Payments Canada is at the forefront of the Canadian payment ecosystem. Our purpose is to make payments easier, smarter and safer for all Canadians. Every day we are working diligently to ensure your payments are cleared and settled. In 2025 alone, our systems cleared approximately $103 trillion or $411.9 billion every business day! If you are passionate about payments and want to help ensure that these financial transactions in Canada are carried out safely and securely, working with us is for you!
Who we are
We are a public purpose, non-profit organization situated at the center of Canada’s payment ecosystem. We own and operate payment systems that process hundreds of billions of dollars’ worth of payment transactions every business day. We convene ecosystem participants to discuss their multiple and diverse interests and ideas and to navigate industry-level challenges. We adhere to a set of values that are our north star:
Inspire trust, build community and enable change.
Payments Canada — where our country connects
Our culture
With our people in mind, we have created a culture that fosters authenticity, collaboration, innovation and development. We empower one another, make meaningful contributions that not only impact the organization, but our country! We develop and nurture meaningful connections that drive innovation in our ecosystem. We are Payments Canada!
Do you want to make payments easier, smarter and safer for Canada? Join us today!
You need to work here if
- You love working with passionate, ambitious and collaborative colleagues.
- You want to be challenged and lead unique initiatives.
- You want to grow, develop and become a subject matter expert in your field.
- You want your work to make an impact in your community and country.
Come and join us — where payments meet purpose!
What we are looking for
Reporting to the Manager, Security Compliance, this position carries out the day-to-day work of the Security Compliance function. Working from direction set by the Manager, the incumbent performs control assessments, gathers and documents evidence, keeps compliance trackers and registers current and prepares compliance reporting against internal mandates and external regulations. As a representative of the organization's security function, the incumbent helps promote a culture of security compliance among all employees and works day to day with colleagues across other Payments Canada divisions and with members and user groups as required.
Duties and Responsibilities of the Security Compliance Analyst will include but is not limited to:
Security Compliance
- Support the development of information security controls by drafting and documenting control statements against existing policies, standards, procedures, regulatory guidelines and security frameworks and routing them to stakeholders for feedback and approval.
- Carry out assessments and validation of security controls across Payments Canada, following the approach and scope set by the Manager, Security Compliance.
- Process and review Security Exception Requests, checking submissions for completeness, documenting the control gap and any compensating controls, and referring risk acceptance decisions to the Manager, Security Compliance.
- Promote day-to-day compliance with internal policies, standards and procedures, and with external regulatory requirements.
- Support security related audits (for example, ISO/IEC 27001 and the SWIFT CSP) by gathering evidence, preparing the requested documentation and responding to auditor questions within agreed timelines.
- Respond promptly to routine security compliance questions, and escalate those that call for a decision to the Manager, Security Compliance.
- Work with the other lines of defense= to support improvements in compliance maturity.
- Support Third-Party Risk Management by reviewing the security clauses, schedules and assurance evidence for third- and fourth-party engagements, working in support of and facilitated through Procurement, Vendor Management and the TPRM function; the vendor relationship and any direct engagement with the vendor are led by those functions.
- Prepare reports and slide decks covering control assessment results, key control indicators and key risk indicators, for the Manager's review ahead of management reporting.
Security Governance
- Support the Technology Governance function on information security policies and standards, checking that they line up with the security control framework and flagging any discrepancies.
- Provide supporting input to the Cyber Resiliency Framework where Security Compliance is asked to contribute, in line with the review cadence.
- From a compliance-review perspective, flag opportunities to improve the clarity of security policies and standards and route them to the Technology Governance owner for action.
Security Architecture and Support
- Take part in security assessments and reviews for the Security Architecture and Engineering Work Groups, checking new solutions and designs against the applicable security controls.
- Apply Secure by Design principles in the reviews completed, so that adequate security controls are considered during the design and architecture phases.
Security Information Improvement
- Suggest improvements to internal processes, reporting and documentation that support compliance.
- Track security assessment findings and improvement actions through to closure, following up with internal stakeholders and escalating delays.
- Provide support in the closure of security related audit findings, engaging with Internal Audit and the control owners to develop and document action plans, and tracking progress.
- Other tasks as assigned by the manager.
Technical Competencies
- Working understanding of information security principles, practices, technologies and procedures.
- Working understanding of information risk management methods and techniques for assessing risks, threats and vulnerabilities.
- Ability to weigh security controls against the risks they address, including the use of compensating controls.
- Knowledge of security control frameworks such as ISO/IEC 27001 and NIST CSF, and how they apply to the security governance and compliance practice.
- Awareness of industry security standards, laws and regulations (for example, ISO/IEC 27001, SWIFT CSP, PIPEDA and Bank of Canada oversight expectations).
- Security audit and findings management — tracking findings to closure with documented action plans and evidence, and supporting second- and third-line assessments and internal audits.
- Third-party and vendor risk management (TPRM) fundamentals, including reviewing vendor security assurance evidence and the security clauses and schedules in third-party contracts, in support of and facilitated through Procurement, Vendor Management and the TPRM function.
