обновлено 3 дня назад
Senior Information Security, Risk & Compliance Specialist (IoT)
104 400 - 135 700CAD
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Information Security, Risk & Compliance Specialist (IoT): Leading security audits, compliance programs, and technical risk assessments for connected transportation systems with an accent on SOC 2, ISO 27001, NIST, FedRAMP, and third-party risk. Focus on coordinating audit evidence and remediation, developing security governance, assessing supply chain risks, and applying AI to compliance and risk analysis.
Location: Hybrid role based in Oakville, Toronto, or Waterloo, Ontario, Canada
Salary: $104,400–$135,700 CAD annually
Company
develops IoT and connected transportation solutions, web-based fleet analytics, and an open vehicle-data platform.
What you will do
- Lead internal and external security audits, including planning, evidence collection, auditor liaison, and remediation tracking.
- Manage compliance with SOC 2 Type 2, ISO 27001, NIST SP 800-53, NIST SP 800-171, and FedRAMP.
- Develop and maintain information security policies, standards, procedures, and governance documentation.
- Conduct technical security risk, supply chain risk, and third-party vendor assessments.
- Advise cross-functional teams on security controls, regulatory compliance, and risk mitigation.
- Mentor junior specialists, support complex security initiatives, and apply AI tools to automate compliance and improve risk analysis.
Requirements
- 5–8 years of experience in security evaluation, risk assessment, and/or compliance within a technology-focused industry.
- Strong knowledge of system and network security engineering practices and GRC platforms.
- Hands-on experience with security audits, third-party risk management, and supply chain risk assessments.
- Strong familiarity with SOC 2 Type 2, ISO 27001, NIST SP 800-53, NIST SP 800-171, and FedRAMP certification and reporting processes.
- Post-secondary diploma or degree in Computer Science, Engineering, or a related field, or equivalent experience.
- Excellent written and verbal communication, analytical, organizational, presentation, and stakeholder-management skills.
Nice to have
- Professional certification such as CISSP, CISM, CRISC, CISA, ISO 27001 Lead Auditor, or ISO 42001.
- Experience using Google Workspace applications and willingness to adopt AI-driven security and compliance tools.
Culture & Benefits
- Flexible hybrid work model with virtual and in-person collaboration.
- Home office reimbursement and online learning and networking opportunities.
- Medical and dental benefits, retirement savings program, parental leave top-up, and baby bonus.
- Electric vehicle purchase incentive and work-life balance initiatives.
- Benefits listed above are available to full-time permanent employees.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
9 дней назад
Senior Manager, Information Security & IT (Cybersecurity)
150 000 - 165 000CAD
7 дней назад
Governance, Risk & Compliance (GRC) Manager (SaaS)
140 000 - 165 000CAD
5 дней назад
Technical Program Management, Guidewire Security (AI)
120 000 - 150 000CAD
9 дней назад
Staff Security Engineer (IAM)
168 000 - 238 000$
Mercury
6 дней назад
Senior Cloud Security Engineer - InfoSec (Fintech)
166 600 - 208 300$
6 дней назад