About the Role
As an Analyst II, Governance, Risk & Compliance (GRC), you will support the Information Security team in maintaining compliance, managing risk, and strengthening Moneris’ security posture. This role offers exposure to industry-standard security frameworks including Payment Card Industry Data Security Standard (PCI DSS), National Institute of Standards and Technology Cybersecurity Framework (NIST CSF), ISO 27001, and SOC 2. You will contribute to control testing, audit readiness, and risk assessments in a regulated environment where compliance and data security are critical. Working alongside senior analysts, you’ll build hands-on experience with governance processes, third-party risk, and compliance tooling while supporting initiatives that directly impact enterprise security and operational resilience.
Responsibilities
- Support administration and tracking of compliance controls across PCI DSS, ISO 27001, NIST CSF, and SOC 2.
- Collect, validate, and maintain audit evidence for regulatory and internal assessments.
- Assist in risk assessments, control testing, and remediation tracking.
- Maintain and update security policies, standards, and control documentation.
- Update and manage risk and compliance data within GRC platforms (e.g., MetricStream).
- Support third-party and vendor risk assessments, including documentation and evidence review.
- Prepare reports, metrics, and dashboards for stakeholders and leadership.
- Participate in security awareness and compliance training initiatives.
Requirements
- 2+ years of experience in information security, compliance, risk management, or IT audit.
- Foundational knowledge of security frameworks (PCI DSS, NIST CSF, ISO 27001, SOC 2).
- Experience supporting audits, security assessments, or control testing.
- Experience working with or exposure to GRC tools (e.g., MetricStream).
- Strong analytical skills with the ability to identify trends and summarize findings.
- Strong attention to detail and experience managing documentation and evidence.
Skills
- PCI DSS
- ISO 27001
- NIST CSF
- SOC 2
- GRC platforms
- MetricStream
Location
- Toronto (Hybrid)
Work Type
- Hybrid
Experience Level
- 2+ years
Education Level
- Bachelor’s degree in Information Security, IT, Risk Management, or related field.
- Industry certifications (e.g., Security+, CISA, CRISC Fundamentals, CISSP – Associate level).
Salary/Compensations
- $66,000 - $93,000
Benefits
- Total compensation may also include variable or discretionary incentive components, including but not limited to bonuses and commissions.
About the Company
- We’re the original Canadian fintech. Powering businesses—from the smallest micro-merchant to large enterprises—with the commerce solutions, expert knowledge and local support they need to reach their full potential.
- For 25 years and counting, we’re proud to be the partner Canadians rely on to kickstart their dreams online, expand to a brick-and-mortar space or find new ways to connect with customers in their community and beyond.
- From coast to coast to coast, Moneris is proudly powering Canadian commerce for businesses, big and small.
- Our success is rooted in the dedication of our team members, whose skills, talent, and passion make it all possible.
- We provide resources, opportunities and an inclusive environment that empower our people to drive their careers forward and, together, create a positive impact on Canadian businesses.
- Powering Canadian commerce. Empowering you.
- Moneris is proud to be recognized as a 5-Star DEI Employer, reflecting our commitment to creating an inclusive, welcoming workplace where everyone belongs.
Equal Opportunity
- We welcome and encourage applications from Indigenous peoples, people of colour, people with disabilities, people of all genders, sexual orientation and intersectional identities.
- All AI outputs are reviewed and validated by our recruitment team.
- We acknowledge that people from equity-deserving groups (including racialized individuals, women, gender diverse individuals, individuals with disabilities, neurodivergent individuals, members of 2SLGBTQIA+ communities and those born outside of Canada) are less likely to apply for jobs unless they feel they meet all the requirements posted.
- At Moneris, we believe candidates bring experience to their work in many ways. We encourage you to apply and share, in the application form, the transferrable experience you bring, and how this will support your success in this role.
