Analyst II, Security GRC

MonerisToronto, ON
CA$66,000 - CA$93,000Hybrid

About The Position

As an Analyst II, Governance, Risk & Compliance (GRC), you will support the Information Security team in maintaining compliance, managing risk, and strengthening Moneris’ security posture. This role offers exposure to industry-standard security frameworks including Payment Card Industry Data Security Standard (PCI DSS), National Institute of Standards and Technology Cybersecurity Framework (NIST CSF), ISO 27001, and SOC 2. You will contribute to control testing, audit readiness, and risk assessments in a regulated environment where compliance and data security are critical. Working alongside senior analysts, you’ll build hands-on experience with governance processes, third-party risk, and compliance tooling while supporting initiatives that directly impact enterprise security and operational resilience.

Requirements

  • 2+ years of experience in information security, compliance, risk management, or IT audit.
  • Foundational knowledge of security frameworks (PCI DSS, NIST CSF, ISO 27001, SOC 2).
  • Experience supporting audits, security assessments, or control testing.
  • Experience working with or exposure to GRC tools (e.g., MetricStream).
  • Strong analytical skills with the ability to identify trends and summarize findings.
  • Strong attention to detail and experience managing documentation and evidence.

Nice To Haves

  • Bachelor’s degree in Information Security, IT, Risk Management, or related field.
  • Industry certifications (e.g., Security+, CISA, CRISC Fundamentals, CISSP – Associate level).
  • Experience with third-party risk or vendor assessments.
  • Exposure to regulated industries (e.g., payments, financial services).

Responsibilities

  • Support administration and tracking of compliance controls across PCI DSS, ISO 27001, NIST CSF, and SOC 2.
  • Collect, validate, and maintain audit evidence for regulatory and internal assessments.
  • Assist in risk assessments, control testing, and remediation tracking.
  • Maintain and update security policies, standards, and control documentation.
  • Update and manage risk and compliance data within GRC platforms (e.g., MetricStream).
  • Support third-party and vendor risk assessments, including documentation and evidence review.
  • Prepare reports, metrics, and dashboards for stakeholders and leadership.
  • Participate in security awareness and compliance training initiatives.

Benefits

  • Total compensation may also include variable or discretionary incentive components, including but not limited to bonuses and commissions.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service