- Security architecture and SDLC compliance gating: assessing projects against the Enterprise Architecture Methodology and Secure by Design principles ahead of go-live.
Personal Competencies
- Energetic, self-motivated, quick to learn, and comfortable taking responsibility for assigned work.
- High degree of initiative and flexibility.
- Strong communication and organizational skills.
- Strong relationship management skills.
- Strong interpersonal and teamwork skills.
- Ability to work with colleagues in Procurement, Legal, GRC/TPRM, Privacy, TPRM and project teams, explaining security requirements clearly and following up to a workable outcome.
- Care and accuracy in preparing the material that supports responses to regulators (for example, the Bank of Canada), where inquiries and attestations carry firm external deadlines.
- Persistence in carrying contractual security requirements through successive review rounds, with support from the Manager where a position needs to be negotiated.
- Ability to stay organized and composed when demand is deadline-driven and unpredictable, managing a queue of competing commitments.
- Strong attention to detail when documenting exceptions, control gaps and the supporting evidence.
- Ownership of assigned work and the ability to deliver it reliably in a small team, adapting as responsibilities and priorities shift.
- Discretion and integrity in handling sensitive vendor, audit and regulatory information.
What you need to be successful
- Post-secondary degree or diploma in computer science or other field related to information systems and technology or information security management or equivalent work experience.
- A minimum of three (3) years of combined relevant work experience in an information security, IT audit or information risk management capacity.
Regular activities will have included control assessment, evidence gathering and compliance reporting.
- Sound organizational and time management skills, with the ability to deliver assigned work to agreed timelines.
- Ability to work with stakeholders across teams, take ownership of assigned work and follow it through to completion.
- Working knowledge of security frameworks such as ISO/IEC 27001, ISO/IEC 27002 and NIST, with general awareness of other industry security frameworks, regulations and standards.
- Practical exposure to cybersecurity compliance, audit support and risk management.
- Industry certifications, or demonstrated progress towards them, are considered an asset (CISA, CRISC, CISSP, CISM, etc.).
- Eligibility to successfully complete background checks that will be carried out by Payments Canada, including criminal, credit, identity, employment, and education checks.
- Clear written and verbal communication, with solid report writing skills.
You will really stand out with
The following are considered an asset, and can be developed in the role:
- Third-party assurance analysis: reviewing SOC 1 and SOC 2 (Type II) reports, exceptions and bridge letters, and validating Complementary User Entity Controls (CUECs) for critical service providers.
- Working knowledge of the SWIFT Customer Security Programme (CSP) and Customer Security Controls Framework (CSCF) — architecture types, mandatory and advisory controls, independent assessment and annual attestation.
- Familiarity with financial market infrastructure oversight, including the Bank of Canada's PFMI (Annex F) self-attestation reviews and cyber-resilience expectations for designated systems.
- Control-framework mapping and controls-library maintenance across ISO/IEC 27001, 27002, 27017/27018 (cloud), 27701 (privacy) and 42001 (AI), NIST CSF, CIS, COBIT and SOC 2.
- Working knowledge of privacy and data-protection obligations (PIPEDA), personal-information handling and cross-border data-flow considerations in vendor
Salary range
Our target starting rate for this role is $83,300 with flexibility based on your experience and qualifications. The full salary range and perks package are detailed below.
Please submit your application by September 11, 2026.
What's in it for you?
- Flexible, hybrid (remote/office) environment.
- Competitive compensation package, including annual variable bonus and defined contribution pension plan with employer matching percentage (if eligible).
- Comprehensive health and dental benefit coverage, including mental health coverage, life insurance and a health spending account for you and your dependents (Permanent and temporary employees with contracts 12 months and over).
- Paid time off: minimum four weeks paid vacation, sick and personal days, December holiday shutdown and cultural holiday observance days.
- 26 weeks of paid maternity and parental leave top-up (if eligible)
- Rewards and recognition program.
- Access to office gym facilities.
- Internal and external professional development opportunities.
- Fun team and organizational events.
- Monthly all staff forums led by our Executive Leadership Team.
Our Commitment to Fair Hiring
At Payments Canada, we are dedicated to fair, transparent and inclusive hiring. We are an equal opportunity employer and value diversity at our company. Our recruitment process uses automated tools, but not generative AI, to objectively screen and evaluate applications and confirm that a candidate’s qualifications meet job requirements.
It is important to remember that these tools support, but do not replace, human decision-making. Our trained recruitment professionals and hiring managers always make the final hiring decisions.
Our diversity, inclusion and equity commitment
At Payments Canada, we are committed to making everyone feel they can be themselves and thrive at work. We will continue to build on a foundation of respect and appreciation for diversity in all forms and collectively create an inclusive and equitable culture where our differences are valued.
We are committed to employment equity and actively encourage applications from women, Aboriginal people, persons with disabilities and visible minorities. If selected for an interview, please advise us if you require special accommodation by emailing
[email protected].
We thank all applicants for their interest in this opportunity. Preference will be given to Canadian citizens and permanent residents. Only selected candidates will be contacted for an interview.
📌 Security Compliance Analyst (Toronto)
🏢 Payments Canada
📍 Toronto