IT Security Risk & Compliance Specialist
LeverageTek Staffing Solutions is seeking an IT Security Risk & Compliance Specialist for a 6-month contract based in Ottawa.
Work Location: The candidate must work 1x/week onsite at the Ottawa client location.
Key Tasks
- Develop and perform cybersecurity risk, compliance, and threat management, focusing on threat risk assessments and risk management involving vendors, partners, and technology solutions.
- Provide IT security and risk advisory support, including vendor and supply-chain security, SDLC, and project risks.
- Contribute to security risk and compliance management programs, governance frameworks, and processes.
- Conduct IT security risk assessments, prepare assessment reports, and deliver summary presentations.
- Perform supply chain security assessments for IT products, SaaS, hosted services, and third-party partners to ensure security controls meet business needs.
- Improve risk assessment processes and governance documentation continuously.
- Support integration of security risk and compliance into IT architecture, engineering, and SDLC processes.
- Prepare high-standard reports, policies, standards, and cybersecurity guidance documentation.
- Develop and document cybersecurity policies, guidelines, and operational procedures.
- Provide high-quality support to IT and internal stakeholders, responding promptly and professionally.
- Perform other related duties as needed.
Key Qualifications
- 8+ years in IT security threat and risk assessments, with formal reporting experience.
- Expertise in assessing compliance against IT security frameworks, standards, or audit objectives.
- Experience in developing IT security policies, standards, and guidelines.
Qualifications
- University degree in Computer Science/Engineering or College diploma.
- Experience in risk, compliance, and security program planning and reporting.
- Knowledge of industry standards like NIST, ISO/IEC 27001/2, COBIT, SOC 2, PCI-DSS, etc.
- Experience with security controls for SaaS, Azure, Microsoft 365, on-premises infrastructure, and mobile devices.
- Proficiency in Azure and M365 compliance, vulnerability management, and security scoring.
- Experience with governance frameworks and documentation for security risk management.
- Knowledge of Microsoft Purview and information protection controls.
- Ability to develop security strategies and maturity assessments.
- Experience with GCP security concepts.
- Excellent communication skills and project management abilities.
Assets
- French language skills are a strong asset.
About LeverageTek Staffing Solutions
Founded in 2003, LeverageTek provides staffing solutions across North America, specializing in technology, accounting, finance, sales, HR, supply chain, and legal talent acquisition. We offer both contract and permanent staffing, executive search, and related services.
LeverageTek is committed to diversity, inclusion, and equal opportunity employment. Accessibility accommodations are available upon request.