Назад
Company hidden
обновлено 3 дня назад

Senior Information Security, Risk & Compliance Specialist (IoT)

104 400 - 135 700CAD
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Information Security, Risk & Compliance Specialist (IoT): Leading security audits, compliance programs, and technical risk assessments for connected transportation systems with an accent on SOC 2, ISO 27001, NIST, FedRAMP, and third-party risk. Focus on coordinating audit evidence and remediation, developing security governance, assessing supply chain risks, and applying AI to compliance and risk analysis.

Location: Hybrid role based in Oakville, Toronto, or Waterloo, Ontario, Canada

Salary: $104,400–$135,700 CAD annually

Company

hirify.global develops IoT and connected transportation solutions, web-based fleet analytics, and an open vehicle-data platform.

What you will do

  • Lead internal and external security audits, including planning, evidence collection, auditor liaison, and remediation tracking.
  • Manage compliance with SOC 2 Type 2, ISO 27001, NIST SP 800-53, NIST SP 800-171, and FedRAMP.
  • Develop and maintain information security policies, standards, procedures, and governance documentation.
  • Conduct technical security risk, supply chain risk, and third-party vendor assessments.
  • Advise cross-functional teams on security controls, regulatory compliance, and risk mitigation.
  • Mentor junior specialists, support complex security initiatives, and apply AI tools to automate compliance and improve risk analysis.

Requirements

  • 5–8 years of experience in security evaluation, risk assessment, and/or compliance within a technology-focused industry.
  • Strong knowledge of system and network security engineering practices and GRC platforms.
  • Hands-on experience with security audits, third-party risk management, and supply chain risk assessments.
  • Strong familiarity with SOC 2 Type 2, ISO 27001, NIST SP 800-53, NIST SP 800-171, and FedRAMP certification and reporting processes.
  • Post-secondary diploma or degree in Computer Science, Engineering, or a related field, or equivalent experience.
  • Excellent written and verbal communication, analytical, organizational, presentation, and stakeholder-management skills.

Nice to have

  • Professional certification such as CISSP, CISM, CRISC, CISA, ISO 27001 Lead Auditor, or ISO 42001.
  • Experience using Google Workspace applications and willingness to adopt AI-driven security and compliance tools.

Culture & Benefits

  • Flexible hybrid work model with virtual and in-person collaboration.
  • Home office reimbursement and online learning and networking opportunities.
  • Medical and dental benefits, retirement savings program, parental leave top-up, and baby bonus.
  • Electric vehicle purchase incentive and work-life balance initiatives.
  • Benefits listed above are available to full-time permanent employees.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →