NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Compliance Specialist in Canada
5 days ago
Apply with autofill
Apply with autofill
Equisoft·5 days ago
5 days ago

Security Assurance and Compliance Specialist

HYBRID, CanadaFull-timeHybridMid · 2-5 yearsCompliance Specialist

Sign up free to see how well your resume matches this role.

Boost your chances at equisoft

How you compare FREE

?
Your scoreYour score: not yet known
→
16
Top 10%Top 10%: 16 out of 100

Top 10% of NextRaise users matched against Compliance Specialist roles in Canada.

Must-have skills for this role

  • soc 2
  • iso 27001
  • french
  • english

PDF or DOCX · no account needed

Apply faster with autofill FREEThe NextRaise extension autofills your application in one click.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Support the control environment for SOC 2, ISO 27001, ISO 22301, and ISO 42001 — control mapping, evidence collection, auditor liaison. Manage policy lifecycle (review, versioning, publication, attestation). Prepare audit evidence packages and report gaps to closure.
  • Own the end-to-end DPIA process (Trust Center/SOC review, DPA/sub-processor analysis, SCC/residency checks, AI assessment, risk rating), vendor intake, the vendor risk register, and fourth-party tracking — chasing missing certs, bridge letters, and remediation commitments.
  • Complete due diligence questionnaires and RFP security sections within SLA; maintain a response library. Coordinate client audit evidence requests. Issue SOC 2 reports and bridge letters. Serve as security point of contact for Sales, pre-sales, and Legal.
  • Own the quarterly access review (OIPA, Design, SQL, Azure, bastion) — data collection, reviewer follow-up, revocations, closure evidence. Drive access-review automation with the managed services partner.
  • Track findings (Tenable, UpGuard, SentinelOne, external ASM), categorize by product/owner, drive remediation tickets and trend reporting. Coordinate the annual pentest (scoping, scheduling, provisioning) and drive findings to closure.
  • Generate monthly patching tickets, confirm completion with infrastructure, and maintain the server software/middleware inventory.
  • Run the monthly training cycle, produce completion reporting, escalate outstanding completions, and administer the annual training needs survey.
  • Supply DR exercise/continuity evidence for client requests; support BIA cycles and tabletop exercises.
  • Produce recurring KPI/leadership reporting. Identify manual control work suitable for automation (asset inventory, ticket creation, evidence extraction, training reporting) and build/commission agentic workflows, with SOPs for each.

What they're looking for

  • 5+ years in InfoSec GRC or IT audit in software/regulated services
  • Hands-on ownership of at least one full SOC 2 Type II or ISO 27001 cycle
  • Experience with B2B client security questionnaires/due diligence
  • Working knowledge of GDPR, Quebec Law 25, and PIPEDA
  • Practical familiarity with vulnerability management/endpoint tooling (Tenable, SentinelOne preferred)
  • Fluent in French and English (due to recurrent contact with international teams and customer)
  • Proven ability to drive completion through teams you don’t manage; comfortable escalating slipped commitments
  • Clear, client/auditor-ready writing; strong prioritization under high inbound demand; meticulous attention to detail

Nice to have

  • CISA, CISSP, CRISC, ISO 27001 Lead Implementer/Auditor
  • ISO 42001 or AI management system exposure
  • Insurance/wealth management industry experience
  • Agentic/Power Automate automation experience
  • Experience managing an MSSP

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

HYBRID - Québec City, Canada

What is Equisoft?  Equisoft is a global provider of digital solutions for insurance and investment, recognized by over 250 of the world's leading financial institutions. We offer a comprehensive ecosystem of scalable solutions that help our customers meet all the challenges brought about by this era of digital transformation, thanks to our business needs-driven approach, industry knowledge, cutting-edge technologies and experts. With its business-driven approach, in-depth industry knowledge, cutting-edge technologies and multicultural team of experts based in North America, the Caribbean, Latin America, Europe, Africa, Asia and Australia, Equisoft helps its customers meet the challenges of this era of digital transformation.    

Why Choose Equisoft? With 950+ employees, we are a stable organization that offers career advancement opportunities and fosters a stimulant environment. If that’s not enough, then check out these other perks below:       

  • Hiring Location: Canada (Montreal)  

  • You are working hybrid in a collaborative workspace  

  • Full-time Permanent Role

  • Benefits available day 1: Medical, Dental, Retirement Plan, Telemedicine Program, Employee Assistance Program, etc. 

