Coca-Cola Canada Bottling Limited

Cybersecurity Analyst – Governance, Risk and Compliance

Coca-Cola Canada Bottling Limited

full-time

Posted on:

Origin:  • 🇨🇦 Canada

Visit company website
AI Apply
Manual Apply

Job Level

Mid-LevelSenior

Tech Stack

Cyber Security

About the role

  • Assist in the development, implementation, and maintenance of cybersecurity policies, standards, and controls
  • Lead and support third-party risk assessments, vendor onboarding reviews, and due diligence activities
  • Collaborate with procurement and legal to evaluate vendor risk and mitigation plans
  • Conduct and track internal risk assessments and audits of cybersecurity controls
  • Support the oversight and governance of Data Loss Prevention (DLP) policies and exceptions in coordination with SOC and IT teams
  • Manage and execute the cybersecurity awareness program, including training content, phishing simulations, and employee engagement campaigns
  • Monitor compliance with internal policies and regulatory standards (e.g., PCI-DSS, NIST)
  • Maintain documentation such as risk registers, audit logs, policy repositories, and exception records
  • Track and report GRC performance metrics and risk indicators to stakeholders
  • Research new and evolving compliance regulations and best practices, and contribute to policy updates accordingly

Requirements

  • Degree in a relevant field such as cybersecurity, information systems, or risk management
  • Certifications such as CISM, CRISC, CISSP, ISO 27001 Lead Implementer, or Security+ considered assets
  • 3–5 years of experience in cybersecurity, with demonstrated knowledge in GRC, TPRM, or audit functions
  • Experience with third-party risk management tools, frameworks, and processes
  • Familiarity with DLP tools and governance (e.g., Microsoft Purview, Forcepoint, Symantec)
  • Experience managing or supporting cybersecurity awareness initiatives
  • Understanding of security frameworks such as NIST CSF, ISO 27001, and CIS Controls
  • Strong analytical and organizational skills; capable of managing multiple priorities
  • Excellent written and verbal communication skills with the ability to engage technical and non-technical audiences