TU PRÓXIMO CAPÍTULO
Program Manager – Security Operations, Compliance
Sobre el puesto
• Maintain and continue to develop Anovia's ISO/IEC 27001 Information Security Management System, including policies, procedures, controls, risks, objectives, evidence, and ongoing improvement activities
• Support ISO 27001, SOC 2, HIPAA, and other security and compliance initiatives
• Coordinate internal and external audit activities, including preparing evidence, scheduling and facilitating meetings, maintaining action items, and ensuring findings and resulting actions are addressed
• Maintain the information asset inventory and data classification program, including assigning and tracking ownership
• Support identity and access management activities, including provisioning and de-provisioning, access reviews, least-privilege requirements, and privileged access controls
• Monitor and improve security tooling and processes, including Microsoft 365 security capabilities, Microsoft Defender, Intune, Entra ID, security monitoring, endpoint protection, and vulnerability management
• Coordinate vulnerability identification, remediation tracking, and escalation of significant findings
• Coordinate third-party and vendor security assessments, including security questionnaires and contract review support
• Develop, maintain, and support adoption of information security policies, standards, and operating procedures
• Coordinate security awareness training and phishing simulation programs
• Support security incident response activities, including detection, containment, investigation, root-cause analysis, and post-incident reporting
• Support business continuity and disaster recovery activities, including maintenance of recovery requirements, testing, and related evidence
• Lead or coordinate technical and operational initiatives from initial scope through implementation, establishing plans, identifying dependencies and owners, coordinating stakeholders, tracking risks and issues, and driving work to completion
• Serve as a primary point of contact for internal and external auditors and coordinate responses with relevant business and technical stakeholders
• 4+ years of progressively responsible experience in information security, IT compliance, GRC, security operations, or a related field
• Practical experience working with ISO/IEC 27001, SOC 2, or a comparable security and compliance framework
• Meaningful participation in an audit or certification process, including policy development, control implementation, evidence collection, audit preparation, management meetings, action tracking, and remediation
• Experience with GRC processes and tools, including risk and control management, evidence collection, compliance tracking, audit preparation, and remediation or corrective-action management
• Working experience with the Microsoft 365 security environment, including Microsoft Defender, Intune, Entra ID, and related security and compliance capabilities
• Ability to structure ambiguous technical or operational initiatives by defining scope, developing plans, coordinating stakeholders, managing dependencies and issues, and driving completion
• Working knowledge of information security principles, risk management, access control, vulnerability management, incident response, and security awareness
• Ability to work directly with auditors, technical teams, business stakeholders, vendors, and leadership
• Strong organizational and communication skills, with the ability to manage multiple ongoing activities and follow through on commitments
• Bachelor's degree in Information Security, Computer Science, IT, or a related field, or equivalent practical experience
• Experience with HIPAA Security and Privacy Rule requirements or other healthcare security and privacy requirements
• Experience with GRC platforms such as Secureframe, Vanta, Drata, or OneTrust
• Experience with SIEM, EDR/endpoint protection, vulnerability scanners, or related security tooling beyond the Microsoft 365 environment
• Experience with NIST CSF or other complementary security frameworks
• Experience managing contractors or vendors during technical or security initiatives
• Experience helping establish or improve security monitoring, NOC, SOC, or similar operational capabilities
• Experience with business continuity and disaster recovery planning
• Certifications are useful supporting evidence of knowledge, but are not a substitute for practical experience
• Relevant certifications are preferred but not required, including ISO/IEC 27001 Lead Implementer or Lead Auditor, CISA, CISSP, and CISM
• Comprehensive Health Insurance policy
• Employee Wellness Program with focus on mental health
• Robust reward and recognition programs
• Company incentive programs offered
• Attractive leave policy: Holiday Leave, Maternity Leave, Paternity Leave, Birthday leave, Bereavement Leave and Paid Leave for personal time off
• Ample growth and learning opportunities
• Remote work opportunities
• Focus on work/life balance
• Immigration Program supporting immigration to Canada for eligible employees