FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in managing InfoSec GRC processes, including SOC 2 and ISO compliance, while effectively coordinating audit evidence and vendor risk management. Proficient in vulnerability management and automation, with strong communication skills in both French and English.
Highest-signal resume keywords
SOC 2 Type II ManagementISO 27001 ComplianceVulnerability ManagementB2B Client Security QuestionnairesCISA, CISSP, CRISC Certification
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Control MappingEvidence CollectionPolicy Lifecycle ManagementDPIA Process OwnershipAudit Evidence PreparationAccess Review ManagementKPI ReportingDisaster Recovery EvidenceAutomation WorkflowsDue Diligence Questionnaires
Soft Skills
Meticulous Attention to DetailStrong PrioritizationClient CommunicationTeam CollaborationEscalation Management
Tools & Technologies
TenableSentinelOnePower AutomateAzureSQL
Certifications & Qualifications
CISACISSPCRISCISO 27001 Lead ImplementerISO 27001 Auditor
Industry Keywords
InfoSec GRCIT AuditRegulated ServicesGDPRPIPEDAQuebec Law 25Insurance IndustryWealth ManagementMSSP ManagementBusiness Continuity
Tech Stack
Tools & technologiesAzureSQL
About the role
Key responsibilities & impact- Support the control environment for SOC 2, ISO 27001, ISO 22301, and ISO 42001 through control mapping, evidence collection, and auditor liaison
- Manage policy lifecycle, including review, versioning, publication, and attestation
- Prepare audit evidence packages and report gaps to closure
- Own the end-to-end DPIA process, vendor intake, vendor risk register, and fourth-party tracking
- Complete due diligence questionnaires and RFP security sections within SLA and maintain a response library
- Coordinate client audit evidence requests; issue SOC 2 reports and bridge letters
- Serve as security point of contact for Sales, pre-sales, and Legal
- Own quarterly access reviews across OIPA, Design, SQL, Azure, and bastion systems
- Drive access-review automation with the managed services partner
- Track vulnerability findings, drive remediation tickets, and provide trend reporting
- Coordinate the annual penetration test and drive findings to closure
- Generate monthly patching tickets, confirm completion, and maintain server software/middleware inventory
- Run monthly security awareness training, produce completion reporting, escalate outstanding completions, and administer the annual training needs survey
- Supply disaster recovery and business continuity evidence for client requests; support BIA cycles and tabletop exercises
- Produce recurring KPI and leadership reporting
- Identify manual control work suitable for automation and build or commission agentic workflows with SOPs
Requirements
What you’ll need- 5+ years in InfoSec GRC or IT audit in software/regulated services
- Hands-on ownership of at least one full SOC 2 Type II or ISO 27001 cycle
- Experience with B2B client security questionnaires/due diligence
- Working knowledge of GDPR, Quebec Law 25, and PIPEDA
- Practical familiarity with vulnerability management/endpoint tooling (Tenable, SentinelOne preferred)
- Fluent in French and English
- Proven ability to drive completion through teams you don’t manage; comfortable escalating slipped commitments
- Clear, client/auditor-ready writing; strong prioritization under high inbound demand; meticulous attention to detail
- CISA, CISSP, CRISC, or ISO 27001 Lead Implementer/Auditor preferred
- ISO 42001 or AI management system exposure preferred
- Insurance/wealth management industry experience preferred
- Agentic/Power Automate automation experience preferred
- Experience managing an MSSP preferred
Benefits
Comp & perks- Career advancement opportunities
- Collaborative workspace
- Medical benefits available day 1
- Dental benefits available day 1
- Retirement Plan available day 1
- Telemedicine Program available day 1
- Employee Assistance Program available day 1
- Flexible hours
- Educational Support (LinkedIn Learning, LOMA Courses and Equisoft University)
