
Senior Information Security Compliance Analyst
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Canada.
• Assist the organization in adhering to regulatory, statutory, contractual, and internal security obligations.
• Uphold information security policies, standards, and guidelines.
• Engage in audits and assessments to identify compliance deficiencies.
• Collaborate with the Legal team on necessary contract modifications to ensure compliance and manage risk.
• Take part in risk assessments and aid teams in addressing compliance issues.
• Monitor and handle risk exceptions with the necessary documentation and approvals.
• Support various audits, including internal, external, regulatory, client security, and third-party evaluations.
• Prepare and present evidence that demonstrates compliance.
• Oversee audit findings and the implementation of corrective actions.
• Facilitate management updates with ISO ISPMS Leads.
• Keep abreast of regulatory changes and industry developments.
• Suggest and execute enhancements to the compliance program.
• Assist in the management of security and compliance tools, processes, and frameworks.
• Contribute to risk mitigation through Threat Modeling outcomes and Post-Security Reviews.
• Maintain security operations documentation, such as Incident Response Plans, runbooks, Incident Management, and Business Continuity/Disaster Recovery plans.
• Coordinate and evaluate penetration testing results.
• Support the Information Security strategy and roadmap.
• Monitor and report on compliance with international regulations like the EU CRA and EU Radio Equipment Directive.
• Keep the organizational Risk Register updated.
• A Bachelor’s degree in Information Security, Computer Science, Information Technology, or a related discipline; or equivalent professional experience.
• Over 4 years of experience in information security, compliance, or similar positions.
• Experience in supporting compliance initiatives related to regulatory requirements and industry standards, including GDPR, HIPAA, ISO 27001, NIST, SOC 2, and PCI DSS.
• Fundamental understanding of risk assessment methodologies, control frameworks, and compliance obligations.
• Familiarity with compliance management tools and Governance, Risk, and Compliance (GRC) platforms.
• Skilled in assisting with audit preparation and remediation strategies.
• Knowledge of cloud security and third-party risk management.
• Comfortable utilizing AI tools to aid compliance efforts.
• Possession of relevant entry-level certifications, such as CompTIA Security+, ISACA CSX Fundamentals, CISA, CISM, or CISSP.
• Acquainted with EU and UK compliance regulations, laws, and frameworks.
• No travel is required.
• Candidates must be capable of performing daily responsibilities under general supervision while ensuring a high level of due diligence.
• Equal Opportunity Employer.
• Inclusive and accessible recruitment process.
• Reasonable accommodations available for candidates with disabilities or other physical or mental health conditions.
ALB Conciergerie
Meiks Affiliate Tipps
StanMindsetMomentum
LEARN Behavioral
Get handpicked remote jobs straight to your inbox weekly.