Job Specifications
Position Snapshot
Business areas: Nespresso Canada
Job title: ISIT Risk and Compliance Specialist
Location: Montreal, QC located at 300 Léo-Pariseau, suite 2300 Montréal, QC Canada H2X 4B3
Compensation Range: $71,000 – $82,500 CAD
Hybrid
At Nestle Canada, we are committed to transparency and fairness in our compensation and job posting practices. This position offers a competitive salary within the range specified above, in compliance with Ontario's pay transparency regulations.
A Little Bit About Us
Nestlé Nespresso SA is the pioneer and reference for highest-quality portioned coffee. The company works with more than 120,000 farmers in 15 countries through its AAA Sustainable Quality™ Program to embed sustainability practices on farms and the surrounding landscapes. Launched in 2003 in collaboration with the NGO Rainforest Alliance, the program helps to improve the yield and quality of harvests, ensuring a sustainable supply of high-quality coffee and improving livelihoods of farmers and their communities.
In 2022, Nespresso has achieved B Corp™ certification - joining an international movement of 4,900 purpose-led businesses that meet B Corp’s high standards of social and environmental responsibility and transparency.
Headquartered in Vevey, Switzerland, Nespresso operates in 81 countries and has over 13'000 employees. In 2021, it operated a global retail network of 802 boutiques. For more information, visit the Nespresso corporate website: www.nestle-nespresso.com
Position Summary
We are looking for an IS/IT Risk and Compliance Specialist to join Nespresso Canada at our Montreal office, reporting to the IS/IT Manager. In this role, you will support and coordinate the implementation of our integrated risk, compliance, and security management framework, aligned with the business’s risk appetite. You will help identify, document, measure, and address compliance requirements across key areas such as data protection, identity and access management, privacy, third‑party/vendor oversight, information security, and procurement. The Specialist ensures that teams can effectively manage all risk, compliance, and security obligations through our management system, contributing to the delivery of secure and compliant products and platforms. This position is an existing vacancy.
A day in the life of a Risk and Compliance Specialist:
Responsible for implementing, coaching and reporting on Governance, Risk, Compliance & Security through the Nestlé Compliance and Information Security management system within IS/IT:
Supports risk identification and controls mapping for all solutions and processes in IS/IT teams using the Nestlé Security, Risk & Compliance framework and management system
Responsible for conducting system and reporting reviews to assess the IS/IT security compliance index
Supports teams in identifying and applying Internal and External (legal, regulatory and commercial) compliance requirements
Coaches and supports teams in managing Risk, Compliance & Security gaps through documented corrective & preventative actions, tracked through the management system
Advises on and promotes the importance of IS/IT related Risk, Compliance and Security outside the IS/IT community
Responsible for implementing and sustaining the tools and process for the Nestlé Compliance & Information Security Management System:
Support an integrated Risk, Compliance & Security Framework (including regulatory requirements such as PCI and GDPR)
Collaborates with Internal Control and IS/IT teams to ensure one source of truth through integration of reporting corrective & preventative actions and audit findings
Supports the execution of IS/IT audit activities and requests:
Works with IS/IT teams and internal and external auditors, tracking and following up all IS/IT audits, internal review or regulatory findings as corrective & preventative actions through the management systems
Monitors and reports on progress and status of corrective & preventative actions in the management system to address compliance gaps.
Supports IS/IT teams in ensuring the required levels of documentation and evidence is available to support audit and regulatory requirements
Acts as a partner to all IS/IT units for IS/IT compliance questions and advice:
Drives the development & roll out of the Risk, Compliance & Security competency framework for IS/IT team including the roll out and tracking of the awareness and behaviour training
Performs risk assessment according to agreed Risk & Compliance framework in collaboration with IS/IT teams
Oversee market's PCI compliance. Collaborates to manage the Attestation of Compliance process (AoC) and SAQs
Coaches IS/IT teams on standards, policies, frameworks and regulatory requirements
What will make you successful?
2+ years of experience in a combination of risk management, compliance, information security and IS/IT jobs
Bachelor degree in the field of computer science or IS/IT Security
Demonstrated ability
About the Company
Coffee is at the heart of everything we do, and consumer satisfaction is why we do it.
Our story started with one simple idea: everyone should be able to make the perfect cup of coffee at home. Something we still believe today, which is why we think delivering the highest quality coffee, sip after sip, is so important.
To achieve this, we continuously strive for innovation. Our coffee experts look for the world’s most exclusive coffees, and create new and exciting blends through a very strict coffee selection process. We...
Know more