Senior Security & Compliance Engineer (Kitchener)

Senior Security & Compliance Engineer (Kitchener)

07 Sep
|
Insight Global
|
Kitchener

07 Sep

Insight Global

Kitchener

Job Description
We are seeking an experienced Senior Security & Compliance Engineer to strengthen security, privacy, and compliance across our Microsoft-based corporate and product environments.

The successful candidate will lead the implementation and continuous improvement of controls aligned with ISO 27001, SOC 2, GDPR, and other applicable customer or regulatory requirements.

This role will translate framework requirements into practical policies, technical controls, evidence, and remediation plans; coordinate risk assessments, audits, vulnerability assessments, and penetration testing; and use Microsoft Azure, Microsoft Defender, Microsoft Entra, Microsoft Purview, Microsoft Intune, and related technologies to improve our security posture.

You will collaborate with engineering, IT, leadership, auditors, and third-party assessors to ensure that security and compliance requirements are embedded in daily operations and the software development lifecycle.

This is a senior individual contributor role with significant influence over security architecture, governance, and compliance decisions.

Key Responsibilities
• Risk and Control Management: Maintain security risk registers, conduct risk assessments, define control owners, track remediation activities, and report security and compliance posture to leadership.
• Audit and Assurance: Coordinate internal and external audits, prepare and validate evidence, respond to auditor requests, manage findings, and ensure corrective actions are completed and documented.
• Vulnerability Management and Penetration Testing: Manage vulnerability scanning and penetration testing programs, define test scope, coordinate qualified internal or third-party testers, evaluate findings, prioritize remediation, and verify closure through retesting.
• Security Governance and Compliance: Lead the implementation, maintenance, and continuous improvement of the information security management system and control workplace.

Support customer, contractual, and regulatory security requirements, including ISO 27001, SOC 2, GDPR, Canadian Controlled Goods Program requirements,



and future cybersecurity frameworks such as NIST SP 800-171 or equivalent.
• Security Architecture and Risk Review: Review proposed cloud, software, and data architectures to identify security, compliance, privacy, and operational risks; recommend proportionate controls and document required remediation or risk acceptance.
• Security & Compliance Automation: Automate security and compliance checks within CI/CD pipelines.
• Microsoft Security Engineering: Assess and improve security configurations across Azure, Microsoft 365, Microsoft Entra, Microsoft Defender, Microsoft Purview, and Microsoft Intune using Microsoft recommendations, secure configuration baselines, and recognized industry practices.
• Secure Development Lifecycle: Partner with software and platform engineers to integrate threat modelling, secure design reviews, dependency and code scanning, secrets protection, security testing, and compliance gates into the software development lifecycle and Git

Hub workflows.
• Security Operations and Incident Response: Improve security monitoring, investigate alerts and incidents, coordinate containment and recovery activities, support breach assessment and notification processes, and lead post-incident reviews and corrective actions.
• Privacy and Data Protection: Translate GDPR and other applicable privacy requirements into technical and organizational controls covering data inventories, retention, access, encryption, processing activities, data subject requests, and third-party processing.
• Third-Party Risk Management: Perform security and privacy due diligence for vendors and service providers, review assurance reports and contractual controls, document risks, and monitor remediation or compensating measures.
• Policies, Procedures, and Evidence: Develop and maintain security policies,



standards, procedures, control narratives, architecture and data-flow diagrams, audit evidence, and operational records in a clear, version-controlled format.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day.

We are an equal opportunity/affirmative action employer that believes everyone matters.

Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances.

If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to [email protected].

To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Skills and Requirements
o 5+ years of progressive experience in information security, cloud security, governance, risk, compliance, or related roles, including substantial hands-on experience securing and administering Microsoft Azure and Microsoft 365 environments.
o Microsoft Azure (Compute, Networking, Storage, Security), with hands-on experience equivalent to Azure Administrator Expert responsibilities
o Git

Hub and Git

Hub Actions
o Infrastructure as Code (Bicep, ARM)
o Git and version control best practices
o Security frameworks and compliance standards (ISO 27001, SOC 2, GDPR, NIST 800171 )
o Azure API Management and Web API design
o Microsoft Entra External ID (CIAM / external identity)
o Microsoft Purview
o Microsoft Defender
o Sentinel
o Azure Policies
o DLP o Markdown and Mermaid for architecture and infrastructure documentation
o Policy as Code

📌 Senior Security & Compliance Engineer (Kitchener)
🏢 Insight Global
📍 Kitchener

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior security & compliance engineer (kitchener) / kitchener