Security & Compliance Lead
Offre en anglaisThe role involves building and maturing information security, privacy, and compliance programs while implementing cloud and application security controls. The lead will manage security audits, conduct risk assessments, and collaborate with engineering teams to ensure operational excellence.
- Sur place
- Toronto, ON
- Publié 6 août 2026
- Postuler avant le 5 sept. 2026
- 1 poste
Résumé du poste
Security & Compliance Lead – Full-Time / Canada A growing technology company operating in a highly regulated environment is seeking a Security & Compliance Lead to build and mature its information security, privacy, and compliance programs. This full-time opportunity is ideal for a candidate who enjoys combining strategy with execution, helping the business establish scalable security practices while supporting growth, customer trust, and operational excellence. This role offers the chance to take ownership of the organization's compliance initiatives and become a key partner to both technical and business teams. You'll have the opportunity to shape security processes from the ground up, influence product and infrastructure decisions, and work closely with stakeholders across engineering, operations, and leadership. The ideal candidate is someone who thrives in dynamic environments, embraces continuous improvement, and enjoys solving complex compliance and risk challenges. Required Skills & Experience 5+ years of experience in information security, governance, risk, compliance, or related cybersecurity functions Proven experience managing compliance initiatives within cloud-based or technology-focused organizations Strong understanding of security frameworks, regulatory requirements, and risk management principles Experience preparing for and supporting security audits, assessments, and certification programs Ability to collaborate with technical teams to implement practical security controls and risk mitigation strategies Experience conducting security reviews, vendor assessments, and customer due diligence activities Strong communication skills with the ability to explain technical requirements to non-technical stakeholders Demonstrated success owning programs and driving cross-functional initiatives from planning through execution Desired Skills & Experience Experience supporting or managing compliance programs related to SOC 2, ISO 27001, HIPAA, GDPR, or similar standards Familiarity with privacy regulations, cybersecurity governance models, and emerging compliance requirements Knowledge of cloud infrastructure security and secure software development practices Experience developing security programs within startup or high-growth environments Exposure to AI governance, responsible AI practices, or related risk management frameworks Experience improving or automating compliance and audit processes Background in industries requiring elevated security and data protection controls What You Will Be Doing Tech Breakdown 40% Security Governance, Risk & Compliance 35% Cloud & Application Security Controls 25% Audit Management, Monitoring & Reporting Daily Responsibilities 40% Developing and enhancing security and compliance programs 35% Working with engineering and business teams to implement controls and manage risk 25% Supporting audits, customer reviews, reporting, and compliance initiatives The Offer $140,000 - $170,000 You Will Receive The Following Benefits Medical, Dental, and Vision Insurance Vacation Time Stock Options Current Vacancy: Yes Use of AI in Hiring: Yes Applicants must be currently authorized to work in Canada on a full-time basis now and in the future. Posted By: Matt Rehman
Ce que vous ferez
The role involves building and maturing information security, privacy, and compliance programs while implementing cloud and application security controls. The lead will manage security audits, conduct risk assessments, and collaborate with engineering teams to ensure operational excellence.
Exigences
Candidates need over 5 years of experience in cybersecurity GRC and a proven track record of managing compliance in cloud-based environments. Proficiency in security frameworks and the ability to communicate technical requirements to non-technical stakeholders are essential.
Avantages
• Medical Insurance • Dental Insurance • Vision Insurance • Vacation Time • Stock Options
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- Information Security
- Governance Risk and Compliance
- Cloud Security
- Risk Management
- Security Auditing
- Vendor Assessments
- SOC 2
- ISO 27001
- HIPAA
- GDPR
- Privacy Regulations
- AI Governance
- Secure Software Development
- Cross-functional Leadership
- Stakeholder Communication
- Compliance Automation
Domaines d’emploi
- Security & Safety
- Technology
- Management & Leadership
- Software
- Consulting
Renseignements supplémentaires
- Expérience minimale
- 5+ ans
- Postuler avant le
- 5 sept. 2026
- Langue de l’offre
- anglais
- Heures de travail
- 40 heures par semaine
- Niveau d’expérience
- Mid-Senior level