
Information Security Specialist
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in Canada.
• Lead and implement the comprehensive corporate IT security strategy, roadmap, and governance framework, collaborating with internal risk/compliance, operational, clinical, technical, and business teams, along with external customers and relevant third-party stakeholders.
• Grasp business processes and information system requirements, along with the associated information risks involved in those processes.
• Work closely with the internal Canadian legal/privacy team to ensure compliance and alignment with Canadian privacy, data governance, and regulatory standards, as well as the business's contractual obligations.
• Collaborate directly with the Canadian commercial team and client base to comprehend market business and functional needs, providing compliance, security, and risk assessment support and guidance as necessary.
• Establish and carry out formal vendor security evaluations, including pre-onboarding due diligence and the continuous monitoring of third-party vendors and sub-processors managing sensitive information.
• Execute all aspects of information security, encompassing security breaches, business continuity, and regulatory compliance programs, including legal requirements, industry regulations, and best practices (e.g., ISO27001, SOC 2 Type II, etc.).
• Oversee the complete SOC 2 Type II and ISO 27001 audit cycles, including gap assessments, evidence collection using GRC tools (e.g., Vanta), and act as the primary liaison for external auditors to facilitate certifications.
• Create information security guidelines, procedures, and responsibilities while supporting the development and implementation of technical and administrative security controls and related training and education.
• Manage technical incident response planning and execution, participating in incident response, root cause analysis, and remediation efforts.
• Evaluate our technology environment and software development methodology (SDLC) to identify and mitigate risks and gaps related to information security, including potential data breaches.
• Design, implement, and sustain security controls across infrastructure, applications, integrations, and cloud environments, collaborating with our technology team and third-party vendors, including: Applications and other systems and middleware components, such as operating systems, web servers, databases, and DNS services (e.g., Salesforce, Mulesoft, APIs, etc.).
• Develop network security architecture, including firewalls, segmentation, and secure communication protocols.
• Address logging and monitoring security needs, incorporating SIEM platforms.
• Implement encryption standards necessary for compliance.
• Document security configurations, processes, and controls.
• Manage the digital certificate lifecycle, including issuance, renewal, and revocation.
• Communicate information security and compliance risks to leadership and other stakeholders, both technical and non-technical, to ensure proper awareness and informed decision-making.
• Additional duties as assigned.
• Bachelor’s degree in computer science or relevant equivalent experience.
• Over 10 years of pertinent technical work experience, with at least 5 years in an information security role.
• Familiarity with highly regulated environments or electronic record systems; experience in healthcare is preferred.
• CISM, CISA, CISSP, ISO 27001 LA, or other relevant information security certifications are highly valued.
• Strong oral and written communication skills are essential for engaging both technical and non-technical audiences across geographically dispersed locations.
• Ability to collaborate effectively across functions with both technical and non-technical teams.
• Excellent prioritization and time management abilities.
• A robust understanding (with practical experience) of relevant information security technologies and concepts, including access and authentication, network and application security, message and transmission security, and vulnerability management best practices.
• Proven knowledge of security program frameworks and assessments, ideally with SOC 2 and ISO27001.
• Familiarity with cloud security concepts and experience securing both public and private cloud environments (AWS is essential, Azure is preferred).
• Practical experience and knowledge of: Operating systems (Linux, Windows), Web servers (e.g., Apache, Nginx), Databases (e.g., MySQL, PostgreSQL, SQL Server), Network security principles and architecture (TCP/IP, firewalls, VPNs, segmentation, and secure communication protocols), SIEM tools and their integration, and Application, cloud, and SaaS integrations, particularly with platforms like Salesforce, Containers, and/or Kubernetes, along with Automation tools.
• Health insurance
• 401(k) matching
• Flexible work hours
• Paid time off
• Remote work options
actago GmbH
Zscaler
Thomson Reuters
DSV - Global Transport and Logistics
Get handpicked remote jobs straight to your inbox weekly.