Information Security Compliance

2 months ago


Old Toronto, Canada Athennian Group Full time

Athennian increases trust in business. Our products help legal, finance, and tax teams be transaction and audit-ready by organizing business entity and corporate structure information. Over 370,000 business entities in almost every country are managed on Athennian to automate workflows for ownership, company secretarial, governance, tax, and compliance.

We are seeking a Head of Privacy and Information Security to join our Engineering Technology team in a full-time, permanent capacity. Reporting to the Engineering Manager, DevOps, and Infrastructure, the Head of Privacy and Information Security will play a key role in shaping a culture of privacy-first principles and data security, ensuring Athennian complies with evolving privacy regulations while strengthening its overall security posture through robust policies, technical controls, and educational initiatives.


Key Responsibilities:
  • RFP/RFI Management - Oversee the end-to-end process of responding to security-related RFPs, RFIs, and questionnaires. This includes analyzing requirements, collaborating with internal teams to create thorough responses, and ensuring timely, accurate submissions. Maintain detailed records and facilitate clear communication with clients, vendors, and internal stakeholders.
  • Privacy and Security Strategy & Oversight: Develop and implement an organization-wide privacy and information security strategy that aligns with regulatory requirements and best practices. As the Company’s Head of Privacy, serve as the primary point of contact for data privacy matters, ensuring compliance with privacy laws, overseeing data protection practices, and advising on privacy implications across all company operations and new initiatives.
  • Compliance and Data Protection Standards: Ensure compliance with industry regulations (e.g., GDPR, SOC2, ISO 27001) by establishing and maintaining robust data protection policies and information security standards. Assist with audits and evidence gathering related to SOC2 compliance and other privacy frameworks, providing oversight for security controls and data protection measures.
  • Data Governance and Risk Management: Conduct and document security and data privacy risk assessments, compliance reviews, and communicate risk mitigation strategies to senior leadership, engineering, and relevant stakeholders.
  • Security Infrastructure and Vulnerability Management: Monitor both on-prem and cloud infrastructure for vulnerabilities, assess risk factors, and implement solutions to improve security and data protection.
  • Privacy by Design: Partner with product and engineering teams to embed privacy and data protection principles in the product lifecycle, from initial design to deployment.
  • Security and Privacy Awareness: Lead employee security and privacy training initiatives focused on email threats, data handling, and best practices in protecting sensitive information.
  • Incident Response and Recovery: Manage incident response for security and data privacy breaches, conduct root cause analyses, and oversee remediation efforts.
  • Third-Party Vendor Management: Coordinate with third parties on security and privacy audits, assessments, and remediation efforts (e.g., penetration testing, bug bounty programs).
  • Policy Development and Access Management: Oversee development of information security and privacy policies, conduct regular access management reviews, and implement technical controls for data protection.
  • Privacy Impact Assessments (PIAs): Conduct and review PIAs to evaluate privacy risks associated with new projects, technologies, and data processing activities.
  • Security Metrics and Reporting: Gather, document, and report security and privacy metrics, analyzing trends to guide continuous improvement.
Qualifications:
  • Experience: 7+ years in information security, data protection, and privacy roles.
  • Technical Skills: Proficiency in cloud technologies (e.g., AWS) and experience securing hybrid environments (on-premises and cloud).
  • Security Solutions: Hands-on experience managing security solutions such as SIEM, EDR, firewalls, IPS/IDS, and encryption.
  • Privacy Frameworks: In-depth knowledge of data protection regulations and standards (GDPR, SOC2, ISO 27001, NIST 800-171).
  • Certifications: Industry-recognized certifications (CISSP, CIPP, CISA, Certified Ethical Hacker, CompTIA Security+) are preferred.
  • Incident Management: Proven experience in incident response, management, and root cause analysis.
  • Analytical Skills: Ability to conduct privacy and security risk assessments and analyze network traffic, system alerts, and data logs for trends.
  • Communication and Collaboration: Excellent ability to convey complex privacy and security concepts to technical and non-technical audiences.
  • Autonomy and Organization: Ability to work independently, prioritize tasks effectively, and manage multiple projects concurrently.

