Information Systems Security Manager securing RideCo’s cloud-based on-demand transit platform. Leading compliance, risk management, incident response, and security operations.
Responsibilities
Design, implement, maintain and enforce security policies and protocols
Protect RideCo’s data and IT infrastructure
Develop and enforce comprehensive security policies and procedures aligned with business objectives and legal compliance
Own and maintain the organizational security roadmap using NIST SP 800-53 and NIST CSF 2.0
Lead the strategy and annual audit for SOC 2 Type 2 certification and compliance
Lead RideCo’s Privacy Program
Conduct threat assessments, vulnerability scanning and audits
Develop and enforce governance policies for secure AI adoption
Monitor network traffic, firewalls, endpoints and data systems for suspicious activity
Review contracts, RFPs and security questionnaires
Establish and maintain agency-based security and privacy procedures
Identify, contain and remediate security breaches or attempts
Oversee security awareness programs and specialized training against AI-generated threats
Oversee deployment of encryption tools, antivirus software and access controls
Assess third-party vendor security protocols
Requirements
Bachelor’s degree in Cybersecurity, IT or related field
5+ years of related experience
Certified Information Systems Security Professional (CISSP)
Proficient understanding of network infrastructure, firewalls and compliance frameworks
Experience coordinating with IT teams
Knowledge of NIST SP 800-53 and NIST CSF 2.0
Experience with SOC 2 Type 2 certification and compliance
Knowledge of GDPR and HIPAA
Experience with vulnerability scanning, threat assessments, audits and incident response
Experience with security technologies including encryption tools, antivirus software and access controls
Head of Information Security leading OpenZeppelin’s enterprise security, privacy, IT, and AI governance programs. Securing open - source infrastructure used across onchain finance and digital assets.
Red Team Security Engineer evaluating Motive's fleet - management platform and cloud environments. Executing adversary simulations, validating detection coverage, and driving remediation of security issues.
Senior Security Specialist securing RBC’s cloud banking environments across AWS, Azure, and Google Cloud. Executing red/purple team exercises and refining offensive security tooling.
Senior Security Specialist operating BloodHound Enterprise for RBC, a Canadian bank. Mapping identity attack paths and prioritizing remediation across cloud, AD, DevOps, and PAM environments.
Staff Security Researcher conducting vulnerability research and penetration testing for GitLab’s AI - powered DevSecOps platform. Developing attack methodologies, tooling, and security improvements.
Principal Security Researcher securing GitLab’s AI - powered DevSecOps platform. Leading vulnerability research, AI attack analysis, penetration testing, and remediation across GitLab’s codebase.
Senior security advisor strengthening Desjardins's security posture across governance, data protection, and fraud prevention. Leading complex strategic initiatives for the Desjardins financial services organization.