Retour à la recherche
T
TureSource d’offres vérifiée

Security & Compliance Operations Manager

Offre en anglais
  • Toronto, ON
  • Hybride
  • Publié 15 sept. 2026
  • 1 poste

110 000 $–130 000 $ / année

Ouvre un site externe

Connectez-vous pour enregistrer ce poste
Type d’emploi
Temps plein
Niveau d’expérience
Expérimenté · 5+ ans
Langue de l’offre
anglais
Heures de travail
40 heures par semaine

Résumé du poste

You will build and operate the company's security and compliance program by translating frameworks into practical operating controls. Responsibilities include coordinating audits, managing risk registers, conducting vendor reviews, and supporting engineering teams with security initiatives.

Détails du poste

ABOUT TURE Ture handles sensitive career, employment, organizational, and program data. Trust, privacy, and security are foundational product requirements—not secondary administrative concerns. We are building a platform for enterprise and public-sector customers that need strong controls, clear evidence, responsible data practices, and confidence in how their information is managed. THE ROLE We are looking for a Security & Compliance Operations Manager to build and operate Ture’s security and compliance program. You will translate frameworks, customer commitments, and company policies into practical operating controls. You will coordinate evidence collection, risk assessments, vendor reviews, customer questionnaires, incident readiness, employee training, and audit activities. This is an operational role for someone who understands that a control is only useful when it is clearly owned, consistently performed, and supported by evidence. WHAT YOU’LL DO * Operate and mature Ture’s information-security and compliance program. * Maintain policies, control descriptions, evidence requirements, and ownership records. * Coordinate SOC 2 and other applicable assurance or certification activities. * Manage recurring control testing and evidence collection. * Maintain company risk, issue, exception, and remediation registers. * Lead vendor-security and third-party-risk reviews. * Coordinate customer security questionnaires, due-diligence requests, and evidence packages. * Partner with engineering on access controls, logging, vulnerability management, secure development, and incident readiness. * Support privacy operations, data inventories, retention practices, and data-processing documentation. * Coordinate security-awareness training and workforce attestations. * Maintain incident-response plans and support tabletop exercises. * Track remediation commitments through completion. * Help assess new products, vendors, and integrations for security and compliance risk. * Make compliance processes efficient enough to support rather than obstruct the company. WHAT YOU’LL BRING * 5+ years of experience in security compliance, governance, risk, privacy operations, audit, or related work. * Hands-on experience with SOC 2 or comparable security frameworks. * Strong understanding of control design, evidence, risk assessment, and remediation. * Experience managing security questionnaires and customer due diligence. * Familiarity with cloud and SaaS security concepts. * Strong documentation and project-management skills. * Ability to work effectively with engineering, legal, operations, sales, and customer teams. * Sound judgment when handling confidential and sensitive information. NICE TO HAVE * Experience at an early-stage B2B SaaS company. * Familiarity with ISO 27001, NIST, CIS Controls, PIPEDA, GDPR, or public-sector requirements. * Experience with GRC and trust-centre platforms. * Security or privacy certifications such as CISA, CISM, CISSP, CRISC, or CIPP. * Experience supporting Canadian data-residency or multi-jurisdiction requirements. WHAT SUCCESS LOOKS LIKE Within your first six months, you will have: * Established clear ownership and operating rhythms for core controls. * Improved audit and customer-evidence readiness. * Created stronger visibility into security risks and remediation work. * Reduced friction in customer security reviews. * Strengthened Ture’s security culture without creating unnecessary bureaucracy.

Ce que vous ferez

You will build and operate the company's security and compliance program by translating frameworks into practical operating controls. Responsibilities include coordinating audits, managing risk registers, conducting vendor reviews, and supporting engineering teams with security initiatives.

Exigences

The role requires 5+ years of experience in security compliance, governance, risk, or audit, with hands-on experience in SOC 2 or similar frameworks. Candidates must possess strong documentation skills and the ability to effectively collaborate across engineering, legal, and customer-facing teams.

Compétences indiquées

  • Risk Management · Souhaitée
  • Audit · Souhaitée
  • Gestion de projet · Souhaitée

Autres compétences pertinentes

Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.

  • Security compliance
  • Governance
  • Risk management
  • Privacy operations
  • Audit
  • SOC 2
  • Control design
  • Evidence collection
  • Vendor security
  • Third-party risk
  • Customer security questionnaires
  • Incident readiness
  • Project management
  • Cloud security
  • SaaS security
  • Certified Information System Auditor (CISA)
  • General Data Protection Regulation (GDPR)
  • Internal Controls Testing And Monitoring
  • Compliance Risk
  • SaaS Security
  • Evidence Collection
  • Access Controls
  • Auditing
  • Business To Business
  • Certified Information Systems Security Professional
  • Certified Information Security Manager
  • Cured-In-Place Pipe
  • Software As A Service (SaaS)
  • Data Processing
  • Training And Development
  • Certified In Risk And Information Systems Control
  • Due Diligence
  • Incident Response
  • Sales
  • Governance Risk Management And Compliance
  • ISO/IEC 27001
  • Project Management
  • Operations Management
  • Operations
  • Personal Information Protection And Electronic Documents Act
  • Risk Analysis
  • Security Awareness
  • Vulnerability Management

Domaines d’emploi

  • Security & Safety
  • Technology
  • Software
  • Management & Leadership
  • Legal
  • Security Compliance Manager
  • Cyber Security Manager / Administrator
  • Database and Network Professionals Not Elsewhere Classified
  • Information Security Engineers
  • Computer Occupations, All Other

D’autres postes auxquels postuler directement

Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.

Voir tous les postes à candidature simplifiée