Security Compliance Analyst (Toronto)

Security Compliance Analyst (Toronto)

25 Sep
|
Payments Canada
|
Toronto

25 Sep

Payments Canada

Toronto

Reporting to the Manager, Security Compliance, this position carries out the day-to-day work of the Security Compliance function. Working from direction set by the Manager, the incumbent performs control assessments, gathers and documents evidence, keeps compliance trackers and registers current and prepares compliance reporting against internal mandates and external regulations. As a representative of the organization's security function, the incumbent helps promote a culture of security compliance among all employees and works day to day with colleagues across other Payments Canada divisions and with members and user groups as required. Duties and Responsibilities of the Security Compliance Analyst will include but is not limited to: Security Compliance Support the development of information security controls by drafting and documenting control statements against existing policies, standards, procedures, regulatory guidelines and security frameworks and routing them to stakeholders for feedback and approval. Carry out assessments and validation of security controls across Payments Canada, following the approach and scope set by the Manager, Security Compliance. Process and review Security Exception Requests, checking submissions for completeness, documenting the control gap and any compensating controls, and referring risk acceptance decisions to the Manager, Security Compliance. Promote day-to-day compliance with internal policies, standards and procedures, and with external regulatory requirements. Support security related audits (for example, ISO/IEC 27001 and the SWIFT CSP) by gathering evidence,



preparing the requested documentation and responding to auditor questions within agreed timelines. Respond promptly to routine security compliance questions, and escalating those that call for a decision to the Manager, Security Compliance. Work with the other lines of defense= to support improvements in compliance maturity. Support Third-Party Risk Management by reviewing the security clauses, schedules and assurance evidence for third- and fourth-party engagements, working in support of and facilitated through Procurement, Vendor Management and the TPRM function; the vendor relationshipand any direct engagement with the vendor are led by those functions. Prepare reports and slide decks covering control assessment results, key control indicators and key risk indicators, for the Manager's review ahead of management reporting. Security Governance Support the Technology Governance function on information security policies and standards, checking that they line up with the security control framework and flagging any discrepancies. Provide supporting input to the Cyber Resiliency Framework where Security Compliance is asked to contribute, in line with the review cadence. From a compliance-review perspective,



flag opportunities to improve the clarity of security policies and standards and route them to the Technology Governance owner for action. Security Architecture and Support Take part in security assessments and reviews for the Security Architecture and Engineering Work Groups, checking recent solutions and designs against the applicable security controls. Apply Secure by Design principles in the reviews completed, so that adequate security controls are considered during the design and architecture phases. Security Information Improvement Suggest improvements to internal processes, reporting and documentation that support compliance. Track security assessment findings and improvement actions through to closure, following up with internal stakeholders and escalating delays. Provide support in the closure of security related audit findings, engaging with Internal Audit and the control owners to develop and document action plans, and tracking progress. Other tasks as assigned by the manager. Technical Competencies Working understanding of information security principles, practices, technologies and procedures. Working understanding of information risk management methods and techniques for assessing risks, threats and vulnerabilities. Ability to weigh security controls against the risks they address, including the use of compensating controls. Knowledge of security control frameworks such as ISO/IEC 27001 and NIST CSF, and how they apply to the security governance and compliance practice. Awareness of industry security standards, laws and regulations (for example, ISO/IEC 27001, SWIFT CSP, PIPEDA and

📌 Security Compliance Analyst (Toronto)
🏢 Payments Canada
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security compliance analyst (toronto) / toronto

Subscribe to this job alert:

Get the latest job offers by email for: security compliance analyst (toronto) / toronto