Security Compliance Engineer

3 weeks ago


Canada Sophos Group Full time

About Us Sophos is a global leader and innovator of advanced security solutions for defeating cyberattacks. The company acquired Secureworks in February 2025, bringing together two pioneers that have redefined the cybersecurity industry with their innovative, native AI-optimized services, technologies and products. Sophos is now the largest pure-play Managed Detection and Response (MDR) provider, supporting more than 28,000 organizations. In addition to MDR and other services, Sophos’ complete portfolio includes industry-leading endpoint, network, email, and cloud security that interoperate and adapt to defend through the Sophos Central platform. Secureworks provides the innovative, market-leading Taegis XDR/MDR, identity threat detection and response (ITDR), next-gen SIEM capabilities, managed risk, and a comprehensive set of advisory services. Sophos sells all these solutions through reseller partners, Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs) worldwide, defending more than 600,000 organizations worldwide from phishing, ransomware, data theft, other everyday and state-sponsored cybercrimes. The solutions are powered by historical and real-time threat intelligence from Sophos X-Ops and the newly added Counter Threat Unit (CTU). Sophos is headquartered in Oxford, U.K. More information is available at Role Summary We are seeking a technically skilled and proactive Security Compliance Engineer to support and enhance our compliance automation and monitoring capabilities. This role will serve as the technical subject matter expert and a key contributor within the Trust and Assurance team, focusing on integrating and expanding the capabilities of our GRC platform. The role will collaborate cross-functionally with product, engineering, and security teams to enable continuous control monitoring, establish key risk indicators, and support security assurance objectives. The ideal candidate will have light programming and scripting skills, familiarity with cloud technologies, and an understanding of compliance frameworks. What You Will Do Serve as a technical SME for compliance automation and integration efforts. Design and implement automated workflows for evidence collection and control monitoring. Expand and optimize the capabilities of the compliance platform through technical configuration and integration. Develop and maintain dashboards to visualize compliance posture and key risk indicators. Integrate GRC tools with cloud platforms and internal systems using APIs and scripting. Collaborate with product, engineering, and security teams to implement technical controls. Conduct gap analysis and support implementation of new compliance frameworks. Monitor compliance with internal controls and external regulatory requirements (e.g., ISO 27001, NIST, SOC 2, GDPR, HIPAA). Stay current with emerging technologies, regulations, and best practices in compliance automation. What You Will Bring Required Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience). 2+ years of experience in technical GRC, compliance automation, or security engineering roles. Knowledge of industry frameworks such as NIST, ISO 27001, COBIT, or CIS Controls. Understanding of various technologies used to meet compliance objectives. Strong analytical, problem-solving, and documentation skills. Excellent communication and collaboration skills. Preferred: Certifications such as CISA, CISM, CRISC, CISSP, or Security+. Experience with GRC tools (e.g., Archer, ServiceNow GRC, OneTrust). Basic programming or scripting skills (e.g., Python, Bash) and familiarity with APIs. Working knowledge of AWS and cloud security controls. Compensation and Location In Canada, the base salary for this role ranges from $80,000 to $136,000. In addition to base salary, we offer additional compensation including bonus eligibility and a comprehensive benefits package. A candidate’s specific pay within this range will depend on a variety of factors, including job-related skills, training, location, experience, relevant education, certifications, and other business and organizational needs. Ready to Join Us? At Sophos, we believe in the power of diverse perspectives to fuel innovation. Research shows that candidates sometimes hesitate to apply if they don’t check every box in a job description. We challenge that notion. Your unique experiences and skills might be exactly what we need to enhance our team. Don’t let a checklist hold you back – we encourage you to apply. What’s Great About Sophos? • Sophos operates a remote-first working model, making remote work the primary option for most employees. However, some roles may necessitate a hybrid approach. While we are a remote-first organization, applicants must have legal authorization to work in the jurisdiction where the position is posted, without requiring employer sponsorship. • Our people – we innovate and create, all of which are accompanied by a great sense of fun and team spirit • Employee-led diversity and inclusion networks that build community and provide education and advocacy • Annual charity and fundraising initiatives and volunteer days for employees to support local communities • Global employee sustainability initiatives to reduce our environmental footprint • Global fitness and trivia competitions to keep our bodies and minds sharp • Global wellbeing days for employees to relax and recharge • Monthly wellbeing webinars and training to support employee health and wellbeing Our Commitment To You We’re proud of the diverse and inclusive environment we have at Sophos, and we’re committed to ensuring equality of opportunity. We believe that diversity, combined with excellence, builds a better Sophos, so we encourage applicants who can contribute to the diversity of our team. All applicants will be treated in a fair and equal manner and in accordance with the law regardless of gender, sex, gender reassignment, marital status, race, religion or belief, color, age, military veteran status, disability, pregnancy, maternity or sexual orientation. We want to give you every opportunity to show us your best self, so if there are any adjustments we could make to the recruitment and selection process to support you, please let us know. Data Protection If you choose to explore an opportunity, and subsequently share your CV or other personal details with Sophos, these details will be held by Sophos for 12 months in accordance with our Privacy Policy and used by our recruitment team to contact you regarding this or other relevant opportunities at Sophos. If you would like Sophos to delete or update your details at any time, please follow the steps set out in the Privacy Policy describing your individual rights. For more information on Sophos’ data protection practices, please consult our Privacy Policy regarding Cybersecurity as a Service Delivered by Sophos. #J-18808-Ljbffr



  • , , Canada Vanta Full time

    Staff Software Engineer - Security & Compliance Frameworks Join to apply for the Staff Software Engineer - Security & Compliance Frameworks role at Vanta . About Vanta At Vanta, our mission is to secure the internet and protect consumer data. We believe security should be monitored and verified continuously, empowering companies to practice better security...


  • , , Canada Extreme Networks Full time

    A global networking leader is seeking a highly experienced Staff Engineer – DevSecOps to drive enterprise security, compliance, and risk management initiatives. With a focus on ISO 27001 and NIST frameworks, candidates should have extensive experience in information security. This role involves developing automated monitoring tools, conducting risk...

  • Compliance Manager

    1 week ago


    Avenue Southwest, Calgary, Alberta, Canada, TP G Phantom Compliance Full time $70,000 - $85,000 per year

    Compliance Manager Reports To: Chief Operating Officer Position Type: Full-Time, 1 vacancy  Location: Calgary, Alberta  Hours of Work: Monday to Friday, 9:00 am to 5:00pm, 37.5 hours per week, MST Salary: $70,000 to start About the Company  We are a one‑stop compliance powerhouse trusted by clients who expect precision, agility, and results. We run...


  • , , Canada Advantage Group International Full time

    A leading technology firm is seeking a Security Engineer to develop and manage security infrastructure. The ideal candidate will have experience in risk management, compliance frameworks, and a proven ability to embed security into operations. Responsibilities include designing security systems, leading vulnerability efforts, and ensuring compliance with...


  • , , Canada Qualified Full time

    Join to apply for the Senior Security Engineer role at Qualified Qualified is the Agentic Marketing Platform for B2B companies. With Piper the AI SDR Agent, Qualified offers a whole new way to grow inbound pipeline. Piper operates across both the website and email, working to engage website visitors, capture leads, and convert buyers into pipeline around the...


  • , , Canada Mechanical Orchard Full time

    At Mechanical Orchard, we specialize in safely rewriting the most critical and complex business applications—the software that runs the world as we know it today—so they’re ready to adapt quickly and easily to market challenges and opportunities. Our approach emerged from observing the decades-long failure patterns in modernization efforts and is...


  • , , Canada S4cloud Us Full time

    We are looking for a skilled Security Engineer to analyze software designs and implementations from a security perspective, and identify and resolve security issues. You will include the appropriate security analysis, defences and countermeasures at each phase of the software development lifecycle, to result in robust and reliable software. Responsibilities...

  • Security Engineer

    2 weeks ago


    , , Canada N3XT Full time

    Security Engineer - Application Security Join to apply for the Security Engineer - Application Security role at N3XT . Liberating Money We're looking for a highly skilled and passionate Security Engineer with a dedicated focus on Application Security to join our team. You'll embed robust security practices throughout the entire software development lifecycle...


  • , , Canada Pantheon Full time

    About Pantheon Pantheon WebOps Platform powers the open web, running more than 300,000 sites in the cloud for customers including Google, Princeton, Salesloft, and Doctors Without Borders. Every day, thousands of developers and marketers create, iterate, and scale WordPress and Drupal sites to reach billions of people globally. Pantheon’s multitenant,...

  • Security Engineer

    1 week ago


    , , Canada Jonas Software Full time

    Job Description Security Engineer Compensation: The expected salary range for this role is between $135,000 and $150,000, depending on experience and qualifications. Reason for Opening: Net New position AI is not used to screen, assess, or select applicants for this role. Company Constellation Payment Processing is a modern Payment Facilitator (PayFac)...