Location

We have embraced a distributed model of working to reach the best talent in Canada. While some roles may require proximity to our Toronto, Calgary and Vancouver offices, roles based outside our office locations can be remote in Canada.

Benefits at Athennian

We offer competitive benefits and perks because we believe that happy people produce great results. We are always adding to this list based on employee feedback: generous vacation/sick/flex days, remote work options, flexible working hours, health/dental/vision/group life/gRRSP/LTD/AD&D/EFAP benefits, high growth environment, team-building, day-to-day variety (never a dull moment), MacBook for all employees, stock options, and a culture of transparency.

#J-18808-Ljbffr

  • Old Toronto, Canada Ezra Full time

    p>Job Role: IT Security, Risk and Compliance Manager - EZRA Location: Toronto, Canada – Hybrid (3 days per week in office) Who we are Ezra is the fastest-growing global virtual coaching company, supporting some of the world’s leading companies. p>The primary purpose of the role is to support the Head of IT Security Risk and Compliance to ensure the...


  • Old Toronto, Canada Knightsbridge Solutions, L.L.C. Full time

    p>Job Role: IT Security, Risk and Compliance Manager - EZRALocation: Toronto, Canada – Hybrid (3 days per week in office)Who we areImagine what even the world’s finest organizations could achieve if all of their employees were coached to be their absolute best. We believe, through coaching, people get to know themselves, their goals, weaknesses, and...


  • Toronto, Ontario, Canada Disability Solutions Full time

    Job SummaryWe are seeking an experienced Information Security Compliance Officer to join our team as a Third-Party Security Risk Manager. The estimated annual salary for this role is $115,000. In this role, you will be responsible for ensuring the security and compliance of our third-party vendors.About the RoleYou will work closely with our technology teams...


  • Old Toronto, Canada LZ Security & Service GmbH Full time

    Job Responsibilities:Plan, coordinate, and direct all information security tasks within the area of responsibility to meet the global and local security goals.Support all security incidents of the location with alignment to the incident management process.Work with the Procurement and Legal departments to review and screen suppliers.Lead IT/security...


  • Old Toronto, Canada LZ Security & Service GmbH Full time

    Job Responsibilities:Plan, coordinate, and direct all information security tasks within the area of responsibility to meet the global and local security goals.Support all security incidents of the location with alignment to the incident management process.Work with the Procurement and Legal departments to review and screen suppliers.Lead IT/security...


  • Toronto, Canada Ripple Full time

    At Ripple, we’re building a world where value moves like information does today. It’s big, it’s bold, and we’re already doing it. Through our crypto solutions for financial institutions, businesses, governments and developers, we are improving the global financial system and creating greater economic fairness and opportunity for more people, in more...


  • Old Toronto, Canada Nova Credit Full time

    At Nova Credit, our mission is to power a more fair and inclusive financial system for the world. We are on our way to accomplishing this mission by rewiring the financial industry with better credit infrastructure, analytics, and workflows, enabling more people to access credit opportunities. Our cross-border credit product, Credit Passport, cash flow...


  • Old Toronto, Canada Nova Credit Full time

    At Nova Credit, our mission is to power a more inclusive and fair financial system. We're on a mission to rewire the financial industry with better credit infrastructure, analytics, and workflows, enabling more people to access credit opportunities.Our cross-border credit product, Credit Passport, cash flow underwriting product, Cash Atlas, and income...


  • Old Toronto, Canada Athennian Group Full time

    Job Title: Chief Information Security OfficerEstimated Salary: $140,000 - $180,000 per yearAbout Athennian GroupAthennian Group is a leading provider of technology solutions for businesses, with a focus on increasing trust and efficiency in the market.Job DescriptionWe are seeking an experienced Chief Information Security Officer to join our team. The...


