ISIT Risk and Compliance Specialist

1 week ago


Montreal administrative region, Canada Nestlé Full time

Position Snapshot Business areas: Nespresso Canada Job title: ISIT Risk and Compliance Specialist Location: Montreal, QC located at 300 Léo-Pariseau, suite 2300 Montréal, QC Canada H2X 4B3 Compensation Range: $71,000 – $82,500 CAD Hybrid At Nestle Canada, we are committed to transparency and fairness in our compensation and job posting practices. This position offers a competitive salary within the range specified above, in compliance with Ontario's pay transparency regulations. A little bit about us Nestlé Nespresso SA is the pioneer and reference for highest-quality portioned coffee. The company works with more than 120,000 farmers in 15 countries through its AAA Sustainable Quality™ Program to embed sustainability practices on farms and the surrounding landscapes. Launched in 2003 in collaboration with the NGO Rainforest Alliance, the program helps to improve the yield and quality of harvests, ensuring a sustainable supply of high-quality coffee and improving livelihoods of farmers and their communities. In 2022, Nespresso has achieved B Corp™ certification - joining an international movement of 4,900 purpose-led businesses that meet B Corp’s high standards of social and environmental responsibility and transparency. Headquartered in Vevey, Switzerland, Nespresso operates in 81 countries and has over 13'000 employees. In 2021, it operated a global retail network of 802 boutiques. For more information, visit the Nespresso corporate website: www.nestle-nespresso.com Position Summary We are looking for an IS/IT Risk and Compliance Specialist to join Nespresso Canada at our Montreal office, reporting to the IS/IT Manager. In this role, you will support and coordinate the implementation of our integrated risk, compliance, and security management framework, aligned with the business’s risk appetite. You will help identify, document, measure, and address compliance requirements across key areas such as data protection, identity and access management, privacy, third‑party/vendor oversight, information security, and procurement. The Specialist ensures that teams can effectively manage all risk, compliance, and security obligations through our management system, contributing to the delivery of secure and compliant products and platforms. This position is an existing vacancy. A day in the life of a Risk and Compliance Specialist Responsible for implementing, coaching and reporting on Governance, Risk, Compliance & Security through the Nestlé Compliance and Information Security management system within IS/IT: Supports risk identification and controls mapping for all solutions and processes in IS/IT teams using the Nestlé Security, Risk & Compliance framework and management system Responsible for conducting system and reporting reviews to assess the IS/IT security compliance index Supports teams in identifying and applying Internal and External (legal, regulatory and commercial) compliance requirements Coaches and supports teams in managing Risk, Compliance & Security gaps through documented corrective & preventative actions, tracked through the management system Advises on and promotes the importance of IS/IT related Risk, Compliance and Security outside the IS/IT community Responsible for implementing and sustaining the tools and process for the Nestlé Compliance & Information Security Management System: Support an integrated Risk, Compliance & Security Framework (including regulatory requirements such as PCI and GDPR) Collaborates with Internal Control and IS/IT teams to ensure one source of truth through integration of reporting corrective & preventative actions and audit findings Supports the execution of IS/IT audit activities and requests: Works with IS/IT teams and internal and external auditors, tracking and following up all IS/IT audits, internal review or regulatory findings as corrective & preventative actions through the management systems Monitors and reports on progress and status of corrective & preventative actions in the management system to address compliance gaps. Supports IS/IT teams in ensuring the required levels of documentation and evidence is available to support audit and regulatory requirements Acts as a partner to all IS/IT units for IS/IT compliance questions and advice: Drives the development & roll out of the Risk, Compliance & Security competency framework for IS/IT team including the roll out and tracking of the awareness and behaviour training Performs risk assessment according to agreed Risk & Compliance framework in collaboration with IS/IT teams Oversee market's PCI compliance. Collaborates to manage the Attestation of Compliance process (AoC) and SAQs Coaches IS/IT teams on standards, policies, frameworks and regulatory requirements What will make you successful? 2+ years of experience in a combination of risk management, compliance, information security and IS/IT jobs Bachelor degree in the field of computer science or IS/IT Security Demonstrated ability to apply IS/IT-related knowledge and experience in solving compliance issues Effective communication skills in both English and French, with the ability to engage at various organizational levels. Experience working in a global environment with cross-functional teams Independent, organized, strong collaborator, dynamic and a fast learner Nice to have: certifications in industry-related compliance, risk, or security management (CRISC, CISM, CISSP) Nice to have: Experience with ISMS certification, developing and submitting IS/IT audit and compliance reports, and knowledge of Archer. Bilingualism in English and French language skills are a requirement, as this position requires collaboration with stakeholders across the Canadian market (and/or globally). We have a friendly, supportive team with a coaching and mentoring environment. There are real opportunities for future development and progression – this really could be a move towards the exciting functional area career you’ve always wanted. Benefits Comprehensive total rewards benefits package including Health and Dental benefits that start on day one of employment Company matched pension plan Three weeks of Vacation and six personal days (Personal Paid Holidays) Flexible and hybrid work arrangements Excellent training and development programs as well as opportunities to grow within the company Access to Educational Assistance & Tuition Reimbursement Bonus eligibility Free Headspace Account – guidance to create habits to support your mental health Free Nespresso Coffee Machines and $100 monthly coffee credit Up to 50% off – Nespresso Coffee Machine, Capsules and accessories Access to the Discount Company store with Nestlé, Nespresso, and Purina products (Located across various Nestle offices/sites) Additional discounts on a variety of products and services offered by our preferred vendors and partnerships What you need to know We will be considering applicants as they apply, so please don’t delay in submitting your application. Nestlé Canada is an equal-opportunity employer committed to diversity, equity, inclusion, and accessibility. We welcome qualified applicants to bring their diverse and unique experiences as a result of their education, perspectives, culture, ethnicity, race, sex, gender identity and expression, nation of origin, age, languages spoken, veteran’s status, colour, religion, disability, sexual orientation and beliefs. If you are selected to participate in the recruitment process, please inform Human Resources of any accommodations you may require. Nestlé will work with you in an effort to ensure that you are able to fully participate in the process. #J-18808-Ljbffr



