IT & Security Manager / Administrator - Toronto On.

dokaco

Toronto

On-site

CAD 110,000 - 160,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Dokainish & Company seeks an IT & Security Manager/Administrator to lead security governance, cloud security, and SOC 2 readiness across corporate and product environments. You will partner with Product & Technology to enforce security standards and drive risk reduction.

The role covers administration of Microsoft 365, Entra ID, Azure, and end-to-end security controls, with oversight of incidents, vulnerability management, and vendor security assessments.

Qualifications

  • Bachelor's degree in a related technical field.
  • 5–8 years of professional experience in IT administration, infrastructure, cybersecurity, cloud environments, or technology operations.
  • Hands-on experience administering Microsoft 365, Microsoft Entra ID, and Microsoft Azure.
  • Strong understanding of identity and access management, MFA, conditional access, privileged access, endpoint security, encryption, device management, and least-privilege principles.
  • Experience implementing cybersecurity policies, standards, technical controls, and governance processes.

Responsibilities

  • Administer and maintain Microsoft 365, Entra ID, Azure identities, access controls, and licensing.
  • Oversee employee technology lifecycle including provisioning and offboarding.
  • Manage corporate endpoints, devices, licenses, and security controls.
  • Implement endpoint management, patching, antivirus/EDR, encryption, and MFA.
  • Maintain security policies, standards, and governance documentation.
  • Lead SOC 2 readiness activities and coordinate with auditors.

Skills

Security governance
Analytical skills
Documentation
Stakeholder management
Cybersecurity

Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, Computer Engineering

Tools

Microsoft 365
Microsoft Entra ID
Microsoft Azure

Job description

About Dokainish & Company

Since 2011, Dokainish & Company has been delivering world-class project management and project controls consultancy services. We specialize in working diligently and collaboratively with our clients to achieve long-lasting, impactful results across numerous business functions.

Our areas of expertise include Project Controls, Project Management, Quantitative Risk Analysis, Organizational Change Management, Enterprise Reporting, Estimating, Asset Management, and System Implementation for Capital Projects. We draw upon decades of project experience to deliver customized solutions to our clients’ most complex challenges.

We are currently seeking an experienced IT & Security Manager / Administrator to join our growing team and lead the administration, security, and governance of our corporate and product technology environments.

The Opportunity

The IT & Security Manager / Administrator will be responsible for maintaining a secure, reliable, and professionally managed technology environment across Dokainish & Company.

This is a hands-on role spanning corporate IT administration, cybersecurity, cloud infrastructure, privacy, technology risk, and security compliance. The role will manage the company’s Microsoft and Azure environments, employee technology lifecycle, endpoint and identity security, and technology controls while supporting the secure development and operation of internal tools, client technology solutions, and software products.

The successful candidate will work closely with the Product & Technology team and company leadership to establish practical security standards, strengthen technology governance, support client security requirements, and advance the organization’s readiness for frameworks such as SOC 2.

Location & Travel

This is a full-time, non-remote, in-office position based in downtown Toronto, Ontario.

