Jobs.ca
Jobs.ca
Language
CareRx logo

Senior Cybersecurity GRC Analyst

CareRxabout 20 hours ago
Hybrid
Toronto, Ontario, Canada
Senior Level
Full-Time

Top Benefits

Medical coverage
Dental coverage
Flexible benefits

About the role

CareRx is looking for an experienced Senior Cybersecurity Governance &

Compliance Analyst for a 3 month contract, reporting to the Director, Cybersecurity, to join our team in a highly regulated healthcare environment where protecting sensitive patient and prescription data is critical to our mission. As a senior member of the Cybersecurity team, you will support CareRx's cybersecurity governance program through PCI DSS readiness, enterprise risk management, policy development, and compliance initiatives that strengthen the organization's overall cybersecurity posture. Working closely with business and technology stakeholders, you will help mature CareRx's governance and compliance capabilities.

You should be able to work in a fast-paced and collaborative environment, with

the ability to be nimble, multi-task, and problem solve. You take initiative, excel at strategic planning, and can handle multiple initiatives in parallel.

The role is expected to grow in scope and responsibility as the cybersecurity

program continues to mature, with measurable impact across risk reduction, detection quality, and incident readiness.

Why you should join CareRx

Collaborative Team: Work with colleagues who share a passion for shaping the

future of senior care.  

Make a Real Impact: Feel fulfilled knowing your work directly benefits others

within the communities we serve.  

Flexible Benefits: For eligible roles, enjoy flexible medical and dental

coverage that fits your needs.  

Defined Work Schedule: Offers a healthy work-life balance with predictable

hours.  

Focus on Care: Work in an environment where your clinical expertise takes

priority without the demands of retail pharmacy.  

Supportive Culture: Be part of a respectful, inclusive workplace where

collaboration, connection and shared purpose drive everything we do.  

Stability and Growth: Join a well-established Canadian company with a strong

foundation for job security and opportunities to grow your career.  

Appreciation in Action: We recognize great work through peer-nominated awards, team shout-outs and everyday moments of appreciation.  

Celebrations and Community: From cultural events to team socials and holiday

fun, we make time to connect, celebrate and enjoy the moments that bring us together.  

Role Accountabilities

  • Lead activities supporting CareRx's PCI DSS readiness program by assessing business processes, documenting control gaps, and developing risk-based remediation recommendations.
  • Assess payment workflows, security controls, supporting documentation, and operational processes to identify PCI DSS compliance gaps and opportunities for improvement.
  • Partner with business and technology stakeholders to document current-state processes, validate requirements, and support PCI DSS readiness initiatives.
  • Develop executive and business level reports on remediation recommendations to support PCI DSS readiness initiatives.
  • Develop practical, risk-based remediation recommendations and work with stakeholders to prioritize activities that improve PCI DSS readiness and overall cybersecurity maturity.
  • Monitor remediation initiatives and provide regular reporting on compliance progress, cybersecurity risks, and outstanding actions.
  • Develop, maintain, and continuously improve the enterprise cybersecurity risk register by identifying, documenting, assessing, and tracking cybersecurity risks.
  • Conduct cybersecurity risk assessments and collaborate with stakeholders to evaluate organizational risk and recommend practical mitigation strategies.
  • Develop and maintain cybersecurity policies, standards, procedures, and governance documentation aligned with industry best practices and regulatory requirements.
  • Monitor compliance with cybersecurity policies, standards, and applicable regulatory requirements.
  • Support internal and external compliance activities through evidence collection, documentation, control validation, and remediation tracking.
  • Support third-party risk management activities, including vendor security assessments, security due diligence, and remediation tracking.
  • Develop governance metrics, Key Performance Indicators (KPIs), and Key Risk Indicators (KRIs) to measure program effectiveness and support executive reporting.
  • Participate in cybersecurity assessments, governance reviews, and continuous improvement initiatives.
  • Stay current on emerging cybersecurity threats, governance frameworks, regulatory requirements, and industry best practices.
  • Perform other related duties as assigned.

What you will bring to the team

  • 5+ years of professional experience in cybersecurity governance, risk management, cybersecurity compliance, PCI Readiness or a related cybersecurity discipline.
  • Demonstrated experience supporting PCI DSS assessments, gap analyses, remediation planning, control assessments, or readiness initiatives.
  • Experience assessing business processes, documenting workflows, identifying control gaps, and developing remediation recommendations.
  • Experience working with cross-functional stakeholders to document, propose solutions to and address control and compliance gaps.
  • Experience conducting cybersecurity risk assessments and developing and maintaining enterprise cybersecurity risk registers.
  • Strong understanding of cybersecurity governance frameworks, including the NIST Cybersecurity Framework (CSF), ISO/IEC 27001, CIS Critical Security Controls (CIS Controls), and COBIT.
  • Experience developing cybersecurity policies, standards, procedures, and governance documentation.
  • Experience using Governance, Risk, and Compliance (GRC) platforms.
  • Strong analytical and problem-solving skills with the ability to assess risk, prioritize remediation activities, and communicate recommendations effectively.
  • Excellent written, presentation, and verbal communication skills with the ability to communicate effectively with technical and non-technical stakeholders.

Nice to Have

  • Experience within healthcare, pharmacy, or another regulated industry.
  • Knowledge of Canadian privacy legislation, including PIPEDA, and experience supporting regulatory compliance programs.
  • Relevant security certifications such as PCIP, CISSP, CISM, GRISC, CGRC, and ISO/IEC 27001

Compensation Range: 105,000.00 – 115,000.00

Location:  This is a hybrid role out of our 320 Bay Street location for a 3

month contract

Opportunity: This is a current existing position

AI Disclosure: CareRx does not use AI to screen candidates

Application Process

CareRx is committed to employment equity and a diverse, inclusive workplace

where everyone can thrive. We welcome applicants of all abilities and will provide accommodations upon request throughout the selection process.  

All applicants must successfully pass satisfactory background screening which

can include depending on role, Criminal Record Check, Credit Check, Driver’s Abstract, Education Verification, Current Professional Registration and Referencing.

About CareRx

Hospitals and Health Care
1001-5000
Founded in 2001

CareRx Corporation is Canada's leading provider of specialty pharmacy services to seniors. We serve long-term care homes, retirement homes, assisted living facilities, and group homes. We are a national organization with a large network of pharmacy fulfillment centres strategically located across the country. This allows us to deliver medications in a timely and cost-effective manner and quickly respond to routine changes in medication management.

We take an active role in working with our home operator partners to promote resident health, staff education, and medication system quality and efficiency.

Similar Jobs