  • Montreal (administrative region), Canada Nestlé Nespresso SA Full time

    Position SnapshotBusiness areas: Nespresso CanadaJob title: ISIT Risk and Compliance SpecialistLocation: Montreal, QC located at 300 Léo-Pariseau, suite 2300 Montréal, QC Canada H2X 4B3Compensation Range: $71,000 – $82,500 CADHybridAt Nestle Canada, we are committed to transparency and fairness in our compensation and job posting practices. This position...

  • IS/IT Risk

    1 week ago


    Montreal (administrative region), Canada Nestlé Full time

    An international coffee company in Montreal seeks an ISIT Risk and Compliance Specialist. This role requires collaboration on risk and compliance management. Candidates should have a bachelor's degree in computer science or IS/IT Security, with 2+ years in related fields and bilingual skills in English and French. The position offers a salary between $71,000...


  • Montreal (administrative region), Canada Canada Mortgage and Housing Corporation Full time

    A national housing agency in Toronto is seeking an IT Risk Specialist to join its Information & Technology Risk and Compliance team. You will assess and interpret data to manage risk, ensuring alignment with risk management frameworks. Candidates should possess a bachelor’s degree and a minimum of five years of experience in risk auditing or management....


  • Montreal (administrative region), Canada Canada Mortgage and Housing Corporation Full time

    A national housing agency in Toronto is seeking an IT Risk Specialist to join its Information & Technology Risk and Compliance team. You will assess and interpret data to manage risk, ensuring alignment with risk management frameworks. Candidates should possess a bachelor’s degree and a minimum of five years of experience in risk auditing or management....

  • IS/IT Risk

    2 minutes ago


    Montreal (administrative region), Canada Nestlé Nespresso SA Full time

    A leading coffee company in Montreal is seeking an IS/IT Risk and Compliance Specialist to join their team. In this role, you will ensure compliance with IS/IT-related regulations and manage risk across various teams. You will support the implementation of an integrated risk and compliance framework while actively participating in audit activities. The ideal...

  • Specialist, IT Risk

    3 weeks ago


    Montreal (administrative region), Canada Canada Mortgage and Housing Corporation Full time

    Select how often (in days) to receive an alert: Travel Requirement:Travel not required Language Skill Levels (Read/Write/Speak):ZZZ Security Requirement: Secret Salary:Our salaries generally range from $86816.59 to $108520.74 and are based on qualifications and experience. About CMHC The work you do and the work we do together matters. We come to work...

  • Specialist, IT Risk

    10 minutes ago


    Montreal (administrative region), Canada Canada Mortgage and Housing Corporation Full time

    Select how often (in days) to receive an alert: Travel Requirement:Travel not required Language Skill Levels (Read/Write/Speak):ZZZ Security Requirement: Secret Salary:Our salaries generally range from $86816.59 to $108520.74 and are based on qualifications and experience. About CMHC The work you do and the work we do together matters. We come to work every...

  • Model Risk Governance

    2 weeks ago


    Montreal (administrative region), Canada KYYBA Inc Full time

    A financial services provider based in Montreal is looking for a Model Risk Governance Specialist. You will ensure compliance with regulatory requirements and internal standards related to model risk management. Responsibilities include preparing reports, coordinating with model validators, and providing training on best practices. The ideal candidate holds...


  • Montreal (administrative region), Canada Infotree Global Solutions Full time

    A leading risk management firm in Montreal seeks a Model Risk Governance Specialist. The role involves ensuring compliance with model risk standards, preparing reports on model risk status, and providing guidance to stakeholders. Candidates should possess a degree in relevant fields and 3+ years of experience in model risk management, with strong analytical...


  • Montreal (administrative region), Canada Cynet Systems Inc Full time

    Job Description The Model Risk Governance Specialist ensures that the organization’s models meet regulatory and internal model risk management requirements. This role is responsible for maintaining accurate model and recommendation inventories, coordinating issue resolution with validation and implementation teams, and preparing regular model risk status...