Platform Security & Governance Engineer

RAN BioLinks

Toronto

On-site

CAD 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

RAN BioLinks is looking for a Platform Security & Governance Engineer based in Canada. This role involves protecting clinical research data, enforcing access controls, and ensuring compliance with regulations like PIPEDA and ISO 27001.

Candidates should have over 4 years in security engineering and a Bachelor's degree in a related field. Join us to play a crucial role in maintaining data security and governance.

Qualifications

  • 4+ years in application/platform security or security engineering.
  • Strong understanding of authentication and authorization.
  • Familiarity with privacy and security frameworks like PIPEDA, GDPR.

Responsibilities

  • Design and enforce role-, study- and site-scoped access control.
  • Own the immutable audit trail across every module.
  • Drive data governance, including classification and retention.

Skills

Application/platform security
Authentication and authorization
Encryption
Secrets management
Audit logging
Compliance requirements

Education

Bachelor's degree in Computer Science, Cybersecurity or related field
Master's degree (not required)

Job description

Platform Security & Governance Engineer
About the role

Clinical research data is among the most sensitive data there is — participant information, safety records, regulatory documents, and the evidence trials are ultimately inspected on. MAESTRO's job is not only to protect that data, but to prove it is protected, on demand, to auditors and regulators. This role owns both halves of that promise.

You'll own how MAESTRO enforces access, records every consequential action, and demonstrates compliance — from role-, study- and site-scoped access control, to immutable audit trails, to the governance program behind our certifications and our customers' inspections. Security and governance here aren't a gate at the end; they're a core part of the product we sell.

This is a hands‑on role for someone who can move fluidly between engineering controls and the compliance program they satisfy.

What you'll do
  • Design and enforce role-, study- and site-scoped access control and separation of duties across a multi‑tenant platform.
  • Own the immutable audit trail — a defensible record of who changed what, and when — across every module.
  • Drive data governance: classification, retention, residency, encryption and key management, so sensitive data stays in‑region and within policy.
  • Lead PIPEDA alignment and SOC 2 / ISO 27001 readiness — owning policies, evidence collection, and vendor/third‑party reviews.
  • Run threat modelling and security reviews, and coordinate penetration testing and remediation.
  • Translate regulatory expectations (21 CFR Part 11, EU Annex 11, ICH GCP, Health Canada) into concrete, testable engineering controls — and into the evidence that proves they work.
What you'll bring
  • 4+ years in application/platform security or security engineering.
  • Strong understanding of authentication and authorization, encryption, secrets management and audit logging.
  • Familiarity with privacy and security frameworks — PIPEDA, GDPR, SOC 2, ISO 27001, NIST.
  • The ability to turn compliance requirements into shipped engineering controls, not just documentation.
Nice to have
  • Experience in healthcare, life‑sciences or other regulated domains.
  • Knowledge of 21 CFR Part 11 audit‑trail and electronic‑signature requirements.
  • Hands‑on experience with cloud security tooling and infrastructure‑as‑code security scanning.
Education
  • Minimum: a Canadian Bachelor's degree (baccalauréat) in Computer Science, Cybersecurity, Information Security/Systems or a related technical field — or a college diploma / advanced diploma (DEC, 2–3 years) in a relevant program combined with significant security‑engineering experience.
  • An asset (not required): a Master's degree (maîtrise) in cybersecurity, information security or a related technical field; or recognized security or privacy certifications (e.g. CISSP, CISM, CCSP, or equivalent).
  • Internationally educated candidates are welcome; foreign credentials should be assessed for Canadian equivalency (e.g. WES, ICAS or a comparable recognized service) to confirm the equivalent Canadian level.
Location & eligibility

This role is open only to candidates who are based in Canada and legally entitled to live and work in Canada (Canadian citizens, or permanent/legal residents with valid Canadian work authorization). We are not able to sponsor relocation or work authorization for this position.

Why join

Security and governance aren't an afterthought here — they're the product. You'll build the controls that let a customer hand an inspector a link instead of scrambling for evidence, and you'll see your work directly enable trials to keep moving.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Full-Stack Engineer — Clinical Trials
Senior Full-Stack Engineer — Clinical Trials

RAN BioLinks • Toronto

On-site
CAD 80,000 - 100,000
Data Security Analyst
Data Security Analyst

Pomerleau • Montreal (administrative region)

Hybrid
CAD 90,000 - 130,000
RRSP with up to 5% employer matching
Hybrid work model for corporate roles
Employee stock ownership program
+3
Senior Cloud Security Engineer, Information Security
Senior Cloud Security Engineer, Information Security

Peoples Group • Calgary

Hybrid
CAD 140,000 - 190,000
Hybrid work environment
Profit sharing
RRSP matching
+2
Senior Cloud Security Engineer, Information Security
Senior Cloud Security Engineer, Information Security

Peoples Group • Toronto

Hybrid
CAD 140,000 - 180,000
Senior Cloud Security Engineer, Information Security
Senior Cloud Security Engineer, Information Security

Peoples Group • Vancouver

Hybrid
CAD 150,000 - 190,000
Hybrid work environment
Competitive salary
Profit sharing
Senior Security Engineer
Senior Security Engineer

Magnet Forensics • Canada

On-site
CAD 111,000 - 191,000
Competitive Compensation
Healthcare Benefits
Retirement Benefits
+1
Intermediate to Senior Software Engineer
Intermediate to Senior Software Engineer

DataStealth.io • Mississauga

On-site
CAD 100,000 - 110,000
Information Security Engineer (Cloud Security Engineer) - 1 Year Contract
Information Security Engineer (Cloud Security Engineer) - 1 Year Contract

Numeris • Toronto

On-site
CAD 85,000 - 90,000
Health, Dental, Vision and Personal
Perkopolis discounts
Cyber Security Manager
Cyber Security Manager

Akkodis • Toronto

Hybrid
CAD 120,000 - 180,000
Performance-based bonuses
Defined contribution pension plan
Professional growth opportunities
+4
IT Security Analyst
IT Security Analyst

Pomerleau • Montreal (administrative region)

Hybrid
CAD 80,000 - 120,000
RRSP with up to 5% employer matching
Hybrid work model for corporate roles
Employee stock ownership program
+3