Назад
Company hidden
9 часов назад

Security & Compliance Manager (Cybersecurity)

130 000 - 150 000CAD
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security & Compliance Manager (Cybersecurity): Managing EarthDaily’s governance, risk, and compliance program, IT general controls, audit readiness, and cybersecurity governance with an accent on SOC 2, SOX 302/404, policy lifecycle management, and compliance evidence. Focus on assessing enterprise risk, coordinating audits and access reviews, supporting public-company disclosure readiness, and driving remediation across IT, Finance, Legal, HR, and Engineering.

Location: Vancouver, BC, Canada; hybrid with ongoing in-office work required and occasional travel for audits, team meetings, or vendor assessments.

Salary: $130,000–$150,000 CAD annually

Company

hirify.global develops Earth Observation technology and geospatial analytics for agriculture, mining, insurance, government intelligence, disaster mitigation, environmental monitoring, and crop yield improvement.

What you will do

  • Own and continuously improve the governance, risk, and compliance program, including the enterprise risk register, assessments, mitigation plans, and policy lifecycle.
  • Lead the IT general controls component of SOX 302 and 404, including scoping, documentation, testing, deficiency evaluation, and remediation tracking.
  • Coordinate SOC 2, certification, audit, and public-company readiness activities, including evidence collection, walkthroughs, auditor requests, and follow-up.
  • Support cybersecurity disclosure readiness, incident response tabletop exercises, and controls related to SEC Item 1.05 and public-company reporting.
  • Manage third-party risk assessments, vendor attestations, contract security requirements, and coordination with privacy stakeholders.
  • Coordinate privileged access reviews, user access certifications, compliance metrics, and readiness reporting for senior leadership.

Requirements

  • 5+ years of experience in IT security, risk management, compliance, or audit, including 3+ years with GRC programs, policy management, or audit preparation.
  • Bachelor’s degree in information security, computer science, business administration, accounting, or a related field; relevant experience or certifications may substitute.
  • Experience with SOC 2, NIST CSF, ISO 27001, SOX/ICFR, SOX Sections 302 and 404, and IT general controls.
  • Experience liaising with external auditors or supporting compliance certification efforts.
  • Working knowledge of COSO 2013, risk assessment methodologies, identity and access management, cloud security, GDPR, and CCPA.
  • Strong written and verbal communication skills, organization, independent judgment, and the ability to drive cross-functional remediation initiatives.

Nice to have

  • CISA, CRISC, CISSP, CISM, or CGRC certification.
  • Experience with Vanta, Drata, or ServiceNow GRC.
  • IT administration or technical operations experience, including scripting or independently retrieving system reports and audit evidence.
  • Experience with IPO readiness, SEC cybersecurity disclosure support, publicly traded companies, technology, SaaS, or data-intensive industries.

Culture & Benefits

  • Work with a global, distributed team developing software and production-critical systems for space and Earth monitoring.
  • Hybrid work with work-from-home opportunities and collaboration from the Vancouver office.
  • Full benefits, competitive compensation, and flexible time off.
  • Meaningful work supporting sustainable solutions for the planet.
  • Subsidized lunches, lunch-and-learns, and Friday afternoon social hours.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →