Talent.com
Canadian Bank Note Company
Auditor, IT Risk and Compliance - Corporate Information Systems GroupCanadian Bank Note Company • Ottawa, Ontario, Canada
Auditor, IT Risk and Compliance - Corporate Information Systems Group

Auditor, IT Risk and Compliance - Corporate Information Systems Group

Canadian Bank Note Company • Ottawa, Ontario, Canada
18 days ago
Job type
  • Full-time
  • Permanent
  • Remote
Job description
Job Description

Internal Job Title: Auditor, IT Risk and Compliance

Job Type: Permanent, Full-Time

Location: 18 Auriga Drive, Ottawa ON

Work Model: Remote

Position Summary

As an Auditor, IT Risk and Compliance in our Corporate Information Systems group, you will play a central role in developing, delivering and managing the compliance and risk programs and activities while also investigating and participating in relevant IT security projects that support the business needs of the organization.

Key Responsibilities

Audit Planning Execution and Reporting

  • Design Audit Plans and Schedules: Create detailed audit plans and schedules aligning with the organization’s compliance requirements.
  • Conduct Audits: Perform comprehensive internal audits aligned with recognized frameworks (ISO/IEC 27001, ISO 14298, PCI DSS, SOC 2, CIS Controls etc.) of IT systems, applications, and processes with a strong focus on IT and cybersecurity risk.
  • Document Findings: Prepare detailed reports on audit findings, update registers, and highlight areas of concern and assessing corrective actions to ensure they will meet compliance requirements.
  • Present to Management: Present findings to senior management and compliance committees, ensuring transparency and accountability.

Compliance Monitoring and Management

  • Compliance: Ensure IT systems and procedures comply with industry standards and regulations such as ISO-27001, PCI, and SOC 2.
  • Framework Evaluation: Maintain currency for emerging compliance frameworks or as standards evolve. Update internal control frameworks, assess gaps and work with stakeholders to maintain our compliance.
  • Internal Policies: Create internal policies and procedures to meet emerging or evolving standards and as new technologies or threats are defined.

Risk Assessment and Management

  • Risk Program: Participate in the maintenance of our ongoing risk management program following CBN standard procedures.
  • Identify and Evaluate Risks: Collaborating with stakeholders and SMEs across the business to continuously assess IT risks.
  • Risk Documentation: Document identified risks and communicate them to relevant stakeholders, updating risk registers and following up with risk owners and reporting as necessary to executive committees.

Technical Guidance

  • Investigations: As required assist in investigating security events and participate in relevant root cause analysis development.
  • Consulting: Provide subject-matter guidance to business and technology teams on the interpretation and application of applicable compliance frameworks and standards, supporting informed decision-making and consistent execution.
  • Implementation Support: Provide advisory support during the implementation of compliance frameworks and control enhancements, including reviewing design approaches, validating alignment to requirements, and providing practical, risk-based recommendations without assuming control ownership.

Continuous Improvement

  • Supervise Corrective Actions: Oversee the implementation of corrective actions to ensure compliance issues are resolved effectively and promptly.
  • Process Enhancement: Continuously seek ways to improve processes and methodologies to enhance efficiency and effectiveness.

Qualifications

Mandatory Requirements

  • Legally eligible to work in Canada
  • Fluent in English (speak, read, write)
  • Able to obtain (in a timely manner) and maintain Government of Canada Secret (Level II) security clearance
  • Able to travel 2-6 weeks/year

Minimum Qualifications

  • Bachelor’s degree in Information Systems (or similar) or equivalent combination of relevant education and additional relevant work experience or overall additional relevant work experience.
  • Certification and/or demonstrable knowledge/experience in compliance frameworks including ISO 27001:2022 and PCI-DSS v4.0+.
  • Working knowledge of industry recognized threat and risk management methodologies and frameworks.
  • Comprehensive knowledge of Unified Compliance Frameworks and GRC tools.
  • Thorough knowledge of current security trends, threat vectors and cyber security threats.
  • 3+ years of experience in a relevant auditing, compliance and/or risk role.
    • Experience in cybersecurity, corporate security, or highly regulated organization.
    • Experience in developing and delivering compliance and risk assessments, creating, and presenting reports to management and liaising with external auditors.

