CareRx Corporation

Senior Cybersecurity GRC Analyst

CareRx Corporation · Toronto, Ontario, Canada · CA$105K–CA$115K/yr

Hospitals and Health Care · 1,001-5,000 employees

4 h ago
Senior (5-10 yrs) Full-time Canada
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Senior Cybersecurity GRC Analyst will lead PCI DSS readiness initiatives and manage the enterprise cybersecurity risk register. They will also develop cybersecurity policies, conduct risk assessments, and provide executive reporting on compliance and risk mitigation.

What they look for

Cybersecurity governance Risk management PCI DSS Compliance Policy development Enterprise risk management NIST CSF ISO/IEC 27001 CIS Controls COBIT GRC platforms Vendor security assessments Gap analysis Remediation planning Strategic planning Stakeholder management

Requirements

Candidates must have 5+ years of experience in cybersecurity governance, risk management, and compliance, with specific expertise in PCI DSS. Strong analytical skills and proficiency in frameworks like NIST, ISO 27001, and CIS are required to effectively communicate with stakeholders.

Benefits

Medical coverage Dental coverage Flexible benefits Work-life balance Professional development

Full description

CareRx is looking for an experienced Senior Cybersecurity Governance & Compliance Analyst for a 3 month contract, reporting to the Director, Cybersecurity, to join our team in a highly regulated healthcare environment where protecting sensitive patient and prescription data is critical to our mission. As a senior member of the Cybersecurity team, you will support CareRx's cybersecurity governance program through PCI DSS readiness, enterprise risk management, policy development, and compliance initiatives that strengthen the organization's overall cybersecurity posture. Working closely with business and technology stakeholders, you will help mature CareRx's governance and compliance capabilities.

You should be able to work in a fast-paced and collaborative environment, with the ability to be nimble, multi-task, and problem solve. You take initiative, excel at strategic planning, and can handle multiple initiatives in parallel. The role is expected to grow in scope and responsibility as the cybersecurity program continues to mature, with measurable impact across risk reduction, detection quality, and incident readiness.

Why you should join CareRx 

Collaborative Team: Work with colleagues who share a passion for shaping the future of senior care. 

Make a Real Impact: Feel fulfilled knowing your work directly benefits others within the communities we serve. 

Flexible Benefits: For eligible roles, enjoy flexible medical and dental coverage that fits your needs. 

Defined Work Schedule: Offers a healthy work-life balance with predictable hours. 

Focus on Care: Work in an environment where your clinical expertise takes priority without the demands of retail pharmacy. 

Supportive Culture: Be part of a respectful, inclusive workplace where collaboration, connection and shared purpose drive everything we do. 

Stability and Growth: Join a well-established Canadian company with a strong foundation for job security and opportunities to grow your career. 

Appreciation in Action: We recognize great work through peer-nominated awards, team shout-outs and everyday moments of appreciation. 

Celebrations and Community: From cultural events to team socials and holiday fun, we make time to connect, celebrate and enjoy the moments that bring us together. 

Role Accountabilities:

  • Lead activities supporting CareRx's PCI DSS readiness program by assessing business processes, documenting control gaps, and developing risk-based remediation recommendations.
  • Assess payment workflows, security controls, supporting documentation, and operational processes to identify PCI DSS compliance gaps and opportunities for improvement.
  • Partner with business and technology stakeholders to document current-state processes, validate requirements, and support PCI DSS readiness initiatives.
  • Develop executive and business level reports on remediation recommendations to support PCI DSS readiness initiatives.
  • Develop practical, risk-based remediation recommendations and work with stakeholders to prioritize activities that improve PCI DSS readiness and overall cybersecurity maturity.
  • Monitor remediation initiatives and provide regular reporting on compliance progress, cybersecurity risks, and outstanding actions.
  • Develop, maintain, and continuously improve the enterprise cybersecurity risk register by identifying, documenting, assessing, and tracking cybersecurity risks.
  • Conduct cybersecurity risk assessments and collaborate with stakeholders to evaluate organizational risk and recommend practical mitigation strategies.
  • Develop and maintain cybersecurity policies, standards, procedures, and governance documentation aligned with industry best practices and regulatory requirements.
  • Monitor compliance with cybersecurity policies, standards, and applicable regulatory requirements.
  • Support internal and external compliance activities through evidence collection, documentation, control validation, and remediation tracking.
  • Support third-party risk management activities, including vendor security assessments, security due diligence, and remediation tracking.
  • Develop governance metrics, Key Performance Indicators (KPIs), and Key Risk Indicators (KRIs) to measure program effectiveness and support executive reporting.
  • Participate in cybersecurity assessments, governance reviews, and continuous improvement initiatives.
  • Stay current on emerging cybersecurity threats, governance frameworks, regulatory requirements, and industry best practices.
  • Perform other related duties as assigned.

What you will bring to the team:

  • 5+ years of professional experience in cybersecurity governance, risk management, cybersecurity compliance, PCI Readiness or a related cybersecurity discipline.
  • Demonstrated experience supporting PCI DSS assessments, gap analyses, remediation planning, control assessments, or readiness initiatives.
  • Experience assessing business processes, documenting workflows, identifying control gaps, and developing remediation recommendations.
  • Experience working with cross-functional stakeholders to document, propose solutions to and address control and compliance gaps.
  • Experience conducting cybersecurity risk assessments and developing and maintaining enterprise cybersecurity risk registers.
  • Strong understanding of cybersecurity governance frameworks, including the NIST Cybersecurity Framework (CSF), ISO/IEC 27001, CIS Critical Security Controls (CIS Controls), and COBIT.
  • Experience developing cybersecurity policies, standards, procedures, and governance documentation.
  • Experience using Governance, Risk, and Compliance (GRC) platforms.
  • Strong analytical and problem-solving skills with the ability to assess risk, prioritize remediation activities, and communicate recommendations effectively.
  • Excellent written, presentation, and verbal communication skills with the ability to communicate effectively with technical and non-technical stakeholders.

Nice to Have:

  • Experience within healthcare, pharmacy, or another regulated industry.
  • Knowledge of Canadian privacy legislation, including PIPEDA, and experience supporting regulatory compliance programs.
  • Relevant security certifications such as PCIP, CISSP, CISM, GRISC, CGRC, and ISO/IEC 27001

Compensation Range: 105,000.00 – 115,000.00

Location: This is a hybrid role out of our 320 Bay Street location for a 3 month contract

Opportunity: This is a current existing position 

AI Disclosure: CareRx does not use AI to screen candidates 

Application Process 

CareRx is committed to employment equity and a diverse, inclusive workplace where everyone can thrive. We welcome applicants of all abilities and will provide accommodations upon request throughout the selection process. 

All applicants must successfully pass satisfactory background screening which can include depending on role, Criminal Record Check, Credit Check, Driver’s Abstract, Education Verification, Current Professional Registration and Referencing.