15 Aug
|
Experis
|
Ontario
Job Type: Permanent, Full-Time
Compensation: $70,000 - $100,000
About the Opportunity We're seeking an IT Risk & Compliance Analyst to join a growing technology risk and governance team. This role is ideal for a qualified with experience in IT risk management, compliance, IT audit, or cybersecurity governance who enjoys conducting risk assessments, evaluating IT controls, supporting audits, and partnering with stakeholders to strengthen enterprise risk management practices.
You will play a key role in helping ensure compliance with industry standards and regulatory requirements while contributing to a mature and evolving Governance, Risk, and Compliance (GRC) program.
Key Responsibilities Conduct IT risk assessments and document findings, recommendations, and mitigation plans.
Perform IT control design and effectiveness testing across technology environments.
Support internal and external audits, assessments, and compliance reviews.
Collect, review, and organize audit evidence and documentation.
Track remediation activities and monitor progress against action plans.
Assist with maintaining risk registers, risk profiles, key risk indicators (KRIs), and compliance dashboards.
Prepare reports and presentations for management on IT risk and compliance activities.
Participate in the development and maintenance of IT risk, compliance, and information security policies, standards, and frameworks.
Work closely with technology, security, audit, and business stakeholders to identify and mitigate risks.
Assist with compliance reviews of technology implementations, architecture designs, and operational processes.
Support ongoing governance and compliance initiatives across the organization.
Participate in activities such as firewall rule reviews, privileged access reviews, penetration testing coordination,
and data protection initiatives.
Required Qualifications 3+ years of experience in IT Risk, IT Compliance, IT Audit, Cybersecurity Governance, or a related field.
Hands-on experience conducting IT risk assessments and IT control testing.
Experience supporting internal and external audits, including evidence collection, review, and remediation tracking.
Working knowledge of industry frameworks and standards such as:
PCI DSS
ISO 27001 / ISO 27002
COBIT
SOC / Trust Services Criteria
Experience using Governance, Risk, and Compliance (GRC) platforms.
Strong analytical, organizational, and stakeholder management skills.
Post-secondary degree or diploma in Information Technology, Cybersecurity, Risk Management, Audit, or a related discipline.
Preferred Qualifications Experience within financial services, payments, banking, insurance, or other highly regulated industries.
Professional certifications such as:
CISA
CISM
CRISC
CISSP
CIA
CGEIT
Experience with:
Firewall rule reviews
Privileged access management reviews
Security risk reporting
Risk registers and dashboards
SSL certificate management
Coordination of internal and external penetration testing
Why Join Us? Competitive compensation and bonus program
Retirement and savings programs
Flexible hybrid work environment
Opportunities for professional development and certification growth
Collaborative and inclusive team culture
Exposure to enterprise-scale technology risk, compliance, and security initiatives
We are committed to creating an inclusive workplace and encourage applications from candidates of all backgrounds. Accommodations are available throughout the recruitment process upon request.
IT Risk & Compliance Analyst | Hybrid (Mississauga) | $70K-$100K + Bonus | IT Risk, IT Audit, GRC, PCI DSS, ISO 27001, COBIT
#J-18808-Ljbffr
📌 IT Risk and Compliance Analyst (Ontario)
🏢 Experis
📍 Ontario