Sr. Compliance Officer
- Location: Ottawa, Ontario (Hybrid 3 days in office, 2 days work from home)
- Pay Rate: $51.50/hr
- Contract Length: 12 months
Responsibilities:
1. Cybersecurity Compliance Programs:
- Serve as the point of contact for managing all compliance and audit activities related tassigned Cloud Services, acting as a trusted partner tthe assigned Cloud Services.
- Lead interactions with both internal and external auditors (including external regulatory bodies, internal Thales auditors, and third-party auditors), ensuring efficient and effective audit processes.
- Support the development, implementation, and maintenance of compliance programs tmeet the organization's strategic objectives and regional regulatory requirements.
2. Audit Strategy and Execution:
- Lead the preparation and execution of internal and external audits across assigned Cloud Service, ensuring compliance with established corporate policies/standards, industry standards, and regulatory requirements.
- Develop and implement audit strategies for the assigned Cloud Services, ensure audits are proactive, risk-based, and aligned with business priorities, while ensuring a continuous improvement approach.
3. Advanced Compliance and Risk Management:
- Lead and enhance the risk management and improve controls for assigned Cloud Services, ensuring compliance with both internal policies and external regulatory requirements.
- Support and improve the Cloud Services Change Management, Business Continuity Plan (BCP), and Disaster Recovery (DR) related controls tensure compliance with corporation policies/standards and business continuity regulations and best practices.
- Maintain and update key governance, risk management and compliance documentation, including ISMS 27001, IS27017/18 mandatory documents, ensuring alignment with corporate policy and evolving industry standards.
4. Policy Development and Process Improvement:
- Support the develop, review, and implement cybersecurity compliance policies, standards and procedures tensure continuous improvement of internal controls, audit readiness, and risk mitigation.
- Recommend and drive the implementation of cybersecurity policies and standards aimed at improving Cloud Services’ compliance posture, ensuring policies are aligned with business objectives and regulatory expectations.
- Regularly assess and refine compliance workflows toptimize efficiency and alignment with evolving compliance frameworks.
5. Global Compliance Management:
- Partner with cross-functional teams in analyzing cybersecurity compliance requirements cross functions, ensuring adherence tlocal and international regulations (e.g., GDPR, CCPA, etc.).
- Support the development of global compliance strategies, ensuring supported Cloud Services units are aware of evolving global cybersecurity and privacy laws and that cross-border data transfers are compliant with corporate policies and standards.
6. Support and Advisory for Cloud Services Units:
- Provide cybersecurity compliance guidance and support tsales, presales, product management, and other business units on cybersecurity compliance-related matters, including RFPs, RFIs, security & compliance questionnaires, and client security inquiries.
- Be the primary advisor tassigned Cloud Services on complex compliance and security topics, providing recommendations for risk mitigation, process improvements, and regulatory adherence.
7. Customer and Stakeholder Engagement:
- Engage directly with key customers taddress complex compliance and security questions, and tsupport ongoing trust-building initiatives.
- Ensure the communication of compliance requirements and audit results trelevant stakeholders, including customers, partners, and regulators.
8. Continuous Monitoring and Reporting:
- Oversee the ongoing monitoring of compliance programs tensure that they remain effective and aligned with the organization’s security goals and business objectives.
- Develop and provide regular compliance reports tsenior management, highlighting audit results, risk areas, and the status of corrective actions.
Minimum Requirements:
- 7+ years of experience in cybersecurity compliance and certifications, preferably within cloud services environments.
- Proven experience independently leading and conducting internal and external audits, including risk assessments and remediation activities.
- Strong knowledge and experience working with industry-leading information security standards, such as: IS27001, IS27017/27018, SOC2, FedRAMP, CSA, PCI-DSS and Data Privacy Regulations (e.g. GDPR)
- Solid understanding of cloud environments (e.g., AWS, Azure, GCP) and cloudsecurity fundamentals.
- Demonstrated ability teffectively communicate and collaborate with a broad range of internal and external stakeholders, including business units, senior leadership, auditors, and regulators.
Preferred Qualifications
- Experience: 7-10 years of experience in cybersecurity compliance, risk management, or information security. Experience in cloud computing or SaaS environments is highly preferred.
- Certifications: Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), or similar certifications are strongly preferred.
- Expertise in Standards & Frameworks: Strong knowledge and practical experience with IS27001, SOC 2, PCI DSS, and other relevant frameworks (e.g., GDPR, NIST).
- Leadership Skills: Proven experience in leading complex audits, with the ability twork closely with senior leadership, legal, data privacy, operations, and technical teams.
- Communication Skills: Excellent written and verbal communication skills, with the ability tpresent complex compliance and audit findings tboth technical and non-technical stakeholders.
- Strategic Thinking: Ability take a strategic approach tcompliance management, with a focus on risk mitigation, continuous improvement, and aligning compliance initiatives with business goals.
Looking for meaningful work? We can help!
We strive to build teams that reflect the diversity of the communities we work in. We encourage all qualified applicants to apply, including people from traditionally underrepresented groups such as women, visible minorities, Indigenous peoples, people identifying as LGBTQ2SI, veterans, and people with visible/nonvisible disabilities.
We have a dedicated webpage for accommodations where you can learn more about what we offer and request accommodation: https://raise.jobs/accommodations/
In order to submit candidates for roles, our clients will sometimes require personal information to confirm the identity of applicants and their legal status to work. Raise will never ask you for personal or banking information unless you have been selected for a job. If you are ever unsure about the legitimacy of this or another job posting by Raise (or have any other questions), please contact us at +1 800-567-9675 or hello@raiserecruiting.com
We value inclusivity and equity in the job application process, and want it to be easy to request accommodations for people with disabilities.
#CEN24