← Back to job listings
ST
Security Analyst - Security & Governance Compliance
Staples · Richmond Hill, ON, Canada
About The Role
Some of what you will do
The Security Analyst, Security Risk & Compliance will support the management and continuous improvement of Staples Canada’s PCI compliance program and broader cybersecurity risk activities. This role will work closely with cybersecurity, technology, audit, and business stakeholders to coordinate PCI compliance tasks, gather evidence, track remediation activities, support security projects, and help business teams understand PCI and cyber-risk requirements.
Specifically, You Will
Governance & Policy Management
- -
- Support the development, review, approval, communication, and refresh of information security and risk management policies.
- -
- Maintain policy repositories and assist with governance reporting, metrics, and committee materials.
Risk Management
- -
- Participate in enterprise and IT risk assessments, including risk identification, scoring, documentation, and mitigation tracking.
- -
- Support risk workshops, maintain risk registers, and follow up on remediation activities with business and technology teams.
Compliance & Assurance
- -
- Support compliance programs aligned to frameworks such as SOC 1/SOC 2, ISO/IEC 27001, PCI DSS, NIST CSF, and NIST 800-53.
- -
- Assist with audits, evidence collection, control testing, issue tracking, and security/compliance inquiries.
Third-Party Risk Management
- -
- Support vendor risk assessments, evidence reviews, issue tracking, and coordination with procurement, legal, and security teams.
- -
- Identify opportunities to improve GRC processes, documentation, tooling, and support GRC platform maintenance.
Some of what you need
- -
- Diploma or degree in cybersecurity, IT, computer science, risk management, or a related field; equivalent experience may be considered.
- -
- 2–4 years of experience in cybersecurity, IT risk, compliance, audit, or technology.
- -
- Experience supporting assessments, audits, control testing, compliance activities, and evidence collection.
- -
- Basic understanding of cybersecurity risk, compliance, and frameworks such as PCI DSS, NIST CSF, ISO 27001, SOC 2, or CIS Controls.
- -
- Strong documentation, analytical, communication, and stakeholder coordination skills.
- -
- Ability to track risks, issues, action items, remediation plans, and compliance evidence.
- -
- Experience with tools such as Microsoft Office, SharePoint, Teams, ServiceNow, Jira, or Confluence; retail, payment, PCI, or relevant certifications are assets.
Physical Environment/Working Conditions
- -
- Office environment.
- -
- May require limited travel.
- -
- May require evening and weekend work based on business requirements.
Some of what you will get
- -
- Associate discount
- -
- Health and Dental benefits
- -
RRSP/DPSP
- -
- Performance bonuses
- -
- Learning & Development programs
- -
- And more…
Similar roles you might like
See all →BO
Leader - AI Compliance, Audit & Risk
Bank of Montreal
C$85,500 – 185,000/yrPosted today
Z
Associate General Counsel & Privacy Officer (Remote First)
Zensurance
Salary not disclosedPosted today
T
General Counsel
Techo-Bloc
Salary not disclosedPosted 1 day ago
CG
Director, Global Regulatory Compliance, Risk & Compliance
Canada Goose Inc.
C$145,000 – 181,000/yrPosted 1 day ago
OS
Senior Litigation Counsel
Ontario Securities Commission
Salary not disclosedPosted 1 day ago
IF
Security Advisor Specialist – Governance, Risk & Compliance
Intact Financial Corporation
C$118,700 – 145,100/yrPosted 2 days ago
CO
Manager, Legal Counsel
Capital One
C$157,400 – 179,600/yrPosted 3 days ago
B
SENIOR LEGAL COUNSEL - SPECIALIZED FINANCING
bdc
Salary not disclosedPosted 3 days ago
This is an external listing. JobSpring does not represent or verify the employer. Report this listing