Security & Compliance Manager
Job in
Mississauga, Ontario, Canada
Listed on 2026-09-27
Listing for:
PACT
Full Time
position Listed on 2026-09-27
Job specializations:
-
Security
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Because member companies second staff and retain the endpoints they issue, endpoint management, HR and office physical security are not centralized, and control ownership splits across PACT tenant-managed, inherited, shared and client-owned scopes.
RESPONSIBILITIES
Programme Ownership and ISMS Documentation
Own the ISO/IEC 27001:2022 certification initiative to the Q1 2027 target and the SOC 2 Type 2 initiative
Run both as one control programme with two reporting outputs, sharing roughly 75-80 percent of control intent
Author, approve, publish, version-control and maintain the information security policy suite, retaining acknowledgement records
Author and maintain the Statement of Applicability across the applicable control set, justifying inclusion, exclusion and inheritance
Operate the document-control procedure, competence matrix, improvement log and corrective-action register in a governed SharePoint library
Represent certification and attestation status accurately in internal, member-company, client and external communications
Report status to the IT Steering Committee and provide input to security budget, tooling spend and vendor selection
Risk Management and Control Operation
Define a risk methodology covering acceptance criteria, impact and likelihood scales, ownership and treatment options
Establish and maintain the risk register through formal risk assessment, sustained as a live record
Produce and track the risk treatment plan, verifying control effectiveness rather than accepting reported completion
Operate annual and event-triggered reassessment on new SaaS, tenant change, incident, audit finding or joint-venture change
Maintain the evidence inventory, coordinate the quarterly privileged, guest and application access review cycle, and review logs
Ensure audit logging and retention across the tenant meet certification and investigative requirements
Ensure backup and recovery controls are evidenced, covering schedule, immutability, retention and restore testing
Maintain the information asset register and baseline configuration review, recording drift and approvals
Third-Party and Member-Company Assurance
Maintain the supplier security register and review cadence covering the ICT supply chain and managed service provider
Review Entra application registrations as privileged suppliers, documenting owner, purpose, permission scope and review date
Maintain the control-ownership split across PACT tenant-managed, inherited, shared and client-owned scopes
Collect and refresh member-company attestations for inherited endpoint, AV/EDR, patching, physical security and HR controls
Coordinate shared controls with member-company IT and security teams, covering classification, awareness and business continuity
Maintain the joiner, mover and leaver process with each member company, and manage dual member-company and PACT identities
Security Architecture, Operations and Tenant Hardening
Provide input into platform security architecture, security standards and the multi-year security roadmap
Assess new platforms,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×