Назад
Company hidden
2 месяца назад

CIT Information Security & GRC, Lead

103 500 - 126 500CAD
Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
CIT Information Security & GRC, Lead (Microsoft Security/GRC): Designing, operating, and improving security operations and governance across a distributed portfolio of global businesses with an accent on incident response, Microsoft Defender, DLP, and compliance frameworks. Focus on investigating complex security alerts, coordinating containment and remediation, strengthening SOC maturity, and translating technical risks into actionable business outcomes.

Location: Markham, Ontario, Canada

Salary: CAD 103,500–126,500 per year for roles performed in Ontario and British Columbia

Company

A software operating group managing a diverse portfolio of global businesses and operating environments.

What you will do

  • Monitor, investigate, and respond to security alerts across endpoint, identity, email, and data protection platforms.
  • Coordinate incident containment, remediation, root cause analysis, documentation, and full incident lifecycle tracking.
  • Operate enterprise security tooling, including EDR/XDR, DLP, email security, identity monitoring, and endpoint protection platforms.
  • Conduct endpoint, identity, insider risk, DLP, email, and phishing investigations, including simulation campaigns and reporting.
  • Implement security policies aligned with NIST, ISO 27001, PCI-DSS, SOC, and GDPR frameworks; support risk assessments, audits, control validation, and evidence collection.
  • Mentor SOC analysts, guide cross-functional teams, document runbooks, and drive process improvements and automation.

Requirements

  • 3–5 years of experience in information security operations, governance, or risk.
  • Experience supporting a Security Operations Center and managing end-to-end incident response.
  • Hands-on experience with endpoint detection, monitoring, alerting, detection tuning, and signal-quality improvement.
  • Experience with Microsoft Defender for Endpoint, Microsoft 365, and Identity, plus DLP across Microsoft 365 workloads.
  • Working knowledge of NIST, ISO 27001, PCI-DSS, and GDPR in enterprise environments.
  • Strong analytical, communication, troubleshooting, documentation, prioritization, and customer service skills; availability for occasional after-hours operations, infrequent travel, and schedule adjustments.

Nice to have

  • KQL query development, analytics rule creation, incident correlation, and Microsoft Purview.
  • Experience with Defender for Cloud Apps, cloud security posture management, enterprise XDR, and centralized security architecture.
  • Experience improving SOC maturity through playbooks, automation, and process development.
  • Experience with hybrid or multi-cloud environments and distributed security programs.
  • CISSP, GIAC, or Microsoft Security certifications.

Culture & Benefits

  • Full-time employment with a full benefits package.
  • Competitive base salary with bonus potential.
  • Work with geographically distributed teams and diverse business environments.
  • Inclusive workplace and equal-opportunity employment environment.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →