Associate Information Security Compliance Officer

4 days ago


Waterloo, Canada IMS Full time

**Company Overview**

At IMS, we're transforming the way the world drives. As a leading provider of connected car and telematics solutions, we deliver cutting-edge services and analytics to insurers, governments, and enterprises worldwide.

Our cloud-based DriveSync® platform is at the heart of what we do - an industry-recognized solution that empowers smarter decision-making and better driving outcomes. From enhancing road safety to enabling intelligent mobility strategies, our technology is designed to make driving safer and smarter for everyone, from global insurers to local governments and everyday drivers.

**Description**

At IMS, we’re on a mission to make driving safer and smarter through connected car and telematics innovation.

The **Associate Information Security Compliance Officer (AISCO)** is an important member of the IMS Information Security team, assisting in safeguarding the company’s data, infrastructure, and digital assets. This role helps to ensure that IMS’s security framework aligns with ISO27001, industry best practices, and legal and regulatory requirements. The AISCO will help carry out security audits, policy review, incident management, and continuous improvement of IMS’s cybersecurity posture along with adherence and adoption of relevant market regulations.

In this role, you will be responsible for:
**Security Compliance & Risk Management**
- Assist in the development, implementation, and enforcement of information security policies, standards, and procedures in compliance with ISO27001, GDPR, NIST, and SOC frameworks.
- Conduct internal security audits and coordinate external audits to assess compliance and effectiveness of security controls.
- Perform privacy impact assessments in line with regulatory requirements.
- Identify and assess cybersecurity risks across IMS systems and recommend appropriate remediation actions.
- Maintain all InfoSec framework certifications, ensuring compliance with regulatory and customer requirements.
- Collaborate with legal and compliance teams to ensure IMS meets data privacy laws and security regulations across different jurisdictions.

**Incident Detection, Response & Management**
- Monitor network and system logs for security incidents, unauthorized access, or vulnerabilities.
- Investigate security breaches, analyze attack vectors, and document security incidents, including impact assessments and recommended mitigations.
- Maintain incident response plans (IRPs) to ensure rapid and effective response to security events.
- Coordinate forensic analysis and liaise with law enforcement or regulatory agencies when required.
- Ensure security alerts are appropriately triaged, investigated, and escalated following IMS security protocols.

**Third-Party Security Assessments**
- Conduct risk assessments and security audits for IMS’s third-party vendors, partners, and suppliers.
- Work with external security consultants to evaluate and approve new third-party integrations.
- Ensure third parties comply with IMS’s security and data protection requirements before onboarding.
- Review and update vendor security contracts, ensuring alignment with IMS security standards.

**Customer Security Assessments**
- Complete security questionnaires and assessments from current and prospective clients.
- Facilitate remote and onsite data privacy audits with IMS customers.
- Review contractual security clauses and verify operational adherence.

**Security Operations & Infrastructure Protection**
- Oversee the implementation and operation of firewalls, intrusion detection systems (IDS), endpoint protection, data loss protection (DLP) tools, and other security solutions.
- Work closely with IT and DevOps teams to ensure secure cloud architecture and adherence to IAM (Identity & Access Management) policies.
- Maintain encryption, access control, and authentication protocols to secure sensitive data.
- Assist with the co-ordination of regular penetration testing and vulnerability scanning to assess security posture.
- Monitor emerging cybersecurity threats and recommend updates to IMS security technologies and defenses.
- Oversee the continual development and testing of Business Continuity (BC) and Disaster Recovery (DR) plans.

**Policy Development & Employee Training**
- Assist within the update of information security policies, ensuring they reflect evolving threats and business needs.
- Conduct company-wide security awareness training to educate employees on best practices, phishing prevention, and data protection.
- Serve as an internal security advisor, providing guidance to IT teams, leadership, and employees on secure operations.
- Check for adherence to secure coding practices for IMS software development teams.

**Continuous Improvement & Industry Trends**
- Stay informed on latest cybersecurity trends, threats, and evolving regulatory requirements.
- Research and suggest innovative security technologies to enhance IMS’s resilience against cyber threats.
- Dri


  • Compliance Officer

    4 days ago


    Waterloo, Canada Carta Full time

    **The Company You'll Join**: Carta develops purpose-built software that transforms traditional accounting into a powerful growth engine. Carta's world-class fund administration platform supports nearly 7,000 funds and SPVs, and represents nearly $130B in assets under management in venture capital and private equity. Trusted by more than 40,000 companies,...


  • Waterloo, Canada Sun Life Full time

    You are as unique as your background, experience and point of view. Here, you’ll be encouraged, empowered and challenged to be your best self. You'll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day, you'll...


  • Waterloo, Canada Trustwave Full time

    About Trustwave The Information Security Advisor function provides a single point of contact for all security-related activities for designated customer accounts, and takes a key leadership role by providing extensive hands-on guidance in the development and implementation of security policies as related to designated accounts. The role extends further by...


  • Waterloo, Canada Trustwave Full time

    About Trustwave The Information Security Advisor function provides a single point of contact for all security-related activities for designated customer accounts, and takes a key leadership role by providing extensive hands-on guidance in the development and implementation of security policies as related to designated accounts. The role extends further by...


  • Waterloo, Canada IMS (Insurance and Mobility Solutions) Full time

    **Job Types**: Full-time, Permanent **Salary**: $80,000.00-$85,000.00 per year **Benefits**: - Casual dress - Dental care - Employee assistance program - Extended health care - Life insurance - Paid time off - RRSP match - Vision care - Wellness program - Work from home Flexible Language Requirement: - French not required Schedule: - 8 hour...


  • Waterloo, Canada eSentire Full time

    About eSentire Founded in 2001, the company’s mission is to hunt, investigate and stop cyber threats before they become business-disrupting events. Combining cutting-edge machine learning XDR technology, 24/7 Threat Hunting, and proven security operations leadership, eSentire mitigates business risk and enables security at scale. The Team eSentire...


  • Waterloo, Ontario, Canada Arctic Wolf Full time $120,000 - $180,000 per year

    At Arctic Wolf, we're not just navigating the cybersecurity landscape - we're redefining it. Our global team of dedicated Pack members is driving innovation and setting new industry standards every day. Our impact speaks for itself: we've earned recognition on theForbes Cloud 100, CNBC Disruptor 50, Fortune Future 50, and Fortune Cyber 60lists, and we...


  • Waterloo, Ontario, Canada Arctic Wolf Full time $90,000 - $120,000 per year

    At Arctic Wolf, we're not just navigating the cybersecurity landscape - we're redefining it. Our global team of dedicated Pack members is driving innovation and setting new industry standards every day. Our impact speaks for itself: we've earned recognition on the Forbes Cloud 100, CNBC Disruptor 50, Fortune Future 50, and Fortune Cyber 60 lists, and we...


  • Waterloo, Ontario, Canada Equitable Full time $90,000 - $120,000 per year

    At Equitable, we believe work should be a place where you feel supported, inspired, and empowered to grow. In our caring and collaborative environment, your curiosity is encouraged, your passion is recognized, and your contributions truly matter. Together, we create meaningful impact; for our clients, our communities, and each other.Position...


  • Waterloo, Canada Ontario Security Defence Services Inc. Full time

    We’re looking for reliable and alert Security Officer to protect active land development and construction sites in across Waterloo, ON. As part of our expanding team, you’ll play a key role in preventing theft, trespassing, and vandalism during critical phases of residential or commercial development. **Your Responsibilities**: - Patrol undeveloped or...