  • Old Toronto, Canada Munich Re Full time

    The Information Security & Cyber Manager, as part of the Enterprise Risk Management team, is the second line of defense for Cyber Security covering Munich Re’s Life and Health North America (LHNA) entities. The role supports the identification, prioritization, communication, and monitoring of cyber security risks in the Life and Health North America...


  • Old Toronto, Canada Munich Re Full time

    The Information Security & Cyber Manager, as part of the Enterprise Risk Management team, is the second line of defense for Cyber Security covering Munich Re’s Life and Health North America (LHNA) entities. The role supports the identification, prioritization, communication, and monitoring of cyber security risks in the Life and Health North America...


  • Old Toronto, Canada Munich Re Full time

    The Information Security & Cyber Manager, as part of the Enterprise Risk Management team, is the second line of defense for Cyber Security covering Munich Re’s Life and Health North America (LHNA) entities. The role supports the identification, prioritization, communication, and monitoring of cyber security risks in the Life and Health North America...


  • Old Toronto, Canada Loopio Full time

    Loopio is a workplace that unleashes learning & growth opportunities for our Loopers. We provide autonomous, challenging work that allows each employee to master their craft. We attract and retain people who are naturally curious, have grit and are eager to grow and build their careers. At Loopio, we genuinely support each other, because true success comes...


  • Old Toronto, Canada Loopio Full time

    Loopio is a workplace that unleashes learning & growth opportunities for our Loopers. We provide autonomous, challenging work that allows each employee to master their craft. We attract and retain people who are naturally curious, have grit and are eager to grow and build their careers. At Loopio, we genuinely support each other, because true success comes...


  • Old Toronto, Canada Loopio Full time

    Loopio is a workplace that unleashes learning & growth opportunities for our Loopers. We provide autonomous, challenging work that allows each employee to master their craft. We attract and retain people who are naturally curious, have grit and are eager to grow and build their careers. At Loopio, we genuinely support each other, because true success comes...


  • Old Toronto, Canada TD Bank Full time

    TD Bank Job DescriptionJob Overview:TD Bank is seeking a highly skilled and experienced Chief Information Security Officer to join our Regulatory, Audit & ORM Assurance team. As a trusted advisor, you will provide guidance and challenge on regulatory inquiries, responses, and interactions for Platforms and Technology.Key Responsibilities:Ensure effective...


  • Toronto, Canada CAS Cyber Security Full time

    CAS Cyber Security is a one-stop shop for all matters cyber security. Offering various consulting and a comprehensive managed service, CAS takes the mystery out of cyber security and allows you to focus on running your business. Leveraging our military background, we ensure you stay one step in front of cyber criminals deploying the most advanced systems...


  • Old Toronto, Canada Four Seasons Hotels Ltd Full time

    h3>Business Information Security ManagerApply locations: Four Seasons Corporate Office, TorontoTime type: Full timePosted on: Posted 2 Days AgoTime left to apply: End Date: January 19, 2025 (29 days left to apply)Job requisition id: REQ10333835About Four Seasons:Four Seasons is powered by our people. b>Four Seasons Hotels and Resorts is a global, luxury...


  • Old Toronto, Canada LZ Security & Service GmbH Full time

    Job OverviewLZ Security & Service GmbH is seeking a highly skilled and experienced Chief Information Security Officer to lead our information security efforts. This role is responsible for planning, coordinating, and directing all information security tasks within the organization to meet global and local security goals.


  • Old Toronto, Canada TD Full time

    Are you a seasoned IT security professional looking to take on a leadership role in regulatory compliance? Look no further! At TD, we're seeking an experienced Senior Manager, Information Security (Regulatory Supervision) to join our team.Job DescriptionWe're seeking a highly skilled and knowledgeable leader who can provide strategic guidance and oversight...