Information Security Specialist enhancing security posture across systems and cloud environments for Teladoc Health Canada. Championing corporate IT security strategy and regulatory compliance efforts.
Responsibilities
Champion and execute the overall corporate IT security strategy, roadmap and governance structure, partnering with internal risk/compliance, operational, clinical, technical and business teams as well as external customers and relevant third-party stakeholders
Understand business processes and information system requirements and the associated information risk in those processes
Liaise closely with internal Canadian legal/privacy team to ensure adherence and alignment with Canadian privacy, data governance and regulatory requirements, and the business’ contractual commitments
Work directly with the Canadian commercial team and client base to understand market business and functional requirements and provide compliance, security, and risk assessment support and guidance as required
Establish and execute formal vendor security assessments, including pre-onboarding due diligence and ongoing monitoring of third-party vendors and sub-processors handling sensitive information
Implement all information security, including security breaches, business continuity, and regulatory compliance programs including legal requirements, industry regulations, and best practices (e.g., ISO27001, SOC 2 Type II, etc.)
Lead end-to-end SOC 2 Type II and ISO 27001 audit cycles, including gap assessments, evidence collection via GRC tooling (e.g. Vanta) and act as the primary liaison for external auditors to support certifications
Develop information security guidelines, procedures, and responsibilities and support the development and implementation of technical and administrative security controls and related training and education
Oversee technical incident response planning and implementation and participate in incident response, root cause analysis, and remediation activities
Assess our technology environment and development methodology (SDLC) to identify and mitigate risks and gaps related to information security including potential data breaches
Design, implement, and maintain security controls across infrastructure, applications, integrations and cloud environments in collaboration with our technology team and third-party vendors including: Applications and other systems and middleware components, including operating systems, web servers, databases, and DNS services (e.g. Salesforce, Mulesoft, APIs, etc.)
Network security architecture, including firewalls, segmentation, and secure communication protocols
Logging and monitoring security needs, including SIEM platforms
Encryption standards needed for compliance
Document security configurations, processes, and controls
Digital certificate lifecycle management, including issuance, renewal, and revocation
Communicate information security and compliance risks to leadership and other technical and non-technical stakeholders for proper awareness and decision making
Other duties as assigned
Requirements
Bachelor’s degree in computer science or comparable knowledge
10+ years of relevant technical work experience, with 5+ years of experience in an information security role
Experience in a highly regulated environment or electronic record systems, health care experience preferred
CISM, CISA, CISSP, ISO 27001 LA or other relevant information security certifications are strong assets
Essential effective oral and written communication skills with both technical and non-technical audiences in geographically dispersed locations
Ability to work effectively cross-functionally with technical and non-technical teams
Strong prioritization and time management skills
A deep understanding (with practical experience) of related information security technologies and concepts including access and authentication, network and application, message and transmission security as well vulnerability management best practices
Proven knowledge of security program frameworks and assessments, ideally SOC 2 and ISO27001
Understanding of cloud security concepts and experience with securing cloud environments both public and private (AWS essential and Azure preferred)
Hands-on experience and familiarity with: Operating systems (Linux, Windows), Web servers (e.g., Apache, Nginx), Databases (e.g., MySQL, PostgreSQL, SQL Server), Network security principles and architecture (TCP/IP, firewalls, VPNs, segmentation and secure communication protocols), SIEM tools and its integration, Application, cloud, and SaaS integrations, particularly platforms including Salesforce, Containers and/or Kubernetes, Automation tools
Enterprise Security Architect securing technology for Vancity, a member - owned Canadian credit union. Designing enterprise application security frameworks, controls, and risk - based cybersecurity solutions.
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.
Join RBC's Application Security Group to develop innovative security solutions, mentor junior staff, and collaborate across teams to enhance decision - making and automate tasks.
Lead SCADA and cybersecurity engineer designing compliant substation systems for GE Vernova. Guiding project teams, vendor designs, estimates, and acceptance testing for cleaner energy infrastructure.
Senior security advisor simulating cyber threats and strengthening defenses for Desjardins, North America's largest cooperative financial group. Leading complex initiatives, methodologies and cybersecurity risk mitigation.