  • Flexible hours    

  • Number of hours per week: 40   

  • Educational Support (LinkedIn Learning, LOMA Courses and Equisoft University) 

Role: The Specialist, Security Assurance and Compliance reports to the Manager, Information Security and GRC. This role is the operating center of Equisoft’s security governance program. You’ll keep four certifications current (SOC 2 Type II, ISO 27001, ISO 22301, ISO 42001), answer the security questions standing between Equisoft and closed business, and drive recurring control activities — access reviews, patching, vulnerability remediation, pentest follow-up, and awareness training — to completion across teams you don’t manage. This is a coordination, evidence, and automation role, not an engineering one: you define what must happen, track whether it did, produce proof, and automate what shouldn’t require a person. Success is measured by audit outcomes, questionnaire turnaround time, and the percentage of control work running on schedule without escalation.  

What You’ll Do:    

  • GRC: Support the control environment for SOC 2, ISO 27001, ISO 22301, and ISO 42001 — control mapping, evidence collection, auditor liaison. Manage policy lifecycle (review, versioning, publication, attestation). Prepare audit evidence packages and report gaps to closure.

  • Vendor & Third-Party Risk: Own the end-to-end DPIA process (Trust Center/SOC review, DPA/sub-processor analysis, SCC/residency checks, AI assessment, risk rating), vendor intake, the vendor risk register, and fourth-party tracking — chasing missing certs, bridge letters, and remediation commitments.

  • Client Security Assurance: Complete due diligence questionnaires and RFP security sections within SLA; maintain a response library. Coordinate client audit evidence requests. Issue SOC 2 reports and bridge letters. Serve as security point of contact for Sales, pre-sales, and Legal.

  • Identity Governance: Own the quarterly access review (OIPA, Design, SQL, Azure, bastion) — data collection, reviewer follow-up, revocations, closure evidence. Drive access-review automation with the managed services partner.

  • Vulnerability & Pentest Management: Track findings (Tenable, UpGuard, SentinelOne, external ASM), categorize by product/owner, drive remediation tickets and trend reporting. Coordinate the annual pentest (scoping, scheduling, provisioning) and drive findings to closure.

  • Patch & Configuration Hygiene: Generate monthly patching tickets, confirm completion with infrastructure, and maintain the server software/middleware inventory.

  • Security Awareness: Run the monthly training cycle, produce completion reporting, escalate outstanding completions, and administer the annual training needs survey.

  • BCDR Support: Supply DR exercise/continuity evidence for client requests; support BIA cycles and tabletop exercises.

  • Reporting & Automation: Produce recurring KPI/leadership reporting. Identify manual control work suitable for automation (asset inventory, ticket creation, evidence extraction, training reporting) and build/commission agentic workflows, with SOPs for each.

Requirements   

Technical   

  • 5+ years in InfoSec GRC or IT audit in software/regulated services  

  • Hands-on ownership of at least one full SOC 2 Type II or ISO 27001 cycle  

  • Experience with B2B client security questionnaires/due diligence  

  • Working knowledge of GDPR, Quebec Law 25, and PIPEDA  

  • Practical familiarity with vulnerability management/endpoint tooling (Tenable, SentinelOne preferred)  

Soft Skills   

  • Fluent in French and English (due to recurrent contact with international teams and customer)

  • Proven ability to drive completion through teams you don’t manage; comfortable escalating slipped commitments  

  • Clear, client/auditor-ready writing; strong prioritization under high inbound demand; meticulous attention to detail  

Nice to Have:   

  • CISA, CISSP, CRISC, ISO 27001 Lead Implementer/Auditor  

  • ISO 42001 or AI management system exposure  

  • Insurance/wealth management industry experience  

  • Agentic/Power Automate automation experience  

  • Experience managing an MSSP  

Equisoft is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.     

Company

Equisoft
HYBRID, Canada

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Equisoft's careers site·first seen 19 Sept 2026·last verified 19 Sept 2026·How we source jobs

Similar jobs

  • Expert Group Insurance Operations Governance Consultant at benevaQuebec, Canada–match not yet calculated
  • CMC Regulatory Consultant (Biologics Must Have) - Canada Remote Based at syneoshealthCAN-Remote–match not yet calculated
  • Regulatory Consultant (Veeva RIM) at syneoshealthCAN-Remote–match not yet calculated
  • Compliance Specialist at altasciencesLaval, Canada–match not yet calculated
  • Senior Compliance Advisor at iaQuebec, Canada–match not yet calculated

Browse more jobs

  • Compliance Specialist jobs in Canada
  • Compliance Manager jobs in Canada
  • Company Secretary jobs in Canada
  • Data Privacy Officer jobs in Canada
  • Compliance Specialist jobs in United States
  • Compliance Specialist jobs in United Kingdom