Senior Risk & Audit Specialist supporting audits and compliance at Upsun. Collaborating across teams to ensure security posture and operational readiness.
Responsibilities
Support active and upcoming audits, including ISO 27001, SOC 2, PCI DSS, HIPAA, and other relevant assurance work by coordinating evidence collection, reviewing evidence quality, scheduling walkthroughs, and following up with control owners.
Support risk assessments, risk register updates, control monitoring, issue tracking, and risk treatment follow-up by working with teams to identify control gaps, agree on practical actions, and track remediation through to completion.
Conduct third-party risk management reviews to support a comprehensive view of organizational risk.
Support ongoing compliance activities across established frameworks and emerging readiness work (including Australia ISM/IRAP/HCF, NIS2, and ISO 42001/AIM) while maintaining policies, procedures, control narratives and supporting documentation.
Respond to customer and prospect security or compliance questions in partnership with Sales, Legal, Security, and Product, and support updates to the Trust Center and other trust documentation.
Prepare clear updates on audit status, risks, blockers, metrics, and remediation progress for leadership and look for opportunities to simplify repeatable processes and reduce audit friction for control owners.
Use risk, audit, and compliance tools to keep work organized, traceable, and easy to report on.
Support internal audit and review activities as needed.
Requirements
5+ years of experience in risk, audit, compliance, governance, security assurance, or a closely related area.
Hands-on experience supporting audits, evidence collection, control testing or monitoring, and remediation tracking.
Working knowledge of security and compliance frameworks such as ISO 27001, SOC 2, PCI DSS, HIPAA, ISO 42001, GDPR, PIPEDA or similar standards.
Ability to explain requirements clearly to both technical and non-technical audiences.
Strong organization and prioritization skills, especially when managing several deadlines at once.
Good judgement, attention to detail, and a practical approach to solving problems.
Comfort working in a remote, global environment with cross-functional teams across varied timezones.
Benefits
Flexible PTO
Comprehensive healthcare coverage (UK, Canada, France, Spain, USA)
Audit Manager overseeing IT audits for TD, conducting audit work per established plans and standards. Engaging with stakeholders and presenting findings on internal controls.
Technicien informatique de niveau 2 chez GC Brieau offrant assistance technique et support aux clients. Intervenant sur place et à distance pour résoudre des problématiques techniques complexes.
Hiring an RSA Archer architect for a full - time permanent role in Toronto, ON. Requires strong experience in RSA Archer GRC platform configuration and core solutions.
IT Specialist optimizing Kubernetes clusters for Telesat, a global satellite operator. Collaborating with teams to ensure scalable and secure applications in hybrid environments.
Enterprise Architect managing Dynamics 365 Finance & Operations solutions for Long View, delivering innovative engagements and overseeing design and implementation.
Junior IT Administrator supporting a remote - first SaaS veterinary company with helpdesk and operational tasks. Join a collaborative team enhancing technology solutions in the health tech space.
We are hiring a Helpdesk/Technical Support Specialist to provide technical assistance, troubleshoot issues, and ensure smooth operations across multiple platforms. Hybrid role in Scarborough, ON.
Senior Risk & Audit Specialist overseeing audits and compliance for a cloud application platform. Collaborating cross - functionally, ensuring security posture across global operations.
Bilingual IT Administrator providing technical support to users in Montreal, Sherbrooke, and Cornwall. Resolving hardware issues and maintaining network infrastructure under the Regional IT Manager's guidance.
Hiring an RSA Archer architect for a full - time permanent role in Toronto, ON, responsible for support, enhancement, and configuration of the RSA Archer GRC platform.