IT Compliance Specialist II

Canada

Applications have closed

Achievers

Achievers' award-winning employee recognition software creates a culture that accelerates engagement and performance for UK businesses.

View company page

The "Achievers Employee Experience Platform™" delivers high-frequency recognition that drives business outcomes for HR and business leaders, from decreased turnover to increased engagement. Designed specifically to meet the needs of today’s workforce, it empowers employees to recognize each other in real time and aligns them to the values and goals of the company. With more than 3 million users, the Employee Experience Platform inspires brilliant performance in 170 countries. Visit us at www.achievers.com to learn more and join us in our mission to Change the Way the World Works™.

We are looking for a highly motivated and organized individual to join our Information Security Team that will be responsible for providing security governance, compliance and risk mitigation support while ensuring controls and processes are in place to maintain a secure and compliant environment. 
As an IT Compliance Specialist you will be assisting the team conducting security policies review, security risk assessments, participating in multiple internal and external audits, supporting the business with IT Security & Compliance related tasks, performing third-party vendor assessments and executing on the day-to-day departmental operational activities. 

What you'll do:

  • Participate in internal and/or external audits and security assessments (e.g. ISO 27001, CSA STAR, PCI, SOC 2, etc.).
  • Conduct periodic IT Compliance reviews to ensure appropriate design and operating effectiveness of primary controls. Identifying gaps in controls and propose remediation plans.
  • Assist in the day-to-day compliance and audit operational activities.
  • Work with control owners to ensure timely review and updates to documentation, controls, and the completion of remediation items.
  • Attend periodical status meeting with internal/external audit teams.
  • Perform third-party vendor risk assessments by reviewing vendors security posture and architecture, drafting security assessment reports outlining risks identified.
  • Provide technical knowledge and analysis of information assurance, including, but not limited to: application controls; operating systems; physical security; identity and access management; risk assessment; privacy, infrastructure continuity and contingency planning; security awareness and training, etc.
  • Initiate, facilitate, and promote activities to foster information security awareness within the organization.
  • Excellent communication and presentations skills with the ability to deliver complex concepts to both technical and non-technical audiences.
  • Lead the ongoing and annual security awareness training program, reviewing the content, coordinating assignments and follow ups with end users to ensure training is completed timely.
  • Relationship building skills especially in areas where diplomacy is needed to help ensure that new policies and procedures gain the support they need to be adopted by the organization.
  • Proactively offer internal security consulting on policy, controls, standards and best practices to business functions and end users.
  • Day-to-day assistance with InfoSec. departmental operational actives.
  • Work independently with minimal oversight from management.

What you'll bring:

  • 3-5 years of proven Information security, vendor governance, IT compliance, audit, and risk management related experience.
  • Strong experience with IT compliance frameworks, requirements and regulatory standards such as, but not limited to: ISO 27001, HIPAA, PCI, CSA STAR, SOC 2, GDPR, NIST, etc.
  • Knowledge of corporate security policies, procedures and information security best practices.
  • Bachelor’s degree in Computer Science, Engineering.
  • Professional certifications are an asset: CISSP, CISA, CISM, or CRISC.
  • Experience with security and compliance as it relates to a SaaS offering.
  • Knowledge of European security and privacy practices.
  • Extremely well organized, detailed oriented and attentive to deadlines
#LI-REMOTE

About Achievers:
 
As Achievers employees, we are passionate about disruptive technology, welcome constant change, and understand the value of employee success in the workplace. We enjoy coming to work every day because we believe in our product and love our culture. Achievers is more than just a software company; we are industry leaders in the HR space. 

We have been recognized in numerous publications for our contributions to HR, for technical excellence and for our outstanding workplace culture!


Achievers does not offer employment to prospects without first ensuring that qualified candidates speak directly with the hiring manager and a member of our HR team. All qualification will be done face-to-face, whether that is in person or over Zoom. Achievers does not send out offers of employment without meeting candidates and does not offer employment via text. If you are requested for any personal information via text and/or without having met a member of our hiring team in person, please disregard.
 
Our employees are a diverse and inclusive team of passionate, hardworking individuals. Achievers is committed to creating an environment where our employees can do the best work of  their lives. We encourage all qualified candidates to apply to join our A-Player family. Accommodations are available on request for candidates taking part in all aspects of the selection process. 

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Tags: Audits CISA CISM CISSP Compliance Computer Science CRISC GDPR Governance HIPAA IAM ISO 27001 NIST Privacy Risk assessment Risk management SaaS Security assessment Security Assessment Report SOC SOC 2

Perks/benefits: Career development Team events

Regions: Remote/Anywhere North America
Country: Canada
Job stats:  22  6  0
Category: Compliance Jobs

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.