Security & Compliance Manager
- ON
- Sur place
- Publié 20 sept. 2026
- 1 poste
Ouvre un site externe
- Type d’emploi
- Temps plein
- Niveau d’expérience
- Expérimenté · 5+ ans
- Formation minimale
- Baccalauréat
- Langue de l’offre
- anglais
- Heures de travail
- 40 heures par semaine
Résumé du poste
The Security & Compliance Manager is responsible for owning the information security programme, including ISO/IEC 27001 and SOC 2 Type 2 certification initiatives. They will manage risk assessments, maintain security policies, and coordinate security architecture and compliance across the organization.
Détails du poste
PACT is a General Partnership of Alberici, Amico, Kenaidan and Obayashi delivering the Toronto Pearson Accelerator program. The Manager, Security & Compliance owns PACT's information security programme, combining ownership with hands-on execution: the role personally operates controls, collects evidence, authors policy and works in the Microsoft 365 tenant, and carries no direct reports. The role owns the ISO/IEC 27001:2022 certification initiative targeted at Q1 2027 and the parallel SOC 2 Type 2 initiative, run as one control programme with two reporting outputs, and contributes to security architecture and strategy through input into platform security standards and the multi-year security roadmap. Because member companies second staff and retain the endpoints they issue, endpoint management, HR and office physical security are not centralized, and control ownership splits across PACT tenant-managed, inherited, shared and client-owned scopes. RESPONSIBILITIES Programme Ownership and ISMS Documentation Own the ISO/IEC 27001:2022 certification initiative to the Q1 2027 target and the SOC 2 Type 2 initiative Run both as one control programme with two reporting outputs, sharing roughly 75-80 percent of control intent Author, approve, publish, version-control and maintain the information security policy suite, retaining acknowledgement records Author and maintain the Statement of Applicability across the applicable control set, justifying inclusion, exclusion and inheritance Operate the document-control procedure, competence matrix, improvement log and corrective-action register in a governed SharePoint library Represent certification and attestation status accurately in internal, member-company, client and external communications Report status to the IT Steering Committee and provide input to security budget, tooling spend and vendor selection Risk Management and Control Operation Define a risk methodology covering acceptance criteria, impact and likelihood scales, ownership and treatment options Establish and maintain the risk register through formal risk assessment, sustained as a live record Produce and track the risk treatment plan, verifying control effectiveness rather than accepting reported completion Operate annual and event-triggered reassessment on new SaaS, tenant change, incident, audit finding or joint-venture change Maintain the evidence inventory, coordinate the quarterly privileged, guest and application access review cycle, and review logs Ensure audit logging and retention across the tenant meet certification and investigative requirements Ensure backup and recovery controls are evidenced, covering schedule, immutability, retention and restore testing Maintain the information asset register and baseline configuration review, recording drift and approvals Third-Party and Member-Company Assurance Maintain the supplier security register and review cadence covering the ICT supply chain and managed service provider Review Entra application registrations as privileged suppliers, documenting owner, purpose, permission scope and review date Maintain the control-ownership split across PACT tenant-managed, inherited, shared and client-owned scopes Collect and refresh member-company attestations for inherited endpoint, AV/EDR, patching, physical security and HR controls Coordinate shared controls with member-company IT and security teams, covering classification, awareness and business continuity Maintain the joiner, mover and leaver process with each member company, and manage dual member-company and PACT identities Security Architecture, Operations and Tenant Hardening Provide input into platform security architecture, security standards and the multi-year security roadmap Assess new platforms, integrations and tenant changes against security architecture principles and target-state control design Operate and evidence the Entra ID Conditional Access posture: MFA enforcement, legacy authentication blocking and glass-break accounts Hold the managed detection and response provider to service expectations for Microsoft 365 monitoring and response Tune Microsoft Defender for Office 365 anti-phishing, anti-malware, Safe Links and Safe Attachments with the Azure 365 Administrator Define Purview label, DLP and retention policy requirements configured by the Azure 365 Administrator, and drive classification roll-out with the SharePoint Administrator Govern privileged access, with privileged access management deployed and operated by the Azure 365 Administrator Coordinate patch and vulnerability activity, act as security voice in change advisory, and direct the managed service provider Incident Response, Awareness and Improvement Author and publish the incident response plan, event triage matrix, vendor runbook and evidence-preservation procedure Publish and promote a security event reporting channel for all users, with defined response expectations Run and document tabletop exercises and lead post-incident review through to verified corrective-action closure Administer the security awareness platform and monthly programme, harvesting completion and new-hire onboarding records Deliver awareness uplift for privileged users and leadership, and coordinate analytics governance with the Manager, Data & Innovation Own and govern the AI-use policy through access gating and record-keeping, with Copilot platform readiness and licensing owned by the Azure 365 Administrator Certification, Audit Readiness and Reporting Engage external assessors and consultants, and prepare for Stage 1 and Stage 2 certification assessment Liaise with external consultants and the