
Information Security Specialist
Posted Jul 25

Posted Jul 25
This is a fully remote position, open to applicants in Canada.
• Monitoring for threats
• Actively observe and evaluate security data to identify advanced threats and vulnerabilities.
• Generate key indicators (risk and performance) and actionable insights to enhance the organization’s security posture.
• Handle security incidents from initial analysis to complete resolution.
• Conduct post-incident evaluations and suggest preventive measures.
• Independently carry out comprehensive security assessments to pinpoint vulnerabilities and propose remediation strategies.
• Maintain the information security risk register, supervise audits, and evaluate vendor security practices.
• Create materials for information security awareness.
• Serve as a subject-matter expert to support cybersecurity program goals and compliance initiatives.
• Draft, revise, and manage information security policies, procedures, and standards (including access management, passwords, network security, PAP, etc.).
• Ensure documentation is in line with best practices (NIST, ISO 27001, etc.).
• Coordinate SOC 2 (Type 1 and Type 2) compliance activities, including preparation for audits.
• Document and implement necessary security controls.
• Address security questionnaires from clients or partners (covering cybersecurity, privacy, business continuity, etc.).
• Work collaboratively with internal teams to gather pertinent technical or organizational responses.
• Participate in defining and executing technical and organizational controls (such as access management, logging, backups, etc.).
• Develop procedures for security response (including incident response, vulnerability management, SIEM alert handling, etc.).
• Establish repeatable and well-documented processes.
• Strong understanding of SOC 2, ISO 27001, NIST, and CIS Controls
• Experience in creating policies and security documentation
• Capability to grasp technical concepts and convey them to non-technical audiences
• Familiarity with cloud environments (AWS, Azure, GCP) is a plus
• Certifications such as CCSP, CISM, ISO 27001 Lead Implementer
• Degree in information security, information technology, or a related field
• At least three to five years of experience in a comparable IT security or governance position
• Proficient in both French and English
• Demonstrated ability to manage multiple projects simultaneously with diligence and independence
• Experience with governance, risk, and compliance (GRC) tools
• Familiarity with the GRC tool DRATA is advantageous
• At Nöord Technologies, we prioritize diversity and inclusion as key factors for innovation and growth.
• We are dedicated to forming inclusive teams and ensuring a fair workplace where employees can express their true selves.
• We also aim to provide an accessible application experience for candidates with various abilities. Please inform us if you need any accommodations during the recruitment process.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.