Security & Compliance Specialist
Job description
Security & Compliance Specialist at Bamboohr.
About the role
As a Security & Compliance Specialist at Bamboohr, you will play a pivotal role in safeguarding our information systems and ensuring adherence to regulatory standards. Your expertise will help us maintain a secure environment while fostering trust with our clients and stakeholders. This position is ideal for individuals who are passionate about cybersecurity and compliance, and who thrive in a dynamic and collaborative environment. You will be instrumental in developing and implementing security policies, conducting risk assessments, and ensuring that our practices align with industry standards.
Key facts
What you'll do
- Develop, implement, and maintain security policies and procedures to protect sensitive information and ensure compliance with applicable laws and regulations.
- Conduct regular risk assessments to identify vulnerabilities within the organization's systems and processes, and recommend appropriate mitigation strategies.
- Collaborate with cross-functional teams to ensure that security measures are integrated into all aspects of the organization's operations.
- Monitor and analyze security incidents, breaches, and vulnerabilities, providing timely reports and recommendations for remediation.
- Stay current with emerging security threats, compliance regulations, and industry best practices to ensure that Bamboohr remains at the forefront of security and compliance.
- Facilitate security training and awareness programs for employees to promote a culture of security within the organization.
- Assist in the preparation for audits and assessments by regulatory bodies, ensuring that all necessary documentation and evidence are in place.
- Work closely with IT teams to implement security technologies and solutions that enhance the organization's security posture.
- Participate in incident response planning and execution, ensuring that the organization is prepared to respond effectively to security incidents.
- Maintain relationships with external vendors and partners to ensure compliance with security standards and practices.
- Prepare and present reports to senior management on the status of security initiatives and compliance efforts.
- Contribute to the continuous improvement of the organization's security framework and compliance programs.
Requirements
- Bachelor's degree in Information Technology, Cybersecurity, or a related field.
- A minimum of 3 years of experience in security and compliance roles, preferably within a technology-focused organization.
- Strong understanding of security frameworks and standards such as ISO 27001, NIST, and GDPR.
- Proven experience conducting risk assessments and vulnerability assessments.
- Familiarity with security technologies, including firewalls, intrusion detection systems, and encryption methods.
- Excellent analytical and problem-solving skills, with the ability to think critically under pressure.
- Strong communication skills, both written and verbal, with the ability to convey complex information to non-technical stakeholders.
- Relevant certifications such as CISSP, CISM, or CISA are highly desirable.
- Ability to work independently and collaboratively in a fast-paced environment.
Nice to have
- Experience with cloud security and compliance, particularly in AWS or Azure environments.
- Knowledge of privacy regulations and frameworks, including PIPEDA and CCPA.
- Familiarity with security incident response and management processes.
- Previous experience in a consulting role or working with external clients on security matters.
- Understanding of software development lifecycle (SDLC) and secure coding practices.
Skills & tools
- Proficient in security assessment tools and methodologies.
- Familiarity with compliance management software and frameworks.
- Knowledge of network security protocols and practices.
- Experience with data loss prevention (DLP) technologies.
- Strong project management skills, with the ability to manage multiple initiatives simultaneously.
Practical notes
- This position is based in North Bay, Ontario, and may require occasional travel for audits or training sessions.
- The role may involve on-call responsibilities for incident response outside of regular business hours.
- Bamboohr is committed to fostering a diverse and inclusive workplace; we encourage applications from individuals of all backgrounds.
- Candidates must be eligible to work in Canada; sponsorship is not available for this position.
META
Company: Bamboohr
Title: Security & Compliance Specialist
Listed
location: North Bay, Ontario
Job type: Full-time
Apply URL: https://itps.bamboohr.com/careers/136
Tags: Security, Compliance