certification body, assembling evidence packs and tracking findings to closure Drive SOC 2 Type 2 readiness across the Security, Availability and Confidentiality criteria and operate quarterly self-assessment Prepare for, coordinate and remediate against audits without performing the ISMS internal audit, as Clause 9.2 requires independent auditors Support the internal audit programme hosted under Quality / QMS or co-sourced externally Report quarterly on phishing-simulation click rate, MFA and phishing-resistant coverage, patch mean-time-to-remediate by severity, audit-log retention coverage, evidence completeness and corrective-action closure Qualifications 7-10 years experience in information security, IT compliance, governance risk and compliance, or audit Bachelor's degree in information technology, information security, risk management or a related discipline preferred Demonstrated ownership of an ISO 27001 ISMS or equivalent such as SOC 2, NIST CSF or ISO 27002 Hands-on Microsoft 365 security administration across Entra ID Conditional Access, Microsoft Purview and Microsoft Defender Contribution to security architecture, security standards and multi-year security roadmap development at manager level Practical risk assessment experience, including facilitating workshops and maintaining a risk register and treatment plan Policy authoring through approval and publication, and evidence collection for an external certification body Third-party and vendor security assessment experience, with input to vendor selection and security budget Experience reporting to a steering committee and coordinating across organisations that do not report to the role Certification such as ISO 27001 Lead Implementer or Lead Auditor, CISA, CRISC, CISM, CISSP or SC-400 preferred SOC 2 Type 2 readiness, major capital program delivery, joint-venture or multi-employer environments, and PIPEDA exposure considered assets Key Deliverables ISMS documentation set and information security policy suite published and maintained under document control Statement of Applicability authored and maintained across the applicable control set, with inheritance justified Live risk register and risk treatment plan maintained through formal risk assessment and scheduled reassessment Incident response plan published, event reporting channel operating, and response tested through regular tabletop exercise Security architecture input and multi-year security roadmap maintained and reviewed with the IT Steering Committee Evidence inventory maintained, quarterly KPI reporting into management review, and readiness sustained against the Q1 2027 target WORKING CONDITIONS The position will be based at our office in Mississauga, Ontario, with visits to the Airport site as required. Your work schedule will be Monday to Friday during regular office or site hours. At times, operational needs may require work outside these hours, with reasonable notice provided. All schedule or on‑call adjustments will comply with applicable employment standards legislation. It is mandatory for all employees to complete a Criminal Background check and successfully attain a Restricted Access Identity Card (RAIC) upon joining the company. PACT is an equal opportunity employer and is committed to providing employment accommodation in accordance with the Ontario Human Rights Code and the Accessibility for Ontarians with Disabilities Act. We are committed to providing an inclusive and barrier free candidate experience and work environment. If you require accommodation to apply or if selected to participate in an assessment process, please advise Human Resources.
Ce que vous ferez
The Security & Compliance Manager is responsible for owning the information security programme, including ISO/IEC 27001 and SOC 2 Type 2 certification initiatives. They will manage risk assessments, maintain security policies, and coordinate security architecture and compliance across the organization.
Exigences
Candidates must have 7-10 years of experience in information security, IT compliance, or risk management, along with a bachelor's degree in a related field. Hands-on experience with Microsoft 365 security administration and a strong understanding of security frameworks are essential.
Avantages
• Employment accommodation • Inclusive work environment
Compétences indiquées
- Microsoft 365 · Souhaitée
- Compliance · Souhaitée
- Risk Management · Souhaitée
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- ISO/IEC 27001
- SOC 2 Type 2
- Information security
- Risk management
- Microsoft 365
- Entra ID
- Microsoft Purview
- Microsoft Defender
- Compliance
- Audit readiness
- Policy authoring
- Security architecture
- Incident response
- Vendor management
- Governance
- Tabletop exercises
- Authentications
- Business Continuity
- Incident Response
- Communication
- Management
- Operations
- Coordinating
- Software As A Service (SaaS)
- Tooling
- Risk Management
- Leadership
- Innovation
- Artificial Intelligence
- Managed Services
- IT Security Architecture
- Security Policies
- Information Technology
- Risk Analysis
- Auditing
- Microsoft Azure
- Vulnerability Management
- Hardening
- Triage
- Certified Information Systems Security Professional
- Evidence Collection
- KPI Reporting
- Supply Chain
- Confidentiality
- Record Keeping
- Microsoft SharePoint
- Labor Law
- Legislation
- Risk Register
- Employee Onboarding
Domaines d’emploi
- Security & Safety
- Technology
- Management & Leadership
- Software
- Security Compliance Manager
- Cyber Security Manager / Administrator
- Database and Network Professionals Not Elsewhere Classified
- Information Security Engineers
- Computer Occupations, All Other
D’autres postes auxquels postuler directement
Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.
Bédard Ressources Humaines
ITAD Services Representative #1265
CommanditéEmployeur directCandidature simplifiée- Sur place
- Mississauga, ON
- Publié 16 sept. 2026
Bédard Ressources Humaines
Gestionnaire d'usine - Industrie alimentaire #1812
CommanditéEmployeur directCandidature simplifiée- Sur place
- Publié 9 sept. 2026
Bédard Ressources Humaines
Formateur(trice) aux tables de jeu #1414
CommanditéEmployeur directCandidature simplifiée- Sur place
- Publié 8 sept. 2026