Enable job alerts via email!

Senior Compliance Analyst (Tech)

Integrated Resources, Inc.

Mississauga

On-site

CAD 80,000 - 110,000

Full time

30+ days ago

Job summary

An established industry player is seeking a dedicated professional to enhance its digital security and privacy operations. In this role, you will collaborate with a dynamic team to implement innovative security concepts and ensure compliance with regulations like GDPR and HIPAA. Your expertise will guide the organization in navigating complex compliance landscapes while promoting a culture of security awareness. This position offers the chance to make a significant impact in a fast-paced environment where your contributions will help shape the future of healthcare technology. Join us in our mission to transform lives through science and technology.

Qualifications

  • 5+ years of experience in Information Security, Privacy & Risk Management.
  • Fluent in English with excellent verbal and written skills.

Responsibilities

  • Oversee compliance activities and coordinate audit work.
  • Conduct risk assessments and manage multiple projects simultaneously.

Skills

Information Security
Privacy Management
Risk Management
Audit Experience
Project Management
Cloud Security
Vulnerability Management
Communication Skills

Education

University degree in Computer Science
Equivalent experience

Tools

AWS
Jira
GRC Tools

Job description

Description:
At Client, we are passionate about transforming patients' lives and we are fearless in both decision and action - we believe that good business means a better world. That is why we come to work each day. We commit ourselves to scientific rigor, unassailable ethics, and access to medical innovations for all. We do this today to build a better tomorrow.
Data security and privacy are key success factors in our digital transformation and essential to reach our ambitions.
You are inspired to contribute to the overall Client vision by applying end-to-end product security and privacy operations to keep our products and services secure and privacy compliant throughout the entire lifecycle. You believe in the potential of science, technology, data, and insights to improve the standard of care for humankind and you are eager to help navigate through unchartered territory to lift this potential.

The opportunity
As a member of the Compliance Product Team, you are given this opportunity in a team with a strong focus on collaboration and teamwork to support the Digital Products domain with state-of-the-art and innovative security and privacy concepts.
You will oversee or consult on technical architecture implementation activities, particularly for new and/or shared solutions.
You coordinate compliance activities at a global/regional level.
You help others (like engineers, cross-functional team members) interpret laws and regulations (like GDPR, HIPAA, HITRUST, and other regulations) correctly and ensure consistent adherence.

In addition, you will:

  1. Help with audit related work internally and externally - check controls compliance, collect evidence and coordinate audit work (like ISO 27001, 27017, and 27018).
  2. Coordinate routine activities like Pen Testing, Disaster Recovery and tasks stemming from them, recording results in tools like Jira, tracking any findings and remediation work.
  3. Define and implement security and privacy risk management governance and insights.
  4. Assist in drafting new or updated compliance policies and procedures, including specifying actual or potential implications to existing business operations and practices.
  5. Help prepare and deliver communication and training materials/sessions to educate others on the evolving compliance landscape and potential new or updated policies and related changes.
  6. Leverage your working knowledge of controls for cloud security, mobile application security, data privacy laws, AWS architecture, and services.
  7. Put in practice your project management skills and ability to manage multiple projects simultaneously to meet objectives and key deadlines.
  8. Conduct Risk assessments by analyzing the current risks and identifying potential risks that are affecting the business and product groups.

Who you are
You have a University degree in computer science, engineering, law, business or other related fields, or equivalent experience.
You bring experience working in a multicultural environment and proven cultural awareness.
You are fluent in English on a business level with excellent verbal and written skills; other languages welcome, but not required.
You have a minimum of 5+ years related work experience in Information Security, Privacy & Risk Management, Audit.

You bring solid experience in:
  1. Conducting or being the subject of security and/or privacy audits.
  2. Working with cloud environments required.
  3. Expert planner with business process definition experience and a strong IT aptitude.
  4. System hardening, analysis, and vulnerability management.
  5. Understanding of applicable and accepted audit and risk frameworks (such as COBIT, NIST, and ISO), standards (ISO 27000 family, HITRUST) and government guidelines and laws (HIPAA, GDPR).
  6. Clinical workflow solutions or in a clinical environment a plus.
  7. Knowledge of AWS and Cloud Security preferred.
  8. Relevant certifications like CISA, CISM, CRISC, CISSP preferred.

You bring the following competencies:
  1. Strong business acumen; sensitive to business needs; view change as an opportunity; eager to work in a fast-paced environment.
  2. Best in class attitude; challenge status constructively and contribute to improvements; results oriented; ability to influence; solution-oriented mindset.
  3. Strong organizational skills and ability to prioritize and manage multiple projects simultaneously if needed.
  4. Effective at engaging with teams in various functions and across different levels.
  5. Pro-active and confident individual who is committed to driving change.
  6. Ability to communicate complex and highly technical information clearly and concisely.
  7. Commitment to working as a team player across Business Areas and Divisions.
  8. Excellent interpersonal skills with high cross-cultural sensitivity.
  9. Healthcare software experience preferred.

Compliance Tech
With the great knowledge in GRC tooling preferably GRC hands-on experience and ability to identify and automate Quality Privacy Risk and Compliance tasks throughout multiple internal and external stakeholders integrated into our services to help in upcoming FedRAMP, C5 or similar attestations and authorizations.
Understands Quality, Risk, Privacy and Compliance from a technical perspective and is able to articulate and communicate the same in a written format with fluency in English. Ability to understand what the stakeholders or consumers do not and bring it to surface. Knowledge to write clear Policy and Standard Operating Procedures.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.