Security Assurance and Compliance Specialist

Equisoft Inc. (Canada)

Montreal (administrative region)

Hybrid

CAD 90,000 - 130,000

Full time

9 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Educational Support
Medical
Dental
Retirement Plan
Telemedicine Program
Employee Assistance Program
etc.

Job summary

Equisoft is seeking a Specialist, Security Assurance and Compliance to join our Quebec City hub. This hybrid role focuses on governance, evidence collection, and automation to support audits and control activities across teams you don’t manage.

You’ll coordinate SOC 2, ISO 27001, ISO 22301, and ISO 42001 programs, lead DPIA reviews, manage vendor risk, and drive quarterly access reviews and vulnerability remediation with a strong emphasis on documentation and process improvement.

Qualifications

  • 5+ years in InfoSec GRC or IT audit in software/regulated services.
  • Hands-on ownership of at least one full SOC 2 Type II or ISO 27001 cycle.
  • Experience with B2B client security questionnaires/due diligence.
  • Working knowledge of GDPR, Quebec Law 25, and PIPEDA.
  • Fluent in French and English for international coordination.

Responsibilities

  • GRC: support SOC 2, ISO 27001, ISO 22301, and ISO 42001; control mapping, evidence collection, auditor liaison.
  • Vendor risk: manage the end-to-end DPIA process, DPA/sub‑processor analysis, SCC/residency checks, risk rating.
  • Client security: complete due diligence questionnaires and RFP security sections; coordinate audit evidence requests.
  • Identity governance: own quarterly access reviews (OIPA, Design, SQL, Azure) and automation with MSP.
  • Vulnerability & pentest: track findings, drive remediation tickets, coordinate annual pentest.
  • Patch & config: monthly patching tickets and inventory maintenance.
  • Security awareness: run training cycles and report completion.
  • BCDR: provide evidence for drills and continuity exercises.

Skills

InfoSec GRC
IT audit
GDPR knowledge
French & English

Tools

Tenable
SentinelOne
Azure
SQL
Power Automate

Job description

HYBRID - Québec City, Canada

Hiring Location: Canada (Montreal)

You are working hybrid in a collaborative workspace

Full-time Permanent Role

Flexible hours

Number of hours per week: 40

Educational Support (LinkedIn Learning, LOMA Courses and Equisoft University)

Role: The Specialist, Security Assurance and Compliance reports to the Manager, Information Security and GRC.

This role is the operating centre of Equisoft’s security governance program. You’ll keep four certifications current (SOC 2 Type II, ISO 27001, ISO 22301, ISO 42001), answer the security questions standing between Equisoft and closed business, and drive recurring control activities — access reviews, patching, vulnerability remediation, pentest follow‑up, and awareness training — to completion across teams you don’t manage. This is a coordination, evidence, and automation role, not an engineering one: you define what must happen, track whether it did, produce proof, and automate what shouldn’t require a person. Success is measured by audit outcomes, questionnaire turnaround time, and the percentage of control work running on schedule without escalation.

Why Choose Equisoft?

Equisoft is a stable organization offering career advancement opportunities and fostering a stimulant environment with 950+ employees.