Key Responsibilities
  • Administer and maintain Microsoft 365, Microsoft Entra ID, Azure, user accounts, groups, permissions, licensing, and identity and access controls.
  • Manage the employee technology lifecycle, including account provisioning, device setup, onboarding, role changes, and secure offboarding.
  • Administer corporate laptops, endpoints, applications, software licenses, mobile devices, and other technology assets.
  • Implement and maintain endpoint management, patching, antivirus/EDR, encryption, device compliance, MFA, conditional access, and related security controls.
  • Manage corporate networking, Wi-Fi, VPN, backup, recovery, and other core IT infrastructure.
  • Establish and maintain identity and access management standards based on least privilege, appropriate segregation of duties, and controlled privileged access.
  • Maintain cybersecurity policies, standards, procedures, and technical controls appropriate to the company’s operations and client requirements.
  • Monitor vulnerabilities, security alerts, and technology risks, and coordinate remediation with internal teams and external providers.
  • Manage cybersecurity incidents, including investigation, containment, escalation, remediation, root-cause analysis, and documentation.
  • Coordinate penetration testing, vulnerability assessments, and security reviews for corporate infrastructure, internal applications, client technology solutions, and software products.
  • Support secure cloud and application architecture by reviewing authentication, authorization, data storage, integrations, secrets management, environment segregation, logging, and deployment controls.
  • Work with software development teams to embed appropriate security requirements throughout the software development lifecycle.
  • Establish minimum security requirements for internally developed applications, SaaS products, client technology builds, and third-party integrations.
  • Support security and privacy requirements associated with client technology Statements of Work, proposals, and delivery engagements.
  • Lead the organization’s SOC 2 readiness activities, including control design, evidence collection, documentation, remediation tracking, and coordination with external auditors or advisors.
  • Support client security questionnaires, vendor assessments, cybersecurity due diligence, insurance requirements, and technology compliance reviews.
  • Maintain technology risk registers, access reviews, asset inventories, system documentation, incident records, and other security and governance documentation.
  • Assess third-party software and technology vendors for cybersecurity, privacy, operational, and data-handling risks.
  • Develop and maintain backup, disaster recovery, incident response, and business continuity procedures, and coordinate periodic testing where required.
  • Provide day-to-day IT support and troubleshoot employee technology, access, device, application, and infrastructure issues.
  • Act as a trusted advisor to leadership and the Product & Technology team on cybersecurity, privacy, infrastructure, technology risk, and required security investments.
Qualifications & Experience
  • 4-year university degree in Computer Science, Information Technology, Cybersecurity, Information Systems, Computer Engineering, or a related technical field.
  • 5–8 years of relevant professional experience across IT administration, infrastructure, cybersecurity, cloud environments, or technology operations.
  • Demonstrated hands-on experience administering Microsoft 365, Microsoft Entra ID, and Microsoft Azure environments.
  • Strong understanding of identity and access management, MFA, conditional access, privileged access, endpoint security, encryption, device management, and least-privilege principles.
  • Experience administering Windows endpoints and modern device-management and endpoint-security technologies.
  • Practical knowledge of cloud security, network security, vulnerability management, logging and monitoring, backup and recovery, and incident response.
  • Experience implementing or administering cybersecurity policies, standards, technical controls, and technology governance processes.
  • Experience supporting cybersecurity or compliance frameworks such as SOC 2, ISO 27001, NIST Cybersecurity Framework, or CIS Controls is strongly preferred.
  • Experience supporting security audits, client security assessments, vendor risk assessments, security questionnaires, or compliance evidence collection.
  • Understanding of application security and secure software development practices, including authentication, authorization, secrets management, data protection, environment segregation, vulnerability management, and secure deployment.
  • Experience working with software development, product, or technical delivery teams is strongly preferred.
  • Working knowledge of privacy and data-protection requirements applicable to corporate, employee, client, and application data.
  • Experience coordinating penetration testing, vulnerability assessments, remediation activities, or external security providers is an asset.
  • Relevant professional certifications such as CISSP, CISM, CompTIA Security+, Microsoft Certified: Azure Administrator Associate, Microsoft Certified: Azure Security Engineer Associate, or equivalent are considered an asset.
  • Ability to independently troubleshoot technical issues, evaluate security risks, develop practical solutions, and execute required remediation.
  • Strong analytical, communication, documentation, and stakeholder-management skills.
  • Ability to communicate technical and cybersecurity risks clearly to both technical and non-technical stakeholders.
  • Comfortable operating in a growing organization where technology processes, infrastructure, governance, and controls are continuing to mature.
  • Must be legally eligible to work in Canada without sponsorship.
  • This is a full-time, non-remote, in-office position based in downtown Toronto, Ontario.
Note

This role description is intended to provide a general overview of the position. It is not an exhaustive list of all responsibilities, duties, skills, or qualifications required.

We take immense pride in our high-performing, collaborative team. We recognize and value the uniqueness of every individual, and you’ll be part of a growing consulting firm where your expertise will directly contribute to the security, reliability, and scalability of our technology environment.

We thank all applicants for their interest in joining Dokainish & Company. Please note that only those candidates considered for an initial interview will be contacted.

Notes

VACANCY STATUS: This job post is for a new position.

AI USAGE: Artificial intelligence may be used to support the initial screening and evaluation of applications for this position. Applications are also reviewed by members of our Talent Acquisition team, and all employment decisions are made by human decision-makers.

Dokainish & Company is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to age, gender, race, colour, religion, sexual orientation, gender identity, national origin, disability, age and veteran status, or any other protected status required by applicable law.

In accordance with the Ontario Human Rights Code, Accessibility for Ontarians with Disabilities Act, 2005, and Dokainish & Company AODA Policy, accommodation will be provided in all parts of the hiring process. Applicants need to make their needs known in advance.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Software Engineering Lead - Toronto, On.
Software Engineering Lead - Toronto, On.

Dokainish & Company • Toronto

On-site
CAD 150,000 - 190,000
Software Engineering Lead - Toronto, On.
Software Engineering Lead - Toronto, On.

dokaco • Toronto

On-site
CAD 150,000 - 210,000
Project Controls Manager - Toronto, On.
Project Controls Manager - Toronto, On.

dokaco • Toronto

On-site
CAD 120,000 - 180,000
Project Controls Manager - Toronto, On.
Project Controls Manager - Toronto, On.

Dokainish & Company • Toronto

Hybrid
CAD 110,000 - 170,000
Senior Scheduler - Toronto, On
Senior Scheduler - Toronto, On

Dokainish & Company • Toronto

On-site
CAD 90,000 - 140,000
Senior Scheduler - Toronto, On.
Senior Scheduler - Toronto, On.

Dokainish & Company • Toronto

On-site
CAD 110,000 - 150,000
Senior Cost Manager - Project Controls - Calgary, AB
Senior Cost Manager - Project Controls - Calgary, AB

dokaco • Calgary

Hybrid
CAD 120,000 - 180,000
Quality Assurance Lead (SAP S/4HANA) - Toronto, On.
Quality Assurance Lead (SAP S/4HANA) - Toronto, On.

dokaco • Toronto

On-site
CAD 120,000 - 160,000
Senior Scheduler - Toronto, On.
Senior Scheduler - Toronto, On.

dokaco • Toronto

On-site
CAD 110,000 - 140,000
IT Systems & Database Administrator
IT Systems & Database Administrator

TAO Solutions Inc. • Toronto

On-site
CAD 19,000 - 34,000