About the Role
Payments Canada is seeking a Security Compliance Analyst to support the Security Compliance function by performing control assessments, gathering evidence, maintaining compliance trackers, and preparing reports. This role promotes a culture of security compliance and collaborates with internal teams and external stakeholders.
Responsibilities
- Support the development of information security controls by drafting and documenting control statements against existing policies, standards, procedures, regulatory guidelines and security frameworks.
- Carry out assessments and validation of security controls across Payments Canada.
- Process and review Security Exception Requests, checking submissions for completeness, documenting control gaps and compensating controls.
- Promote day-to-day compliance with internal policies, standards and procedures, and with external regulatory requirements.
- Support security related audits (e.g., ISO/IEC 27001 and SWIFT CSP) by gathering evidence and preparing documentation.
- Respond promptly to routine security compliance questions and escalate complex issues.
- Work with other lines of defense to support improvements in compliance maturity.
- Support Third-Party Risk Management by reviewing security clauses and assurance evidence for third- and fourth-party engagements.
- Prepare reports and slide decks covering control assessment results, key control indicators and key risk indicators.
- Support the Technology Governance function on information security policies and standards.
- Provide supporting input to the Cyber Resiliency Framework.
- Flag opportunities to improve the clarity of security policies and standards.
- Take part in security assessments and reviews for the Security Architecture and Engineering Work Groups.
- Apply Secure by Design principles in reviews.
- Suggest improvements to internal processes, reporting and documentation that support compliance.
- Track security assessment findings and improvement actions through to closure.
- Provide support in the closure of security related audit findings.
- Perform other tasks as assigned by the manager.
Requirements
- Post-secondary degree or diploma in computer science or other field related to information systems and technology or information security management or equivalent work experience.
- A minimum of three (3) years of combined relevant work experience in an information security, IT audit or information risk management capacity.
- Regular activities will have included control assessment, evidence gathering and compliance reporting.
- Sound organizational and time management skills, with the ability to deliver assigned work to agreed timelines.
- Ability to work with stakeholders across teams, take ownership of assigned work and follow it through to completion.
- Working knowledge of security frameworks such as ISO/IEC 27001, ISO/IEC 27002 and NIST, with general awareness of other industry security frameworks, regulations and standards.
- Practical exposure to cybersecurity compliance, audit support and risk management.
- Eligibility to successfully complete background checks that will be carried out by Payments Canada, including criminal, credit, identity, employment, and education checks.
- Clear written and verbal communication, with solid report writing skills.
Skills
- Information security principles, practices, technologies and procedures
- Information risk management methods and techniques for assessing risks, threats and vulnerabilities
- Weighing security controls against risks, including compensating controls
- Security control frameworks (ISO/IEC 27001, NIST CSF)
- Industry security standards, laws and regulations (ISO/IEC 27001, SWIFT CSP, PIPEDA, Bank of Canada oversight expectations)
- Security audit and findings management
- Third-party and vendor risk management (TPRM) fundamentals
- Security architecture and SDLC compliance gating
- Energetic, self-motivated, quick to learn
- Comfortable taking responsibility for assigned work
- High degree of initiative and flexibility
- Strong communication and organizational skills
- Strong relationship management skills
- Strong interpersonal and teamwork skills
- Ability to work with colleagues in Procurement, Legal, GRC/TPRM, Privacy, TPRM and project teams
- Care and accuracy in preparing material for regulators
- Persistence in carrying contractual security requirements through review rounds
- Ability to stay organized and composed when demand is deadline-driven and unpredictable
- Strong attention to detail when documenting exceptions, control gaps and supporting evidence
- Ownership of assigned work and ability to deliver reliably
- Discretion and integrity in handling sensitive information
Location
- Hybrid (remote/office)
Work Type
- Hybrid
- Full-time
Experience Level
- Minimum of three (3) years of combined relevant work experience in an information security, IT audit or information risk management capacity.
Education Level
- Post-secondary degree or diploma in computer science or other field related to information systems and technology or information security management or equivalent work experience.
Salary/Compensations
- Target starting rate for this role is $83,300
Benefits
- Flexible, hybrid (remote/office) environment.
- Competitive compensation package, including annual variable bonus and defined contribution pension plan with employer matching percentage (if eligible).
- Comprehensive health and dental benefit coverage, including mental health coverage, life insurance and a health spending account for you and your dependents (Permanent and temporary employees with contracts 12 months and over).
- Paid time off: minimum four weeks paid vacation, sick and personal days, December holiday shutdown and cultural holiday observance days.
- 26 weeks of paid maternity and parental leave top-up (if eligible)
- Rewards and recognition program.
- Access to office gym facilities.
- Internal and external professional development opportunities.
- Fun team and organizational events.
- Monthly all staff forums led by our Executive Leadership Team.
About the Company
- Payments Canada is at the forefront of the Canadian payment ecosystem, making payments easier, smarter and safer for all Canadians.
- We own and operate payment systems that process hundreds of billions of dollars’ worth of payment transactions every business day.
- We are a public purpose, non-profit organization situated at the center of Canada’s payment ecosystem.
- We adhere to a set of values: Inspire trust, build community and enable change.
- Our culture fosters authenticity, collaboration, innovation and development.
- We empower one another, make meaningful contributions that not only impact the organization, but our country!
- We develop and nurture meaningful connections that drive innovation in our ecosystem.
Equal Opportunity
- At Payments Canada, we are dedicated to fair, transparent and inclusive hiring.
- We are an equal opportunity employer and value diversity at our company.
- Our recruitment process uses automated tools, but not generative AI, to objectively screen and evaluate applications and confirm that a candidate’s qualifications meet job requirements.
- Our trained recruitment professionals and hiring managers always make the final hiring decisions.
- We are committed to making everyone feel they can be themselves and thrive at work.
- We will continue to build on a foundation of respect and appreciation for diversity in all forms and collectively create an inclusive and equitable culture where our differences are valued.
- We are committed to employment equity and actively encourage applications from women, Aboriginal people, persons with disabilities and visible minorities.
- If selected for an interview, please advise us if you require special accommodation by emailing hrinfo@payments.ca.
- Preference will be given to Canadian citizens and permanent residents.