Benefits available day 1:
  • Medical
  • Dental
  • Retirement Plan
  • Telemedicine Program
  • Employee Assistance Program
  • etc.
What You’ll Do:
  • GRC: Support the control environment for SOC 2, ISO 27001, ISO 22301, and ISO 42001 — control mapping, evidence collection, auditor liaison. Manage policy lifecycle (review, versioning, publication, attestation). Prepare audit evidence packages and report gaps to closure.
  • Vendor & Third-Party Risk: Own the end-to-end DPIA process (Trust Center/SOC review, DPA/sub‑processor analysis, SCC/residency checks, AI assessment, risk rating), vendor intake, the vendor risk register, and fourth‑party tracking — chasing missing certs, bridge letters, and remediation commitments.
  • Client Security Assurance: Complete due diligence questionnaires and RFP security sections within SLA; maintain a response library. Coordinate client audit evidence requests. Issue SOC 2 reports and bridge letters. Serve as security point of contact for Sales, pre‑sales, and Legal.
  • Identity Governance: Own the quarterly access review (OIPA, Design, SQL, Azure, bastion) — data collection, reviewer follow‑up, revocations, closure evidence. Drive access‑review automation with the managed services partner.
  • Vulnerability & Pentest Management: Track findings (Tenable, UpGuard, SentinelOne, external ASM), categorize by product/owner, drive remediation tickets and trend reporting. Coordinate the annual pentest (scoping, scheduling, provisioning) and drive findings to closure.
  • Patch & Configuration Hygiene: Generate monthly patching tickets, confirm completion with infrastructure, and maintain the server software/middleware inventory.
  • Security Awareness: Run the monthly training cycle, produce completion reporting, escalation outstanding completions, and administer the annual training needs survey.
  • BCDR Support: Supply DR exercise/continuity evidence for client requests; support BIA cycles and tabletop exercises.
  • Reporting & Automation: Produce recurring KPI/leadership reporting. Identify manual control work suitable for automation (asset inventory, ticket creation, evidence extraction, training reporting) and build/commission agentic workflows, with SOPs for each.
Requirements Technical
  • 5+ years in InfoSec GRC or IT audit in software/regulated services
  • Hands‑on ownership of at least one full SOC 2 Type II or ISO 27001 cycle
  • Experience with B2B client security questionnaires/due diligence
  • Working knowledge of GDPR, Quebec Law 25, and PIPEDA
  • Practical familiarity with vulnerability management/endpoint tooling (Tenable, SentinelOne preferred)
  • Fluent in French and English (due to recurrent contact with international teams and customer)
  • Proven ability to drive completion through teams you don’t manage; comfortable escalating slipped commitments
  • Clear, client/auditor‑ready writing; strong prioritization under high inbound demand; meticulous attention to detail
  • Nice to Have: CISA, CISSP, CRISC, ISO 27001 Lead Implementer/Auditor ISO 42001 or AI management system exposure Insurance/wealth management industry experience Agentic/Power Automate automation experience Experience managing an MSSP

Equisoft is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.

What is Equisoft?

Equisoft is a global provider of digital solutions for the insurance and investment sectors, trusted by more than 300 of the world’s leading financial institutions. We offer a comprehensive ecosystem of scalable solutions that help our clients meet the challenges of digital transformation—driven by a business‑centric approach, deep industry knowledge, cutting‑edge technologies, and a multicultural team of experts located across North America, the Caribbean, Latin America, Europe, Africa, Asia, and Australia.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Assurance and Compliance Specialist
Security Assurance and Compliance Specialist

Equisoft • Quebec

Hybrid
CAD 100,000 - 140,000
Medical
Dental
Retirement Plan
+5
Security Assurance and Compliance Specialist
Security Assurance and Compliance Specialist

Socket.dev • Montreal (administrative region)

Hybrid
CAD 110,000 - 130,000
Hybrid workspace
Benefits from day 1
Flexible hours
+1
Security Assurance and Compliance Specialist
Security Assurance and Compliance Specialist

Equisoft • Montreal (administrative region)

Hybrid
CAD 90,000 - 130,000
Medical & Dental
Retirement Plan
Telemedicine Program
+4
Senior Project Manager IT - SaaS
Senior Project Manager IT - SaaS

EquiSoft • Montreal (administrative region)

Hybrid
CAD 110,000 - 150,000
Day 1 Benefits
Flexible hours
Education Support
Global Compensation Specialist
Global Compensation Specialist

Equisoft Inc. (Canada) • Montreal (administrative region)

Hybrid
CAD 100,000 - 150,000
Medical insurance
Dental insurance
Retirement plan
+4
Global Delivery Manager (IT- SaaS)
Global Delivery Manager (IT- SaaS)

Equisoft Inc. (Canada) • Montreal (administrative region)

Hybrid
CAD 90,000 - 135,000
Medical
Dental
Retirement Plan
+3
Security GRC Specialist - SOC 2 & ISO 27001 Compliance
Security GRC Specialist - SOC 2 & ISO 27001 Compliance

Equisoft Inc. (Canada) • Montreal (administrative region)

Hybrid
CAD 90,000 - 130,000
Educational Support
Medical
Dental
+4
GRC Security & Compliance Specialist — Hybrid QC
GRC Security & Compliance Specialist — Hybrid QC

Socket.dev • Montreal (administrative region)

On-site
CAD 110,000 - 130,000
Hybrid workspace
Benefits from day 1
Flexible hours
+1
Full-Stack Application Developer (Kotlin-Java/React)
Full-Stack Application Developer (Kotlin-Java/React)

Equisoft • Montreal (administrative region)

Hybrid
CAD 90,000 - 120,000
Medical Insurance
Dental Insurance
Retirement Plan
+3
Global Compensation Specialist
Global Compensation Specialist

Equisoft • Montreal (administrative region)

Hybrid
CAD 90,000 - 140,000
Medical benefits from day 1
Dental benefits
Retirement plan
+4