×
Register Here to Apply for Jobs or Post Jobs. X

IT Security Governance & Compliance Specialist

Job in Toronto, Ontario, C6A, Canada
Listing for: YM Inc
Full Time position
Listed on 2026-08-08
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 65000 - 75000 CAD Yearly CAD 65000.00 75000.00 YEAR
Job Description & How to Apply Below

Pay:CA $65,000.00 – CA $75,000.00 per year

Job description:

YM Inc. was founded on the strength of a single retail store in the heart of downtown Toronto in 1975, under the name Stitches. Today we are one of North America’s leading apparel retailers operating over 700 stores across Canada and the United States under the following banners:
Stitches, Urban Planet, Urban Behavior, Sirens, Forever 21, Urban Kids, Suzy Shier, Bluenotes, West 49, Amnesia, Charlotte Russe, Rue 21 and Mandee.

Our goal is to sustain performance that exceeds expectations. We are committed to creating a culture where people feel valued and inspired to achieve results. We give our people the appropriate tools, freedom and authority to make decisions. They are accountable for their actions and we recognize their efforts and reward their results. We attract and nurture the best people by providing leadership opportunities, career development and continuous learning.

We are committed to leading by example and with integrity. We treat people with respect and dignity, promote the benefits of diversity and address challenges in a direct and compassionate manner. We engage people in our goals and objectives; we listen and act on new ideas where possible. That is our Philosophy.

Role Overview

The
IT Security Governance & Compliance Specialist
is responsible for
governing, coordinating, and overseeing YM’s information security program
, ensuring that security risks are identified, documented, mitigated, and communicated effectively across the organization.

This role is
not a hands‑on technical implementation role
. Instead, it serves as the
central authority for IT security governance
, working with internal technical teams and external vendors to ensure security controls are defined, approved, enforced, documented, and continuously improved.

The role acts as the
primary interface for security vendors, audits, compliance efforts, risk management activities, and security incident coordination
, while ensuring policies, procedures, and awareness programs are consistently maintained and applied.

Key Responsibilities

1. Security Governance & Policy Management

  • Develop, maintain, and periodically update all IT security policies, standards, and guidelines.
  • Ensure policies align with organizational risk tolerance, business requirements, and regulatory obligations.
  • Translate technical security requirements into clear, business‑understandable policies.
  • Present and explain security policies and risk posture to management as required.

2. Risk Management & Exception Tracking

  • Conduct and document IT security risk assessments across infrastructure, applications, and business processes.
  • Maintain a centralized Risk Register, including:
  • Accepted risks (e.g., EOL servers/applications required for business reasons)
  • Risk owners
  • Expiry/review dates
  • Document and track compensating controls for each accepted risk.
  • Manage risk exception requests, approvals, and renewals, ensuring formal sign‑off by leadership.

3. PCI & Compliance Oversight (Control Gap)

  • Own PCI compliance end‑to‑end from a governance and coordination perspective.
  • Coordinate with Control Gap to:
  • Schedule and facilitate tabletop exercises and assessments
  • Collect and organize audit evidence
  • Review, validate, and challenge findings where appropriate
  • Track remediation items and ensure issues are driven to closure with responsible teams.
  • Act as the primary point of contact for PCI‑related audits and compliance activities.

4. SOC & Threat Monitoring Oversight (LCM / FortiSIEM)

  • Serve as the primary liaison with the SOC vendor (LCM).
  • Review security alerts, incident reports, and threat notifications.
  • Actively respond to SOC tickets/emails by:
  • Reviewing severity and impact
  • Validating false positives
  • Approving or coordinating response actions
  • Ensure SOC recommendations are reviewed, approved, and implemented by the appropriate IT teams.
  • Own escalation of security incidents to server, network, DBA, POS, and other technical teams.

5. Security Incident Coordination

  • Act as the first point of coordination for security incidents (non‑technical).
  • Coordinate incident response activities across internal teams and vendors.
  • Ensure incidents are properly…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary