Information Security Manager supporting Qohash's operational security excellence and regulatory alignment. Collaborating with various teams to implement security and compliance requirements.
Responsibilities
You’ll support the execution and continuous improvement of Qohash’s security program, ensuring operational excellence and regulatory alignment.
You’ll be part of the Operations team, collaborating closely with Engineering, Product and Customer Success teams to help implement and maintain security and compliance requirements.
You’ll support risk assessments, track identified risks, and help coordinate remediation efforts.
You’ll support and coordinate security audits and compliance efforts, including SOC 2, ISO 27001, ITSG-33, and third-party risk assessments.
You’ll help document and improve security and compliance procedures to support organizational preparedness and resilience.
You’ll maintain security policies, standards, awareness materials, and support internal security training initiatives.
You’ll leverage AI wherever possible to accelerate delivery and standardize processes.
You’ll work remotely full-time, within the province of Quebec or Ontario, with a small number of team get-togethers in either Montreal or Quebec City.
Requirements
A strong alignment with our core values
4-5 years of experience in information security, with direct accountability for risk management and compliance functions.
Experience in AI systems security compliance.
Strong familiarity with ISO 27001 and/or SOC 2 as an auditor or auditee.
Solid technical understanding of cloud security and SaaS infrastructure - ideally a background in IT or software engineering prior to information security.
Experience with compliance management tools (Vanta, Drata, SecureFrame, etc) and AI tools to enhance productivity and streamline workflows.
Bachelor's degree in Computer Science, Information Security, or equivalent practical experience.
Benefits
Competitive base salary.
Enjoy up to six weeks of paid time off annually. At Qohash, we recognize your dedication and believe in giving you ample time to rejuvenate.
Comprehensive health benefits package, including life insurance, short- and long-term disability insurance, paramedical and telemedicine services, and an HSA account.
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.
Join RBC's Application Security Group to develop innovative security solutions, mentor junior staff, and collaborate across teams to enhance decision - making and automate tasks.
Lead SCADA and cybersecurity engineer designing compliant substation systems for GE Vernova. Guiding project teams, vendor designs, estimates, and acceptance testing for cleaner energy infrastructure.
Senior security advisor simulating cyber threats and strengthening defenses for Desjardins, North America's largest cooperative financial group. Leading complex initiatives, methodologies and cybersecurity risk mitigation.
SA&A Lead securing Azure applications and Microsoft platforms for PLATO, Canada’s Indigenous - owned software testing company. Leading authorization, control testing, evidence collection, and risk remediation.