The Lead IT Compliance Analyst will oversee compliance with regulatory standards, lead PCI DSS efforts, and guide internal control assessments.
Role
The Information Security Team is looking for a Lead IT Compliance Analyst to join the IT Compliance Team. The Lead IT Compliance Analyst will help support Morningstar Information Security's compliance responsibilities around regulatory compliance and PCI DSS. This individual will help Morningstar meet current and future compliance obligations, assist in identifying and following up on information security findings, gather evidence required for internal and external regulatory audits.
Responsibilities
Requirements
Nice To Have
Morningstar's hybrid work environment gives you the opportunity to work remotely and collaborate in-person each week. We've found that we're at our best when we're purposely together on a regular basis, at least three days each week. A range of other benefits are also available to enhance flexibility as needs change. No matter where you are, you'll have tools and resources to engage meaningfully with your global colleagues.
100_MstarResCanad Morningstar Research, Inc. (Canada) Legal Entity
The Information Security Team is looking for a Lead IT Compliance Analyst to join the IT Compliance Team. The Lead IT Compliance Analyst will help support Morningstar Information Security's compliance responsibilities around regulatory compliance and PCI DSS. This individual will help Morningstar meet current and future compliance obligations, assist in identifying and following up on information security findings, gather evidence required for internal and external regulatory audits.
Responsibilities
- Lead the Information Security Team's efforts in the field of regulatory compliance and serve as the internal Subject Matter Expert (SME) for regulatory compliance assessments.
- Oversee and guide efforts to ensure the information security program's compliance with regulatory standards and guidelines issued by the SEC, ESMA, and other applicable regulators.
- Serve as the main point of contact for information security regulatory compliance, facilitating communication between compliance teams and other internal stakeholders.
- Collaborate with relevant teams to remediate gaps and deficiencies identified during regulatory gap assessments or audits.
- Communicate compliance program results, including assessment status, workflow, remediation, and reporting, to a broad audience including peers, seniors, and leaders.
- Lead PCI DSS compliance efforts, ensuring that all relevant systems and processes meet or exceed the required standards.
- Collaborate with cross-functional teams to identify, implement, and monitor controls to maintain PCI DSS compliance.
- Lead the internal control assessments run by the team, including conducting assessments, identifying efficiency improvements, and proposing enhancements to strengthen the internal control monitoring program.
Requirements
- A bachelor's degree and 5+ years' experience in an IT Compliance position.
- Experience conducting PCI-DSS assessments.
- Ability to conduct internal regulatory audit readiness assessments.
- Familiarity with regulatory frameworks and guidelines issued by SEC and ESMA.
- Strong interpersonal skills to interact with compliance personnel, senior leadership, and other team members.
- Excellent oral and written communication skills.
- Strong organizational skills to prioritize work and balance multiple projects.
- Ability to work independently and as part of a broader team.
Nice To Have
- Experience working in a legal or regulatory compliance role.
Morningstar's hybrid work environment gives you the opportunity to work remotely and collaborate in-person each week. We've found that we're at our best when we're purposely together on a regular basis, at least three days each week. A range of other benefits are also available to enhance flexibility as needs change. No matter where you are, you'll have tools and resources to engage meaningfully with your global colleagues.
100_MstarResCanad Morningstar Research, Inc. (Canada) Legal Entity
Top Skills
Esma Guidelines
Pci Dss
Sec Regulations
Similar Jobs at Morningstar
Enterprise Web • Fintech • Financial Services
Lead security detection and response initiatives to improve security monitoring and mitigation. Collaborate with teams for optimized threat response and mentoring.
Top Skills:
AWSAzureBashCisEdrGCPIso 27001NistPowershellPythonSIEMSoar
Enterprise Web • Fintech • Financial Services
The Senior Application Security Architect will guide product teams on security measures, perform threat modeling, and enhance application security standards.
Top Skills:
Application SecurityCloud SecurityRisk AssessmentSecure CodingThreat ModelingVulnerability Management
Enterprise Web • Fintech • Financial Services
The Senior Software Engineer will develop stable, scalable features for Morningstar Direct, manage projects, mentor team members, enforce engineering practices, and ensure product quality while embracing collaboration and continuous improvement.
Top Skills:
AWSCloudbeesCloudFormationHarnessJavaScriptJenkinsLinuxNuxtTerraformUnixVue
What you need to know about the Montreal Tech Scene
With roots dating back to 1642, Montreal is often recognized for its French-inspired architecture and cobblestone streets lined with traditional shops and cafés. But what truly sets the city apart is how it blends its rich tradition with a modern edge, reflected in its evolving skyline and fast-growing tech industry. According to economic promotion agency Montréal International, the city ranks among the top in North America to invest in artificial intelligence, making it le spot idéal for job seekers who want the best of both worlds.
Key Facts About Montreal Tech
- Number of Tech Workers: 255,000+ (2024, Tourisme Montréal)
- Major Tech Employers: SAP, Google, Microsoft, Cisco
- Key Industries: Artificial intelligence, machine learning, cybersecurity, cloud computing, web development
- Funding Landscape: $1.47 billion in venture capital funding in 2024 (BetaKit)
- Notable Investors: CIBC Innovation Banking, BDC Capital, Investissement Québec, Fonds de solidarité FTQ
- Research Centers and Universities: McGill University, Université de Montréal, Concordia University, Mila Quebec, ÉTS Montréal