Cybersecurity Administrator providing operational support for compliance activities in information security. Assisting vendor risk management, audit coordination, and vulnerability tracking.
Responsibilities
Manage inbound security questionnaires/RFIs and coordinate inputs across IT, Legal, Engineering, and other stakeholders
Maintain and continuously improve a centralized library of standardized, policy-aligned security responses
Track questionnaire/RFI status, deadlines, and follow-ups to ensure accurate, on-time delivery
Support the end-to-end third-party vendor risk lifecycle, including onboarding, periodic reviews, and offboarding
Conduct vendor security risk assessments using established frameworks and questionnaires (e.g., SIG, CAIQ, custom templates)
Maintain the vendor risk register, including risk ratings, evidence requests, remediation actions, and review schedules; escalate high-risk findings
Coordinate audit readiness activities (e.g., SOC 2 Type II, TISAX, internal audits), including continuous evidence collection and audit calendars
Serve as a point of contact during audit fieldwork by scheduling walkthroughs, gathering artifacts, and tracking auditor requests
Track audit findings and management responses and follow remediation commitments through closure; help update control narratives, policies, and procedures
Monitor and track vulnerabilities (scans, penetration tests, threat intel), maintain the vulnerability register, drive follow-ups, and produce status reporting.
Requirements
Bachelor's degree in Information Security, Computer Science, Information Systems, or a related field — or equivalent practical experience
1–2 years of experience in information security, IT compliance, risk management, or a related discipline
Familiarity with common compliance frameworks and standards such as SOC 2, ISO 27001, TISAX, NIST, or similar
Strong organizational skills with the ability to manage multiple workstreams, deadlines, and stakeholders simultaneously
Excellent written and verbal communication skills — able to translate technical concepts for non-technical audiences
Detail-oriented with a structured, process-driven approach to work
Proficiency in standard productivity tools (Microsoft 365, Google Workspace) and experience with spreadsheets and tracking tools
Entry-level security certification or active pursuit thereof: CompTIA Security+, CC (ISC²), or equivalent
Understanding of cloud security concepts (AWS, Azure, or GCP environments)
Understanding / Experience supporting external audits or regulatory examinations.
Principal Security Architect securing Menlo Security’s browser and AI - agent protection platform. Leading cryptography, cloud, vulnerability, and product security architecture.
BDC banking manager overseeing commercial loan security and disbursements across Western Canada. Coordinating due diligence, risk evaluation, lending partners and compliant loan funding.
Cybersecurity new graduate rotating through Intact’s 24 - month tech development program. Supporting threat detection, incident response, infrastructure security, and AI - enhanced security insights.
Information Security Manager leading enterprise EUC governance technology deployment and product roadmaps at TD, a global financial institution. Driving risk controls, adoption, delivery and assurance across business segments.
Principal Cloud Security Engineer securing Pax8’s cloud marketplace, infrastructure, and AI - enabled platforms. Establishing cloud, Kubernetes, identity, and software - delivery security standards across USA and Canada.