Security and Compliance Lead
Job in
Surrey, BC, Canada
Listing for:
Emterra Group
Full Time
position
Listed on 2026-07-21
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 125000 - 140000 CAD Yearly
CAD
125000.00
140000.00
YEAR
Job Description & How to Apply Below
Security and Compliance Lead
Surrey, BC Full-time $125000.00-$140000.00/year
Who We Are
Emterra Group is a dynamic, growth-oriented, and safety-focused group of companies. Our organization have been deemed to be an “essential service” by providing collection and processing for recycling, organics, and waste that keep our communities clean and safe. With customer service and safety as our focus, we are looking for an energetic and driven employee to support our growing company and play a crucial role in waste diversion and the circular economy.
Emterra is proud to be recognized as one of Canada’s Greenest Employers, a certified diverse supplier of the Canadian Aboriginal and Minority Supplier Council (CAMSC) and the Canadian Women Business Enterprise National Council (WBE).
Job Summary
Emterra Group is seeking a Security and Compliance Lead to own and advance our cybersecurity posture and regulatory compliance program across our Microsoft 365 and Azure cloud environments. This is a hands-on leadership role responsible for designing, implementing, and maintaining security controls while ensuring alignment with applicable frameworks and standards.
Position Description
Security Operations & Architecture
Design and maintain security architecture across Microsoft Azure, Microsoft 365, and on-premises infrastructureManage and optimize (Endpoint, Identity, Cloud Apps, Office 365), SIEM, and Entra (Azure AD)Lead vulnerability management, threat detection, and incident response activitiesConfigure and maintain Conditional Access policies, Zero Trust network access, and Privileged Identity Management (PIM)Oversee Azure Security Center / Defender for Cloud recommendations and remediationCompliance & Governance
Develop and maintain the organization's information security policies, standards, and proceduresLead compliance efforts across applicable frameworks (NIST, PIPEDA, or industry-specific regulations)Manage Microsoft Purview for data classification, DLP policies, information protection labels, and eDiscoveryConduct and coordinate internal audits, risk assessments, and third-party security reviewsMaintain compliance posture within the Microsoft 365 Compliance Center and Secure Score benchmarksIdentity & Access Management
Administer and mature Entra (Azure AD) including RBAC, MFA, SSO, and lifecycle managementManage privileged access through PIM and Just-in-Time (JIT) provisioningOversee identity governance and access reviewsRisk Management
Conduct regular risk assessments and maintain the organizational risk registerDevelop and test the Business Continuity Plan (BCP) and Disaster Recovery (DR) proceduresEvaluate and manage vendor and third-party security riskTraining & Awareness
Design and deliver security awareness training programs across the organizationAct as internal subject matter expert and advisor on security matters for all departmentsReport security metrics and compliance status to IT leadership and stakeholdersSkills & Qualifications
Required Qualifications
5+ years of progressive experience in information security or cybersecurity roles3+ years of hands-on experience with Microsoft Azure and Microsoft 365 security toolingDeep expertise with Microsoft security products:
Sentinel, Purview, Entra ,Working knowledge of Azure networking, Azure Policy, and cloud governance frameworksExperience with at least one compliance framework (SOC 2, ISO 27001, NIST CSF, CIS Controls)Strong understanding of identity and access management principlesExcellent written and verbal communication skills; ability to present risk clearly to non-technical stakeholdersPreferred Qualifications
Relevant certifications: MS-500 (Microsoft Security Administrator), SC-200 (Microsoft Security Operations Analyst), SC-300 (Identity and Access Administrator), AZ-500 (Azure Security Engineer), CISSP, CISM, or CompTIA Security+Experience in a regulated or multi-site operations environmentFamiliarity with PIPEDA and Canadian privacy legislationExperience with Microsoft Copilot for SecurityWhat We Offer
Competitive salary and benefits packageHybrid work flexibilityCollaborative and mission-driven team environmentOpportunity to shape and…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here: