Governance & Compliance Security Analyst at EdgeUno improving information security and ISO 27001 compliance. Collaborating with teams to maintain an effective Information Security Management System.
Responsibilities
Maintain and update the Information Security Management System (ISMS) in line with ISO/IEC 27001
Coordinate periodic risk assessments, Statement of Applicability (SoA) updates, and treatment plans
Support internal and external audits (preparation, evidence collection, tracking of nonconformities and corrective actions)
Develop, review, and maintain information security policies, standards, and procedures
Monitor and support compliance with applicable laws, regulations, and contractual security requirements (telecom, data protection, client demands)
Support third party risk management process: security assessments of vendors, service providers, and partners
Keep ISMS and governance documentation well organized and current
Produce reports and dashboards on compliance status, audit results, and ISMS performance for management
Contribute to security awareness initiatives around policies, acceptable use, and data protection
Act as a point of contact for questions related to policies, compliance, and third party security requirements
Work closely with IT, Security Operations, Legal, HR, Procurement, and business units to ensure controls are understood and applied
Requirements
Bachelor’s degree in Information Security, Systems Engineering, Law, Business, or related field (or equivalent experience)
2–5+ years of experience in information security, GRC (Governance, Risk & Compliance)
Good understanding of ISO/IEC 27001 and related standards
Experience with security policies, procedures, and audit processes
Familiarity with basic risk management concepts and methods
Ability to review and interpret contracts, SLAs, and security clauses (desirable)
Strong documentation, organization, and reporting skills
Ability to work collaboratively with technical and non-technical teams
Attention to detail, structured thinking, and a proactive mindset
Nice to Have: Experience in telecom, ISP, hosting, or cloud environments
Knowledge of data protection regulations (e.g., local privacy laws, GDPR exposure)
Certifications such as ISO 27001 Lead Implementer/Auditor, CISA, or similar.
Benefits
Competitive compensation aligned with senior technical roles in the region
Opportunity to influence software quality standards across the organization
Strong engineering culture focused on ownership, automation, and continuous improvement
Intern supporting IT Security team at OneDigital with hands - on experience and mentoring. Engaging in real - world assignments and responsibilities within IT Security.
Cyber Threat Intelligence Analyst at AIG specializing in cyber threat research and intelligence production. Collaborating with an interdisciplinary team to enhance cybersecurity situational awareness and reporting.
Senior Cyber Security Analyst protecting customers from cyber threats while enhancing cyber security services at technology firm. Focused on both security operations and technical delivery.
Cybersecurity Analyst assisting in the review and implementation of cybersecurity initiatives across a large environment at Kemper. Responding to cyber threats and improving processes and technologies.
Senior Information Security Analyst managing Information Security Management System at BMLL Technology. Supporting compliance with ISO 27001 and enhancing security measures.
Graduate Cyber Security Analyst at McKesson participating in a 24 - month Cyber Academy program. Monitor security alerts and contribute to incident response efforts while gaining mentorship.
Threat Intelligence Analyst role analyzing cyber threats and providing strategic recommendations. Working with cybersecurity teams at PwC Canada to safeguard client data and systems.
Contract Security Analyst specializing in security operations and incident response for cloud security at Embark. Focus on alert handling, detection engineering, and data loss prevention.
Cyber Security Analyst providing security operations support for USAF Cloud One project. Engaging in incident response and cybersecurity compliance activities within a hybrid environment.
Cybersecurity Analyst responsible for monitoring, analyzing, and responding to security incidents in SOC. Developing detection rules and conducting threat - hunting campaigns within a hybrid work setup.