $62,350 - $86,200 A Year

Boston CollegeVaughan, Canada
Full-time

Supports compliance programs related to export control, sanctions, and research security, including screening international shipments and personnel, and assisting with risk mitigation plans. Show more