Preferred Qualifications

  • Certification in a relevant audit discipline: BSI Internal Auditor, ISACA CISA, PECB Internal Auditor, or other relevant industry certification e.g. ISC2, GIAC, SANS, or equivalent
  • Certification and/or demonstrable knowledge/experience in various compliance frameworks including but not limited to ISO 14298, NASPO, SOC 2 (Type I and II), FedRamp, CSA and CSA Star-II.
  • 7+ years of experience in a relevant auditing, compliance and/or risk role
  • Fluent in Spanish (speak, read, write)

Soft Skills and Characteristics

  • Critical thinking skills
  • Organization and time management skills
  • Interpersonal skills
  • Teamwork and collaboration
  • Growth mindset


Additional Information

Equal Opportunity Statement

Our organization is committed to employment equity and diversity in the workplace. We actively encourage applications from women, Indigenous Peoples, persons with disabilities, members of visible minorities, and LGBTQ2+ individuals.

We are dedicated to removing barriers and fostering an inclusive workplace that reflects society and we are committed to providing an accessible and inclusive recruitment process in accordance with the Accessibility for Ontarians with Disabilities Act (AODA).

If you require accommodation at any stage of the hiring process, please contact us at recruitment@cbnco.com so that appropriate arrangements can be made.

AI Use in Recruitment Statement

As part of our commitment to transparency and fairness in hiring, we disclose that artificial intelligence (AI) tools may be used at certain stages of our recruitment process. These tools assist in tasks such as resume screening, candidate matching, and interview scheduling. All AI-assisted decisions are subject to human oversight to ensure fairness, accuracy, and compliance with applicable laws.

We are committed to the responsible, transparent, and accountable use of AI, in alignment with Ontario’s Responsible Use of Artificial Intelligence Directive and the requirements under the Working for Workers Four Act. This includes taking steps to mitigate bias, protect candidate privacy, and ensure that AI does not unfairly influence hiring outcomes.

If you have questions or concerns about how AI is used in our hiring process, please contact us at recruitment@cbnco.com .

Create a job alert for this search

Auditor, IT Risk and Compliance - Corporate Information Systems Group • Ottawa, Ontario, Canada

Similar jobs

Manager, Security & IT

KnakOttawa
Full-time

The Role: Team Lead, Security & Compliance.As Team Lead, Security & Compliance at Knak, you’ll lead the programs that keep our platform, customers, and company secure.This is a hands‑on leadership ... Show more

 • Promoted

Head of Risk - Remote

BitfinexOttawa, ON, CA
Remote
Full-time

Be among the first 25 applicants.Inspired by Bitcoin's vision of financial freedom, we are committed to empowering individuals to transact and connect seamlessly across the globe.From the early day... Show more

 • Promoted

Governance, Risk & Compliance Consultant

MalleumOttawa, ON, CA
Full-time

Governance, Risk & Compliance Consultant.Governance, Risk & Compliance Consultant.We are a premier cybersecurity consultancy, blending advanced offensive and defensive strategies to safeguard our c... Show more

 • Promoted

Information Security and Compliance Manager

MDA SpaceOttawa, ON, CA
Full-time

Building the space between proven and possible, MDA Space is a trusted mission partner to the global space industry.A robotics, satellite systems and geointelligence pioneer with a 55-year+ story o... Show more

 • Promoted

Security Governance, Risk and Compliance Specialist

Tecsys Inc.Ottawa, ON, CA
Full-time +1

Security Governance, Risk and Compliance Specialist.Having recognized the advantages of remote work, such as improved employee morale, increased productivity, and positive impacts on both employee ... Show more

 • Promoted

IT Security Risk Analyst

Onico SolutionsOttawa, ON, CA
Permanent

The IT Security Risk Analyst supports the Information Security Risk Management and Governance programs.They work with technology and business stakeholders to identify Information Security risks, co... Show more

