Description
The Security Analyst, Security Risk & Compliance will support Staples Canada’s PCI compliance program and broader cybersecurity risk activities. The role coordinates PCI and compliance tasks, gathers evidence, tracks remediation, supports security projects, and helps business teams understand PCI and cyber-risk requirements. Responsibilities include information security governance, risk assessments, enterprise and IT risk registers, compliance assurance across frameworks such as PCI DSS, SOC 2, ISO 27001, NIST CSF, and NIST 800-53, and third-party risk management. The position requires a diploma or degree in a relevant field and 2–4 years of experience in cybersecurity, IT risk, compliance, audit, or technology, with an office environment and possible limited travel and evening or weekend work.
