04 Sep
|
Atheris
|
Greater Toronto Area
04 Sep
Atheris
Greater Toronto Area
About UsAtheris has always been about making science meaningful — helping pharmaceutical and biotechnology partners transform complex science into clear, actionable strategy. For years we’ve supported life-science organizations by guiding launches, shaping evidence, and building clarity across the most complex therapeutic landscapes.
Position OverviewAtheris is seeking an agency IT Security & Identity Manager to work closely with a fast-growing organization.
We're a multi-entity consulting organization, a parent company plus several distinct operating brands, running client-facing pharma consulting work alongside internal product development. Because our consultants work across sponsor accounts that can be commercially or competitively adjacent, we need real separation between entities at the identity layer, the data layer, and inside the tools our teams use every day, not just separate folders. This role owns that architecture from design through implementation to audit, and can defend it to an external auditor or a client security questionnaire.
This is a hands-on individual contributor role, not a people-management role. You will be the most senior technical decision-maker on identity, access, and platform governance, reporting directly to the CAIO.
Key ResponsibilitiesTenant and identity architecture
·
Design and maintain an access model across Microsoft 365 (Entra ID, SharePoint, Teams) that supports roughly 30 staff split across a parent organization and multiple sub-entities. Staff who need access to more than one entity are handled as named, documented, time-boxed exceptions, not default access.
·
Own the identity lifecycle: provisioning,
de-provisioning, access reviews, least-privilege enforcement.
·
Evaluate and implement the right control layer for cross-entity conflict separation (for example, Microsoft Purview Information Barriers or an equivalent),
and understand the difference between a collaboration boundary and a true knowledge boundary.
Platform administration
·
Administer and scope tools like Claude
Enterprise and Microsoft Copilot per entity, including connector scoping,
workspace and project boundaries, and skill or agent provisioning, so these tools respect the same entity boundaries as human access.
·
Build and maintain the evidence trail an auditor or client would need: access inventories,
connector scope documentation, audit logs, and a documented exception process.
·
Partner with practice leadership to translate business-side conflict-of-interest requirements into technical access policy.
Cybersecurity
·
Own security posture across the M365 environment and the company's web infrastructure (Vercel-hosted sites, Neon-managed databases; currently four properties).
·
Run or coordinate periodic access and security reviews; remediate findings.
·
Establish monitoring,
logging, and incident response basics appropriate to a 30-person firm: auditable and defensible, not enterprise SOC scale.
Audit readiness
·
Prepare the organization to pass a compliance or security audit on request, whether that's a client-driven security questionnaire, a cyber-insurance requirement, or an internal governance review.
·
Note: the firm does not store PHI or process data in scope of HIPAA or GDPR today. Healthcare-adjacent compliance familiarity is preferred as a signal of rigor, not because it's a current regulatory obligation.
Cybersecurity and access-control audit experience (SOC 2, ISO 27001, or equivalent hands-on audit work) is valued just as highly.
Web infrastructure
·
Oversee four company websites on Vercel with Neon as the database layer, including deployments, environment and secrets separation, and access control per site.
·
Direct the work of a part time SharePoint and infrastructure consultant on assigned projects. This is a working relationship,
not a supervisory one.
Qualifications:·
5+ years in IT administration, identity and access management, or infrastructure security,
with demonstrated ownership (not just participation) of an access-control architecture.
·
Hands-on Microsoft 365, Entra ID, and
SharePoint administration at a multi-team or multi-business-unit organization.
·
Direct experience with at least one formal audit process (security, financial, or healthcare-compliance) as the person who prepared evidence or remediated findings.
·
Working knowledge of administering modern platforms like Claude Enterprise or Copilot, specifically the distinction between access control and what these tools can retrieve or see.
·
Comfortable operating as a sole individual contributor with no team to delegate to,
so strong hands-on execution across identity, security, and basic web operations.
What This Role Is Not
· Not a people-management position. No direct reports.
· Not a software engineering role. Occasional deployment and configuration work, not feature development.
· Not scoped to build new products. That sits with the CAIO and the product team. This role secures and governs the infrastructure those products and consultants run on.
Soft Skills & Mindset· Highly responsive
· Operates with a growth mindset
· Service oriented
· Highly organized
$110-$130k
📌 IT Security & Identity Manager (Greater Toronto Area)
🏢 Atheris
📍 Greater Toronto Area