 • Promoted

Senior IT Compliance Program Manager

PathlionOttawa, ON, CA
Full-time

A leading project management firm in Canada is looking for a Senior Project Manager to lead the compliance program development.In this role, you will establish project foundations, drive the creati... Show more

 • Promoted

Senior IT Compliance & Audit Lead — Remote

P2POttawa, ON, CA
Remote
Full-time

A leading crypto firm is seeking a senior IT audit professional.This fully remote role emphasizes managing SOC examinations and establishing audit rigor.Ideal candidates will have over 5 years of e... Show more

 • Promoted

Senior Incident Response Consultant at CrowdStrike

CrowdStrikeOttawa, ON, CA
Full-time

Join CrowdStrike as a Senior Incident Response Consultant and play a critical role in modern cybersecurity.This position allows you to shape responses to sophisticated cyber threats.We are looking ... Show more

 • Promoted

Remote IT Security Risk Analyst: Governance & Risk

Onico SolutionsOttawa, ON, CA
Remote
Permanent

A leading IT security firm in Richmond Hill is looking for an IT Security Risk Analyst to support their Information Security Risk Management programs.The role requires expertise in risk assessments... Show more

 • Promoted

Transformation Risk and Advisory Manager

PwC CanadaOttawa, ON, CA
Full-time

At PwC, our people in risk and compliance focus on maintaining regulatory compliance and managing risks for clients, providing advice, and solutions.They help organisations navigate complex regulat... Show more

 • Promoted

Remote IT Security Consultant - Leading Security Initiatives

ExperisOttawa, ON, CA
Remote
Full-time

A leading technology staffing firm is seeking experienced IT Security Consultants to enhance cybersecurity initiatives across Canada.In this remote role, you will lead security implementations, con... Show more

 • Promoted

Senior Technology Risk Consultant at EY

Ernst & Young Advisory Services Sdn BhdOttawa
Full-time

Lead technology risk solutions at EY as a Senior Consultant.Maximize efficiencies for clients through guiding IT engagements and security practices in hybrid work settings.As a Senior Consultant in... Show more

 • Promoted

Remote GRC & Cybersecurity Compliance Consultant

MalleumOttawa, ON, CA
Remote
Full-time

A leading cybersecurity consultancy in Montreal is seeking a Governance, Risk & Compliance Consultant.The role requires 5-8 years of experience in IT security and risk management, with a deep under... Show more

 • Promoted

Senior IT Technical BA – Health Systems & Interoperability

PathlionOttawa, ON, CA
Full-time

A government agency is seeking a Senior IT Technical Business Analyst for a 24-month term with an option to extend.The role involves advanced business analysis and working closely with multiple sta... Show more

 • Promoted

IT & Security Professional at Senstar

SenstarOttawa, ON, CA
Full-time

Advance your career with Senstar as an IT & Security Professional, where you will ensure IT operations security in a hybrid work setting.As an integral part of Senstar, you will handle the daily op... Show more

 • Promoted

Senior Technology Risk Consultant at EY

EYOttawa
Full-time

Elevate your expertise at EY as a Senior Consultant in Technology Risk Assurance.Oversee audit teams and assist clients in navigating complex IT environments to mitigate risks.This position entails... Show more

 • Promoted

IT Infrastructure and Security Manager

Senstar CorporationOttawa, ON, CA
Full-time

Become an IT Infrastructure and Security Manager at Senstar, a pioneer in security technology.Your role will encompass end-user support and overall management of complex IT environments.In this pos... Show more

 • Promoted

Transformation Risk and Advisory Manager

PwC South AfricaOttawa, ON, CA
Full-time

Transformation Risk & Advisory, Manager.Transformations risk and advisory team continues to grow, offering strategic risk management to support digital transformation across our client base.Assist ... Show more

 • Promoted

Senior Cloud Compliance Leader

ThalesOttawa, ON, CA
Full-time

A global technology company is seeking a Senior Compliance Officer to oversee compliance initiatives for Cloud Services.This role requires managing complex audit processes, collaborating with busin... Show more