Some of what you will do:
The Security Analyst, Security Risk & Compliance will support the management and continuous improvement of Staples Canada’s PCI compliance program and broader cybersecurity risk activities. This role will work closely with cybersecurity, technology, audit, and business stakeholders to coordinate PCI compliance tasks, gather evidence, track remediation activities, support security projects, and help business teams understand PCI and cyber-risk requirements.
Specifically, You Will:
Governance & Policy Management
Support the development, review, approval, communication, and refresh of information security and risk management policies.
Maintain policy repositories and assist with governance reporting, metrics, and committee materials.
Risk Management
Participate in enterprise and IT risk assessments, including risk identification, scoring, documentation, and mitigation tracking.
Support risk workshops, maintain risk registers, and follow up on remediation activities with business and technology teams.
Compliance & Assurance
Support compliance programs aligned to frameworks such as SOC 1/SOC 2, ISO/IEC 27001, PCI DSS, NIST CSF, and NIST 800-53.
Assist with audits, evidence collection, control testing, issue tracking, and security/compliance inquiries.
Third-Party Risk Management
Support vendor risk assessments, evidence reviews, issue tracking, and coordination with procurement, legal, and security teams.
Identify opportunities to improve GRC processes, documentation, tooling, and support GRC platform maintenance.
Physical Environment/Working Conditions:
Office environment.
- May require limited travel.
- May require evening and weekend work based on business requirements.
Some of what you need:
Diploma or degree in cybersecurity, IT, computer science, risk management, or a related field; equivalent experience may be considered.
2–4 years of experience in cybersecurity, IT risk, compliance, audit, or technology.
Experience supporting assessments, audits, control testing, compliance activities, and evidence collection.
Basic understanding of cybersecurity risk, compliance, and frameworks such as PCI DSS, NIST CSF, ISO 27001, SOC 2, or CIS Controls.
Strong documentation, analytical, communication, and stakeholder coordination skills.
Ability to track risks, issues, action items, remediation plans, and compliance evidence.
Experience with tools such as Microsoft Office, SharePoint, Teams, ServiceNow, Jira, or Confluence; retail, payment, PCI, or relevant certifications are assets.
Some of what you will get:
Associate discount
Health and Dental benefits
RRSP/DPSP
Performance bonuses
Learning & Development programs
And more…
About Us
Skills Required
- Diploma or degree in cybersecurity, IT, computer science, risk management, or related field (or equivalent experience)
- 2-4 years of experience in cybersecurity, IT risk, compliance, audit, or technology
- Experience supporting assessments, audits, control testing, compliance activities, and evidence collection
- Basic understanding of cybersecurity risk and frameworks (PCI DSS, NIST CSF, ISO 27001, SOC 2, CIS Controls)
- Strong documentation, analytical, communication, and stakeholder coordination skills
- Ability to track risks, issues, action items, remediation plans, and compliance evidence
- Experience with tools such as Microsoft Office, SharePoint, Teams, ServiceNow, Jira, or Confluence
- Retail, payment, PCI, or relevant certifications (assets)
Staples Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Staples and has not been reviewed or approved by Staples.
-
Wellbeing & Lifestyle Benefits — Wellbeing offerings are described as broad, including wellness reimbursements, emotional support and coaching, legal services, identity theft protection, and pet insurance. Employee discounts and select on-site amenities are also positioned as meaningful add-ons beyond basic coverage.
-
Leave & Time Off Breadth — Time-off provisions are presented as relatively expansive, including paid time off, company-recognized holidays, and a personal or flexible holiday option. Vacation that grows with tenure and PTO flexibility are highlighted as valued elements.
-
Inclusive Benefits Coverage — Healthcare benefits explicitly include gender-affirming care alongside medical, dental, and vision coverage. Family and caregiver programs also include support that references LGBTQ+ considerations and broader life-stage needs.
Staples Insights
What We Do
For nearly 40 years, Staples has been a trusted leader in delivering end-to-end workplace solutions for consumers and businesses of all sizes across a broad range of industries. The company provides a comprehensive portfolio of products, strategic solutions, and services including print and marketing, shipping, technology, and travel. Its specialized assortment includes high-quality office supplies, janitorial products, technology, furniture, and breakroom essentials, all supported by best-in-class supply chain capabilities and a dedicated team of experts committed to making the workday easier. Headquartered near Boston, Massachusetts, Staples operates throughout North America via direct B2B sales, e-commerce, and more than 900 retail stores. To learn more, visit your local U.S. Staples store, download the Staples app, explore Staples.com or StaplesBusiness.com, or follow @Staples on social media.
.png)







