ISIT Risk and Compliance Specialist

Montreal, CA

Nestlé

Nestlé is the world's largest food & beverage company. We unlock the power of food to enhance quality of life for everyone, today and for generations to come.

View all jobs at Nestlé

Apply now Apply later

Position Snapshot
Business area: Nespresso Canada
Job title: IT Risk and Compliance Specialist 
Location: Montreal, QC located at 300 Léo-Pariseau, suite 2300 Montréal, QC Canada H2X 4B3
Hybrid

 

A little bit about us


Nestlé Nespresso SA is the pioneer and reference for highest-quality portioned coffee. The company works with more than 120,000 farmers in 15 countries through its AAA Sustainable Quality™ Program to embed sustainability practices on farms and the surrounding landscapes.  Launched in 2003 in collaboration with the NGO Rainforest Alliance, the program helps to improve the yield and quality of harvests, ensuring a sustainable supply of high-quality coffee and improving livelihoods of farmers and their communities. 

In 2022, Nespresso has achieved B Corp™ certification - joining an international movement of 4,900 purpose-led businesses that meet B Corp’s high standards of social and environmental responsibility and transparency.

Headquartered in Vevey, Switzerland, Nespresso operates in 81 countries and has over 13'000 employees. In 2021, it operated a global retail network of 802 boutiques. For more information, visit the Nespresso corporate website: www.nestle-nespresso.com

 

Position Summary
We are looking for an ISIT Risk and Compliance Specialist for Nespresso based at our Montreal office reporting into the IS/IT Manager.  This person is responsible for implementing (or coordinating implementation), coaching and supporting integrated risk, compliance and security management systems in accordance with the business risk appetite. The management systems enable the IS/IT teams globally to identify, document, measure and address its compliance requirements, including but not limited to data protection, privacy, 3rd party/vendor, information security and procurement. The Risk and Compliance Specialist responsibilities include ensuring the teams can drive all their risk, compliance and security requirements through the management system, ensuring compliant and secure products & platforms meeting the business risk appetite. 


A day in the life of a ISIT Risk and Compliance Specialist:

 

Responsible for implementing, coaching and reporting on Risk, Compliance & Security through the Nestlé Compliance and Information Security management system within IS/IT:

•    Supports risk identification and controls mapping for all solutions and processes in IS/IT teams using the Nestlé Security, Risk & Compliance framework and management system
•    Responsible for conducting system and reporting reviews to assess the IS/IT security compliance index
•    Supports teams in identifying and applying Internal and External (legal, regulatory and commercial) compliance requirements
•    Coaches and supports teams in managing Risk, Compliance & Security gaps through documented corrective & preventative actions, tracked through the management system
•    Advises on and promotes the importance of IS/IT related Risk, Compliance and Security outside the IS/IT community

 

Responsible for implementing and sustaining the tools and process for the Nestlé Compliance & Information Security Management System:

•    Support an integrated Risk, Compliance & Security Framework (including regulatory requirements such as PCI and GDPR)
•    Collaborates with Internal Control and IS/IT teams to ensure one source of truth through integration of reporting corrective & preventative actions and audit findings 

 

Supports the execution of IS/IT audit activities and requests:
•    Works with IS/IT teams and internal and external auditors, tracking and following up all IS/IT audits, internal review or regulatory findings as corrective & preventative actions through the management systems
•    Monitors and reports on progress and status of corrective & preventative actions in the management system to address compliance gaps.
•    Supports IS/IT teams in ensuring the required levels of documentation and evidence is available to support audit and regulatory requirements

 

Acts as partner to all IS/IT units for IS/IT compliance questions and advice:
•    Drives the development & roll out of the Risk, Compliance & Security competency framework for IS/IT team including the roll out and tracking of the awareness and behaviour training
•    Performs risk assessment according to agreed Risk & Compliance framework in collaboration with IS/IT teams
•    Oversee market's PCI compliance. Manages Attestation of Compliance process (AoC) and SAQs 
•    Coaches IS/IT teams on standards, policies, frameworks and regulatory requirements

 

What will make you successful?

 

•    3+ years of experience in a combination of risk management, compliance, information security and IS/IT jobs 
•    Bachelor degree in the field of computer science or IS/IT Security
•    Demonstrated ability to apply IS/IT-related knowledge and experience in solving compliance issues
•    Effective communication skills in both English and French, with the ability to engage at various organizational levels.
•    Experience working in a global environment with cross-functional teams
•    Independent, organized, strong collaborator, dynamic and a fast learner
•    Preferred certifications in industry-related compliance, risk, or security management (CRISC, CISM, CISSP)
•    Nice to have: Experience with ISMS certification, developing and submitting IS/IT audit and compliance reports, and knowledge of Archer.
•    Bilingualism in English and French language skills are a requirement, as this position requires collaboration with stakeholders across the Canadian market (and/or globally).

 

We have a friendly, supportive team with a coaching and mentoring environment. There are real opportunities for future development and progression – this really could be a move towards the exciting [functional area] career you’ve always wanted. 
 

Benefits

 

•    Comprehensive total rewards benefits package including Health and Dental benefits that start on day one of employment 
•    Company matched pension plan 
•    Flexible and hybrid work arrangements 
•    Excellent training and development programs as well as opportunities to grow within the company 
•    Access to Educational Assistance & Tuition Reimbursement 
•    Bonus eligibility 
•    Free Headspace Account – guidance to create habits to support your mental health 
•    Free Nespresso Coffee Machines and $100 monthly coffee credit 
•    Up to 50% off – Nespresso Coffee Machine, Capsules and accessories 
•    Access to the Discount Company store with Nestlé, Nespresso, and Purina products (Located across various Nestle offices/sites) 
•    Additional discounts on a variety of products and services offered by our preferred vendors and partnerships 

 

What you need to know


We will be considering applicants as they apply, so please don’t delay in submitting your application. 
 
Nestlé Canada is an equal-opportunity employer committed to diversity, equity, inclusion, and accessibility. We welcome qualified applicants to bring their diverse and unique experiences as a result of their education, perspectives, culture, ethnicity, race, sex, gender identity and expression, nation of origin, age, languages spoken, veteran’s status, colour, religion, disability, sexual orientation and beliefs.

If you are selected to participate in the recruitment process, please inform Human Resources of any accommodations you may require. Nestlé will work with you in an effort to ensure that you are able to fully participate in the process.


#LI-RH1
 

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0
Category: Compliance Jobs

Tags: Audits CISM CISSP Compliance Computer Science CRISC GDPR ISMS Privacy Risk assessment Risk management

Perks/benefits: Career development Equity / stock options Flex hours Health care Salary bonus Startup environment Transparency

Region: North America
Country: Canada

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.